Hello JP,

It's by design as nobody cared yet :-) I think it's easy to implement it. 
Unfortunately,
it requires a slight modification of the libdnssec API, so it won't be possible 
to backport it to 3.1.

Daniel

On 5/6/22 16:12, Jan-Piet Mens wrote:
I note that the key label is not set when Knot generates new keys via PKCS#11.
Invoking `p11tool --list-all' shows a key as

Object 449:
         URL: pkcs11:model=;manufacturer=nCipher%20Corp.%20Ltd;serial=xxx;\
         token=YYY;\
         id=%04%66%D0%9C%0D%9E%24%D9%79%0A%17%D3%5D%A0%CC%5A%3F%E2%A3%26;\
         type=public
         Type: Public key (RSA-2048)
         Label:
         ID: 04:66:d0:9c:0d:9e:24:d9:79:0a:17:d3:5d:a0:cc:5a:3f:e2:a3:26

The ID is that which `keymgr list' displays (with colons in it), but the label
is empty.

Is this by design? Would it be possible for Knot to actually set the label
(e.g. zone name - key type: example.com-ksk)?

Best regards,

     -JP
--
--

Reply via email to