pkinit slotid=N ?

Glenn Barry Glenn.Barry at sun.com
Tue Jan 8 16:06:36 EST 2008


Hi,

I had the Solaris KMF (Key Management Framework) team review the pkinit
options in MIT Kerberos V 1.6.3-beta1 and for this one:

  
PKCS11:[module_name=]module-name[:slotid=slot-id][:token=token-label][:certid=cert-id][:certlabel=cert-label]

they noted that slotid= is not a good idea as there is no guaranteed
ordering of numbering of slots returned from C_GetSlotList().

That is, slot or token names are useful but numbers are not.

I see slotid= is optional but was wondering if it was useful for anybody?

(And likewise for certid=)


thx.

Glenn Barry
Solaris Kerberos




More information about the krbdev mailing list