Bug#1141891: ITP: attezt -- An open-source TPM device-attest-01 CA server

Simon Josefsson <[email protected]> Sun, 12 Jul 2026 12:40:56 +0200
Newsgroups gmane.linux.debian.devel.general
Message-ID <878q7gsd6v.fsf__13529.7854941868$1783853018$gmane$org@josefsson.org>
Package: wnpp
Severity: wishlist
Owner: Simon Josefsson <[email protected]>

* Package name    : attezt
  Version         : 0.0~git20260321.c4c2d28-1
  Upstream Author : Morten Linderud
* URL             : https://github.com/Foxboron/attezt
* License         : Expat
  Programming Lang: Go
  Description     : An open-source TPM device-attest-01 CA server

 attezt is a suite of remote attestation tools.
 .
 It provides several components that allows Linux systems to have
 hardware backed device certificates over the device-attest-01 ACME
 challenge. This is useful for environments where you want a strong
 device identity claim for things like x509 certificates used for mTLS
 setups.
 .
 It currently supports smallstep, but also has it's own client
 implementation to administer device certificates.
 .
 atteztd provides an Attestation Certificate Authority. It has an backend
 inventory API that is able to query a CMDB setup for device inventory
 and validate devices.
 .
 attezt-agent provides a client agent that can serve the TPM certificate
 over a PKCS11 agent. This agent can be used for things like mTLS over
 browsers to certify authenticity.
 .
 attezt is the program to manage attezt-agent and atteztd deployments. It
 allows you to check the enrollment of the device, provision
 certificates. Or administer the attestation certificate authority.

Since the upstream project is a WIP I'll keep this on Salsa, or possibly
into experimental once I get it to build, but wanted to file a ITP bug
in case someone else is interested and wants to take over or help move
this along.

https://salsa.debian.org/go-team/packages/attezt
https://salsa.debian.org/jas/attezt/-/pipelines

/Simon
signature.asc (application/pgp-signature, 1.2 KB)
-----BEGIN PGP SIGNATURE-----

iQNoBAEWCgMQFiEEo8ychwudMQq61M8vUXIrCP5HRaIFAmpTbzgUHHNpbW9uQGpv
c2Vmc3Nvbi5vcmfCHCYAmDMEXJLOtBYJKwYBBAHaRw8BAQdACIcrZIvhrxDBkK9f
V+QlTmXxo2naObDuGtw58YaxlOu0JVNpbW9uIEpvc2Vmc3NvbiA8c2ltb25Aam9z
ZWZzc29uLm9yZz6IlgQTFggAPgIbAwULCQgHAgYVCAkKCwIEFgIDAQIeAQIXgBYh
BLHSvRN1vst4TPT4xNc89jjFPAa+BQJp4fWRBQkOa+rdAAoJENc89jjFPAa+hWIA
/1lQvrJeGlQq50lP6tm99D1zDy7J1tQ3ha4x0Jx7rkFTAP9hpUKuTvm6m1fXyiZV
YZlu2+Id/Dq3CIAZvNF+XEr2BLgzBFySz4EWCSsGAQQB2kcPAQEHQOxTCIOaeXAx
I2hIX4HK9bQTpNVei708oNr1Klm8qCGKiPUEGBYIACYCGwIWIQSx0r0Tdb7LeEz0
+MTXPPY4xTwGvgUCaeCW1wUJDmqLVgCBdiAEGRYIAB0WIQSjzJyHC50xCrrUzy9R
cisI/kdFogUCXJLPgQAKCRBRcisI/kdFoqdMAQCgH45aseZgIrwKOvUOA9QfsmeE
8GZHYNuFHmM9FEQS6AD6A4x5aYvoY6lo98pgtw2HPDhmcCXFItjXCrV4A0GmJA4J
ENc89jjFPAa+s7AA+gIIHpBApDpcDj1sKhzDngmpvwQf0VkHme6s+EG7qSgpAQDe
/XMrU0c0Pa3ji85cMqZhvzJOFI/soe662lzL0QY3Bbg4BFySz2oSCisGAQQBl1UB
BQEBB0AxlRumDW6nZY7A+VCfek9VpEx6PJmdJyYPt3lNHMd6HAMBCAeIfgQYFggA
JgIbDBYhBLHSvRN1vst4TPT4xNc89jjFPAa+BQJp4JbXBQkOaottAAoJENc89jjF
PAa+RNUA/2faQO/nFT06E+MlhlQdo/0chlQXC5TZMPTVvVBFwoLOAP9xLJK0ow5E
jTzYJB4K810AL/Iv6PEOAEgA4cPTHVlbCQAKCRBRcisI/kdForzjAQDYf2uUcH1b
u/szjjYlb9gExE/D15k6pWyplEsKUF9S4gD/abZx3kkbWHPoJxMziBVBOLOR1Q3Y
CGQilsKHN2eBPwQ=
=2bCl
-----END PGP SIGNATURE-----