Support for signing key on hardware security modules

ofaklintrafo ofa at klintra.fo
Wed Dec 20 20:14:34 EST 2017


So it would basically work if it can be configured using the Sun PKCS#11
Provider. But this would be transparent to the Shibboleth IdP.

But it would be interesting to know if there is anyone who has an
installation runnning with a Sun PKCS#11 Provider configuration. 

Yes, it is more expensive, but provides better protection of the private key
which may be required in some cases. And a HSM can perform quite many
signing operations pr second.

One way to test it would be to try it out with an instance of the SoftHSM.



--
Sent from: http://shibboleth.1660669.n2.nabble.com/Shibboleth-Users-f1660767.html


More information about the users mailing list