For your PEM formatted keys, why a vault? Don't vaults just advertise "what is in here is SUPER important"? Police love vaults. Wouldn't it be safer on a sd hiding case in a few places (mom's house in attic, one under your oven?)
I should have explained this better: the vault is not to keep the private key safe from home intruders, itβs to keep the key safe from loss and fire and anyone that might compromise my CA machine. It acts as an air gap of sorts.
Once in a blue moon when the intermediate cert expires, I pull out the QR code and scan it and convert it to a PEM on a burner laptop, VM, or phone. There I generate a new intermediate and securely delete the root PEM file and put the QR back in the vault. Then I copy the inermediate off the burner machine and go about my business.
Glue the QR code onto an old boarding pass and keep it in your photo album... then stick a broken yubikey into your grandmothers coffin for plausible deniability.
- the latter is a joke ofcourse! :)
For plausible deniability it's a lot less controversial to mix a broken yubikey in concrete and cast it as pavement.
https://www.amazon.com/US-Mint-Quarter-Covert-Compartment/dp...