psf/psf-tuf-runbook

nitrohsm-provision should not require cleartext security officer pin on the command line

ewdurbin opened this issue · 0 comments

nitrohsm-provision should prompt for security officer pin after starting.

this led to leaking of a single character, and later the full SO pin for one HSM during our ceremony on 2020-10-30, requiring a diceware break.