Skip to content
#

x509

Here are 288 public repositories matching this topic...

certificates
kism
kism commented Jul 31, 2021

What would you like to be added

I'd like to have the option to not have the HSM pin stored in a configuration file, but instead be required to be entered manually by an operator each time the CA is started.

Why this is needed

Having HSM pins sitting on the file system weakens the security in cases of hardware being stolen.

In theory if the PIN is not known then stealing a server a

cli

Improve this page

Add a description, image, and links to the x509 topic page so that developers can more easily learn about it.

Curate this topic

Add this topic to your repo

To associate your repository with the x509 topic, visit your repo's landing page and select "manage topics."

Learn more