Post #2176670
2026-04-18 01:47 UTC
@slink@fosstodon.org @Di4na@hachyderm.io @hipsterelectron@circumstances.run
As a note, you _can_ use your own cosign keys (on hardware you control) but it does put a _massive_ burden on you to run a significant amount of infrastructure to do so.
Replies (1)
-
@groved@mastodon.social 2026-04-18 02:16
@slink@fosstodon.org @Di4na@hachyderm.io @hipsterelectron@circumstances.run You can separately use PKCS11 and ship around public x509 public keys. Which still leaves you with a similar problem to GPG and single token key signing. Similar to what I described in a separate thread off this post, your problem will still lie in trust or needing to do some sort of quorum and split (or multi-sign) approach to prevent single point of trust.