# Mender Artifact signing key stored in smart card

**URL:** <https://hub.mender.io/t/mender-artifact-signing-key-stored-in-smart-card/1458>\
**Category:** General Discussions\
**Tags:** mender-artifact\
**Created:** [January 22, 2020, 5:42am UTC](https://hub.mender.io/t/mender-artifact-signing-key-stored-in-smart-card/1458 "2020-01-22T05:42:04Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![itzSatz](https://avatars.discourse-cdn.com/v4/letter/i/65b543/32.png) [@itzSatz](https://hub.mender.io/u/itzSatz)\
**Post date:** [January 22, 2020, 5:42am UTC](https://hub.mender.io/t/mender-artifact-signing-key-stored-in-smart-card/1458/1 "2020-01-22T05:42:04Z")

</div>

I am trying to use the key pair stored in smart cards to sign the mender artifacts. However mender-artifacts tool doesn’t have any configuration file to read private keys from smart cards. Is there any way to use the private key which is stored in smart cards

---

<div class="post-metadata">

**Author:** ![kacf](https://yyz2.discourse-cdn.com/flex036/user_avatar/hub.mender.io/kacf/32/146_2.png) [@kacf](https://hub.mender.io/u/kacf)\
**Post date:** [January 23, 2020, 7:06am UTC](https://hub.mender.io/t/mender-artifact-signing-key-stored-in-smart-card/1458/2 "2020-01-23T07:06:38Z")

</div>

The tool doesn’t provide it, but you may be able to do it manually with a bit of tinkering. We are using [this Golang call](https://golang.org/pkg/crypto/rsa/#SignPKCS1v15) for the actual signing, with a SHA256 hash of the `manifest` file inside the artifact. The artifact file is just a tar archive. The result is then base64 encoded and put in `manifest.sig`, right after `manifest`, so you can just repack the artifact as a tar file with all the files in the same order, with `manifest.sig` inserted right after `manifest`.

If you figure it out, please post the result, this may be useful for other people too!

---

<div class="post-metadata">

**Author:** ![andrescg](https://avatars.discourse-cdn.com/v4/letter/a/e8c25b/32.png) [@andrescg](https://hub.mender.io/u/andrescg)\
**Post date:** [February 14, 2020, 12:40pm UTC](https://hub.mender.io/t/mender-artifact-signing-key-stored-in-smart-card/1458/3 "2020-02-14T12:40:30Z")

</div>

Hi

I am using google cloud services for storing my private.key, when I signed a mender artifact the google service returns the manifest file and I want to include it in the artifact, is there a guide about how to repack an artifact with this file inside?, if I just add the manifest.sig into the artifact it returns an error when I try to validate it.

Thanks in advance for any help you can provide

---

<div class="post-metadata">

**Author:** ![oleorhagen](https://yyz2.discourse-cdn.com/flex036/user_avatar/hub.mender.io/oleorhagen/32/297_2.png) [@oleorhagen](https://hub.mender.io/u/oleorhagen)\
**Post date:** [February 14, 2020, 1:03pm UTC](https://hub.mender.io/t/mender-artifact-signing-key-stored-in-smart-card/1458/4 "2020-02-14T13:03:37Z")

</div>

I am not sure how you are adding the signature to the Artifact. But the format is specific in that it must be placed right after the manifest, as can be seen here: [https://github.com/mendersoftware/mender-artifact/blob/master/Documentation/artifact-format-v3.md](https://github.com/mendersoftware/mender-artifact/blob/master/Documentation/artifact-format-v3.md)

---

<div class="post-metadata">

**Author:** ![evk1206](https://avatars.discourse-cdn.com/v4/letter/e/9fc348/32.png) [@evk1206](https://hub.mender.io/u/evk1206)\
**Post date:** [April 20, 2020, 7:32am UTC](https://hub.mender.io/t/mender-artifact-signing-key-stored-in-smart-card/1458/5 "2020-04-20T07:32:14Z")

</div>

Hi,

Did you able to sign the mender artifact with keys stored in google cloud successfully?

Thanks & Regards,  
Vinoth

---

<div class="post-metadata">

**Author:** ![drewmoseley](https://yyz2.discourse-cdn.com/flex036/user_avatar/hub.mender.io/drewmoseley/32/47_2.png) [@drewmoseley](https://hub.mender.io/u/drewmoseley)\
**Post date:** [April 20, 2020, 1:26pm UTC](https://hub.mender.io/t/mender-artifact-signing-key-stored-in-smart-card/1458/6 "2020-04-20T13:26:56Z")

</div>

Hi @evk1206 I’m not quite sure what you are asking here but we did do a reference integration with GCP where we used the same certificate to authenticate to both the Mender and GCP servers. You can find details about that here: [https://cloud.google.com/blog/products/iot-devices/mender-and-cloud-iot-facilitate-robust-device-update-management](https://cloud.google.com/blog/products/iot-devices/mender-and-cloud-iot-facilitate-robust-device-update-management)

The signing keys are generally not stored in any cloud for security reasons. In some highly secure setups they are stored in airgapped systems. The verification keys need to be installed on the device.

Drew

---

<div class="post-metadata">

**Author:** ![mirzak](https://yyz2.discourse-cdn.com/flex036/user_avatar/hub.mender.io/mirzak/32/2056_2.png) [@mirzak](https://hub.mender.io/u/mirzak)\
**Post date:** [April 21, 2020, 6:47am UTC](https://hub.mender.io/t/mender-artifact-signing-key-stored-in-smart-card/1458/7 "2020-04-21T06:47:09Z")

</div>

> [@kacf](#):
>
> The tool doesn’t provide it, but you may be able to do it manually with a bit of tinkering. We are using [this Golang call](https://golang.org/pkg/crypto/rsa/#SignPKCS1v15) for the actual signing, with a SHA256 hash of the `manifest` file inside the artifact. The artifact file is just a tar archive. The result is then base64 encoded and put in `manifest.sig` , right after `manifest` , so you can just repack the artifact as a tar file with all the files in the same order, with `manifest.sig` inserted right after `manifest` .
> 
> If you figure it out, please post the result, this may be useful for other people too!

@evk1206, I think you best is to do what is suggested above
