On of the most important facts about a smart card is, that the private key never leaves the card. It is generated there and stays there. If I request a certificate from Thwate like in the How To:

http://alioth.debian.org/docman/view.php/30111/8/musclecard.howto.txt

Whats is done there? A key pair is created and my public key is read and I get a certificate? Or is it done at the insecure computer and the result is transmitted?

Bye, Karsten
_______________________________________________
Muscle mailing list
[email protected]
http://lists.drizzle.com/mailman/listinfo/muscle

Reply via email to