Identity Architecture: OIDC, Trust & Recovery · advanced

TLS Key Custody Is Part of the OpenBao Root of Trust

The server needs its TLS private key to operate, while the CA private key is more powerful and should remain off-host.

Current. Current production engineering note based on the hserver authentication and secret-control-plane architecture.

The OpenBao API is useful only if clients can authenticate the server they are sending secret requests to. TLS is therefore part of the secret-control-plane trust model, not just transport decoration.

The deployment uses a dedicated CSL certificate authority. The CA private key stays on the operator workstation. hserver receives the CA certificate, the issued server certificate and the server private key required to terminate TLS on ports 8200 and 8201.

This split limits what a server compromise can mint. The server must possess its own private key, but it does not need the authority to issue arbitrary trusted certificates for the whole control plane. The runtime key also exposed a practical Linux-permissions lesson: a key can be secure and still unreadable to the non-root service identity, so directory traversal, group ownership and file mode must be designed together.

Trust architecture lives in both cryptography and operating-system permissions. A correct certificate chain is not enough if the process cannot safely access its key.

Engineering evidence

The hserver repository evidence for this note is commit 7843fb3. The architecture is documented as current state or future phase explicitly; planned OIDC integration is not presented as already deployed.

Quick navigationEsc