If I am in a small company, I can give everyone a yubikey and have some process that verifies everyone.
Now I want to eliminate cookies / sessions keys. (just go with me). I want to use client certificates - but I only trust the yubikey.
I am noodling ways that I can generate client certs, install them fairly easily and sign them with the yubikey.
The goal here is that client certs are a really good idea- every request can include one, as opposed to every request including a session cookie / nonce that is open to interception / playback etc etc.
And now we have billions of hardware security modules (am including secure enclaves in phones) - so there really ought to be a way through here.
My problems include "generating client certs client side" - not something many browsers support and signing that in some sensible fashion
But is all seems quiet possible