Hacker News new | ask | show | jobs
by traceroute66 1817 days ago
> inconvenience of now having a single point of failure in the build process (unless multiple certs are purchased).

Except that's not quite true is it.

Most (all ?) devices (even the cheap USB ones) have secure wrapped backup/restore mechanisms.

All you had to do was set up your device correctly in the first place (since the wrapping can't be activated retrospectively).

Some of the cert vendors even have ready-made instructions available to follow on their website telling you exactly how to do this: https://www.ssltrust.co.uk/help/setup-guides/mofn-setup-nitr...

RTFM as they say. ;-)

1 comments

Correct me if I'm wrong, but when a fully preconfigured YubiKey is shipped to you as part of the EV cert fulfillment, then there is no way to do this after-the-fact.