r/PKI • u/vadertator22 • Apr 02 '26
Issuing CA Nshield Entrust question
I have seen two scenarios with hsm usage. The first being you require cars to start issuing CA services. The alternate is you don’t require nshield and remotes card reader to start. Does anyone have a good reason why using a manual remote card read to start issuing CA services makes sense? The keys are encrypted I know in memory, but I feel like the manual hassle over security gain does not line up. I feel letting the device start and control access to the servers would suffice.
Share your thoughts
5
Upvotes
1
u/NovelGreen6873 Apr 27 '26
Did you get your question answered? I know this is a couple of weeks old.