Hello Petr,

> Unfortunately, it is absolutely crucial feature and we can't migrate to v2 
> until we find a way how to do key exports.

Are you talking about wrapped export, or plaintext export of private keys?

> I understand that it is not desirable to enable this by default, it is 
> perfectly fine to provide key export in separate binary (i.e. not built-in 
> into softhsm2-util).

What you want is a bypass for private key protection… which is exactly what 
PKCS #11 is designed to avoid.

This sounds to me like you should not be looking for problem resolution in 
SoftHSM, but in the surrounding process.  It might transpire that your 
application is unsuitable for use with PKCS #11, or requires more advanced 
cryptography that can deal with encapsulated private keys.

Confused,
 -Rick_______________________________________________
Opendnssec-user mailing list
[email protected]
https://lists.opendnssec.org/mailman/listinfo/opendnssec-user

Reply via email to