3 ms·
How does this work? Does Digicert "host" the HSM in the cloud for you and make it possible to automate things again? The goal of us developers is of course to
by atesti 3y ago
How does this work? Does Digicert "host" the HSM in the cloud for you and make it possible to automate things again?
The goal of us developers is of course to fully automatically sign an executable, while the CAB forum seems to want one to always enter a pin code in a hw device anytime you make a build.
Are there any good solutions or hacks to automate it? Does Digicert really make it possible again to just invoke signing of anything from the command line or CI task WITHOUT entering any pin or 2factor stuff? That would be great, and of course ultimately circumvent the CAB forum's demands as anyone who stole the digicert credentials can now sign anything.
- mike_hearn 3y agoThe cheaper option is SSL.com eSigner which is also a cloud hosted HSM where you can access it using ordinary saved credentials. In theory they want you to use a 2FA authenticator for it so their protocol requires TOTP secrets and the like. In practice nothing stops you saving the seed to a file, so you can sign automatically. Of course then you're reducing the security gained by the system. Your CI becomes a very weak point. But it does work. The CAB Forum is well aware that people want to and can sign automatically. The purpose of the HSM is to fix revocation, not to require manual intervention for signing software.