I've just started looking at this, and I've got a couple of 
questions:

1. could this engine be considered a general PKCS#11 engine, or are 
there specific ties to Trustway.  I'd prefer to see a general 
PKCS#11 engine.

2. Those extra functions in the RSA method, are they really needed?  
I understand that they provide a lot of automagic things, but then 
it should be added in the ENGINE framework as something that would 
be potentially available for any hardware (that supports that extra 
functionality).  Also, when it comes to loading keys, the current 
modus operandi is to explicitely use the ENGINE key loading 
functions rather than having some implicit functionality going on.  
The reason is that we'd prefer not to surprise the users too much.

-- 
Richard Levitte
[EMAIL PROTECTED]
______________________________________________________________________
OpenSSL Project                                 http://www.openssl.org
Development Mailing List                       [EMAIL PROTECTED]
Automated List Manager                           [EMAIL PROTECTED]

Reply via email to