3 ms·
There is no threat model, just curiosity, but obviously if the signing device is online then its signing key could potentially be retrieved by an attacker on th
by lizardactivist 4y ago
There is no threat model, just curiosity, but obviously if the signing device is online then its signing key could potentially be retrieved by an attacker on the Internet.
- NovemberWhiskey 4y agoThe CA/B baseline requirements include storage of the private key on a FIPS 140 Level 3 cryptographic device (i.e. an HSM) so there's a certain minimum degree of assurance there.