my users have requested their certificate from the PUB interface clicking on... the "Request a certificate with automatic browser detection" link (but I suppose that I get something different from a token, don't I?) these certificates (now contained in LDAP and in the users' Browsers) will be used for securing message exchange...
In this case the private key is in the keystore of your browser, so you have first to export the key from the browser and than put it onto the token. This has nothing to do with OpenCA and the needed steps depend on the browser you used for requestiong
Oliver -- Diese Nachricht wurde digital unterschrieben oliwel's public key: http://www.oliwel.de/oliwel.crt Basiszertifikat: http://www.ldv.ei.tum.de/page72
smime.p7s
Description: S/MIME Cryptographic Signature
