Code Signing Tool with keys in HSM

取消
显示结果 
显示  仅  | 搜索替代 
您的意思是: 

Code Signing Tool with keys in HSM

98 次查看
ThomasGu
Contributor I

Hi

when signing an bootloader with code signing tool (cst) the private key is needed to create the signature.

We want to have the private keys in a HSM but not the certificates (which are stored on the file system)

All the examples define the certificate to be used for signing (e.g. in the CSF file):

[Install CSFK]
File = "pkcs11:token=CST-HSM-DEMO;object=CSF1_1_sha256_2048_65537_v3_usr;type=cert;pin-value=${USR_PIN}"

So I wondering how I can tell the cst which private key it should use.

Thanks in advance

Thomas

0 项奖励
回复
0 回复数