{"id":30622277,"url":"https://github.com/salrashid123/oauth2","last_synced_at":"2025-08-30T15:36:20.069Z","repository":{"id":57498643,"uuid":"154236012","full_name":"salrashid123/oauth2","owner":"salrashid123","description":"TPM based Google Cloud Credential Access Token","archived":false,"fork":false,"pushed_at":"2025-08-21T10:23:02.000Z","size":1130,"stargazers_count":15,"open_issues_count":0,"forks_count":0,"subscribers_count":3,"default_branch":"master","last_synced_at":"2025-08-21T12:28:05.964Z","etag":null,"topics":["golang","google-cloud","google-cloud-platform","hsm","trusted-platform-module"],"latest_commit_sha":null,"homepage":"https://pkg.go.dev/github.com/salrashid123/oauth2/v3","language":"Go","has_issues":false,"has_wiki":null,"has_pages":null,"mirror_url":null,"source_name":"golang/oauth2","license":"apache-2.0","status":null,"scm":"git","pull_requests_enabled":true,"icon_url":"https://github.com/salrashid123.png","metadata":{"files":{"readme":"README.md","changelog":null,"contributing":null,"funding":null,"license":"LICENSE","code_of_conduct":null,"threat_model":null,"audit":null,"citation":null,"codeowners":null,"security":null,"support":null,"governance":null,"roadmap":null,"authors":null,"dei":null,"publiccode":null,"codemeta":null,"zenodo":null}},"created_at":"2018-10-23T00:33:40.000Z","updated_at":"2025-08-21T10:23:06.000Z","dependencies_parsed_at":null,"dependency_job_id":"751b6cf7-90d6-42a6-844b-581275afe94c","html_url":"https://github.com/salrashid123/oauth2","commit_stats":null,"previous_names":[],"tags_count":29,"template":false,"template_full_name":null,"purl":"pkg:github/salrashid123/oauth2","repository_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/salrashid123%2Foauth2","tags_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/salrashid123%2Foauth2/tags","releases_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/salrashid123%2Foauth2/releases","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/salrashid123%2Foauth2/manifests","owner_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners/salrashid123","download_url":"https://codeload.github.com/salrashid123/oauth2/tar.gz/refs/heads/master","sbom_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/salrashid123%2Foauth2/sbom","scorecard":{"id":647315,"data":{"date":"2025-08-11","repo":{"name":"github.com/salrashid123/oauth2","commit":"f829e54f6677be739b1197931b37a1e01600b752"},"scorecard":{"version":"v5.2.1-40-gf6ed084d","commit":"f6ed084d17c9236477efd66e5b258b9d4cc7b389"},"score":4.7,"checks":[{"name":"Code-Review","score":0,"reason":"Found 0/30 approved changesets -- score normalized to 0","details":null,"documentation":{"short":"Determines if the project requires human code review before pull requests (aka merge requests) are merged.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#code-review"}},{"name":"Dangerous-Workflow","score":10,"reason":"no dangerous workflow patterns detected","details":null,"documentation":{"short":"Determines if the project's GitHub Action workflows avoid dangerous patterns.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#dangerous-workflow"}},{"name":"Maintained","score":10,"reason":"24 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 10","details":null,"documentation":{"short":"Determines if the project is \"actively maintained\".","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#maintained"}},{"name":"Binary-Artifacts","score":10,"reason":"no binaries found in the repo","details":null,"documentation":{"short":"Determines if the project has generated executable (binary) artifacts in the source repository.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#binary-artifacts"}},{"name":"Token-Permissions","score":0,"reason":"detected GitHub workflow tokens with excessive permissions","details":["Warn: topLevel 'packages' permission set to 'write': .github/workflows/release.yaml:11","Warn: topLevel 'contents' permission set to 'write': .github/workflows/release.yaml:9","Warn: no topLevel permission defined: .github/workflows/test.yaml:1","Info: no jobLevel write permissions found"],"documentation":{"short":"Determines if the project's workflows follow the principle of least privilege.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#token-permissions"}},{"name":"Pinned-Dependencies","score":0,"reason":"dependency not pinned by hash detected -- score normalized to 0","details":["Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/release.yaml:19: update your workflow using https://app.stepsecurity.io/secureworkflow/salrashid123/oauth2/release.yaml/master?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/release.yaml:21: update your workflow using https://app.stepsecurity.io/secureworkflow/salrashid123/oauth2/release.yaml/master?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/release.yaml:37: update your workflow using https://app.stepsecurity.io/secureworkflow/salrashid123/oauth2/release.yaml/master?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/release.yaml:41: update your workflow using https://app.stepsecurity.io/secureworkflow/salrashid123/oauth2/release.yaml/master?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/release.yaml:53: update your workflow using https://app.stepsecurity.io/secureworkflow/salrashid123/oauth2/release.yaml/master?enable=pin","Warn: third-party GitHubAction not pinned by hash: .github/workflows/release.yaml:56: update your workflow using https://app.stepsecurity.io/secureworkflow/salrashid123/oauth2/release.yaml/master?enable=pin","Warn: third-party GitHubAction not pinned by hash: .github/workflows/release.yaml:62: update your workflow using https://app.stepsecurity.io/secureworkflow/salrashid123/oauth2/release.yaml/master?enable=pin","Warn: third-party GitHubAction not pinned by hash: .github/workflows/release.yaml:63: update your workflow using https://app.stepsecurity.io/secureworkflow/salrashid123/oauth2/release.yaml/master?enable=pin","Warn: third-party GitHubAction not pinned by hash: .github/workflows/release.yaml:65: update your workflow using https://app.stepsecurity.io/secureworkflow/salrashid123/oauth2/release.yaml/master?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/test.yaml:16: update your workflow using https://app.stepsecurity.io/secureworkflow/salrashid123/oauth2/test.yaml/master?enable=pin","Warn: GitHub-owned GitHubAction not pinned by hash: .github/workflows/test.yaml:18: update your workflow using https://app.stepsecurity.io/secureworkflow/salrashid123/oauth2/test.yaml/master?enable=pin","Info:   0 out of   7 GitHub-owned GitHubAction dependencies pinned","Info:   0 out of   4 third-party GitHubAction dependencies pinned"],"documentation":{"short":"Determines if the project has declared and pinned the dependencies of its build process.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#pinned-dependencies"}},{"name":"SAST","score":0,"reason":"no SAST tool detected","details":["Warn: no pull requests merged into dev branch"],"documentation":{"short":"Determines if the project uses static code analysis.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#sast"}},{"name":"CII-Best-Practices","score":0,"reason":"no effort to earn an OpenSSF best practices badge detected","details":null,"documentation":{"short":"Determines if the project has an OpenSSF (formerly CII) Best Practices Badge.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#cii-best-practices"}},{"name":"Security-Policy","score":0,"reason":"security policy file not detected","details":["Warn: no security policy file detected","Warn: no security file to analyze","Warn: no security file to analyze","Warn: no security file to analyze"],"documentation":{"short":"Determines if the project has published a security policy.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#security-policy"}},{"name":"Fuzzing","score":0,"reason":"project is not fuzzed","details":["Warn: no fuzzer integrations found"],"documentation":{"short":"Determines if the project uses fuzzing.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#fuzzing"}},{"name":"Signed-Releases","score":-1,"reason":"no releases found","details":null,"documentation":{"short":"Determines if the project cryptographically signs release artifacts.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#signed-releases"}},{"name":"License","score":10,"reason":"license file detected","details":["Info: project has a license file: LICENSE:0","Info: FSF or OSI recognized license: Apache License 2.0: LICENSE:0"],"documentation":{"short":"Determines if the project has defined a license.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#license"}},{"name":"Branch-Protection","score":0,"reason":"branch protection not enabled on development/release branches","details":["Warn: branch protection not enabled for branch 'master'"],"documentation":{"short":"Determines if the default and release branches are protected with GitHub's branch protection settings.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#branch-protection"}},{"name":"Packaging","score":10,"reason":"packaging workflow detected","details":["Info: Project packages its releases by way of GitHub Actions.: .github/workflows/release.yaml:32"],"documentation":{"short":"Determines if the project is published as a package that others can easily download, install, easily update, and uninstall.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#packaging"}},{"name":"Vulnerabilities","score":10,"reason":"0 existing vulnerabilities detected","details":null,"documentation":{"short":"Determines if the project has open, known unfixed vulnerabilities.","url":"https://github.com/ossf/scorecard/blob/f6ed084d17c9236477efd66e5b258b9d4cc7b389/docs/checks.md#vulnerabilities"}}]},"last_synced_at":"2025-08-21T12:28:09.077Z","repository_id":57498643,"created_at":"2025-08-21T12:28:09.077Z","updated_at":"2025-08-21T12:28:09.077Z"},"host":{"name":"GitHub","url":"https://github.com","kind":"github","repositories_count":272871255,"owners_count":25007133,"icon_url":"https://github.com/github.png","version":null,"created_at":"2022-05-30T11:31:42.601Z","updated_at":"2022-07-04T15:15:14.044Z","status":"online","status_checked_at":"2025-08-30T02:00:09.474Z","response_time":77,"last_error":null,"robots_txt_status":"success","robots_txt_updated_at":"2025-07-24T06:49:26.215Z","robots_txt_url":"https://github.com/robots.txt","online":true,"can_crawl_api":true,"host_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub","repositories_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories","repository_names_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repository_names","owners_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners"}},"keywords":["golang","google-cloud","google-cloud-platform","hsm","trusted-platform-module"],"created_at":"2025-08-30T15:36:15.243Z","updated_at":"2025-08-30T15:36:20.062Z","avatar_url":"https://github.com/salrashid123.png","language":"Go","funding_links":[],"categories":[],"sub_categories":[],"readme":"\n# TPM based Google Cloud Credential Access Token \n\nImplementations of [TokenSource](https://godoc.org/golang.org/x/oauth2#TokenSource) for use with Google Cloud where the private key is encoded into a TPM. \n\n* **TPM**:  `access_token` or an `id_token` for a serviceAccount where the private key is saved inside a Trusted Platform Module (TPM)\n  *  `TPM based key --\u003e GCP AccessToken`\n\n\u003e NOTE: This is NOT supported by Google\n\n\n*BREAKING CHANGE*\n\n* removed AWS oauth provider (nobody's using it AFAIK)\n* refactor it to top-level package `github.com/salrashid123/oauth2/v3` for simplicity\n\n\n```golang\npackage main\n\nimport (\n\t\"cloud.google.com/go/storage\"\n\n\t\"github.com/google/go-tpm/tpm2\"\n\t\"github.com/google/go-tpm/tpmutil\"\n\tsal \"github.com/salrashid123/oauth2/v3\"\n)\n\nfunc main() {\n\n\trwc, err := tpmutil.OpenTPM(\"/dev/tpmrm0\")\n\n\tts, err := sal.TpmTokenSource(\u0026sal.TpmTokenConfig{\n\t\tTPMDevice: rwc,\n\t\tHandle:    tpm2.TPMHandle(*persistentHandle), // persistent handle\n\t\tEmail:     *serviceAccountEmail,\n\t})\n\n\ttok, err := ts.Token()\n\n\tlog.Printf(\"Token: %v\", tok.AccessToken)\n\n\tctx := context.Background()\n\n\tstorageClient, err := storage.NewClient(ctx, option.WithTokenSource(ts))\n\n\tsit := storageClient.Buckets(ctx, *projectId)\n\tfor {\n\t\tbattrs, err := sit.Next()\n\t\tif err == iterator.Done {\n\t\t\tbreak\n\t\t}\n\t\tlog.Printf(battrs.Name)\n\t}\n}\n```\n\n---\n\n## Additional References\n\n**TPM**\n\n  * [TPM Credential Source for Google Cloud SDK](https://github.com/salrashid123/gcp-adc-tpm)\n  * [PKCS-11 Credential Source for Google Cloud SDK](https://github.com/salrashid123/gcp-adc-pkcs)\n  * [golang-jwt for Trusted Platform Module (TPM)](https://github.com/salrashid123/golang-jwt-tpm)\n  * [TPM2-TSS-Engine hello world and Google Cloud Authentication](https://github.com/salrashid123/tpm2_evp_sign_decrypt)\n  * [Trusted Platform Module (TPM) recipes with tpm2_tools and go-tpm](https://github.com/salrashid123/tpm2)\n\n---\n\n## Usage TpmTokenSource\n\n\nThis library provides the option of returning two different types of access tokens:\n\n*  `JWTAccessToken with scopes` (default)\nor\n* `Oauth2 AccessTokens`\n\n\nBoth will work with GCP apis and its preferable to use the jwt access token since it does not involve a round trip to GCP services.  For more information, see \n\n* [AIP 4111: Self-signed JWT](https://google.aip.dev/auth/4111)\n\n\nYou can enable the oauth2 flow by setting the `UseOauthToken` config value to true\n\n\n### Usage\n\n\n1. Create a VM with a `TPM`.  \n\n\tFor example, create an Google Cloud [Shielded VM](https://cloud.google.com/security/shielded-cloud/shielded-vm).\n\nFrom there you have several options on how to associate a key on a TPM with a service account.  You can either do\n\n* **[A]** download a Google ServiceAccount's `json` file  and embed the private part to the TPM \n\nor\n\n* **[B]** Generate a Key _ON THE TPM_ and then import the public part to GCP.\n\nor\n\n* **[C]**) remote seal the service accounts RSA Private key remotely, encrypt it with the remote TPM's Endorsement Key and load it\n\n---\n\n#### [A] Import Service Account json to TPM:\n\n1) Download Service account json file\n\n2) Extract public/private keypair\n\n```bash\ncat svc-account.json | jq -r '.private_key' \u003e /tmp/f.json\nopenssl rsa -out /tmp/key_rsa.pem -traditional -in /tmp/f.json\nopenssl rsa -in /tmp/key_rsa.pem -outform PEM -pubout -out public.pem\n```\n\n3) Embed the key into a TPM\n\n   There are several ways to do this:  either install and use `tpm2_tools` or use `go-tpm`.  \n\n   The following will load the RSA key and make it persistent at a specific handle and create a PEM encoded private key thats only usable by the TPM.\n  \n   If you choose to use `tpm2_tools`,  first [install TPM2-Tools](https://github.com/tpm2-software/tpm2-tools/blob/master/INSTALL.md)\n\n   Then setup a primary object on the TPM and import `private.pem` we created earlier\n\n```bash\n## if you want to use a software TPM, \n# rm -rf /tmp/myvtpm \u0026\u0026 mkdir /tmp/myvtpm\n# sudo swtpm socket --tpmstate dir=/tmp/myvtpm --tpm2 --server type=tcp,port=2321 --ctrl type=tcp,port=2322 --flags not-need-init,startup-clear\n## then specify \"127.0.0.1:2321\"  as the TPM device path in the examples, export the following var\n# export TPM2TOOLS_TCTI=\"swtpm:port=2321\"\n\n## note  the primary can be the \"H2\" profile from https://www.hansenpartnership.com/draft-bottomley-tpm2-keys.html#name-parent\n## see https://gist.github.com/salrashid123/9822b151ebb66f4083c5f71fd4cdbe40\n### otherwise with defaults\n#tpm2_createprimary -C o -g sha256 -G rsa -c primary.ctx\n\nprintf '\\x00\\x00' \u003e unique.dat\ntpm2_createprimary -C o -G ecc  -g sha256  -c primary.ctx -a \"fixedtpm|fixedparent|sensitivedataorigin|userwithauth|noda|restricted|decrypt\" -u unique.dat\n# tpm2_createprimary -C o -G ecc  -g sha256  -c primary.ctx -a \"fixedtpm|fixedparent|sensitivedataorigin|userwithauth|noda|restricted|decrypt\" \ntpm2_import -C primary.ctx -G rsa2048:rsassa:null -g sha256 -i /tmp/key_rsa.pem -u key.pub -r key.prv\ntpm2_load -C primary.ctx -u key.pub -r key.prv -c key.ctx\n\n## to make persistent\n# tpm2_evictcontrol -C o -c key.ctx 0x81010002\n\n## to create a PEM file\ntpm2_encodeobject -C primary.ctx -u key.pub -r key.prv -o svc_account_tpm.pem\n```\n\nThe encodeobject create a PEM file with the public/private TPM parts encoded into it.  The PEM file looks like this\n\n```bash\n$ cat svc_account_tpm.pem \n-----BEGIN TSS2 PRIVATE KEY-----\nMIHyBgZngQUKAQMCBQCAAAAABDIAMAAIAAsABABSAAAABQALACBnst0f8mx8m2Xk\n2HsQgLV1odcQFhMh85q0d9IzIwRMKASBrACqACB1+h8NZjM64tOkWsjeORqY0kFN\nVqIP6LgJfZ4jJTkgUwAQ0WyWLEfxAeFJLiNFwp9mjO/LLyQ2MaewE0W5Mdsoa/7p\nKVaIFlT7upOmB5/i2MxWPT4Du8EYHI+nlhb7ZHjhuItYpmbK1EhHIeaWHduXiZvc\nObcXb7YqFF53uD1qgaa0R8/6bROu1qZjuFLFOekOTQ4X/8Rs4ty7w1tsjZbIKZqL\nurvq+J0=\n-----END TSS2 PRIVATE KEY-----\n```\n\nAlso see [Importing an external key and load it ot the TPM](https://github.com/salrashid123/tpm2/tree/master/rsa_import)\n\n---\n\n#### [B] Generate key on TPM and export public X509 certificate to GCP\n\n1) Generate Key on TPM and make it persistent\n\nThe following uses `tpm2_tools` but is pretty straightfoward to do the same steps using `go-tpm`\n\n```bash\n## create an H2 primary\nprintf '\\x00\\x00' \u003e unique.dat\ntpm2_createprimary -C o -G ecc  -g sha256 \\\n   -c primary.ctx -a \"fixedtpm|fixedparent|sensitivedataorigin|userwithauth|noda|restricted|decrypt\" -u unique.dat\n\n## create an rsa key, then load and evit it\ntpm2_create -G rsa2048:rsassa:null -g sha256 -u key.pub -r key.priv -C primary.ctx\ntpm2_load -C primary.ctx -u key.pub -r key.priv -c key.ctx\n# tpm2_evictcontrol -C o -c key.ctx 0x81010002\n\n### extract the publicKey PEM\ntpm2_readpublic -c key.ctx -f PEM -o svc_account_tpm_pub.pem\ntpm2_flushcontext -t \u0026\u0026 tpm2_flushcontext -s \u0026\u0026 tpm2_flushcontext -l\n\n## convert the entire TPM public/private key to PEM\n## you may need to add a -p if your tpm2 tools is not recent (see https://github.com/tpm2-software/tpm2-tools/issues/3458)\ntpm2_encodeobject -C primary.ctx -u key.pub -r key.priv -o svc_account_tpm.pem\n```\n\nif you want to use `openssl` to issue a key:\n\n```bash\n## make sure openssl provider is installed\nopenssl list  -provider tpm2  -provider default  --providers\n\n## generate an RSA key\nopenssl genpkey -provider tpm2 -algorithm RSA -pkeyopt rsa_keygen_bits:2048  \\\n       -pkeyopt rsa_keygen_pubexp:65537 -out svc_account_tpm.pem\n\n## extract the public key\nopenssl rsa -provider tpm2  -provider default  -in svc_account_tpm.pem -pubout \u003e svc_account_tpm_pem.pub\n```\n\n2) use the TPM based private key to create an `x509` certificate\n\nGoogle Cloud uses the `x509` format of a key to import.    Note that GCP does not even verify the CA of the x509 you use to upload, you can even just self-sign the the x509.\n\nSo far all we've created ins a private RSA key on the TPM so we need to use it to generate a CSR and then have it signed some CA. \n\nFor this step, you can either\n\n-  Isseue `CSR` which any CA can sign\n\n```bash\nopenssl req  -provider tpm2  -provider default  -new -key svc_account_tpm.pem -out svc_account_tpm.csr\n```\n\n- Issue Self-Signed certificate\n\n```bash\nopenssl req  -provider tpm2  -provider default   -new -x509 -key svc_account_tpm.pem -out ssvc_account_tpm.crt -days 365\n```\n\n- `force` the public key \n\nIts extremely rare to do this but if you have a CA and the public key for the TPM based service account, you can issue an x509 without a CSR by using [-force_pubkey](https://docs.openssl.org/3.2/man1/openssl-x509/#certificate-output-options)\n\n```bash\nopenssl x509 -new -CAkey root-ca.key  -CA root-ca.crt \\\n  -force_pubkey svc_account_tpm_pub.pem \\\n    -subj \"/CN=my svc account Certificate\" -out svc_account_tpm.crt\n```\n\n\u003e\u003e note you can do all these step using go-tpm\n\n3) Import `x509` cert to GCP for a given service account (note ` YOUR_SERVICE_ACCOUNT@$PROJECT_ID.iam.gserviceaccount.com` must exist prior to this step)\n\nThe following steps are outlined [here](https://cloud.google.com/iam/docs/creating-managing-service-account-keys#uploading).\n\n```bash\ngcloud  iam service-accounts keys upload cert.pem  --iam-account YOUR_SERVICE_ACCOUNT@$PROJECT_ID.iam.gserviceaccount.com\n```\n\nVerify...you should see a new certificate.  Note down the `KEY_ID`\n\n```bash\n$ gcloud iam service-accounts keys list --iam-account=YOUR_SERVICE_ACCOUNT@$PROJECT_ID.iam.gserviceaccount.com\n\nKEY_ID                                    CREATED_AT            EXPIRES_AT\na03f0c4c61864b7fe20db909a3174c6b844f8909  2019-11-27T23:20:16Z  2020-12-31T23:20:16Z\n9bd21535c9985ad922c1cf6bb3dbceef0f7375d6  2019-11-28T00:49:55Z  2020-11-27T00:49:55Z \u003c\u003c\u003c\u003c\u003c\u003c\u003c note, this is the pubic cert for the TPM  based key!!\n7077c0c9164252fcfb73d8ccbd68f8c97e0ffee6  2019-11-27T23:15:32Z  2021-12-01T05:43:27Z\n```\n\n\n#### [C]  Remotely transferring an encrypted RSA key into the TPM \n\nIf you already have a list of `EKCerts` you know for sure trust and want to distribute keys to, then its pretty easy:  just use [tpm2_duplicate](https://github.com/salrashid123/tpm2/tree/master/tpm2_duplicate)) with either `tpm2_tools` or `go-tpm`\n\nfor detailed walkthrough of that, see \n\n* [tpmcopy: Transfer RSA|ECC|AES|HMAC key to a remote Trusted Platform Module (TPM)](https://github.com/salrashid123/tpmcopy)\n\n* [https://github.com/tpm2-software/tpm2-tools/wiki/Duplicating-Objects](https://github.com/tpm2-software/tpm2-tools/blob/master/man/tpm2_duplicate.1.md#examples)\n\n\n---\n\n#### Post Step [A] [B] or [C]\n\n4. Use `TpmTokenSource`\n\n\tAfter the key is embedded, you can *DELETE* any reference to `private.pem` (the now exists protected by the TPM and any access policy you may want to setup).\n\n\tThe TPM based `TokenSource` can now be used to access a GCP resource using either a plain HTTPClient or _native_ GCP library (`google-cloud-pubsub`)!!\n\n```bash\ncd example/tpm/\n\ngo run no_policy/main.go --projectId=core-eso \\\n\t   --persistentHandle=0x81010002 \\\n\t    --serviceAccountEmail=\"tpm-sa@core-eso.iam.gserviceaccount.com\" \\\n\t\t--bucketName=core-eso-bucket --keyId=71b831d149e4667809644840cda2e7e0080035d5\n```\n\neg\n\n```golang\n\n\t// open the tpm\n\trwc, err := OpenTPM(*tpmPath)\n\n\t// use it to get a tokensource \n\tts, err := sal.TpmTokenSource(\u0026sal.TpmTokenConfig{\n\t\tTPMDevice: rwc,\n\t\tHandle: tpm2.TPMHandle(*persistentHandle), // persistent handle\n\t\tEmail:         *serviceAccountEmail,\n\t})\n\n\t// use it with a gcp api client\n\tstorageClient, err := storage.NewClient(ctx, option.WithTokenSource(ts))\n```\n\nIf you want to enable [TPM Session Encryption](https://github.com/salrashid123/tpm2/tree/master/tpm_encrypted_session), see [here](https://github.com/salrashid123/gcp-adc-tpm/tree/main?tab=readme-ov-file#encrypted-tpm-sessions).  You will need to modify `example/tpm/main.go` to acquire the Endorsement keys and the supply them after validation as following parameters to `TpmTokenConfig`\n\n```golang\n\tEncryptionHandle tpm2.TPMHandle   // (optional) handle to use for transit encryption\n\tEncryptionPub    *tpm2.TPMTPublic // (optional) public key to use for transit encryption\n```\n\n---\n","project_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2Fsalrashid123%2Foauth2","html_url":"https://awesome.ecosyste.ms/projects/github.com%2Fsalrashid123%2Foauth2","lists_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2Fsalrashid123%2Foauth2/lists"}