Support for signing key on hardware security modules
ofaklintrafo
ofa at klintra.fo
Wed Dec 20 20:14:34 EST 2017
So it would basically work if it can be configured using the Sun PKCS#11
Provider. But this would be transparent to the Shibboleth IdP.
But it would be interesting to know if there is anyone who has an
installation runnning with a Sun PKCS#11 Provider configuration.
Yes, it is more expensive, but provides better protection of the private key
which may be required in some cases. And a HSM can perform quite many
signing operations pr second.
One way to test it would be to try it out with an instance of the SoftHSM.
--
Sent from: http://shibboleth.1660669.n2.nabble.com/Shibboleth-Users-f1660767.html
More information about the users
mailing list