which HSM for secure boot keys

I remember some discussion about how to store the shim keys at
debconf, and some hardware security module being passed around.  I'm
looking for a recommendation for a HSM for my own shim keys.  Was
there ever a conclusion on how to store the keys for debian, and does
anyone remember what that little usb HSM was?

