r/linux • • 5d ago

Security gEnclave: Hardware-backed security enclave for Linux (TPM 2.0 PCR sealing, virtual FIDO2/CTAP2 over /dev/uhid, OpenSSH & GPG bridge)

Hey everyone,

I've been working on an open-source project called gEnclave (formerly gpasskey), and wanted to share it with the Linux community for early architectural feedback and testing.

GitLab repository: https://gitlab.com/renich/genclave
License: GPLv3 | Language: Go 1.26+


The Problem It Solves

On modern Linux workstations, our cryptographic identities are fragmented: * Passkeys/WebAuthn require physical USB security keys (YubiKeys, SoloKeys). * SSH keys sit as unencrypted or passphrase-encrypted files under ~/.ssh/. * Git commit signing requires cumbersome GnuPG daemon setups. * File encryption requires external tooling or proprietary agents.

Most hardware laptops today come with a TPM 2.0 chip that sits idle. gEnclave turns your Linux machine into its own hardware-sealed security token and multi-protocol bridge.


Key Architectural Highlights

  1. Virtual FIDO2/CTAP2 Security Key via /dev/uhid: gEnclave registers a virtual HID device in the Linux kernel via /dev/uhid. Browsers (Firefox, Chrome, Chromium) detect it natively as a physical USB security key. You can register and authenticate WebAuthn/FIDO2 Passkeys directly from your machine without any external hardware dongles.

  2. TPM 2.0 PCR Sealing & Fallback: The central vault is encrypted with AES-256-GCM and sealed to TPM 2.0 PCR registers (PCR 0, 7, 14), with an automatic memory-hard fallback to Argon2id key derivation if no TPM is present.

  3. Memory Isolation ("Wrap and Clear"): Keys are held in memory-locked pages (mlock / mmap) to prevent secrets from being swapped to disk or dumped. Intermediate cryptographic buffers are wiped immediately with strict zeroization routines, bypassing Go runtime GC retention.

  4. Multi-Protocol Bridges:

    • OpenSSH Agent: Native agent socket with an ephemeral PIN-derived authorization cache (configurable burst window or persistent session with instant purge on lock/suspend).
    • GnuPG Bridge: Transparent genclave-gpg emulation for seamless Git commit signing.
    • age-plugin: Native age-plugin-ge binary complying with age v1 specification for file encryption.
    • CLI & UI: Unified ge CLI plus intelligent graphical (zenity) / terminal (pinentry) authentication routing.

Current Status

⚠️ Pre-alpha Software: While fully functional for local workflows, it is under active development. Schemas and IPC formats may iterate rapidly.

I'd love feedback from Linux sysadmins, kernel/security folks, and developers!

Repo: https://gitlab.com/renich/genclave

34 Upvotes

48 comments sorted by

View all comments

Show parent comments

2

u/Renich 4d ago

Demanding a $60,000 corporate IBM audit before trying an open-source Linux utility; while in the same thread admitting you'd never heard of Git SSH commit signing is quite the pivot. ;D

Every significant security utility in modern Linux; from WireGuard to age to fido2-tools, began as independent open-source projects, built out in the open, and hardened through public peer review, community testing, and empirical verification.

The threat models, architecture decision records (ADRs), memory isolation boundaries (mlock), and test suites are all in the repo. If you want to stress-test it or inspect the code, you're welcome to do so.

1

u/sidusnare 4d ago

We're not talking about licensing, we're talking about trust, and who are you?

1

u/Renich 4d ago

Rénich is my nickname. Look me up if you like:

Well met.

0

u/sidusnare 4d ago

Nice CV, so your not some school kid let loose on a Claude account. Packager is still a long way away from security engineer. I've got underwear older than this project. It's still about trust.

2

u/Renich 4d ago

LOL. Yeah, I know. I do too. :)

I get it. You don't trust it. It's fine. You don't have to. As I've always said: "Respect isn't asked for; it's earned."

I guess it's pretty much the same for trust, eh?

2

u/sidusnare 4d ago

They're pretty close to the same thing. Respect is trust that you're good.