> On 15/10/2012, at 3:10 AM, Ondřej Surý <[email protected]> wrote:
>
> > Just a question - would anyone would be interested in joining a
> > project to build an OpenHardware FPGA-based HSM with focus on DNSSEC?

One interesting possibility might be to wire the keys into the FPGA
configuration, so it has to be re-flashed to change keys.

George Michaelson <[email protected]> wrote:
>
> I'm particularly interested in its ability to support a key migration
> mechanism which would prevent capture of the signing materials by a
> single implementation.

Why not do a key rollover rather than a migration?

Tony.
-- 
f.anthony.n.finch  <[email protected]>  http://dotat.at/
Forties, Cromarty: East, veering southeast, 4 or 5, occasionally 6 at first.
Rough, becoming slight or moderate. Showers, rain at first. Moderate or good,
occasionally poor at first.
_______________________________________________
dns-operations mailing list
[email protected]
https://lists.dns-oarc.net/mailman/listinfo/dns-operations
dns-jobs mailing list
https://lists.dns-oarc.net/mailman/listinfo/dns-jobs

Reply via email to