2 ms·
Why not drop the beater token entirely and rely on mTLS for auth? There’s even space in the cert to put metadata that can be used for authorization. ..ah I su
by rexer 4y ago
Why not drop the beater token entirely and rely on mTLS for auth? There’s even space in the cert to put metadata that can be used for authorization.
..ah I suppose if you did that you’d need a certificate per site, and that many keys may not fit in most TPMs.
I suspect one of the big challenges here is interfacing with the OS for hardware backed key signing. Bearer tokens are easy because it’s all contained in the browser.
Another challenge is that it complicates federated auth. Now instead of just validating any token with one of a small number of keys, you must verify the client cert matches that specific user. Signing the client cert may mitigate this, though I’m not sure what issues that may cause.
Anyway, interesting idea! This problem is certainly worth some thought.
- mjg59 4y agoThere isn't really a resource limit for TPMs in this respect (the certs are kept on disk along with encrypted key blobs that are just loaded in and out of the TPM at runtime as needed), but there's no standardised mechanism for a site to provision a hardware-backed cert, so there's no way (eg) Github could give you a unique Github cert and then tie access to that.