<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/"><channel><title>Hsm on Chris Zinda</title><link>https://czinda.io/tags/hsm/</link><description>Recent content in Hsm on Chris Zinda</description><generator>Hugo -- 0.146.0</generator><language>en-us</language><lastBuildDate>Thu, 07 May 2026 00:00:00 +0000</lastBuildDate><atom:link href="https://czinda.io/tags/hsm/index.xml" rel="self" type="application/rss+xml"/><item><title>PKI.Next Part 3: FIPS 140-3 and the Crypto Pluggability Problem</title><link>https://czinda.io/posts/pki-next-part3-fips-and-hsm/</link><pubDate>Thu, 07 May 2026 00:00:00 +0000</pubDate><guid>https://czinda.io/posts/pki-next-part3-fips-and-hsm/</guid><description>How PKI.Next uses Rust feature flags and trait objects to support three cryptographic backends — ring, aws-lc-rs (FIPS 140-3), and PKCS#11 hardware — without a single if-else in the certificate issuance path.</description></item></channel></rss>