On Mon, 2016-03-14 at 21:28 +0000, Blumenthal, Uri - 0553 - MITLL
wrote:
> You are right - the command line was wrong. Here’s the correct line,
> which
> should work, but doesn’t:
> 
> $ openssl cms -engine pkcs11 -aes256 -encrypt -in data.txt -binary
> -outform PEM -out data.txt.enc
> "pkcs11:object=Certificate%20for%20Key%20Management;object-type=cert"

Yeah, that won't work either. 

Perhaps you need the "-certform engine" option.

Which doesn't exist. :)

(My mailer doesn't seem to trust your signing cert, btw. Should you be
including an intermediate certificate in your messages? For that
matter, should I? :)


-- 
David Woodhouse                            Open Source Technology Centre
david.woodho...@intel.com                              Intel Corporation

Attachment: smime.p7s
Description: S/MIME cryptographic signature

-- 
openssl-dev mailing list
To unsubscribe: https://mta.openssl.org/mailman/listinfo/openssl-dev

Reply via email to