{"repo":"smallstep/clients","free":true,"listed":false,"github":"https://github.com/smallstep/clients","clone":"git clone https://github.com/smallstep/clients.git","description":"Various client examples for getting TLS certificates from a Smallstep CA server","language":"Python","stars":20,"topics":["x509","security","jwt","csr"],"license":"Apache-2.0","category":"auth-billing-email","readme_excerpt":"step-ca certificate signing client This repo contains demo client code in various languages, for getting X.509 certificates signed by a step-ca Certificate Authority. How you might use this Use one of these clients if you need to write a custom integration with step-ca that authenticates X.509 certificate requests on behalf of your users. These clients are not designed to be used directly by end users. Their use of an unencrypted JWK for the JWK provisioner gives these clients too much power. For direct end user applications, we recommend using the OIDC provisioner if possible. Alternatively, you could modify this code to interactively ask for a JWK password to decrypt the JWK used by the CA. The examples in this repository let you delegate CA authentication or access control to a custom service that will request TLS certificates on behalf of its clients. Your implementation must be responsible for authentication and access control. For example, say you manage a set of global VPN servers for your company, and each VPN server provides access to an internal network for a given business unit or region. You've created a service for managing VPN access and issuing client certificates. The service maintains an access control database that maps employees to VPN servers. An employee can sign in and request access to a particular server. When access is granted, the service will get an appropriate CSR signed by the CA, and make the certificate available for download. Alternatives If yo","default_branch":null,"files":null,"tree":[],"storefront":"/r/smallstep","claimed":false,"request_supported":{"post":"https://gitbuyer.com/r/smallstep/clients/request-supported","requests":0},"note":"indexed from public GitHub; nothing is for sale on this page. Clone it from GitHub. Paid listings live at /search."}