HSMs best practice

Trevor Lee Oakley <trevor@...>

I have been using softhsm2 and testing that. It has a lot of options. Given the basic problem of CAs being Org based, I was wondering if any guidelines exist for HSMs. I saw AWS have a service and I think Azure has one too.
I am wondering especially if there is any recommended way of storing keys on actual hardware versus a software based service.
Does anyone have any views?

