Re: [PATCH 0/2] Add bulk signing support for PKCS#11 keys
From: Eric Biggers
Date: Fri Oct 09 2026 - 09:59:37 EST
On Fri, Oct 09, 2026 at 12:19:13PM +0200, Massimiliano Marretta wrote:
> Add support for signing kernel modules in bulk when the signing
> key is stored on a PKCS#11 token.
>
> Currently scripts/sign-file signs one module per invocation. When
> the key lives on a PKCS#11 token (e.g. a Nitrokey HSM or a
> SmartCard-HSM), every invocation pays a fixed initialization cost
> of 25-36 seconds, which dominates the actual signing time. For a
> typical build with hundreds of modules this is impractical.
Can you elaborate on what problem you're trying to solve by using not
only asymmetric signatures, but also an HSM to hold the private key?
Have you considered hash-based integrity checking
(https://lore.kernel.org/linux-modules/20260505-module-hashes-v5-0-e174a5a49fce@xxxxxxxxxxxxxx/)?
- Eric