Presenter machine
Holds the machine key and requests one bounded action.
CLM unknownA laptop or server proves which key it holds. kqctp checks policy, stamps one bounded permit, and only then asks OpenBao for a one-time credential.
Machines and protected resources, with their real Certificate Lifecycle Management (CLM) coverage.
Holds the machine key and requests one bounded action.
CLM unknownChecks and consumes the signed permit before forwarding.
Not enrolledTarget of host.restart.
Not enrolledTarget of net.hop.
Not enrolledCreates its own key and CSR. Signs a one-time proof before every permit.
simulated TPM custodyAttests, binds certificate to machine, checks proof, then evaluates policy.
proof before policyStamps the short-lived act permit. Labeled HSM only when the broker reports PKCS#11.
OpenBao does not sign itJump box checks the permit with a public key. OpenBao then supplies and destroys the secret.
secret only after permit