Post #2176671
2026-04-18 02:16 UTC
@slink@fosstodon.org @Di4na@hachyderm.io @hipsterelectron@circumstances.run
You can separately use PKCS11 and ship around public x509 public keys. Which still leaves you with a similar problem to GPG and single token key signing. Similar to what I described in a separate thread off this post, your problem will still lie in trust or needing to do some sort of quorum and split (or multi-sign) approach to prevent single point of trust.
Replies (0)
No replies.