In the last post we put a certificate from an offline certstrap CA on the Vault listener, so clients can check that Vault really is Vault. This one is the other half, and the last post in the Vault series: using certificates the other way round, to prove who you are, with the private key sitting on a YubiKey.
Vault’s cert auth method lets a client present a TLS client certificate instead of a password or a token, and Vault turns that into a short-lived token with a policy attached. The user-facing half of this is done with yubivault, a small tool that logs in to Vault with a client certificate and prints a token. This post is the “why and how it fits together” version of the PKI-SETUP.md guide in that repo.