{"id":13566283,"url":"https://github.com/iqlusioninc/tmkms","last_synced_at":"2025-05-13T16:18:39.556Z","repository":{"id":37802818,"uuid":"244005431","full_name":"iqlusioninc/tmkms","owner":"iqlusioninc","description":"Tendermint KMS: Key Management System for Tendermint Validators","archived":false,"fork":false,"pushed_at":"2024-10-29T18:59:33.000Z","size":2738,"stargazers_count":335,"open_issues_count":27,"forks_count":121,"subscribers_count":17,"default_branch":"main","last_synced_at":"2024-10-29T20:19:01.585Z","etag":null,"topics":[],"latest_commit_sha":null,"homepage":"https://tendermint.com/","language":"Rust","has_issues":true,"has_wiki":null,"has_pages":null,"mirror_url":null,"source_name":null,"license":"apache-2.0","status":null,"scm":"git","pull_requests_enabled":true,"icon_url":"https://github.com/iqlusioninc.png","metadata":{"files":{"readme":"README.fortanixdsm.md","changelog":"CHANGELOG.md","contributing":"CONTRIBUTING.md","funding":null,"license":"LICENSE","code_of_conduct":"CODE_OF_CONDUCT.md","threat_model":null,"audit":null,"citation":null,"codeowners":null,"security":null,"support":null,"governance":null,"roadmap":null,"authors":null,"dei":null,"publiccode":null,"codemeta":null}},"created_at":"2020-02-29T16:49:30.000Z","updated_at":"2024-10-29T18:59:23.000Z","dependencies_parsed_at":"2023-11-21T01:37:25.730Z","dependency_job_id":"c68c17c1-0126-413f-b5c8-0264bc3a085b","html_url":"https://github.com/iqlusioninc/tmkms","commit_stats":{"total_commits":770,"total_committers":32,"mean_commits":24.0625,"dds":0.5324675324675325,"last_synced_commit":"8969f5c0bb60ef0ea7633f489df1851b69a8a16c"},"previous_names":[],"tags_count":71,"template":false,"template_full_name":null,"repository_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/iqlusioninc%2Ftmkms","tags_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/iqlusioninc%2Ftmkms/tags","releases_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/iqlusioninc%2Ftmkms/releases","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/iqlusioninc%2Ftmkms/manifests","owner_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners/iqlusioninc","download_url":"https://codeload.github.com/iqlusioninc/tmkms/tar.gz/refs/heads/main","host":{"name":"GitHub","url":"https://github.com","kind":"github","repositories_count":247097928,"owners_count":20883125,"icon_url":"https://github.com/github.png","version":null,"created_at":"2022-05-30T11:31:42.601Z","updated_at":"2022-07-04T15:15:14.044Z","host_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub","repositories_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories","repository_names_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repository_names","owners_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners"}},"keywords":[],"created_at":"2024-08-01T13:02:06.054Z","updated_at":"2025-04-03T23:31:28.024Z","avatar_url":"https://github.com/iqlusioninc.png","language":"Rust","funding_links":[],"categories":["Tools","Rust"],"sub_categories":["CLI"],"readme":"# Fortanix DSM + Tendermint KMS\n\nFortanix Data Security Manager (DSM) provides integrated data security with encryption, multicloud key management, tokenization, and other capabilities from one platform. \n\nThis document describes how to configure Fortanix DSM for production use with Tendermint KMS.\n\n## Compiling `tmkms` with Fortanix DSM support\n\nRefer the main README.md for compiling `tmkms`\nfrom source code. You will need the prerequisities mentioned as indicated above.\n\nThere are two ways to install `tmkms` with Fortanix DSM, you need to pass the `--features=fortanixdsm` parameter to cargo.\n\n### Compiling from source code (via git)\n\n`tmkms` can be compiled directly from the git repository source code using the\nfollowing method.\n\n```\n$ git clone https://github.com/iqlusioninc/tmkms.git \u0026\u0026 cd tmkms\n[...]\n$ cargo build --release --features=fortanixdsm\n```\n\nIf successful, this will produce a `tmkms` executable located at\n`./target/release/tmkms`\n\n### Installing with the `cargo install` command\n\nWith Rust (1.40+) installed, you can install tmkms with the following:\n\n```\ncargo install tmkms --features=fortanixdsm\n```\n\nOr to install a specific version (recommended):\n\n```\ncargo install tmkms --features=fortanixdsm --version=0.4.0\n```\n\nThis command installs `tmkms` directly from packages hosted on Rust's\n[crates.io] service. Package authenticity is verified via the\n[crates.io index] (itself a git repository) and by SHA-256 digests of\nreleased artifacts.\n\nHowever, if newer dependencies are available, it may use newer versions\nbesides the ones which are \"locked\" in the source code repository. We\ncannot verify those dependencies do not contain malicious code. If you would\nlike to ensure the dependencies in use are identical to the main repository,\nplease build from source code instead.\n\n## Production Fortanix DSM setup\n\n`tmkms` contains support for Fortanix DSM backend, which enables tmkms to access the secure keys on DSM. This requires creation of the keys on the DSM which can be done by referring to this [guide](https://support.fortanix.com/hc/en-us/articles/360038354592-User-s-Guide-Fortanix-Data-Security-Manager-Key-Lifecycle-Management). Creating, enabling and marking the key for signing and export should enable tmkms to use the keys on DSM.\n\n### Configuring `tmkms` for initial setup\n\nIn order to perform setup, `tmkms` needs a  configuration file which\ncontains the authentication details needed to authenticate to the DSM with an API key.\n\nThis configuration should be placed in a file called: `tmkms.toml`.\nYou can specifty the path to the config with either `-c /path/to/tmkms.toml` or else tmkms will look in the current working directory for the same file.\n\nexample: \n\n```toml\n[[providers.fortanixdsm]]\napi_endpoint = \"https://sdkms.fortanix.com\"\napi_key = \"Nzk5MDQ3ZGUtN2Q2NS00OTRjLTgzMDMtNjQwMTlhYzdmOGUzOlF1SU93ZXJsOFU4VUdEWEdQMmx1dFJOVjlvMTRSd3lhNnVDNVNhVkpZOVhzYVgyc0pOVGRQVGJ0RjZJdmVLMy00X05iTEhxMkowamF3UGVPaXJEWEd3\"\nsigning_keys = [\n    { chain_ids = [\"$CHAIN_ID\"], type = \"account\", key_id = \"72e9ed9e-9eb4-46bd-a135-e78ed9bfd611\" },\n    { chain_ids = [\"$CHAIN_ID\"], type = \"consensus\", key_name = \"My Key\" },\n]\n```\nYou can get the api key from the app that holds the security object(key) in DSM. Key can be identified by either using the key-id or the key name, which are available in the details of the security object created on DSM. If you already have the key, you can import the key on DSM following the same DSM user guide mentioned above.\n\n### Generating keys on DSM\n1. Create a security group on DSM, example 'TMKMS group'.\n2. Create a APP under the same security group on DSM, example 'TMKMS'. Select Authentication method to be 'API Key' and copy the API key for use in config fie (tmkms.toml).\n\n3. Create a security Object under the same group in DSM, so that the API key for the app can be used to access the key under the same group. The type of key must be `EC CurveEd25519` for consensus key and `Secp256k1` for account key. Proceed with creation of these keys on DSM and the required key ID has to be passed in the config file, this can be obtained from the details on the security object section on DSM.\n4. To import an existing tendermint key use the following script to convert a tendermint key to Fortanix DSM accepted key format.\n```\n#!/bin/bash\n# Usage: tendermint-ed25519.sh \u003cinput-tendermint\u003e \u003coutput-private-p8der\u003e \u003coutput-public-p8der\u003e\n\ngokey=$(jq -r .priv_key.value $1 | base64 -d| xxd -p -c 64)\necho 302e 0201 0030 0506 032b 6570 0422 0420 \"${gokey:0:64}\" | xxd -p -r \u003e $2\necho 302a 3005 0603 2b65 7003 2100 \"${gokey:64}\" | xxd -p -r \u003e $3\n```\n","project_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2Fiqlusioninc%2Ftmkms","html_url":"https://awesome.ecosyste.ms/projects/github.com%2Fiqlusioninc%2Ftmkms","lists_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2Fiqlusioninc%2Ftmkms/lists"}