Add passkey human logins and short-lived SSH certificates #5

Merged
ams-tech merged 3 commits from codex/passkey-human-login into main 2026-09-28 23:20:28 -04:00
ams-tech commented 2026-09-28 22:26:20 -04:00 (Migrated from github.com)

Human administration currently depends on manually installed SSH grants. This adds a Keycloak passkey realm, an OIDC-authenticated SSH user certificate issuer, a Linux/Nix kaiba login/status/logout client, and explicit host principal mappings. The initial owner must register two passkeys before receiving SSH authority; certificates bind the immutable issuer/subject and expire within eight hours of issuance.

Private credentials remain in runtime storage. Existing owner SSH keys and pilot identities remain separate. Daily snapshots serialize with enrollment changes, encrypt before transfer, and use a restricted receiver. A pinned step-ca patch prevents future-dated certificates from extending the issuance horizon; renew/rekey are denied. Startup waits for Keycloak initialization and verified OIDC discovery, with automatic recovery after restart.

Validation:

  • 56 Python tests and the Nix-packaged selector pass.
  • Combined VM passes cold initialization, two virtual WebAuthn keys, denied premature issuance, password removal/finalization, fresh Keycloak tokens without refresh tokens, actual CA issuance, real kaiba/step login/status/selective logout, and automatic recovery after Keycloak restart.
  • Real SSH VM covers certificate-only login, allowed/denied principals, expiry, selective logout, KRL revocation, restart and owner-key recovery.
  • CA VM covers claims/types/principals/lifetime, future validity windows, renewal/rekey denial, persistence, token-log redaction, verified proxy TLS and recovery from unavailable/untrusted OIDC discovery.
  • Backup VM covers enrollment locking, encryption, transfer confinement, database/state restoration, retention and snapshot failure recovery. Patched issuer upstream Go tests pass on x86_64 and native ARM64.
  • Temporary native Mako activation passed HTTPS, service restart, preservation and encrypted-backup transfer checks. Ace received matching ciphertext; plaintext staging was removed. Both persistent boot profiles remained unchanged.

The native test exposed firmware-disabled memory cgroups on Mako. Companion PseudoDesign/nix-pseudo-design#12 fixes this with a kernel parameter; both PRs are merged and deployed, and Mako has rebooted successfully. Effective memory limits, HTTPS, pilot identity/mount preservation and another encrypted backup all pass after reboot, with no OOM events and approximately 895–899 MiB available RAM. Owner hardware-passkey enrollment, the resulting host principal mapping, and an owner-held backup-key recovery drill remain. No production private credentials are included in this change.

Human administration currently depends on manually installed SSH grants. This adds a Keycloak passkey realm, an OIDC-authenticated SSH user certificate issuer, a Linux/Nix `kaiba login/status/logout` client, and explicit host principal mappings. The initial owner must register two passkeys before receiving SSH authority; certificates bind the immutable issuer/subject and expire within eight hours of issuance. Private credentials remain in runtime storage. Existing owner SSH keys and pilot identities remain separate. Daily snapshots serialize with enrollment changes, encrypt before transfer, and use a restricted receiver. A pinned step-ca patch prevents future-dated certificates from extending the issuance horizon; renew/rekey are denied. Startup waits for Keycloak initialization and verified OIDC discovery, with automatic recovery after restart. Validation: - 56 Python tests and the Nix-packaged selector pass. - Combined VM passes cold initialization, two virtual WebAuthn keys, denied premature issuance, password removal/finalization, fresh Keycloak tokens without refresh tokens, actual CA issuance, real `kaiba`/step login/status/selective logout, and automatic recovery after Keycloak restart. - Real SSH VM covers certificate-only login, allowed/denied principals, expiry, selective logout, KRL revocation, restart and owner-key recovery. - CA VM covers claims/types/principals/lifetime, future validity windows, renewal/rekey denial, persistence, token-log redaction, verified proxy TLS and recovery from unavailable/untrusted OIDC discovery. - Backup VM covers enrollment locking, encryption, transfer confinement, database/state restoration, retention and snapshot failure recovery. Patched issuer upstream Go tests pass on x86_64 and native ARM64. - Temporary native Mako activation passed HTTPS, service restart, preservation and encrypted-backup transfer checks. Ace received matching ciphertext; plaintext staging was removed. Both persistent boot profiles remained unchanged. The native test exposed firmware-disabled memory cgroups on Mako. Companion PseudoDesign/nix-pseudo-design#12 fixes this with a kernel parameter; both PRs are merged and deployed, and Mako has rebooted successfully. Effective memory limits, HTTPS, pilot identity/mount preservation and another encrypted backup all pass after reboot, with no OOM events and approximately 895–899 MiB available RAM. Owner hardware-passkey enrollment, the resulting host principal mapping, and an owner-held backup-key recovery drill remain. No production private credentials are included in this change.
Sign in to join this conversation.
No description provided.