Using Nitrokey 3A Mini for build artifact signing key storage

Petr Štetiar ynezz at true.cz
Thu May 18 07:19:17 PDT 2023


Petr Štetiar <ynezz at true.cz> [2023-05-13 18:17:14]:

Hi,

> Current idea is to start using Nitrokey 3A Mini (nk3) USB security key for
> this purpose, nk3 would contain single Ed25519 based signing key with 10 year
> expiration, that means we're going to use single key for snapshot/release
> signing.

just provisioned the nk3 keys and pushed the public key[1], going to
ship the keys to their designated destinations in the upcoming days.

1. https://git.openwrt.org/6b42a5c8b7dc049b899869b2a1b94daf69ceb2f5

Cheers,

Petr
-------------- next part --------------
A non-text attachment was scrubbed...
Name: signature.asc
Type: application/pgp-signature
Size: 833 bytes
Desc: not available
URL: <http://lists.openwrt.org/pipermail/openwrt-devel/attachments/20230518/83278167/attachment.sig>


More information about the openwrt-devel mailing list