AuthBox documentation — Getting started

Documentation embedded in this build.

2. Enrol your first person

You have a stack running from step 1. Nothing in it will talk to you until you hold a client certificate, so that is what this step gets you.

One thing is true of every path below: your private key is generated on your own machine and never leaves it. AuthBox does not generate your key, does not receive it and does not store it. What you send is a certificate signing request — a public key and the name you are asking to be issued under — never the private half.

First, an invitation

An invitation is a one-time token. It either grants a certificate immediately or names exactly what group membership the holder receives on approval. Create one from the console's Invitations page, or from the command line:

$ export AUTHBOXCTL_CONFIG=<runtime>/authboxctl.yaml
$ ./authboxctl invite create firstperson -profile govie -role admin

The runtime path is the one the bring-up printed. What comes back is a token and a link; the link is what you hand to the person.

Then, the enrolment

The shortest path is the command-line client, which generates the key, fetches the profile so it can tell you locally whether a choice would be refused, builds the request and submits it:

$ authboxclient enroll -server https://<domain>:8443 -ca <runtime>/gen/ca.pem \
    -subject "CN=firstperson,O=authbox,C=US" -invitation YOUR-TOKEN

If the invitation issues immediately, the certificate comes back in the same breath. Otherwise you get status pending and a request identifier, and an administrator approves it from the console's Enrollments page.

You do not need that client. Opening the invitation link in a browser reaches the public enrolment page with the token already filled in, and that page walks the same steps with tools you already have. The console never asks anybody to paste a private key, and could not safely process one if they tried.

What success looks like

$ authboxclient credentials list
$ authboxclient status

The first lists what you hold; the second names the credential that is currently active. From here the certificate is the login: there is no password to set and no session to expire.

Now open the console door with it. You are seeing exactly what this person is authorized to see — no more, and the parts they may not see are absent rather than greyed out.

Next: Protect a service