Confium PKI

Confium PKI is the public-key-infrastructure product: run a CA without a single trusted key. Issue, revoke, and prove via threshold signing.

Components

  • confium-pki — X.509 cert, CSR, CMS SignedData, XMLDSig
  • confium-composite — Composite signatures for PQ migration
  • confium-attributes — Attribute-based signing predicates
  • confium-pkcs11-server — Drop-in HSM replacement via PKCS#11
  • confium-openssl-provider — OpenSSL 3.0 provider
  • confium-jce-provider — Java Cryptography Extension provider
  • confium-tls-signer — TLS 1.3 signature callback

Concepts

How-to

Reference

In this section