* The lack of HSM support is not a concern as HSM manufacturers respond to the decisions of bodies like CABForum.
* There is a set of FIPS requirements and testing regimes etc. for SHA-3
* There are HSMs that have met those requirements. 

What is a concern related to HSMs is that the transition is widely supported so CAs do not have to make major changes to their infrastructure or change suppliers or use different hardware for SHA-3 certificates.

The availability of HSMs is a concern but it is actually the very last but one on the critical path which is at present

* NIST issues FIPS (done)
* IETF publishes specification (started on this)
* CABForum amends guidelines to permit use
* Browsers add support
* HSM vendors ship product
* CAs issue certificates.

This is the broader discussion, had during the last F2F (and some time before) about what the intrinsic goals are with the CA/B Forum requiring the use of a FIPS 140-2/3 Level 3 or CC EAL Level 4 key protection device. If the intent is solely for key protection, then the points Peter raised about utilizing 'raw' signing mode (whether PKCS#1 or literally raw RSA signing) are relevant - it suggests that the key material can be protected sufficiently (for RSA key sizes less than 4096 bits, assuming a FIPS-approved mode of operation) while still producing these signatures. If we take the view that such HSMs must operate in a FIPS-validated mode of operation, then it's very relevant to understand what methods exist to produce such signatures while still maintaining that operation (the method Peter raised is generally not available in a FIPS-approved mode of operation, depending on vendor, due to the fact that to maintain the FIPS mode of operation, the HSM needs to produce the message digest itself using an approved algorithm in an validated mode of operation). I realize that, given your general lack of participation in the Forum, except for pointing out when it's doing something you disagree with, you may not have followed those discussions, and may not have been aware that it's still very much an open and unresolved issue, with relevance to the operation of CAs today (particularly those with >= 4096-bit keys) and tomorrow (for those that would like to adopt EdDSA or SHA-3).

The issue is irrelevant.

The value of performing a transition of this type in advance is precisely that we can make such choices as we see fit. 

I do not see the need to issue SHA-3 certificates tomorrow or even next year. But I would like to be in a situation where we could begin issue in  36 months time should the need arise.

If CABForum decides it wants to do something and it is not completely ridiculous and is technically feasible then I have no doubt that the product managers at the HSM companies will provide product that meets those needs within an acceptable time frame.

The questions you raise are not relevant at this time. In fact they are purely orthogonal to the issue we are discussing.

