Boring infrastructure: Building a secure signing environment (asg2024) episode artwork

EPISODE · Sep 26, 2024 · 42 MIN

Boring infrastructure: Building a secure signing environment (asg2024)

from Chaos Computer Club - archive feed · host David Runge

Many Linux distributions rely on cryptographic signatures for their packages and release artifacts. However, most of the used signing solutions either do not rely on hardware backed private key material or are run in untrusted environments. This presentation will provide a general overview of the [Signstar](https://gitlab.archlinux.org/archlinux/signstar/) project, which is currently under development by Arch Linux to provide a generic signing solution based on a Hardware Security Module (HSM). To improve build automation and general supply chain security for Arch Linux, some of its developers have started to conceptualize and work on a generic, central signing solution: [Signstar](https://gitlab.archlinux.org/archlinux/signstar/). In this context, related work has been evaluated for adoption, but it soon became clear, that to meet the distribution's requirements a custom solution would be implemented. For transparency and auditability reasons Nitrokey's NetHSM has been chosen as Hardware Security Module (HSM). Developers are actively working on a high-level Rust library and CLI to interface with the device over network. In this presentation I will introduce the viewer to some of Arch Linux's relevant history and requirements, the evaluated architecture and setup. Together we will have a look at Signstar's threat model, its design for minimizing credentials exposure of the HSM, as well as its integration with the OpenPGP ecosystem. Additionally, we will explore avenues for future work on other generic cryptographic operations in the context of X.509, SSH and Secure Boot. Licensed to the public under https://creativecommons.org/licenses/by/4.0/de/ about this event: https://cfp.all-systems-go.io/all-systems-go-2024/talk/WWEGGC/

Episode metadata supplied by the publisher feed · Published Sep 26, 2024

Embed this episode

NOW PLAYING

Boring infrastructure: Building a secure signing environment (asg2024)

0:00 42:29

No transcript for this episode yet

We transcribe on demand. Request one and we'll notify you when it's ready — usually under 10 minutes.

No similar episodes found.

No similar podcasts found.

Frequently Asked Questions

How long is this episode of Chaos Computer Club - archive feed?

This episode is 42 minutes long.

When was this Chaos Computer Club - archive feed episode published?

This episode was published on September 26, 2024.

Can I download this Chaos Computer Club - archive feed episode?

Yes. Use the download control on the episode player to save the publisher-provided media file.
URL copied to clipboard!