Michael Stroeder:
> So even if you cannot afford a HSM you can e.g. use ssh-agent via Unix 
> domain socket for your SSH-CA to avoid having to grant direct read 
> access to the SSH-CA's private key to your SSH-CA service. Simple 
> solutions, which you can isolate a bit more with stuff already available 
> on many Linux systems (AppArmor or SELinux, systemd sand-boxing, etc.).

You give client-side examples; at $work, applications use agents
that talk to hardware tokens. But there still needs to be a backend
that is operated securely.

        Wietse

Reply via email to