Signing TLS handshakes inside a TPM
Summary
A detailed technical post about signing TLS handshakes inside a TPM for confidential VMs. The author argues that a TPM-bound private key stays inside the machine, reducing leakage risk, and walks through provisioning, practical constraints, and performance implications, including comparisons with KMS approaches and notes on deployment considerations.