Discussion:
[OpenXPKI-users] HSM support
Cho Chan
2016-05-18 12:35:22 UTC
Permalink
Hi all,

Is openxpki supports PKCS#11 via OpenSC?
I am asking if I can use openxpki with low-end HSMs such as SmartCard-HSM
or Nitrokey HSM?

I tried to find something in the documentation but without success. If
someone is able to provide me with more details I would be grateful!

Thanks.
Cho
Martin Bartosch
2016-05-18 13:49:28 UTC
Permalink
Hi,

I have successfully integrated OpenXPKI with nCipher and - in a test environment - with Gemalto/SafeNet Luna-SA HSM.

A rudimentary PKCS#11 driver exists and AFAIR works with OpenSC (however, I did not test this myself).

Cheers

Martin
Oliver Welter
2016-05-18 17:04:39 UTC
Permalink
Post by Martin Bartosch
A rudimentary PKCS#11 driver exists and AFAIR works with OpenSC (however, I did not test this myself).
I can confirm this - I had a PoC install using a Feitian USB token with
PCSC/OpenSC.

Oliver
--
Protect your environment - close windows and adopt a penguin!
Cho Chan
2016-05-24 09:52:20 UTC
Permalink
Thanks Oliver and Martin.

I ordered one USB hsm device compatible with openSC and after I receive it
I will do some tests.


Regards,
Cho
Post by Martin Bartosch
A rudimentary PKCS#11 driver exists and AFAIR works with OpenSC (however,
Post by Martin Bartosch
I did not test this myself).
I can confirm this - I had a PoC install using a Feitian USB token with
PCSC/OpenSC.
Oliver
--
Protect your environment - close windows and adopt a penguin!
------------------------------------------------------------------------------
Mobile security can be enabling, not merely restricting. Employees who
bring their own devices (BYOD) to work are irked by the imposition of MDM
restrictions. Mobile Device Manager Plus allows you to control only the
apps on BYO-devices by containerizing them, leaving personal data
untouched!
https://ad.doubleclick.net/ddm/clk/304595813;131938128;j
_______________________________________________
OpenXPKI-users mailing list
https://lists.sourceforge.net/lists/listinfo/openxpki-users
Loading...