On 14.03.2007, at 22:40, Andreas Jellinghaus wrote:
I too prefer a config file option a lot over two binary modules.
This does not fit in a config file - only a configure script option
might be possible (read below)
It is only a way to get firefox working as expected, not to replace
the original pkcs11 module.
Regards, Andreas
p.s. if you want we can have some auto detection mechanism - like
matching for something that identifies the estid card and turns it
on per default for that card.
There are two *parallel* modules needed - one with only one pin/cert
that is used with firefox
for authentication purposes just because firefox can't handle the
full pkcs11 module;
and the current, original module for other consumers (like when the
the user signs a transaction at the bank, signature applet/plugin
uses opensc-pkcs11.so/dll to do the signing, or e-vote application
that also needs access to both keys to do its business)
Both are needed. Sounds silly but this turned out to be the fastest
and most reliable way to get firefox back on track (at least
regarding web authentication)
m.
--
Martin Paljak
_______________________________________________
opensc-devel mailing list
opensc-devel@lists.opensc-project.org
http://www.opensc-project.org/mailman/listinfo/opensc-devel