Re: [opensc-devel] Question about pkcs11-helper

2009-04-07 Thread Alon Bar-Lev
Great! Good luck! On Tue, Apr 7, 2009 at 2:35 PM, Stéphanie De Maerteleire wrote: > Hello, > > I haven't tried pkcs11-dump yet, but from a few certificates I looked at, it > looks like their issuer just isn't included on the token, so then it's normal > pkcs11-helper doesn't show them. I'm pret

Re: [opensc-devel] Question about pkcs11-helper

2009-04-06 Thread Alon Bar-Lev
Hello, I did not say that all the certificates are stored on the card. I only said that you wil see those who are. You should use pkcs11-dump or any similar utility in order to see what objects are stored on your token. If there are certificate objects that are not visible, please send me the ou

Re: [opensc-devel] Question about pkcs11-helper

2009-04-03 Thread Alon Bar-Lev
Hello, The issuers you get are the root certificates. All other certificates are stored in the certs. Two facts you should consider: 1. It is not safe to store root certificates on PKCS#11 token, as anyone, even without authentication can add certificates into the token. 2. Storing the complete c