Alexander Bokovoy via FreeIPA-users wrote:
> On Срд, 15 ліс 2023, John Phillips via FreeIPA-users wrote:
>> Thanks for the response Alexander, it sounds like it will be a while
>> before FreeIPA or IdM gets full support for HSM or TPM.
>>
>> I may try using https://github.com/tpm2-software/tpm2-pkcs11 and if I
>> make any progress I will feedback here
> 
> Note also that hardware TPM devices typically don't have enough storage
> space for covering typical CA and especially KRA needs that IPA
> deployments have.
> 
> May be binding a separate storage to a TPM and encrypting it would work.

I poked around at the tpm2-pkcs11 repo and couldn't find any mention of
number or size of keys supported, etc. It mentions using a sqlite3
database for some storage but it wasn't obvious what and I didn't bother
digging into the code.

rob
_______________________________________________
FreeIPA-users mailing list -- freeipa-users@lists.fedorahosted.org
To unsubscribe send an email to freeipa-users-le...@lists.fedorahosted.org
Fedora Code of Conduct: 
https://docs.fedoraproject.org/en-US/project/code-of-conduct/
List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines
List Archives: 
https://lists.fedorahosted.org/archives/list/freeipa-users@lists.fedorahosted.org
Do not reply to spam, report it: 
https://pagure.io/fedora-infrastructure/new_issue

Reply via email to