<?xml version="1.0" encoding="utf-8" standalone="yes"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
  <channel>
    <title>Pki on Problem of Network</title>
    <link>https://www.problemofnetwork.com/tags/pki/</link>
    <description>Recent content in Pki on Problem of Network</description>
    <generator>Hugo</generator>
    <language>en-gb</language>
    <lastBuildDate>Sat, 10 Oct 2026 23:30:00 +0200</lastBuildDate>
    <atom:link href="https://www.problemofnetwork.com/tags/pki/index.xml" rel="self" type="application/rss+xml" />
    <item>
      <title>Securing Vault logins with client certificates</title>
      <link>https://www.problemofnetwork.com/posts/securing-vault-logins-with-client-certificates/</link>
      <pubDate>Sat, 10 Oct 2026 23:30:00 +0200</pubDate>
      <guid>https://www.problemofnetwork.com/posts/securing-vault-logins-with-client-certificates/</guid>
      <description>&lt;p&gt;In the &lt;a href=&#34;https://www.problemofnetwork.com/posts/securing-your-vault-instance-with-tls/&#34;&gt;last post&lt;/a&gt; we put a certificate from an offline certstrap CA on the Vault listener, so clients can check that Vault really is Vault. This one is the other half, and the last post in the Vault series: using certificates the other way round, to prove who &lt;em&gt;you&lt;/em&gt; are, with the private key sitting on a YubiKey.&lt;/p&gt;&#xA;&lt;p&gt;Vault&amp;rsquo;s &lt;code&gt;cert&lt;/code&gt; auth method lets a client present a TLS client certificate instead of a password or a token, and Vault turns that into a short-lived token with a policy attached. The user-facing half of this is done with &lt;a href=&#34;https://github.com/fatred/yubivault&#34;&gt;yubivault&lt;/a&gt;, a small tool that logs in to Vault with a client certificate and prints a token. This post is the &amp;ldquo;why and how it fits together&amp;rdquo; version of the &lt;a href=&#34;https://github.com/fatred/yubivault/blob/main/PKI-SETUP.md&#34;&gt;PKI-SETUP.md&lt;/a&gt; guide in that repo.&lt;/p&gt;</description>
    </item>
  </channel>
</rss>
