edugain-discuss AT lists.geant.org
Subject: An open discussion list for topics related to the eduGAIN interfederation service.
List archive
- From: Alan Lewis <alan.lewis AT geant.org>
- To: Guy Halse <guy AT tenet.ac.za>, "edugain-discuss AT lists.geant.org" <edugain-discuss AT lists.geant.org>
- Subject: RE: [eduGAIN-discuss] HSM use cases
- Date: Thu, 28 Mar 2019 09:20:40 +0000
- Accept-language: en-GB, en-US
- Authentication-results: spf=none (sender IP is ) smtp.mailfrom=alan.lewis AT geant.org;
Hello Guy,
Thanks for the feedback. Some comments below.
Best regards
Alan
Alan Lewis Trust and Identity Services Product Manager
GÉANT Mobile: +44 (0) 7500 891616 Switchboard: +44 (0)1223 371300 Networks • Services • People Learn more at www.geant.org GÉANT Vereniging (Association) is registered with the Chamber of Commerce in Amsterdam with registration number 40535155 and operates in the UK as a branch of GÉANT Vereniging. Registered office: Hoekenrode 3, 1102BR Amsterdam, The Netherlands. UK branch address: City House, 126-130 Hills Road, Cambridge CB2 1PQ, UK.
From: Guy Halse <guy AT tenet.ac.za>
Hi On 2019/03/19 18:44, Alan Lewis wrote:
One thing that is (probably obviously) important is the ability to create secure backups for DR purposes. >> Yes I agree that generating the keys outside the HSM has benefits in terms of key backup and recovery. The key thing is that the process for doing this is itself secure. I >>don’t know what mechanisms the USB tokens have to do this, so it would be useful to take a look if you can point me at any examples. I take your point that given this >>feature could be available on the Cryptech device at a similar price point to the USB token it could be attractive. On 2019/03/26 20:27, Peter Schober wrote: A few federations have deployed NetHSMs (I know about ~3), others maybe using smartcard-based HSMs (maybe 3-6?), the large majority(eduGAIN currently has 60 member federations) probably still signingwith software-based keys?I'm not aware we've asked federations to disclose this information yet. FWIW we're one of the ones using a smartcard-based HSM, specifically the Nitrokey HSM. >> Right. I’ll take a look at this device. I’m not familiar with its capabilities. b. Cryptographic algorithm support;Today pretty much only RSA with SHA2 based hashes is being used, AFAIK.I'll leave that to others. There are a number of people keeping half an eye on ECC too, and certainly if I was deploying something new, I'd like to see support for common EC primes that are likely to become significant over the next ~ 10 years. >>Noted. That would be my thought also. ECC is already widely used in other markets and I would expect it to be important within the community also.
--
|
Attachment:
smime.p7s
Description: S/MIME cryptographic signature
- Re: [eduGAIN-discuss] HSM use cases, (continued)
- Re: [eduGAIN-discuss] HSM use cases, Peter Schober, 26-Mar-2019
- Re: [eduGAIN-discuss] HSM use cases, Shannon Roddy, 26-Mar-2019
- RE: [eduGAIN-discuss] HSM use cases, Alan Lewis, 27-Mar-2019
- Re: [eduGAIN-discuss] HSM use cases, Muhammad Farhan SJAUGI, 27-Mar-2019
- RE: [eduGAIN-discuss] HSM use cases, Alan Lewis, 27-Mar-2019
- Re: [eduGAIN-discuss] HSM use cases, Peter Schober, 27-Mar-2019
- RE: [eduGAIN-discuss] HSM use cases, Alan Lewis, 27-Mar-2019
- Re: [eduGAIN-discuss] HSM use cases, Muhammad Farhan SJAUGI, 28-Mar-2019
- RE: [eduGAIN-discuss] HSM use cases, Alan Lewis, 28-Mar-2019
- Re: [eduGAIN-discuss] HSM use cases, Peter Schober, 27-Mar-2019
- RE: [eduGAIN-discuss] HSM use cases, Alan Lewis, 27-Mar-2019
- Re: [eduGAIN-discuss] HSM use cases, Guy Halse, 28-Mar-2019
- RE: [eduGAIN-discuss] HSM use cases, Alan Lewis, 03/28/2019
- Re: [eduGAIN-discuss] HSM use cases, Peter Schober, 28-Mar-2019
- Re: [eduGAIN-discuss] HSM use cases, Leif Johansson, 28-Mar-2019
- Re: [eduGAIN-discuss] HSM use cases, Peter Schober, 28-Mar-2019
- Re: [eduGAIN-discuss] HSM use cases, Leif Johansson, 28-Mar-2019
- Re: [eduGAIN-discuss] HSM use cases, Peter Schober, 28-Mar-2019
- Re: [eduGAIN-discuss] HSM use cases, Leif Johansson, 28-Mar-2019
- RE: [eduGAIN-discuss] HSM use cases, Alan Lewis, 28-Mar-2019
- Re: [eduGAIN-discuss] HSM use cases, Leif Johansson, 28-Mar-2019
- Re: [eduGAIN-discuss] HSM use cases, Peter Schober, 28-Mar-2019
- Re: [eduGAIN-discuss] HSM use cases, Leif Johansson, 28-Mar-2019
- RE: [eduGAIN-discuss] HSM use cases, Alan Lewis, 28-Mar-2019
- Re: [eduGAIN-discuss] HSM use cases, Shannon Roddy, 28-Mar-2019
- RE: [eduGAIN-discuss] HSM use cases, Alan Lewis, 29-Mar-2019
- Re: [eduGAIN-discuss] HSM use cases, Peter Schober, 28-Mar-2019
- RE: [eduGAIN-discuss] HSM use cases, Alan Lewis, 03/28/2019
Archive powered by MHonArc 2.6.19.