The OpenSSL Corporation Strengthens Code Signing Security, Future-Proofs Against Quantum Threats with Entrust nShield HSMs
The Californer/10325006

Trending...
OpenSSL
NEWARK, Del. - Californer -- The OpenSSL Corporation is preparing its production code signing environment with Entrust nShield 5c network-attached Hardware Security Modules (HSMs). Selecting Entrust HSMs marks a significant step in strengthening the integrity and resilience of the OpenSSL Library's software releases.

The FIPS 140-3 certified HSMs will provide a secure root of trust for the OpenSSL Library code signing keys, helping to ensure production code cannot be forged or tampered with. This step is essential for maintaining the trust placed in the OpenSSL Library, which underpins billions of secure communications worldwide.

The OpenSSL Corporation and Entrust share a longstanding collaboration within various standards bodies that are focused on delivering interoperable solutions. Most recently, the two organisations contributed to activities standardising hybrid algorithms that combine classical and post-quantum algorithms.

By choosing Entrust, the OpenSSL Corporation gains both proven support for classical cryptography and the capability to transition smoothly toward post-quantum security. The nShield 5c includes support for all of the current standardised NIST post-quantum algorithms, including ML-KEM, SLH-DSA, as well as the ML-DSA algorithms, for quantum-safe digital signing, offering future-proof protection as quantum computing advances.

More on The Californer
"We are now in the process of integrating Entrust nShield HSMs within our infrastructure, which will allow us to provide hardware-based code signing with a clear path forward to securing against tomorrow's cryptographic challenges," said Tim Hudson, President of the OpenSSL Corporation.

"Entrust is proud to collaborate with OpenSSL to provide a hardware root of trust for their production code signing environment, powered by our flagship nShield 5c HSMs," said Mike Baxter, President and Chief Technology & Product Officer at Entrust. "By leveraging the production ready post-quantum security capabilities of our HSMs and implementing the NIST-standardised ML-DSA algorithm, OpenSSL can ensure that their code is securely protected today and resilient against future quantum threats."

About the OpenSSL Corporation


The OpenSSL Corporation is a global leader in cryptographic solutions, specialising in developing and maintaining the OpenSSL Library – an essential tool for secure digital communications. The OpenSSL Corporation provides a range of services tailored to assist businesses of all sizes to ensure the secure and efficient implementation of OpenSSL Library solutions. The OpenSSL Corporation also supports Projects aligned with its Mission and Values by providing infrastructure, resources, expert advice, and engagement through advisory committees.

More on The Californer
About Entrust

Entrust fights fraud and cyber threats with comprehensive identity-centric security that protects people, devices, and data. Entrust solutions help enterprises and governments safeguard critical systems from every angle, enabling secure onboarding and issuance, providing everyday identity protection, and empowering them with 360-degree visibility and orchestration across keys, secrets, and certificates so they can transact and grow with confidence. Building on its decades as a pioneer and innovator in establishing trust, Entrust has a global partner network and supports customers in over 150 countries. For more information, visit www.entrust.com.

Contact
OpenSSL Corporation
***@openssl.org


Source: OpenSSL Corporation

Show All News | Report Violation

0 Comments

Latest on The Californer