From: Jakub J. <jj...@re...> - 2016-10-04 09:56:02
|
Hello all, recently we discussed the usefulness of the onepin library and basically came to conclusion that the onepin should be used by default. Most of the cards have only one pin (if there is the second, it is most probably not needed to be visible in the PKCS#11, since should be "signature pin") and also the PKCS#11 specification is moving away from the mapping of multiple pins to multiple PKCS#11 tokens (citation needed?). The intention of this email is to start a discussion, if we still want to have virtual slots by default. Mozilla is not going to expose the "friendly bit" in UI [1], which would be possible workaround. But AFAIK, we could make that default and for the other use cases create some virtual-slots-opensc-pkcs11.so which would behave like the current default. [1] https://bugzilla.mozilla.org/show_bug.cgi?id=322145 Regards, -- Jakub Jelen Security Technologies Red Hat |