[google-auth] Feat: ECP and hardware-backed cert support for X.509 workloads
メンテナーはふだん 1 日以内に返信
評価
この issue はまだ評価されていません。
説明
Determine this is the right repository
- I determined this is the correct repository in which to report this feature request.
Summary of the feature request
I would like to use my hardware-backed (TPM, Secure Enclave, HSM, etc) certificates with a X.509 Workload Identity Provider.
Today google-auth X.509 provider assumes it will be given the private key of the certificate and hard fails if it doesn't:
packages/google-auth/google/auth/external_account.py line 480:
# Inject client certificate into request.
if self._mtls_required():
request = functools.partial(
request, cert=self._get_mtls_cert_and_key_paths()
)
this limits the implementation to only private keys stored directly on the filesystem.
Allowing hardware-backed certificates provides iron-clad security for service account authentication. The library will be able to authenticate as a WIF Identity / Service account using a private key that was generated on the TPM / Secure Enclave and cannot be exported.
Desired code experience
from google.auth import default
from google.auth.transport.requests import AuthorizedSession
# certificate_config.json has ECP libs + macos_keychain (hardware-backed key)
# but NO "workload" section (no private key file on disk)
creds, _ = default(scopes=["https://www.googleapis.com/auth/cloud-platform"])
session = AuthorizedSession(creds)
session.configure_mtls_channel() # ECP handles mTLS via hardware signing
response = session.get("https://cloudresourcemanager.googleapis.com/v1/projects/my-project")
Expected results
_get_cert_bytes() should fall back to the ECP signer library (GetCertPemForPython) to retrieve the certificate from the OS keystore when no workload file path exists. _perform_refresh_token() should skip injecting cert=(cert_path, key_path) when paths are (None, None), letting the session's ECP adapter (via configure_mtls_channel()) handle mTLS. Currently it crashes with TypeError (None path) or SSLError: [SSL] PEM libs (placeholder path).
API client name and version
google-auth 2.56.2
Use case
This feature would be useful in allowing non-GCP service account / WIF authenticating while never needing to expose a private key for export and theft.
Additional context
I'm glad to discuss further internally next week. go/teams/jayhlee.
- 主要言語
- Python
- スター
- 5.4k
- フォーク
- 1.8k
- 平均マージ
- 2日 11時間
- マージ済み PR(30日)
- 129
環境構築
- Dockerfile・Docker Compose ファイルなし
- プルリクエストのテンプレートあり
- コントリビューションガイドを読む
はじめの一歩
- issue を最後まで読み、次にプロジェクトのコントリビューションガイドを読みます。
- 着手することを issue にコメントします — 二人が同じ作業をするのを防げます。
- リポジトリをフォークし、ブランチを切って変更します。
- issue 番号を参照したプルリクエストを送ります。
googleapis/google-cloud-python のほかの issue
-
難易度 2/5 1〜3時間 初心者へのやさしさ 82/100
googleapis/google-cloud-python#18532 ·
メンテナーはふだん 1 日以内に返信
-
auth: call_client_cert_callback() discards passphrase for encrypted keys対応中かも @kwy404 が 5 日前に担当しました。 オープン
難易度 1/5 1〜3時間 初心者へのやさしさ 92/100
googleapis/google-cloud-python#18467 ·
メンテナーはふだん 1 日以内に返信
-
auth: `impersonated_credentials` loses `subject` on copy, so `with_scopes()` and `with_quota_project()` turn off domain wide delegation対応中かも @Om-singhaI が 16 日前に担当しました。 オープンauth priority: p2 type: bug
難易度 2/5 1〜3時間 初心者へのやさしさ 88/100
googleapis/google-cloud-python#18428 ·
メンテナーはふだん 1 日以内に返信
-
priority: p2 type: bug
難易度 2/5 1〜3時間 初心者へのやさしさ 72/100
googleapis/google-cloud-python#18375 · コメント 1 件 ·
メンテナーはふだん 1 日以内に返信
-
ci: enable --strict flag in presubmit twine_check対応中かも @ohmayr が 5 日前に担当しました。 オープン
難易度 1/5 1時間未満 初心者へのやさしさ 76/100
googleapis/google-cloud-python#18339 · コメント 1 件 · 担当者 1 名 ·
メンテナーはふだん 1 日以内に返信
googleapis/google-cloud-python の issue をすべて見る
似ている issue
-
難易度 1/5 1時間未満 初心者へのやさしさ 85/100
-
難易度 1/5 1時間未満 初心者へのやさしさ 75/100
-
難易度 1/5 1時間未満 初心者へのやさしさ 85/100
-
難易度 1/5 1時間未満 初心者へのやさしさ 85/100
data-umbrella/du-event-board#225 ·
-
難易度 2/5 1〜3時間 初心者へのやさしさ 75/100