3 ms·
Disclaimer: excuse my ignorance but this is an honest question. Regarding “1. Uses plaintext private keys in memory and has no support for yubikeys, nitrokeys,
by khalidx 4y ago
Disclaimer: excuse my ignorance but this is an honest question.
Regarding “1. Uses plaintext private keys in memory and has no support for yubikeys, nitrokeys, or other smartcards”.
What is the alternative? Aren’t secrets in memory always plaintext unless you are using something external like a hardware security module chip?
- lrvick 4y agoUsing a yubikey, nitrokey, etc as I suggest would ensure the private key never leaves the external device. Those are personal HSMs.