-
-
Notifications
You must be signed in to change notification settings - Fork 13
Support ECDSAP256SHA256 with real KMIP servers. #986
Copy link
Copy link
Open
Labels
HSMHardware Security Module related.Hardware Security Module related.bugSomething isn't workingSomething isn't workingtestingAutomatic verification of Cascade's correctness and reliability.Automatic verification of Cascade's correctness and reliability.
Description
Activity
Metadata
Metadata
Assignees
Labels
HSMHardware Security Module related.Hardware Security Module related.bugSomething isn't workingSomething isn't workingtestingAutomatic verification of Cascade's correctness and reliability.Automatic verification of Cascade's correctness and reliability.
See NLnetLabs/domain-kmip#5. We don't have this issue with Cascade-HSM-Bridge as Cascade and Cascade-HSM-Bridge each know what the other expects, but with a real KMIP HSM that we connect to directly instead of connecting to the bridge (which if for PKCS#11 HSMs) it isn't currently possible (at least with Securosys Cloud HSM, and maybe/probably? with other HSMs too).
It's unclear to me if https://cascade.docs.nlnetlabs.nl/en/latest/hsms.html is incorrect in stating support for Fortanix DSM via KMIP. I did test with Fortanix DSM, but am unsure if it definitely worked with ECDSAP256SHA256 or only with RSA, and the free trial I used has since expired.