DEV Community

William Rodriguez
William Rodriguez

Posted on

More than text: Encrypting TLS certificates and private keys with set_file().

More than text: Encrypting TLS certificates and private keys with set_file().

Leaving private SSH keys and TLS certificates unencrypted on disk is an open invitation to lateral movement during a breach. wauth's set_file() encrypts binary certificates directly into your machine-locked vault.

Here is the exact production implementation for set_file() & Encrypted Binary Storage:

from wauth import WAuth

auth = WAuth()

# 1. Encrypt and store an SSH private key or TLS certificate
auth.set_file("PROD_TLS_CERT", "/etc/ssl/certs/production_cert.pem")

# 2. Retrieve the decrypted certificate bytes when initializing SSL
cert_bytes = auth.get("PROD_TLS_CERT")
print(f"Loaded certificate ({len(cert_bytes)} bytes) safely into memory.")
Enter fullscreen mode Exit fullscreen mode

Why this changes developer velocity:

  • Native File Encryption: auth.set_file('CERT', path) reads, encrypts, and stores files atomically.
  • Exact Byte Restoration: Retrieval returns pure bytes, ready to write to disk or feed into SSL contexts.
  • Hardware-Salted Shield: Private keys are locked to the machine; unreadable if copied to another host.

Zero Pain:

  • Leaving unencrypted SSH private keys and TLS certificates sitting in vulnerable filesystem paths
  • Accidentally exposing .pem or .key files through permissive file permissions
  • Writing complex base64 conversion scripts to store binary files inside configuration databases

Explore the verified open-source repository on GitHub or install it via:

pip install wauth
Enter fullscreen mode Exit fullscreen mode

Top comments (0)