Hey everyone,
I've been working on an open-source project called gEnclave (formerly gpasskey), and wanted to share it with the Linux community for early architectural feedback and testing.
GitLab repository: https://gitlab.com/renich/genclave
License: GPLv3 | Language: Go 1.26+
---
### The Problem It Solves
On modern Linux workstations, our cryptographic identities are fragmented:
Passkeys/WebAuthn require physical USB security keys (YubiKeys, SoloKeys).
SSH keys sit as unencrypted or passphrase-encrypted files under
~/.ssh/.Git commit signing requires cumbersome GnuPG daemon setups.
File encryption requires external tooling or proprietary agents.
Most hardware laptops today come with a TPM 2.0 chip that sits idle. gEnclave turns your Linux machine into its own hardware-sealed security token and multi-protocol bridge.
---
### Key Architectural Highlights
1. Virtual FIDO2/CTAP2 Security Key via
/dev/uhid:gEnclave registers a virtual HID device in the Linux kernel via
/dev/uhid. Browsers (Firefox, Chrome, Chromium) detect it natively as a physical USB security key. You can register and authenticate WebAuthn/FIDO2 Passkeys directly from your machine without any external hardware dongles.2. TPM 2.0 PCR Sealing & Fallback:
The central vault is encrypted with AES-256-GCM and sealed to TPM 2.0 PCR registers (PCR 0, 7, 14), with an automatic memory-hard fallback to Argon2id key derivation if no TPM is present.
3. Memory Isolation ("Wrap and Clear"):
Keys are held in memory-locked pages (
mlock / mmap) to prevent secrets from being swapped to disk or dumped. Intermediate cryptographic buffers are wiped immediately with strict zeroization routines, bypassing Go runtime GC retention.4. Multi-Protocol Bridges:
OpenSSH Agent: Native agent socket with an ephemeral PIN-derived authorization cache (configurable burst window or persistent session with instant purge on lock/suspend).
GnuPG Bridge: Transparent
genclave-gpg emulation for seamless Git commit signing.age-plugin: Native `age-plugin-ge` binary complying with age v1 specification for file encryption.
CLI & UI: Unified
ge CLI plus intelligent graphical (zenity) / terminal (pinentry) authentication routing.---
### Current Status
⚠️ Pre-alpha Software: While fully functional for local workflows, it is under active development. Schemas and IPC formats may iterate rapidly.
I'd love feedback from Linux sysadmins, kernel/security folks, and developers!
Repo: https://gitlab.com/renich/genclave
https://redd.it/1ws0qau
@r_linux