> Well, in theory maybe, but AFAIK we don't really support any kind of PKCS11 > hardware there. Sorry, I thought keystores natively did now. > Probably more simply, this will be used if the private key is stored in the file > an encrypted format, as opposed to unencrypted. I meant why you might want to, as opposed to what one could do. -- Scott