TGViewer
Linux - Reddit Linux - Reddit @r_linux · 1.06K subscribers
Post #43177 48
gEnclave: Hardware-backed security enclave for Linux (TPM 2.0 PCR sealing, virtual FIDO2/CTAP2 over /dev/uhid, OpenSSH & GPG bridge)

Hey everyone,

I've been working on an open-source project called gEnclave (formerly gpasskey), and wanted to share it with the Linux community for early architectural feedback and testing.

GitLab repository: https://gitlab.com/renich/genclave
License: GPLv3 | Language: Go 1.26+

---

### The Problem It Solves
On modern Linux workstations, our cryptographic identities are fragmented:
Passkeys/WebAuthn require physical USB security keys (YubiKeys, SoloKeys).
SSH keys sit as unencrypted or passphrase-encrypted files under ~/.ssh/.
Git commit signing requires cumbersome GnuPG daemon setups.
File encryption requires external tooling or proprietary agents.

Most hardware laptops today come with a TPM 2.0 chip that sits idle. gEnclave turns your Linux machine into its own hardware-sealed security token and multi-protocol bridge.

---

### Key Architectural Highlights

1. Virtual FIDO2/CTAP2 Security Key via /dev/uhid:
gEnclave registers a virtual HID device in the Linux kernel via /dev/uhid. Browsers (Firefox, Chrome, Chromium) detect it natively as a physical USB security key. You can register and authenticate WebAuthn/FIDO2 Passkeys directly from your machine without any external hardware dongles.

2. TPM 2.0 PCR Sealing & Fallback:
The central vault is encrypted with AES-256-GCM and sealed to TPM 2.0 PCR registers (PCR 0, 7, 14), with an automatic memory-hard fallback to Argon2id key derivation if no TPM is present.

3. Memory Isolation ("Wrap and Clear"):
Keys are held in memory-locked pages (mlock / mmap) to prevent secrets from being swapped to disk or dumped. Intermediate cryptographic buffers are wiped immediately with strict zeroization routines, bypassing Go runtime GC retention.

4. Multi-Protocol Bridges:
OpenSSH Agent: Native agent socket with an ephemeral PIN-derived authorization cache (configurable burst window or persistent session with instant purge on lock/suspend).
GnuPG Bridge: Transparent genclave-gpg emulation for seamless Git commit signing.
age-plugin: Native `age-plugin-ge` binary complying with age v1 specification for file encryption.
CLI & UI: Unified ge CLI plus intelligent graphical (zenity) / terminal (pinentry) authentication routing.

---

### Current Status
⚠️ Pre-alpha Software: While fully functional for local workflows, it is under active development. Schemas and IPC formats may iterate rapidly.

I'd love feedback from Linux sysadmins, kernel/security folks, and developers!

Repo: https://gitlab.com/renich/genclave

https://redd.it/1ws0qau
@r_linux
GitLab René Bon Ćirić (Rénich) / gEnclave · GitLab Centralized, TPM 2.0 hardware-backed cryptographic identity enclave and multi-protocol bridge for Linux (FIDO2/CTAP2 WebAuthn Passkeys, OpenSSH Agent, GnuPG LibAssuan, age-plugin, encrypted config store).
More from @r_linux
  1. Oct 7, 2026What is your opinion on openSUSE in 2026? https://redd.it/1x0736v @r_linux
  2. Oct 7, 2026Budgie 10.10.3 Released | Buddies of Budgie https://buddiesofbudgie.org/blog/budgie-10-10-…
  3. Oct 7, 2026Cloudflare’s eBPF Replatforming Part 3: Technical Challenges Implementing eBPF https://ebp…
  4. Oct 7, 2026dotz v1.0 - Braille and ASCII previews of images and videos in the terminal https://github…
  5. Oct 7, 2026Linux Kernel's LZ4 Compression Code Being Resynced For Better Performance & Cleanliness ht…
  6. Oct 7, 2026Meta Open Sources eBPF Security Tool https://github.com/facebookincubator/bpfjailer https:…
Threads Profile ViewerView any public Threads profile without an account.Open ThreadLook →Writing with AI? Make it sound human.Metric37 rewrites AI drafts so they read naturally. Free AI detector, 1,500 words free.Try Metric37 →