----- Original Message -----
From: "Kick Willemse" <[EMAIL PROTECTED]>
To: "lcs Mixmaster Remailer" <[EMAIL PROTECTED]>
Cc: <[EMAIL PROTECTED]>; <[EMAIL PROTECTED]>
Sent: Friday, September 22, 2000 3:07 PM
Subject: Re: Command-line tools supporting both PKCS#12 and PKCS#11


[...]
> What you would like is a n (application) to n (token) relation.
> Therefore you need to install some middleware on the clientside that
> supports both PKCS#11, CAPI and PKCS#12 and it is preferable that this
> middleware is developed by a non token manufacturer.

Actually, my goals are more modest: I just need a utility that allow me to
import and export a privkey+cert from a script. I already have the dynamic
libraries to present a PKCS#11 API (well, at least some of it) hiding the
details of the underlying communication protocol. Recent versions of
Netscape Communicator can do the import/export, but through a GUI - which is
unsuitable to automated production procedures.

> OpenSSL is supporting pkcs#12 and PKCS#11 at this moment

Uh? I couldn't find any mention of PKCS#11 in the docs. The version 0.9.6
(now in beta) supports external crypto engines, but through an API that
looks like proprietary.

Enzo

P.S. For the record, the device I'm presently dealing with is the Dallas
Java iButton 1.1.



Reply via email to