Michael Stroeder:
> So even if you cannot afford a HSM you can e.g. use ssh-agent via Unix
> domain socket for your SSH-CA to avoid having to grant direct read
> access to the SSH-CA's private key to your SSH-CA service. Simple
> solutions, which you can isolate a bit more with stuff already available
> on many Linux systems (AppArmor or SELinux, systemd sand-boxing, etc.).
You give client-side examples; at $work, applications use agents
that talk to hardware tokens. But there still needs to be a backend
that is operated securely.
Wietse