L13 · IDENTITY AND TRUST
Prove you hold a key
Sign a challenge with a key you generate and let the server check the signature.
Planned
Steps
Start the lab to receive a challenge.
What the server will check: The lab records the challenge for your attempt.
Generate a key pair in your browser or with openssl.
What the server will check: Nothing to check. The private key never leaves your device.
Sign the challenge and submit the signature with your public key.
What the server will check: The signature over your challenge verified.
A fresh challenge means an old signature cannot be replayed. Only the private key could have produced this one.
When it opens
This lab is planned. It opens when these are in place:
- A lab challenge endpoint
A lab endpoint records what it receives for your attempt and grades it on the server.