DM
Dmitry Misharov
— On the schedule —
HSM-Backed OpenPGP Signing for OpenSSL Releases: Architecture and Operations
For years, OpenSSL releases were signed with a private OpenPGP key stored in a file — first the release manager's own, then a shared automated one. This talk covers moving that trust root onto an Entrust nShield HSM: a two-tier key model that keeps a card quorum over the certification key while the pipeline signs unattended, the Rust tool we built to bridge OpenPGP and PKCS#11, and how that same HSM now signs RPM/DEB packages and Java code too.
— Compositor's note —
Dmitry Misharov is a Senior DevOps Engineer at OpenSSL Corporation, working on the infrastructure behind OpenSSL: release automation, the HSM-backed signing pipeline, and performance testing infrastructure. Dmitry designed and built the release-signing migration this talk covers, including the open-source sq-pkcs11 signing tool.