Hi Andreas!

> Try strongSwan from http://www.strongswan.org which has a regular
> PKCS#11 smartcard interface and allows to select certificates
> according to position e.g.
> 
>   leftcert=%smartcard#4
> 
> which is the fourth certificate in the enumeration shown by
> 
>   ipsec listcards
> 
> Read the details in the strongSwan smartcard configuration howto
> 
>   http://www.strongswan.org/docs/readme.htm#section_8

That's definitely a lot betten than selecting a certificate by ID only.
If the PKSCS11-spec would have named this value key-id instead
of just id (with the additional requirement that the id of a certificate
MUST be the same as the id of its key) this whole confusion
could have been avoided.

Peter
_______________________________________________________________________
Viren-Scan für Ihren PC! Jetzt für jeden. Sofort, online und kostenlos.
Gleich testen! http://www.pc-sicherheit.web.de/freescan/?mc=022222

_______________________________________________
opensc-devel mailing list
[email protected]
http://www.opensc-project.org/mailman/listinfo/opensc-devel

Reply via email to