Post #3480024
2026-06-29 21:29 UTC
Did some flash experiments for building secure cryptographic trust roots independently of large technology companies; i.e. for DNSSEC/DANE and/or SSH CA applications. COTS HSMs do not support modern public-key algorithms, e.g. Ed25519, without a great deal of expense. OpenDNSSEC uses SoftHSMv2 via the PKCS#11 standard. I propose to use COTS retail components to build keystores for it.
Replies (1)
-
@bms48@mastodon.social 2026-06-29 21:29
The keystores should be removable so parent intermediary CA keys can get locked in a physical safe. I know someone was like "Just use a [new] NitroKey" but, cost, lead time, and supply chain diversity are factors; That said, the SLC flash vendors were all from Taiwan. I tried a Cactus industrial CompactFlash card and a microSD card in a COTS CF-SD adapter, both in a CF PC rear backplate mounted receptable, behind a SATA-PATA bridge, re-using plentiful SATA ports on a modern PC motherboard.