Re: [Opendnssec-user] ods-hsmutil

2012-07-13 Thread Paul Wouters
On Fri, 13 Jul 2012, Rickard Bellgrim wrote: Remember that the physical keys are stored in the HSM. We also need more properties than just the key values (exponent, modulus, ...). This is why we need the KASP Enforcer Database. This database will have the "key metadata" like KSK, ZSK, CKA_ID, ro

Re: [Opendnssec-user] ods-hsmutil

2012-07-13 Thread Rickard Bellgrim
On Fri, Jul 13, 2012 at 5:57 PM, elsif wrote: > So, this same Keyper HSM with 36 (or more) keys on it... > > I run an "inittoken" now. > > "ods-hsmutil list" shows me no keys. I haven't nuked the APP keys via the > HSM console, though. They're still there but hsmutil doesn't show them. > Why? I

Re: [Opendnssec-user] ods-hsmutil

2012-07-13 Thread elsif
So, this same Keyper HSM with 36 (or more) keys on it... I run an "inittoken" now. "ods-hsmutil list" shows me no keys. I haven't nuked the APP keys via the HSM console, though. They're still there but hsmutil doesn't show them. Why? Is hsmutil really reading ~/Keyper/keymap.db, and not con