<style>
/* Changing the layout to use less space for mobiles */
@media screen and (max-device-width: 480px), screen and (-webkit-min-device-pixel-ratio: 2) {
#email-body { min-width: 30em !important; }
#email-page { padding: 8px !important; }
#email-banner { padding: 8px 8px 0 8px !important; }
#email-avatar { margin: 1px 8px 8px 0 !important; padding: 0 !important; }
#email-fields { padding: 0 8px 8px 8px !important; }
#email-gutter { width: 0 !important; }
}
</style>
<div id="email-body">
<table id="email-wrap" align="center" border="0" cellpadding="0" cellspacing="0" style="background-color:#f0f0f0;color:#000000;width:100%;">
<tr valign="top">
<td id="email-page" style="padding:16px !important;">
<table align="center" border="0" cellpadding="0" cellspacing="0" style="background-color:#ffffff;border:1px solid #bbbbbb;color:#000000;width:100%;">
<tr valign="top">
<td bgcolor="#ffffff" style="background-color:#ffffff;color:#000000;font-family:Arial,FreeSans,Helvetica,sans-serif;font-size:12px;line-height:1;"><img src="https://shibboleth.net/images/shib_240x83.png" alt="" style="vertical-align:top;" /></td>
</tr><tr valign="top">
<td id="email-banner" style="padding:32px 32px 0 32px;">
<table align="left" border="0" cellpadding="0" cellspacing="0" width="100%" style="width:100%;">
<tr valign="top">
<td style="color:#505050;font-family:Arial,FreeSans,Helvetica,sans-serif;padding:0;">
<img id="email-avatar" src="https://issues.shibboleth.net/jira/secure/useravatar?avatarId=10202" alt="" height="48" width="48" border="0" align="left" style="padding:0;margin: 0 16px 16px 0;" />
<div id="email-action" style="padding: 0 0 8px 0;font-size:12px;line-height:18px;">
<a class="user-hover" rel="zccx04fxbfekk/ldylvfqohcyf4=@https://aai-logon.switch.ch/idp/shibboleth" id="email_zccx04fxbfekk/ldylvfqohcyf4=@https://aai-logon.switch.ch/idp/shibboleth" href="https://issues.shibboleth.net/jira/secure/ViewProfile.jspa?name=zccx04fxbfekk%2Fldylvfqohcyf4%3D%40https%3A%2F%2Faai-logon.switch.ch%2Fidp%2Fshibboleth" style="color:#326ca6;">Kaspar Brand</a>
commented on <img src="https://issues.shibboleth.net/jira/images/icons/bug.gif" height="16" width="16" border="0" align="absmiddle" alt="Bug"> <a style='color:#326ca6;text-decoration:none;' href='https://issues.shibboleth.net/jira/browse/XSTJ-19'>XSTJ-19</a>
</div>
<div id="email-summary" style="font-size:16px;line-height:20px;padding:2px 0 16px 0;">
<a style='color:#326ca6;text-decoration:none;' href='https://issues.shibboleth.net/jira/browse/XSTJ-19'><strong>XmlSecTool fails to read from PKCS11 keystore when using the pkcs11Config option</strong></a>
</div>
</td>
</tr>
</table>
</td>
</tr>
<tr valign="top">
<td id="email-fields" style="padding:0 32px 32px 32px;">
<table border="0" cellpadding="0" cellspacing="0" style="padding:0;text-align:left;width:100%;" width="100%">
<tr valign="top">
<td id="email-gutter" style="width:64px;white-space:nowrap;"></td>
<td>
<table border="0" cellpadding="0" cellspacing="0" width="100%">
<tr valign="top">
<td colspan="2" style="color:#000000;font-family:Arial,FreeSans,Helvetica,sans-serif;font-size:12px;padding:0 0 16px 0;width:100%;">
<div class="comment-block" style="background-color:#edf5ff;border:1px solid #dddddd;color:#000000;padding:12px;"><p>I took over the job of maintaining the SWITCH metadata signing machinery from Patrik in the meantime, so allow me to jump in... the way we're using xmlsectool right now, I would actually prefer <tt>--pkcs11Config</tt> being an optional parameter.</p>
<p>Currently the usage states:</p>
<div class="preformatted panel" style="border-width: 1px;"><div class="preformattedContent panelContent">
<pre>PKCS11 Device Certificate/Key Options - these options are mutually exclusive with the PEM/DER and Keystore options. Options 'pkcs11Config' and 'key' are required. Option 'keyPassword' required when signing and, with some PKCS11 devices, during signature verification.
--pkcs11Config The PKCS11 token configuration file.
--key Specifies the key alias for the signing key is read.
--keyPassword Specifies the pin for the signing key.
--keystoreProvider The fully qualified class name of the PKCS11 keystore provider implementation. (default: sun.security.pkcs11.SunPKCS11)
</pre>
</div></div>
<p>In our case, I'm using a custom <tt>java.security</tt> file, which only loads those providers really needed for xmlsectool, i.e. we use</p>
<div class="preformatted panel" style="border-width: 1px;"><div class="preformattedContent panelContent">
<pre>security.provider.1=sun.security.provider.Sun
security.provider.2=sun.security.rsa.SunRsaSign
security.provider.3=sun.security.pkcs11.SunPKCS11 /path/to/pkcs11.cfg
</pre>
</div></div>
<p>which makes dynamic loading of the SunPKCS11 provider by xmlsectool unnecessary. That doesn't preclude Patrik's fix from being applied, of course, but it would be nice if <tt>--pkcs11Config</tt> can be made optional at the same time.</p>
<p>Finally, regarding your actual question: our pkcs11.cfg file just includes two lines - a <tt>name</tt> and the <tt>library</tt> attribute, which points to the PKCS#11 <tt>.so</tt> file (cf. <a href="http://docs.oracle.com/javase/6/docs/technotes/guides/security/p11guide.html#Config" class="external-link">http://docs.oracle.com/javase/6/docs/technotes/guides/security/p11guide.html#Config</a>).</p></div>
<div style="color:#505050;padding:4px 0 0 0;"> </div>
</td>
</tr>
</table>
</td>
</tr>
</table>
</td>
</tr>
</table>
</td><!-- End #email-page -->
</tr>
<tr valign="top">
<td style="color:#505050;font-family:Arial,FreeSans,Helvetica,sans-serif;font-size:10px;line-height:14px;padding: 0 16px 16px 16px;text-align:center;">
This message is automatically generated by JIRA.<br />
If you think it was sent incorrectly, please contact your JIRA administrators<br />
For more information on JIRA, see: <a style='color:#326ca6;' href='http://www.atlassian.com/software/jira'>http://www.atlassian.com/software/jira</a>
</td>
</tr>
</table><!-- End #email-wrap -->
</div><!-- End #email-body -->