OpenSSL 3 and black key?

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 

OpenSSL 3 and black key?

1,209 Views
Christian-R
Contributor I

Hi,

We are interested in being able to use CAAM to support OpenSSL with black keys for signing operations.

OpenSSL 3 recommends using a new interface called "Provider".

It appears there's no ready CAAM "Provider" implementation without using something like OP-TEE. Could someone confirm or deny this?

If there's no ready implementation, any suggestions, is there any official support integrating black key sign/verify operations to mbedTLS, OpenSSH, OpenGPG, etc..?

Thanks,
Christian

0 Kudos
Reply
3 Replies

1,150 Views
Christian-R
Contributor I

If possible we'd like to _not_ have to use OPTEE.
Do you know if that's possible?

Regard,
Christian

0 Kudos
Reply

1,085 Views
Harvey021
NXP TechSupport
NXP TechSupport

Have also checked with internal security team, no positive answer without OPTEE.

 

Regards

Harvey

0 Kudos
Reply

1,158 Views
Harvey021
NXP TechSupport
NXP TechSupport

Hi,

Hope that the section <10.4.8 OpenSSL TLS offload to OP-TEE PKCS#11 via pkcs11-provider> of UG10163.pdf be helpful.

 

Regards

Harvey

0 Kudos
Reply