Skip to main content

Implementation of archival authentication

Project description

TAF (The Archive Framework)

TAF is a framework that aims to provide archival authentication and ensure that Git repositories can be securely cloned/updated. TAF's implementation strongly relies on The Update Framework (TUF), which helps developers maintain the security of a software update system. It provides a flexible framework and specification that developers can integrate into any software update system. TAF integrates Git with TUF:

  • TUF targets were modified to authenticate Git commits instead of individual files. This reduces the metadata size and simplifies authentication.
  • The TUF metadata repository storage utilizes Git. That means TUF metadata files are stored in a Git repository, which is referred to as an authentication repository.

When a TAF authentication repository is cloned, all target repositories are also cloned, and TUF validation is performed against every commit since the repository's inception. When a TAF repository is updated, data is fetched from upstream and each commit is authenticated. A TAF clone/update differs from a standard Git clone/fetch in that remote commits aren't added to the local Git repositories until they've been fully authenticated locally. TAF can be used to secure any git repository, regardless of its content.

Threats

A git repository can be compromised in several ways:

  • An attacker might hack a user's account on a code hosting platform, like GitHub or GitLab.
  • An attacker might compromise the hosting platform itself.
  • An attacker might gain access to a developer's personal computer.

Such an attacker could then:

  • Upload a new GPG key to GitHub.
  • Push new commits to any repository.
  • Add another authorized user with write access.
  • Unprotect the master branch of any repository and force-push to it.

TAF's primary objective is not to prevent the attacks listed above but rather to detect when an attack has occurred and halt an update if necessary. Thus, TAF should be used instead of directly calling git pull and git clone.

Further reading

  1. UELMA whitepaper
  2. TAF implementation and integration with TUF

Installation Steps

From PyPI

pip install taf

From source:

pip install -e .

Install extra dependencies when using Yubikey:

pip install taf[yubikey]

Add bash completion:

  1. copy taf-complete.sh to user's directory
  2. add source ./taf-complete.sh to ~/.bash_profile or ~/.bashrc
  3. source ~/.bash_profile

Development Setup

We are using pre-commit to run black code formatter, flake8 and bandit code quality checks, as well as Mypy static type checker.

pip install -e .[dev]
pip install -e .[test]

pre-commit install # registers git pre-commit hook

pre-commit run --all-files # runs code formatting and quality checks for all files

NOTE: For Windows users: Open settings.json and replace paths.

Running Tests

To run tests with mocked Yubikey:

pytest

To run tests with real Yubikey:

  1. Insert test Yubikey
  2. Run taf setup_test_key WARNING: This command will import targets private key to signature slot of your Yubikey, as well as new self-signed x509 certificate!
  3. Run REAL_YK=True pytest or set REAL_YK=True pytest depending on platform.

Installing Wheels on Windows and MacOS

The newer versions of TAF do not require additional setup, and there are no platform-specific wheels needed. However, older versions required certain platform-specific DLLs, which the CI would copy to taf/libs before building a wheel. Therefore, it's important to install the appropriate platform-specific wheel if you're using an older version.

Installing Wheels on Ubuntu

  • Install dependencies
sudo add-apt-repository ppa:jonathonf/python-3.10
sudo apt-get update
sudo apt-get install python3.10
sudo apt-get install python3.10-venv
sudo apt-get install python3.10-dev
sudo apt-get install swig
sudo apt-get install libpcsclite-dev
sudo apt-get install libssl-dev
sudo apt-get install libykpers-1-dev
  • Create virtual environment
python3.10 -m venv env
pip install --upgrade pip
pip install wheel
pip install taf
  • Test CLI
taf

Acknowledgements

This project was made possible in part by the Institute of Museum and Library Services (LG-246285-OLS-20)

Project details


Download files

Download the file for your platform. If you're not sure which to choose, learn more about installing packages.

Source Distribution

taf-0.32.2.tar.gz (146.5 kB view details)

Uploaded Source

Built Distribution

taf-0.32.2-py3-none-any.whl (238.1 kB view details)

Uploaded Python 3

File details

Details for the file taf-0.32.2.tar.gz.

File metadata

  • Download URL: taf-0.32.2.tar.gz
  • Upload date:
  • Size: 146.5 kB
  • Tags: Source
  • Uploaded using Trusted Publishing? No
  • Uploaded via: twine/3.8.0 pkginfo/1.11.2 readme-renderer/43.0 requests/2.32.3 requests-toolbelt/1.0.0 urllib3/2.2.3 tqdm/4.67.0 importlib-metadata/8.5.0 keyring/23.13.1 rfc3986/2.0.0 colorama/0.4.6 CPython/3.8.18

File hashes

Hashes for taf-0.32.2.tar.gz
Algorithm Hash digest
SHA256 4ed6a37439de0dcfd66e46f44251dd005268ac81a31d803f6f0797026a8a38d1
MD5 b15108d1fcc1019ca62ec9322bfc5242
BLAKE2b-256 10e8bdc8216fc2eb11b0e3d9fdc241796b2dcda7faab95d7428d1b03621c6137

See more details on using hashes here.

File details

Details for the file taf-0.32.2-py3-none-any.whl.

File metadata

  • Download URL: taf-0.32.2-py3-none-any.whl
  • Upload date:
  • Size: 238.1 kB
  • Tags: Python 3
  • Uploaded using Trusted Publishing? No
  • Uploaded via: twine/3.8.0 pkginfo/1.11.2 readme-renderer/43.0 requests/2.32.3 requests-toolbelt/1.0.0 urllib3/2.2.3 tqdm/4.67.0 importlib-metadata/8.5.0 keyring/23.13.1 rfc3986/2.0.0 colorama/0.4.6 CPython/3.8.18

File hashes

Hashes for taf-0.32.2-py3-none-any.whl
Algorithm Hash digest
SHA256 3603d02b256bb8de880fdce1ff7eb9d1f35f16bf2fc2a86ab0c757309c2c7469
MD5 f0834c3cffb9d3be8f09e1927e525036
BLAKE2b-256 eb0a7bac26a76bc9fb94856cc8185300b9a23a4ec39f86d057e3b82200086eee

See more details on using hashes here.

Supported by

AWS AWS Cloud computing and Security Sponsor Datadog Datadog Monitoring Fastly Fastly CDN Google Google Download Analytics Microsoft Microsoft PSF Sponsor Pingdom Pingdom Monitoring Sentry Sentry Error logging StatusPage StatusPage Status page