🚀 Launch Week Day 5:Introducing Immutable Scans.Learn More →
Socket
Book a DemoInstallSign in
Socket

sigsum.org/key-mgmt

Package Overview
Dependencies
Alerts
File Explorer

Advanced tools

Socket logo

Install Socket

Detect and block malicious and high-risk dependencies

Install

sigsum.org/key-mgmt

Go Modules
Version
v0.2.5
Version published
Created
Source

Key management

This repository provides documentation and tooling for managing and accessing the private signing keys in the Sigsum system.

Documentation

  • Quick start instructions on YubiHSM provisioning and signing for log servers and witnesses via SSH agent.
  • Key management procedure using YubiHSMs

Repository overview

  • sigsum-agent A program that can act as a signing oracle, following the SSH agent protocol and conventions. Tailored to the needs of the Sigsum system, it supports Ed25519 signatures only, and it can use either a private key on disk, or a key stored in a YubiHSM (support for other types hardware keys, in particular TKey and Yubikey, is under consideration).
  • provisioning scripts A collection of scripts to provision YubiHSMs for use with Sigsum logs and witnesses.
  • To appear: SSH key and signature formats as importable Go packages

Contact

  • IRC room #sigsum @ OFTC.net
  • Matrix room #sigsum which is bridged with IRC
  • The sigsum-general mailing list

FAQs

Package last updated on 09 Jun 2025

Did you know?

Socket

Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.

Install

Related posts