<?xml version="1.0" encoding="UTF-8"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en-gb">
<link rel="self" type="application/atom+xml" href="https://forum.yubico.com/feed.php?f=22&amp;t=662" />

<title>Yubico Forum</title>
<subtitle>...visit our web-store at</subtitle>
<link href="https://forum.yubico.com/index.php" />
<updated>2016-06-14T23:27:17+01:00</updated>

<author><name><![CDATA[Yubico Forum]]></name></author>
<id>https://forum.yubico.com/feed.php?f=22&amp;t=662</id>
<entry>
<author><name><![CDATA[offset]]></name></author>
<updated>2016-06-14T23:27:17+01:00</updated>
<published>2016-06-14T23:27:17+01:00</published>
<id>https://forum.yubico.com/viewtopic.php?t=662&amp;p=8722#p8722</id>
<link href="https://forum.yubico.com/viewtopic.php?t=662&amp;p=8722#p8722"/>
<title type="html"><![CDATA[Re: RSA key store]]></title>

<content type="html" xml:base="https://forum.yubico.com/viewtopic.php?t=662&amp;p=8722#p8722"><![CDATA[
Would be interested in a HSM that supported RSA sign function with a flexible PIN policy that includes no PIN as an option.<br /><br />Scenario would be automated code signing to protect the private key.<p>Statistics: Posted by <a href="https://forum.yubico.com/memberlist.php?mode=viewprofile&amp;u=4371">offset</a> — Tue Jun 14, 2016 11:27 pm</p><hr />
]]></content>
</entry>
<entry>
<author><name><![CDATA[Anonymous]]></name></author>
<updated>2011-04-15T08:41:54+01:00</updated>
<published>2011-04-15T08:41:54+01:00</published>
<id>https://forum.yubico.com/viewtopic.php?t=662&amp;p=2652#p2652</id>
<link href="https://forum.yubico.com/viewtopic.php?t=662&amp;p=2652#p2652"/>
<title type="html"><![CDATA[RSA key store]]></title>

<content type="html" xml:base="https://forum.yubico.com/viewtopic.php?t=662&amp;p=2652#p2652"><![CDATA[
A use case suggested by a number of applicants to the YubiHSM beta program is to secure private RSA keys used in asymmetric encryption.<br /><br />As can be read on the YubiHSM product page (under Use cases), there is currently only support for symmetric AES ECB encryption/decryption, and HMAC-SHA1 hashing (plus other unrelated features).<br /><br />Just encrypting the RSA private key with AES will not provide very much added security since an attacker that gains access to the host with the YubiHSM could just ask the YubiHSM to decrypt the RSA key.<br /><br />At this stage, we do not think you can achieve meaningful protection of RSA keys using the YubiHSM (but please prove us wrong =)), but we are listening to the feedback and potential use cases for the YubiHSM while refining our product roadmap.<br /><br />/Fredrik<p>Statistics: Posted by Guest — Fri Apr 15, 2011 8:41 am</p><hr />
]]></content>
</entry>
</feed>