{"id":20238534,"url":"https://github.com/smallstep/smallstep-desktop","last_synced_at":"2026-02-06T07:33:38.300Z","repository":{"id":236810660,"uuid":"792911503","full_name":"smallstep/smallstep-desktop","owner":"smallstep","description":null,"archived":false,"fork":false,"pushed_at":"2025-05-07T23:20:43.000Z","size":9,"stargazers_count":2,"open_issues_count":3,"forks_count":1,"subscribers_count":7,"default_branch":"main","last_synced_at":"2025-07-27T08:52:11.827Z","etag":null,"topics":[],"latest_commit_sha":null,"homepage":null,"language":null,"has_issues":true,"has_wiki":null,"has_pages":null,"mirror_url":null,"source_name":null,"license":null,"status":null,"scm":"git","pull_requests_enabled":true,"icon_url":"https://github.com/smallstep.png","metadata":{"files":{"readme":"README.md","changelog":null,"contributing":null,"funding":null,"license":null,"code_of_conduct":null,"threat_model":null,"audit":null,"citation":null,"codeowners":null,"security":null,"support":null,"governance":null,"roadmap":null,"authors":null,"dei":null,"publiccode":null,"codemeta":null}},"created_at":"2024-04-27T22:40:34.000Z","updated_at":"2024-09-11T18:00:45.000Z","dependencies_parsed_at":"2024-05-10T16:39:28.353Z","dependency_job_id":"b46d7179-9030-4302-95c6-c19cbf8c5117","html_url":"https://github.com/smallstep/smallstep-desktop","commit_stats":null,"previous_names":["smallstep/smallstep-desktop"],"tags_count":32,"template":false,"template_full_name":null,"purl":"pkg:github/smallstep/smallstep-desktop","repository_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/smallstep%2Fsmallstep-desktop","tags_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/smallstep%2Fsmallstep-desktop/tags","releases_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/smallstep%2Fsmallstep-desktop/releases","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/smallstep%2Fsmallstep-desktop/manifests","owner_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners/smallstep","download_url":"https://codeload.github.com/smallstep/smallstep-desktop/tar.gz/refs/heads/main","sbom_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/smallstep%2Fsmallstep-desktop/sbom","scorecard":null,"host":{"name":"GitHub","url":"https://github.com","kind":"github","repositories_count":286080680,"owners_count":29154324,"icon_url":"https://github.com/github.png","version":null,"created_at":"2022-05-30T11:31:42.601Z","updated_at":"2026-02-06T07:18:23.844Z","status":"ssl_error","status_checked_at":"2026-02-06T07:13:32.659Z","response_time":59,"last_error":"SSL_connect returned=1 errno=0 peeraddr=140.82.121.6:443 state=error: unexpected eof while reading","robots_txt_status":"success","robots_txt_updated_at":"2025-07-24T06:49:26.215Z","robots_txt_url":"https://github.com/robots.txt","online":false,"can_crawl_api":true,"host_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub","repositories_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories","repository_names_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repository_names","owners_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners"}},"keywords":[],"created_at":"2024-11-14T08:34:38.589Z","updated_at":"2026-02-06T07:33:38.281Z","avatar_url":"https://github.com/smallstep.png","language":null,"funding_links":[],"categories":[],"sub_categories":[],"readme":"# Smallstep for Desktops\n\nSmallstep helps ensure that access to financial data, code repositories, PII and other sensitive resources is only possible from trusted, company-managed devices.\n\n## System Requirements\n\n### Windows\n\n- Windows 10 or later\n- Trusted Platform Module (TPM 2.0)\n\n### Linux\n\n- Flatpak, or Debian 12+, Ubuntu 22.04+, Fedora 38+\n- `systemd`-based service manager\n- Trusted Platform Module (TPM 2.0)\n- p11-kit\n- tpm-tss2\n\n### macOS\n\n- macOS 13 (Ventura) or later\n- Secure Enclave\n\n## Runtime Requirements\n\nAll platforms require an internet connection for normal operation.\n\n### Windows\n\n- *Administrator privileges* - the Smallstep app requires privilege escalation to be able to communicate to the TPM\n\n### macOS\n\n- *Location permission* - to enable management of Wifi networks, the Smallstep app needs location permission\n- *Keychain access* - the Smallstep app uses the macOS keychain to store both keys and certificates it manages\n- *Network Extension entitlement* - the Smallstep app requests the *Network Extension* entitlement so that it can manage VPN connections\n\n### Linux\n\n- *TPM read/write permission* - the Smallstep app communicates to the TPM from user-space using `tpm-tss2`, and the running user must have read/write permissions to the TPM resource manager (typically `/dev/tpmrm0`)\n\nOn all platforms, the Smallstep app manages a directory on the filesystem in a well-known location for management of keys and certificates:\n\n- On macOS: `$HOME/Library/Application Support/Smallstep`\n- On Windows: `%LOCALAPPDATA%/Smallstep`\n- On Linux: `$XDG_RUNTIME_DIR/step-agent` and `$XDG_CONFIG_HOME/step-agent`\n\n## Download\n\nInstallers for macOS, Windows and Linux can be downloaded from [GitHub releases](https://github.com/smallstep/smallstep-desktop/releases). Releases are signed with, and can be verified, by cosign.\n\n| Platform  | Release  |\n|:--|:--|\n| macOS  | \u003ca href='https://packages.smallstep.com/stable/darwin/Smallstep.dmg'\u003eLatest Version\u003c/a\u003e  |\n| Linux (Flatpak) | \u003ca href='https://packages.smallstep.com/stable/flatpak/Smallstep.flatpakref'\u003eLatest Version\u003c/a\u003e  |\n| Linux (.deb) | \u003ca href='https://packages.smallstep.com/stable/deb/smallstep-desktop.deb'\u003eLatest Version\u003c/a\u003e  |\n| Linux (.rpm) | \u003ca href='https://packages.smallstep.com/stable/deb/smallstep-desktop.rpm'\u003eLatest Version\u003c/a\u003e  |\n| Windows (AMD64)  | \u003ca href='https://packages.smallstep.com/stable/windows/Smallstep_amd64.exe'\u003eLatest Version\u003c/a\u003e  |\n| Windows (ARM64)  | \u003ca href='https://packages.smallstep.com/stable/windows/Smallstep_arm64.exe'\u003eLatest Version\u003c/a\u003e  |\n\n## Telemetry\n\nThe Smallstep app collects and reports some data from the host device as part of its normal operation. These are:\n\n- Device Identifiers from TPM-enabled platforms\n- Device/Computer Name\n- Device/Computer Hostname\n- Chipset Architecture\n- Operating System Version\n- WAN IP Address\n\n## Usage\n\n### PKCS#11 Server on Linux\n\nOn Linux, the Smallstep app provides a PKCS#11 server that can be used for a variety of integration use cases, such as Network Manager connections or web browser certificates. The PKCS#11 server is exposed as a UNIX socket at `$XDG_RUNTIME_DIR/step-agent/step-agent-pkcs11.sock`. One usage example would be adding the PKCS#11 tokens to your browser using `modutil` and an NSS database.\n\nOn Chrome (which defaults to `~/.pki/nssdb`), for example:\n\n```bash\nmodutil -dbdir ~/.pki/nssdb -add step-agent -libfile \u003cpath-to-p11-kit-libs\u003e/p11-kit-client.so\nexport P11_KIT_SERVER_ADDRESS=unix:path=$XDG_RUNTIME_DIR/step-agent/step-agent-pkcs11.sock\n```\n\nAfter that, you should see certificates managed by Smallstep in Chrome. You'll want to add `P11_KIT_SERVER_ADDRESS` to your environment more permanents for regular usage. You can use tools like `pkcs11-tool` for troubleshooting:\n\n`pkcs11-tool --module \u003cpath-to-p11-kit-libs\u003e/p11-kit-client.so --list-slots`\n\nRead the [p11-kit](https://p11-glue.github.io/p11-glue/p11-kit/manual/) documentation for more details.\n\n","project_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2Fsmallstep%2Fsmallstep-desktop","html_url":"https://awesome.ecosyste.ms/projects/github.com%2Fsmallstep%2Fsmallstep-desktop","lists_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2Fsmallstep%2Fsmallstep-desktop/lists"}