<?xml version="1.0" encoding="utf-8" standalone="yes"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
  <channel>
    <title>Certstrap on Problem of Network</title>
    <link>https://www.problemofnetwork.com/tags/certstrap/</link>
    <description>Recent content in Certstrap on Problem of Network</description>
    <generator>Hugo</generator>
    <language>en-gb</language>
    <lastBuildDate>Sat, 10 Oct 2026 23:30:00 +0200</lastBuildDate>
    <atom:link href="https://www.problemofnetwork.com/tags/certstrap/index.xml" rel="self" type="application/rss+xml" />
    <item>
      <title>Securing Vault logins with client certificates</title>
      <link>https://www.problemofnetwork.com/posts/securing-vault-logins-with-client-certificates/</link>
      <pubDate>Sat, 10 Oct 2026 23:30:00 +0200</pubDate>
      <guid>https://www.problemofnetwork.com/posts/securing-vault-logins-with-client-certificates/</guid>
      <description>&lt;p&gt;In the &lt;a href=&#34;https://www.problemofnetwork.com/posts/securing-your-vault-instance-with-tls/&#34;&gt;last post&lt;/a&gt; we put a certificate from an offline certstrap CA on the Vault listener, so clients can check that Vault really is Vault. This one is the other half, and the last post in the Vault series: using certificates the other way round, to prove who &lt;em&gt;you&lt;/em&gt; are, with the private key sitting on a YubiKey.&lt;/p&gt;&#xA;&lt;p&gt;Vault&amp;rsquo;s &lt;code&gt;cert&lt;/code&gt; auth method lets a client present a TLS client certificate instead of a password or a token, and Vault turns that into a short-lived token with a policy attached. The user-facing half of this is done with &lt;a href=&#34;https://github.com/fatred/yubivault&#34;&gt;yubivault&lt;/a&gt;, a small tool that logs in to Vault with a client certificate and prints a token. This post is the &amp;ldquo;why and how it fits together&amp;rdquo; version of the &lt;a href=&#34;https://github.com/fatred/yubivault/blob/main/PKI-SETUP.md&#34;&gt;PKI-SETUP.md&lt;/a&gt; guide in that repo.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Securing your Vault instance with TLS</title>
      <link>https://www.problemofnetwork.com/posts/securing-your-vault-instance-with-tls/</link>
      <pubDate>Sat, 10 Oct 2026 22:30:00 +0200</pubDate>
      <guid>https://www.problemofnetwork.com/posts/securing-your-vault-instance-with-tls/</guid>
      <description>&lt;p&gt;This post and &lt;a href=&#34;https://www.problemofnetwork.com/posts/securing-vault-logins-with-client-certificates/&#34;&gt;the next one&lt;/a&gt; wrap up the Vault series, and they are where I pay back a debt. Way back in the &lt;a href=&#34;https://www.problemofnetwork.com/posts/bootstrapping-hashi-vault/&#34;&gt;bootstrap&lt;/a&gt; post I looked at the docker setup and said I would want TLS on something &amp;ldquo;real&amp;rdquo;, but that it was &amp;ldquo;a level of faff i&amp;rsquo;m not up for today&amp;rdquo;. Well, it is today. We have spent a lot of posts putting things into Vault (&lt;a href=&#34;https://www.problemofnetwork.com/posts/hashi-vault-primitives/&#34;&gt;primitives&lt;/a&gt;, &lt;a href=&#34;https://www.problemofnetwork.com/posts/making-use-of-vault-python/&#34;&gt;python&lt;/a&gt;, &lt;a href=&#34;https://www.problemofnetwork.com/posts/making-use-of-vault-ansible/&#34;&gt;ansible&lt;/a&gt;, &lt;a href=&#34;https://www.problemofnetwork.com/posts/building-vault-pki/&#34;&gt;PKI&lt;/a&gt;, &lt;a href=&#34;https://www.problemofnetwork.com/posts/vault-audit-logging/&#34;&gt;audit&lt;/a&gt;, &lt;a href=&#34;https://www.problemofnetwork.com/posts/vault-transit-encryption/&#34;&gt;transit&lt;/a&gt;), all of it over plain HTTP, which is a bit embarrassing for a secrets store.&lt;/p&gt;</description>
    </item>
  </channel>
</rss>
