I just thought of a likely stupid, maybe fun idea.
instead of having the private key on the computer itself might it make sense to use a smartcard or HSM instead to keep the key to the certificate secure?
I just thought of a likely stupid, maybe fun idea.
instead of having the private key on the computer itself might it make sense to use a smartcard or HSM instead to keep the key to the certificate secure?
(post deleted by author)
heck you could even set it to go without PIN, while this obviously would make it possible for soemone to momentarily sign stuff, at the same time you can be sure that a certificate hasnt been taken away, and would not need to be revoked, which is doubly useful as revocation iirc is just an absolute mess.
a cloud “vault” or “cloud HSM” is category no thanks due to me basically trusting the cloud companies as much as I can buy them (i.e. not at all), and the thing is running locally on premise.
also this was more meant as an idea whether it might make sense to use it with caddy, or if it isnt part of caddy’s fearure set, to add it.
If I would have wanted an AI overview on the idea I couldhave done that myself and would not have asked in a forum.
heck, your long ass response doesnt even have ANYTHING about the idea of smartcards or similar things and caddy.
I am NOT criticizing the use of yubikey as an example, after all it IS one of the most widespread devices with PIV support people might be aware of and comes with the obvious bonus of not needing a reader.
but
your post doesnt even mention whether caddy could do this (and if yes how)
at least from how it looks you basically just did a google AI request and dumped the response with no real “human effort” to make a discussion so to speak.
before looking at your Post history I genuinely questioned if you are just a bot trying to grab views by dumping AI responses.
These 2 are the problems I see on your post.
the general arguments on whether a yubikey (or any type of smartcard/HSM for that matter) is a good idea and generally valid, and definitely worth the brainstorm.
Thanks Bruce; I appreciate your efforts to help. In the future though I would suggest avoiding copy-pasta from search engines / AIs, as the dominant content of a post.
I haven’t interfaced with HSMs or secure enclaves before directly, but I don’t think Caddy’s storage interface (CertMagic’s, really) is compatible with HSMs directly. We’d have to abstract it away by storing a locator or similar in storage.
With the help of an expert or, as a last resort LLMs, this would be worthy of exploring… but it is majorly overkill for most sites.