Andreas --

Many thanks for the very quick response!

On Sun, Nov 11, 2012 at 6:31 AM, Andreas Schwier
<andreas.schw...@cardcontact.de> wrote:
> In the current version of OpenSC, the CSR is not exposed at the
> interface, as PKCS#11 does not provide a mechanism to handle device
> generated certificate signing requests. In a later version we will try
> to make the CSR available as a session based data object.

Ok, good to know I'm not going crazy.

> The suggested way in the meantime is to generate the key pair, extract
> the public key and generate a CSR externally, signing it with the
> private key on the device.

That's where I was going next, although I'm having issues with
openssl.  I'll give it another shot later today.

If you happen to have an example session that shows that sequence of
activities, it would be very helpful.

Thanks again!

Best regards,
Anthony Foiani
_______________________________________________
opensc-devel mailing list
opensc-devel@lists.opensc-project.org
http://www.opensc-project.org/mailman/listinfo/opensc-devel

Reply via email to