IETF is standardizing a new ACME challenge (device-attest-01) that enables provisioning of device-bound certificates that cannot be extracted from their intended machines. The attezt project provides a Linux toolkit—an ACME client, attestation server, and PKCS11 agent—to support this challenge, useful for strong device identity in mTLS scenarios.
Background
ACME (Automatic Certificate Management Environment) is widely used for automated certificate issuance via Let's Encrypt and similar CAs. Device attestation extends this by binding certificates to hardware-backed identities, a growing need for zero-trust and supply-chain security.
- Source
- Lobsters
- Published
- Sep 30, 2026 at 08:23 PM
- Score
- 6.0 / 10