[prev in list] [next in list] [prev in thread] [next in thread] 

List:       gnutls-dev
Subject:    Re: [gnutls-devel] gnutls_pkcs11_add_provider() duplicate modules detection
From:       Jan Včelák <jan.vcelak () nic ! cz>
Date:       2016-07-15 9:06:44
Message-ID: 057ce848-6870-6eae-7ae5-7427f15b06ef () nic ! cz
[Download RAW message or body]

Hi.

On 15.7.2016 09:27, Nikos Mavrogiannopoulos wrote:
> I'm not sure if there is a solution to that either. You could compare
> whether the ck_info matches, but I've seen few cases of modules having
> these fields identical (e.g., one could be remoted and the other
> local). However, getting duplicate items can also happen with
> different libraries. E.g., if you register both opensc and
> opensc-onepin, as well as coolkey, you'll get objects in piv card
> listed three times.

Hm, right. I was just wondering how reliable this is expected to be.

> Why not address that in the configuration?

That is what I will have to do, probably. At the moment, our software
(Knot DNS) can be configured to use multiple private key stores. And you
can manually specify the provider for each key store. So we just call
gnutls_pkcs11_add_provider() explicitly when we need to access the keys.

Regards,

Jan

_______________________________________________
Gnutls-devel mailing list
Gnutls-devel@lists.gnutls.org
http://lists.gnupg.org/mailman/listinfo/gnutls-devel
[prev in list] [next in list] [prev in thread] [next in thread] 

Configure | About | News | Add a list | Sponsored by KoreLogic