Carahsoft, in conjunction with its vendor partners, sponsors hundreds of events each year, ranging from webcasts and tradeshows to executive roundtables and technology forums.

Government Events and Resources

Events

Thales_LOGO_.png
Thales Trusted Cyber Technologies (TCT)

CTO Sessions: Quantum-Resistant Code Signing


Event Date: April 25, 2024
Hosted By: Thales TCT & Carahsoft

Stateful hash-based signature (HBS) schemes are digital signature schemes believed to be resistant to the threat posed by a cryptographically relevant quantum computer. NSA’s CNSA 2.0 encourages vendors to adopt stateful HBS schemes as defined in SP 800-208 immediately for all software and firmware code signing, with a requirement to support them by 2025.

SP 800-208 requires that all stateful HBS key generation and signature algorithms be implemented within a FIPS 140 certified HSM with level 3 physical security.  Furthermore, the HSM “shall not allow for the export of private keying material.” This is intended to ensure that the state of the OTS signature keys is always enforced and keys are never reused, which would introduce cryptologic vulnerabilities into the signature scheme.

Attendiees of this webcast learned about Thales TCT’s SP800-208 Compliant Code Signing Solution. Thales TCT’s crypto-expert, Evan Pelecky, discussed topics including:

  • What stateful HBS schemes are
  • How stateful HBS schemes compare to classical algorithms
  • When to use stateful HBS for code signing
  • What SP 800-208 requirements are for hardware security modules
  • How Thales Luna hardware security modules support LMS/HSS

Fill out the form below to view this archived event.


Resources


Featured

From court filings to right of way agreements, notarized documents are essential to completing key government agency transactions. Today, most notarizations are paper-based and are conducted in person. This requires scheduling an office visit for multiple constituents, and wait times for documents t...

With the $550 billion dollars of Infrastructure Investment and Jobs Act funding allotted for states, there is a tremendous opportunity for state-level Departments of Transportation (DoTs) to leverage this funding for transformative efforts. This funding provides an opportunity to modernize and optim...

Digitally transform mission-critical workflows with DocuSign for Government.

This ebook is designed to walk through the details of measuring impact. It combines data from commissioned industry surveys, internal pricing/usage reports, qualitative interviews and more to give actionable answers to some of the most common e-signature questions. By the end of this document, any t...

Docusign is the leader in contract management. Learn how to keep your business moving by streamlining the contract lifecycle. Eliminate manual processes and reduce unnecessary risk.

Docusign eSignature is a secure solution that enables organizations to streamline agreement workflows, reduce manual processes, and accelerate business outcomes. eSignature can be easily integrated with over 400 applications and is backed by enterprise-grade security—empowering organizations t...

More than 3,000 federal, state, and local government agencies in all 50 states use Docusign to work with electronic forms, agreements, applications, correspondence, management, and approval processes. Learn more about how Docusign and ServiceNow are working together to make it easier for government ...

Docusign extends the value of the Salesforce platform considerably by enabling documents to be generated automatically from data in Salesforce, negotiated, edited, and routed through complex workflows. Docusign solutions help agencies accelerate turnaround times, reduce risk, eliminate manual proces...

Docusign helps law enforcement agencies streamline case management by replacing outdated paper-based processes with secure digital workflows. The resources on this page showcase how digital tools such as eWarrants, subpoenas, and Salesforce integrations accelerate criminal investigations while safeg...

Article

State health and human services agencies face growing demands, high caseloads, and outdated manual processes that slow the delivery of critical support to children and families. This brief shows how Docusign Intelligent Agreement Management (IAM) helps streamline workflows from foster care and adopt...