Hi Michael,
I have done this already with a little perl-script, which builds a Mime-Message with the p12-Attachment and the PIN, then using "openssl smime -encrypt ..." to encrypt the whole message-structure.
You run this script on the CA Maschine I guess ?
The encrypted email can be transported via dataexchange and email without any security concerns.
Is your CA connected to the network ? Or do you put the "mails" into the normal dataexchange process ?
Oliver -- Diese Nachricht wurde digital unterschrieben oliwel's public key: http://www.oliwel.de/oliwel.crt Basiszertifikat: http://www.ldv.ei.tum.de/page72
smime.p7s
Description: S/MIME Cryptographic Signature