[Freeipa-users] Re: Freeipa server installation with keys stored in TPM

2023-11-15 Thread Rob Crittenden via FreeIPA-users
Alexander Bokovoy via FreeIPA-users wrote: > On Срд, 15 ліс 2023, John Phillips via FreeIPA-users wrote: >> Thanks for the response Alexander, it sounds like it will be a while >> before FreeIPA or IdM gets full support for HSM or TPM. >> >> I may try using https://github.com/tpm2-software/tpm2-pkc

[Freeipa-users] Re: Freeipa server installation with keys stored in TPM

2023-11-15 Thread Alexander Bokovoy via FreeIPA-users
On Срд, 15 ліс 2023, John Phillips via FreeIPA-users wrote: Thanks for the response Alexander, it sounds like it will be a while before FreeIPA or IdM gets full support for HSM or TPM. I may try using https://github.com/tpm2-software/tpm2-pkcs11 and if I make any progress I will feedback here

[Freeipa-users] Re: Freeipa server installation with keys stored in TPM

2023-11-15 Thread John Phillips via FreeIPA-users
Thanks for the response Alexander, it sounds like it will be a while before FreeIPA or IdM gets full support for HSM or TPM. I may try using https://github.com/tpm2-software/tpm2-pkcs11 and if I make any progress I will feedback here ___ FreeIPA-users

[Freeipa-users] Re: Freeipa server installation with keys stored in TPM

2023-11-15 Thread Alexander Bokovoy via FreeIPA-users
On Срд, 15 ліс 2023, John Phillips via FreeIPA-users wrote: As most servers, physical and virtual are now equipped with a TPM, are there any plans to leverage this to store keys for FreeIPA? We have a use-case where freeipa is a sub-ca and the root-ca will sign our cert. Ideally we would like to