Skip to content

Create integration for OpenPGP certificates with multiple component keys

With !19 (merged) we currently only support OpenPGP certificates with a single component key. This is usually enough for our signing setup, but in the future it would be great to be able to support OpenPGP certificates with multiple component keys.

A setup like that requires us to assign multiple NetHSM keys to the use of an OpenPGP certificate and encode the key IDs of the component keys in the certificate.

To upload designs, you'll need to enable LFS and have an admin enable hashed storage. More information