Re: [opensc-devel] Key renewals in HSMs

2011-01-07 Thread Anders Rundgren
Robert Relyea wrote: > On 01/07/2011 09:25 AM, Anders Rundgren wrote: >> Slightly off-topic but I guess some of you guys have more insight in >> HSMs than most other people have :-) >> >> In a recent project there were a requirement for frequent and *automated* >> renewals of certificates. The ren

Re: [opensc-devel] Key renewals in HSMs

2011-01-07 Thread Andreas Jellinghaus
maybe use a central ca creating the keys and storing them (and the cert) on the cards? that way the key would be created by the hsm of the ca. of course you would need a card with secured and authenticated connection to it, so you can be sure to store key&cert on the card of your choice. opensc u

Re: [opensc-devel] Key renewals in HSMs

2011-01-07 Thread Robert Relyea
On 01/07/2011 09:25 AM, Anders Rundgren wrote: > Slightly off-topic but I guess some of you guys have more insight in > HSMs than most other people have :-) > > In a recent project there were a requirement for frequent and *automated* > renewals of certificates. The renewal procedure is based on c

Re: [opensc-devel] Key renewals in HSMs

2011-01-07 Thread Peter Stuge
Anders Rundgren wrote: > In a recent project there were a requirement for frequent and *automated* > renewals of certificates. The renewal procedure is based on creating > a self-signed request which is then signed by the original key. > > It appears that the new key cannot (for a *remote* CA) be

Re: [opensc-devel] Key renewals in HSMs

2011-01-07 Thread Martin Paljak
On Jan 7, 2011, at 7:25 PM, Anders Rundgren wrote: > Slightly off-topic but I guess some of you guys have more insight in > HSMs than most other people have :-) > > In a recent project there were a requirement for frequent and *automated* > renewals of certificates. The renewal procedure is bas

[opensc-devel] Key renewals in HSMs

2011-01-07 Thread Anders Rundgren
Slightly off-topic but I guess some of you guys have more insight in HSMs than most other people have :-) In a recent project there were a requirement for frequent and *automated* renewals of certificates. The renewal procedure is based on creating a self-signed request which is then signed by th