@alwayscurious@infosec.exchange
Post #2417027
2026-01-15 21:41 UTC
@agl@infosec.exchange I’d have all the complex HSM stuff be in a separate process, and take the same approach to FIPS that Microsoft does: we are working on getting a version certified, but that version might well be end of life before the certification finishes. Alternatively, I’d put the complex abstraction stuff in a proprietary “enterprise” version, and leave the open source version free of that junk.
Replies (0)
No replies.