Skip to content

KBS: Missing Features for Production #836

Open
@zvonkok

Description

@zvonkok

Here is a list of things Trustee doesn't do:

  • KBS is not close to FIPS 140-3 level 1 (software module) nor is it aligned with the relevant protection profiles for HSMs (including soft HSMs).
  • It is not well suited for a system of system attestation.
  • It’s not compliant with KMIP either
  • Does not plug into OSCP
  • Handling of the RIM database
  • Customizable attestation policies
  • Sealed secrets

Should an OTS solution like Vault be preferred? (or a cloud HSM so long as you’re not single infrastructure vendor) and Trustee brokers it to the backend?

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions