Hacktoberfest 2026: những issue maintainer đã đánh dấu cho tháng Mười, đang mở và phù hợp người mới. Xem issue Hacktoberfest

[google-auth] Feat: ECP and hardware-backed cert support for X.509 workloads

Đang mở
#17,967 1 bình luận 0 reaction 1 người được giao Xem trên GitHub

Maintainer thường phản hồi trong vòng 1 ngày

@attharva-24 đang làm issue này rồi.

Từ ngày 24/8/2026.

  • #18222 của @attharva-24 — đang mở

Đánh giá

Issue này chưa được đánh giá.

Mô tả

auth priority: p3 type: feature request
Determine this is the right repository
  • I determined this is the correct repository in which to report this feature request.
Summary of the feature request

I would like to use my hardware-backed (TPM, Secure Enclave, HSM, etc) certificates with a X.509 Workload Identity Provider.

Today google-auth X.509 provider assumes it will be given the private key of the certificate and hard fails if it doesn't:

packages/google-auth/google/auth/external_account.py line 480:

        # Inject client certificate into request.
        if self._mtls_required():
            request = functools.partial(
                request, cert=self._get_mtls_cert_and_key_paths()
            )

this limits the implementation to only private keys stored directly on the filesystem.

Allowing hardware-backed certificates provides iron-clad security for service account authentication. The library will be able to authenticate as a WIF Identity / Service account using a private key that was generated on the TPM / Secure Enclave and cannot be exported.

Desired code experience
from google.auth import default
from google.auth.transport.requests import AuthorizedSession

# certificate_config.json has ECP libs + macos_keychain (hardware-backed key)
# but NO "workload" section (no private key file on disk)

creds, _ = default(scopes=["https://www.googleapis.com/auth/cloud-platform"])
session = AuthorizedSession(creds)
session.configure_mtls_channel()  # ECP handles mTLS via hardware signing
response = session.get("https://cloudresourcemanager.googleapis.com/v1/projects/my-project")
Expected results

_get_cert_bytes() should fall back to the ECP signer library (GetCertPemForPython) to retrieve the certificate from the OS keystore when no workload file path exists. _perform_refresh_token() should skip injecting cert=(cert_path, key_path) when paths are (None, None), letting the session's ECP adapter (via configure_mtls_channel()) handle mTLS. Currently it crashes with TypeError (None path) or SSLError: [SSL] PEM libs (placeholder path).

API client name and version

google-auth 2.56.2

Use case

This feature would be useful in allowing non-GCP service account / WIF authenticating while never needing to expose a private key for export and theft.

Additional context

I'm glad to discuss further internally next week. go/teams/jayhlee.

Ngôn ngữ chính
Python
Star
5.4k
Fork
1.8k
Merge trung bình
2 ngày 16 giờ
Pull request đã merge (30 ngày)
136

Chuẩn bị môi trường

Bắt đầu từ đâu

  1. Đọc hết issue, rồi đọc hướng dẫn đóng góp của dự án.
  2. Bình luận trên issue rằng bạn sẽ nhận — tránh hai người làm cùng một việc.
  3. Fork repository và làm thay đổi trên một nhánh.
  4. Mở pull request có tham chiếu số hiệu của issue.

Issue khác của googleapis/google-cloud-python

Tất cả issue của googleapis/google-cloud-python

Issue tương tự

Thêm issue về Python

Nhận issue mới trong hộp thư của bạn

Bản tóm tắt ngắn những issue GitHub phù hợp với người mới.