Victor Lyuboslavsky
01/09/2024, 8:30 PM--tls_client_cert
and --tls_client_key
.
However, I do not want this sensitive information sitting as files on my device. Can we add a feature to pass these directly on command line as base64 encoded strings? Something like: --tls_client_cert_base64
and --tls_client_key_base64
?
Or any other ideas how to keep the TLS certificate secure?Stefano Bonicatti
01/09/2024, 8:32 PMVictor Lyuboslavsky
01/09/2024, 8:42 PMStefano Bonicatti
01/09/2024, 8:47 PMStefano Bonicatti
01/09/2024, 8:49 PMVictor Lyuboslavsky
01/09/2024, 9:11 PM/Library/Keychains/System.keychain
is accessible using non-deprecated API methods.
What would be the osquery options for getting the certificates from the keychain? I imagine something like:
--tls_client_keychain=System // maybe not needed, can be hardcoded
--tls_client_cert_keychain_name
--tls_client_key_keychain_name
Stefano Bonicatti
01/09/2024, 9:16 PMStefano Bonicatti
01/09/2024, 9:16 PMVictor Lyuboslavsky
01/09/2024, 9:18 PMStefano Bonicatti
01/09/2024, 9:19 PMStefano Bonicatti
01/09/2024, 9:19 PMVictor Lyuboslavsky
01/09/2024, 9:20 PMStefano Bonicatti
01/09/2024, 9:22 PMStefano Bonicatti
01/09/2024, 9:25 PMStefano Bonicatti
01/09/2024, 9:28 PMVictor Lyuboslavsky
01/09/2024, 9:28 PMStefano Bonicatti
01/09/2024, 9:29 PMVictor Lyuboslavsky
01/09/2024, 9:41 PMVictor Lyuboslavsky
01/09/2024, 9:42 PMStefano Bonicatti
01/10/2024, 12:42 PMVictor Lyuboslavsky
01/16/2024, 1:27 PMStefano Bonicatti
01/16/2024, 1:42 PM