← Prev in month ← Prev in thread
Next in thread → Next in month →

CKM_CERTIFY_KEY plus global objects

From
Michael StJohns
Date
2013-04-11T19:05:00+00:00
ID
Thread
CKM_CERTIFY_KEY plus global objects
This is not formatted as a drop in as of yet.
Two parts.
The first adds CKA_GLOBAL as an attribute to describe a class of objects that belong more to the implementation rather than to an initialized token.
This is where a token identity key and token identity certificate would reside.
I've sketched out a few global objects to explain how this might work.
Part two is the early definition of the CKM_CERTIFY_KEY mechanism which can be used by one private key to certify another private key (and its attributes) on the same token.
Note that this is actually dependent on CKA_PUBLIC_KEY_INFO.
Mike Attachment: pkcs11-global-attributes.dotx Description: application/vnd.openxmlformats-officedocument.wordprocessingml.template
← Prev in month ← Prev in thread
Next in thread → Next in month →