Remote signing of images with espsecure using yubikey
Posted: Mon Aug 29, 2022 5:32 pm
To keep the code signing private key secure I would like to configure and use a yubikey to sign the images (2nd stage boot loader / OTA apps). The instructions for signing images and creating the required signature blocks assume the private key is accessible on the signing server. By using an HSM (yubikey) the private key would but be accessible and therefore not be compromised.
Can espsecure be used as is to support this? If not can it be extended? Is this a good idea?
Thanks you!!
Can espsecure be used as is to support this? If not can it be extended? Is this a good idea?
Thanks you!!