There has been several suggestions in various security lists that a HW token
during a CSR (Certificate Signing Request) should be able to counter-
sign the request with a key and cert identifying the container itself.

The reason for this is that certain CA policies require that the users only
have store (and use) keys in "strong cases".

Pardon my ignorance, but is there any kind of standard practice for
deploying vendor keys?  Links would be higly appreciated.

In addition I would like to know how one could handle such keys from
a PKCS #11 interface.

thanx,
Anders Rundgren
_______________________________________________
Muscle mailing list
[email protected]
http://lists.drizzle.com/mailman/listinfo/muscle

Reply via email to