Code Signing Best Practices Pre & Post HSM (Hardware Security Module)

  Рет қаралды 2,538

David Anderson

David Anderson

Күн бұрын

Пікірлер: 6
@espressotonic
@espressotonic 8 ай бұрын
Security best practices are always a struggle between the ideal and the practical. This is one instance where the ideal has won and using code signing is becoming less and less practical.
@BRODZELi
@BRODZELi 2 ай бұрын
Thank you for sharing this valuable information! I have a question: I'm a beginner developer with no experience in code signing (I haven't purchased any certificates yet). I'm currently developing software using Tauri, which will run on both Windows and macOS. As a single developer not working with a team or a company, which certificate authority do you recommend for purchasing a certificate for my app? Any recommendations would be greatly appreciated.
@bdeem20
@bdeem20 4 ай бұрын
Thanks for this video, David - greater primer; we're investigating code signing now and just learned of the changes related to HSM requirements as of June 2023. Sincerely appreciate the knowledge shared here. Stay safe!
@espressotonic
@espressotonic 8 ай бұрын
These HSM changes are great for large companies that have unlimited resources they can dedicate to it. Which small companies or open source developers have the time and energy to implement these complicated processes?
@DX7Dev
@DX7Dev 7 ай бұрын
In the simplest case, you get a USB device with your certificate purchase, and you plug it into the computer that needs to do signing and configure the vendor software that provides access to the certificates. If it's a cloud hosted machine you can setup a VPN connection to an network where the physical machine is located, and script your signing process to sign on the remote machine. There's a little more to it than that, but code signing is still pretty easy to do. You don't necessarily need your own HSM
@GaneshkumarM-ks8my
@GaneshkumarM-ks8my 6 ай бұрын
@@DX7Dev Thanks David, But How we can actually store and retrieve the purchased code signing certificate in the AWS HSM and I'm only able to see an options of siging a file only by using key pair that we generated in the HSM itself.
What is a Hardware Security Module? And why do we really need it?
1:10:55
Please Help This Poor Boy 🙏
00:40
Alan Chikin Chow
Рет қаралды 19 МЛН
From Small To Giant Pop Corn #katebrush #funny #shorts
00:17
Kate Brush
Рет қаралды 70 МЛН
Electric Flying Bird with Hanging Wire Automatic for Ceiling Parrot
00:15
How Does a Hardware Security Key Like YubiKey Work?
11:17
Ask Leo!
Рет қаралды 38 М.
AZ-204 Key Vault Masterclass: Secrets, Security, and Best Practices Explained
46:54
What is a Hardware Security Module?
9:29
TWiT Tech Podcast Network
Рет қаралды 1 М.
NixOS Setup Guide - Configuration / Home-Manager / Flakes
3:01:39
Matthias Benaets
Рет қаралды 190 М.
Network Security - Deep Dive Replay
3:08:19
Kevin Wallace Training, LLC
Рет қаралды 159 М.
An Introductory QGIS Workshop for Beginners
3:49:41
QGIS North America
Рет қаралды 525 М.
CompTIA Security+ Full Course: Public Key Infrastructure (PKI)
43:48
Certify Breakfast
Рет қаралды 12 М.
Hardware Security Module - Executing Unsigned Code in HSM TEE
33:28
Digital Certificates: Chain of Trust
16:41
Dave Crabbe
Рет қаралды 291 М.