KQC Trust Platform · enterprise machine demo

Machine access — Permit to act on the network

A laptop or server proves which key it holds. kqctp checks policy, stamps one bounded permit, and only then asks OpenBao for a one-time credential.

Checking live setupLoading broker configuration…
Demo boundary: the presenter backend calls kqctp with an operator/admin key, as the drone demo does. The machine key is held by a virtual machine TPM in a demo state file; this page does not claim machine mTLS. The target service is a labeled stub, while the certificate, permit, and OpenBao credential paths are live.

Enterprise network topology

Machines and protected resources, with their real Certificate Lifecycle Management (CLM) coverage.

Loading CLMManage in KQCTP CLM
Employee network

Presenter machine

Holds the machine key and requests one bounded action.

CLM unknown
Access boundary

Jump box / proxy

Checks and consumes the signed permit before forwarding.

Not enrolled
Application network

inventory-api

Target of host.restart.

Not enrolled
Protected data network

app-db

Target of net.hop.

Not enrolled
Tenant certificate inventoryReading active device certificates from KQCTP CLM…
No machine certificate yetRun live to enroll the presenter machine, then refresh.
1 · Machine-held identity

Laptop / server

Creates its own key and CSR. Signs a one-time proof before every permit.

simulated TPM custody
2 · Decision

kqctp

Attests, binds certificate to machine, checks proof, then evaluates policy.

proof before policy
3 · Authority

Active signer

Stamps the short-lived act permit. Labeled HSM only when the broker reports PKCS#11.

OpenBao does not sign it
4 · Execution

Jump box + OpenBao

Jump box checks the permit with a public key. OpenBao then supplies and destroys the secret.

secret only after permit

Live trust timeline

Ready
One click, one bounded actSelect a safe path or fail-safe, then click Run live.