OpenSSL and Entrust: Strengthening Software Trust Through Secure Code Signing
OpenSSL Corporation partnered with Entrust to strengthen code-signing security, protect cryptographic signing keys, and support its post-quantum cryptography strategy. Today, Entrust nShield HSMs help secure the software release process behind one of the world's most widely used cryptographic libraries.
Introduction
OpenSSL Corporation, a global leader in cryptographic solutions and the steward of the OpenSSL Library, one of the most widely deployed cryptographic libraries in the world. The software helps secure digital communications across industries ranging from financial services and government to telecommunications, cloud computing, and embedded devices. With millions of downloads and billions of secure connections relying on OpenSSL Library technologies, maintaining trust in every software release is critical.
As OpenSSL Corporation expanded its enterprise offerings and advanced its post-quantum cryptography initiatives, the organization sought a hardware-rooted security solution capable of protecting code-signing operations while supporting future cryptographic requirements. OpenSSL Corporation selected Entrust and its nShield HSM platform to help establish a stronger foundation for software integrity, operational governance, and cryptographic resilience.
The Challenge
As the organization responsible for maintaining one of the world's most trusted cryptographic projects, OpenSSL Corporation faces unique security requirements. Every OpenSSL Library release must be protected against unauthorized modification and distributed with confidence to organizations that depend on it for secure communications.
OpenSSL Corporation needed to strengthen its software-signing infrastructure, protect critical cryptographic keys, and establish governance controls that eliminate single points of trust. The organization also wanted to ensure its security strategy could support the industry's transition to post-quantum cryptography.
Key objectives included:
- Protecting software-signing keys from unauthorized access or exposure.
- Establishing a hardware-based root of trust for code-signing operations.
- Implementing operational controls that prevent any single individual from controlling critical cryptographic activities.
- Supporting future adoption of post-quantum cryptography standards.
- Maintaining security without disrupting OpenSSL Corporation's fast-paced development and release processes.
To achieve these goals, OpenSSL Corporation required a proven technology partner with deep expertise in hardware security and cryptographic infrastructure.
The Solution
OpenSSL Corporation selected Entrust nShield 5c network-attached HSMs to serve as the foundation of its secure code-signing environment. The solution provides tamper-resistant, hardware-based protection for cryptographic operations while helping OpenSSL Corporation align with industry security and compliance requirements.
Entrust's nShield platform enables OpenSSL Corporation to keep private signing keys protected within certified hardware, reducing the risk of exposure while ensuring software releases can be validated and trusted by users worldwide. The solution also supports OpenSSL Corporation's long-term post-quantum strategy through compatibility with emerging cryptographic algorithms and standards.
Key elements of the solution include:
- Entrust nShield HSMs providing hardware-enforced protection for code-signing keys.
- Secure code-signing workflows that help ensure software authenticity and integrity.
- Support for post-quantum cryptographic algorithms, including ML-KEM, ML-DSA, and SLH-DSA.
- Multi-person authorization controls that require collaboration among trusted custodians for critical cryptographic operations.
A notable aspect of OpenSSL Corporation's implementation is its use of the nShield Security World's standard K-of-N quorum model. This well-established control requires multiple authorized custodians to participate in critical operations, helping ensure that no single individual can independently access or control sensitive code-signing processes. The approach aligns with OpenSSL Corporation's broader commitment to transparency, accountability, and operational rigor in protecting the cryptographic assets that underpin its software releases.
OpenSSL and its derivatives are the cryptography most of the internet links against. We protect the signing keys the way that responsibility demands, and we prove it in recurring ceremonies rather than asking anyone to take our word. Entrust cleared our bar. Not many do.
— Tim Hudson, President, OpenSSL Corporation
The Results
With Entrust nShield HSMs now integrated into its code-signing infrastructure, OpenSSL Corporation has strengthened the protection of the software releases trusted by organizations around the world. The deployment provides both technical safeguards and operational controls designed to protect the integrity of the OpenSSL Library software supply chain.
Key outcomes include:
- Hardware-Protected Code Signing
- OpenSSL Corporation's signing keys remain protected within Entrust nShield HSMs, helping safeguard software integrity and authenticity.
- Strong Governance Through Multi-Person Controls
- A quorum-based security model requires participation from multiple trusted custodians before critical actions can be performed.
- Operational Resilience
- Recurring card-check ceremonies help ensure cryptographic assets remain accessible, functional, and recoverable over time.
- Post-Quantum Readiness
- The deployment provides a foundation for future adoption of post-quantum cryptographic standards and algorithms.
- Trust at Global Scale
- Hardware-rooted security and strong governance controls help reinforce trust in software relied upon by billions of secure digital interactions.
Together, these capabilities provide OpenSSL Corporation with a secure foundation for protecting software releases today while supporting future cryptographic innovation.
Looking Ahead
As cryptographic threats continue to evolve and organizations place greater emphasis on software supply chain security, OpenSSL Corporation remains focused on protecting the infrastructure that underpins secure communications worldwide.
Entrust nShield HSMs now provide a critical layer of protection for OpenSSL Corporation's release processes, helping secure cryptographic assets through hardware-backed security, quorum-based controls, and governance practices designed for long-term resilience. OpenSSL Corporation's adoption of operational processes such as card-check ceremonies demonstrates a continued commitment to transparency, accountability, and maintaining trust in one of the world's most important cryptographic projects.
As OpenSSL Corporation advances its post-quantum roadmap and expands its enterprise offerings, Entrust will continue to support the organization's mission of delivering trusted, secure cryptography to the global technology ecosystem.
Related Resources
Entrust nShield 5c
Network-attached HSMs for protecting cryptographic keys and operations.
Entrust nShield Connect
Hardware security modules for high-assurance cryptographic protection.
OpenSSL Corporation
Learn more about OpenSSL Corporation and its cryptographic solutions.
Fill out the form to have one of our experts contact you to discuss how our solutions can serve you.