E-Ink News Daily

← Back to list

attezt: device attestation, PKCS11 and ACME

IETF is standardizing a new ACME challenge (device-attest-01) that enables provisioning of device-bound certificates that cannot be extracted from their intended machines. The attezt project provides a Linux toolkit—an ACME client, attestation server, and PKCS11 agent—to support this challenge, useful for strong device identity in mTLS scenarios.

Background

ACME (Automatic Certificate Management Environment) is widely used for automated certificate issuance via Let's Encrypt and similar CAs. Device attestation extends this by binding certificates to hardware-backed identities, a growing need for zero-trust and supply-chain security.

Source
Lobsters
Published
Sep 30, 2026 at 08:23 PM
Score
6.0 / 10