dual signing keys (Was: Support for signing key on hardware security modules)
Tom Scavo
trscavo at gmail.com
Mon Jan 29 14:47:03 EST 2018
On Mon, Jan 29, 2018 at 2:22 PM, Cantor, Scott <cantor.2 at osu.edu> wrote:
>> I forgot to ask the ultimate question (which is more interesting than
>> the service categorization issue you mentioned): How will you
>> distribute the signing certificate for the short-lived key?
>
> Local metadata feeds for on campus systems, in which case I could do it daily if I really wanted) but mostly manual "login to web UI and update". We're talking annually or bi-annually, not monthly.
Oh, okay, an annual "login to the web UI and update" isn't a big deal,
I suppose.
>> I guess the answer depends on what you mean by "short-lived." If by
>> that you mean O(days), I don't think current infrastructure is
>> adequate.
>
> Metadata is perfectly adequate for that...
Yes but you (as metadata owner) do not have a way to update the
metadata apart from "login to the web UI and update." That wouldn't
work if you wanted to rotate keys daily or weekly or even monthly.
That's an interesting problem in general.
Tom
More information about the users
mailing list