Unresolved
Details
Assignee
Fabio TranchitellaFabio TranchitellaReporter
Fabio TranchitellaFabio TranchitellaLabels
Epic Name
PKCS#11 in mender-artifactPlan
Open sourceStarterProfessionalEnterpriseGoals
NonePriority
(None)Backlog
yesStory Points
0
Details
Details
Assignee
Fabio Tranchitella
Fabio TranchitellaReporter
Fabio Tranchitella
Fabio TranchitellaLabels
Epic Name
PKCS#11 in mender-artifact
Plan
Open source
Starter
Professional
Enterprise
Goals
None
Priority
Backlog
yes
Story Points
0
Zendesk Support
Zendesk Support
Zendesk Support
Checklist
Checklist
Checklist
Created August 7, 2022 at 6:19 AM
Updated October 30, 2022 at 5:50 PM
As of today, mender-artifact supports artifact signing using key pairs (RSA, ECDSA256) read from files, Google Cloud Key Management and Hashicorp Vault. The goal of this epic is adding support ofr PKCS#11 in mender-artifact to use any PKCS#11-compatible interface to sign a Mender Artifact.
Acceptance criteria:
mender-artifact sign command supports a new option to use a pkcs#11 interface to sign the artifact, in addition to --key, --gcp-kms-key and --gcp-kms-key.