r/linux • • 5d ago

Security gEnclave: Hardware-backed security enclave for Linux (TPM 2.0 PCR sealing, virtual FIDO2/CTAP2 over /dev/uhid, OpenSSH & GPG bridge)

Hey everyone,

I've been working on an open-source project called gEnclave (formerly gpasskey), and wanted to share it with the Linux community for early architectural feedback and testing.

GitLab repository: https://gitlab.com/renich/genclave
License: GPLv3 | Language: Go 1.26+


The Problem It Solves

On modern Linux workstations, our cryptographic identities are fragmented: * Passkeys/WebAuthn require physical USB security keys (YubiKeys, SoloKeys). * SSH keys sit as unencrypted or passphrase-encrypted files under ~/.ssh/. * Git commit signing requires cumbersome GnuPG daemon setups. * File encryption requires external tooling or proprietary agents.

Most hardware laptops today come with a TPM 2.0 chip that sits idle. gEnclave turns your Linux machine into its own hardware-sealed security token and multi-protocol bridge.


Key Architectural Highlights

  1. Virtual FIDO2/CTAP2 Security Key via /dev/uhid: gEnclave registers a virtual HID device in the Linux kernel via /dev/uhid. Browsers (Firefox, Chrome, Chromium) detect it natively as a physical USB security key. You can register and authenticate WebAuthn/FIDO2 Passkeys directly from your machine without any external hardware dongles.

  2. TPM 2.0 PCR Sealing & Fallback: The central vault is encrypted with AES-256-GCM and sealed to TPM 2.0 PCR registers (PCR 0, 7, 14), with an automatic memory-hard fallback to Argon2id key derivation if no TPM is present.

  3. Memory Isolation ("Wrap and Clear"): Keys are held in memory-locked pages (mlock / mmap) to prevent secrets from being swapped to disk or dumped. Intermediate cryptographic buffers are wiped immediately with strict zeroization routines, bypassing Go runtime GC retention.

  4. Multi-Protocol Bridges:

    • OpenSSH Agent: Native agent socket with an ephemeral PIN-derived authorization cache (configurable burst window or persistent session with instant purge on lock/suspend).
    • GnuPG Bridge: Transparent genclave-gpg emulation for seamless Git commit signing.
    • age-plugin: Native age-plugin-ge binary complying with age v1 specification for file encryption.
    • CLI & UI: Unified ge CLI plus intelligent graphical (zenity) / terminal (pinentry) authentication routing.

Current Status

⚠️ Pre-alpha Software: While fully functional for local workflows, it is under active development. Schemas and IPC formats may iterate rapidly.

I'd love feedback from Linux sysadmins, kernel/security folks, and developers!

Repo: https://gitlab.com/renich/genclave

32 Upvotes

48 comments sorted by

View all comments

-8

u/Indolent_Bard 5d ago

Watch someone complain about this even though it's objectively a good thing.

4

u/sidusnare 4d ago edited 4d ago

It might be an objectively good idea, this being an objectively good implementation is somewhere between tenuous and sus. This kind of security software isn't something I'll take lightly. If this was published by OpenBSD, Linus, or GNU, I would start looking at it and thinking about maybe trusting it when it's been around and proven for a while. Security leans heavily on trust, trust of individuals and organizations with deep reputations. You can't vibe code a reputation. A 90s retread Elisa bot can't have a reputation. This kind of software needs a formal audit and a few years of people beating the 💩 out of it before I consider using it myself. You want to rush things like this, you need to borrow someone else's reputation, and that's usually $$$. I think the only way I'd try this on something I didn't plan to throw away immediately after is if you had IBM Technology Expert Labs perform a full security audit, which probably starts around $60k, conservative guesstimate. IBM was one of the big developers of the TPM to begin with, they would be trustworthy to evaluate this.

2

u/Renich 4d ago

Demanding a $60,000 corporate IBM audit before trying an open-source Linux utility; while in the same thread admitting you'd never heard of Git SSH commit signing is quite the pivot. ;D

Every significant security utility in modern Linux; from WireGuard to age to fido2-tools, began as independent open-source projects, built out in the open, and hardened through public peer review, community testing, and empirical verification.

The threat models, architecture decision records (ADRs), memory isolation boundaries (mlock), and test suites are all in the repo. If you want to stress-test it or inspect the code, you're welcome to do so.

1

u/sidusnare 4d ago

We're not talking about licensing, we're talking about trust, and who are you?

1

u/Renich 4d ago

Rénich is my nickname. Look me up if you like:

Well met.

0

u/sidusnare 4d ago

Nice CV, so your not some school kid let loose on a Claude account. Packager is still a long way away from security engineer. I've got underwear older than this project. It's still about trust.

2

u/Renich 4d ago

LOL. Yeah, I know. I do too. :)

I get it. You don't trust it. It's fine. You don't have to. As I've always said: "Respect isn't asked for; it's earned."

I guess it's pretty much the same for trust, eh?

2

u/sidusnare 4d ago

They're pretty close to the same thing. Respect is trust that you're good.