XMLSecTool V2, PKCS#11 and Java 11
Ian Young
ian at iay.org.uk
Wed Sep 16 14:45:50 UTC 2020
Hi folks,
If you've been using the XMLSecTool application to sign (e.g.) metadata aggregates for a federation, using a hard token via the PKCS#11 interface, please contact me off-list.
It looks like the --pkcs11Config option for performing this kind of operation doesn't work in XMLSecTool V2 under Java 9+, and specifically under Java 11. There are workrounds, but they're not pretty.
We've been intending to bring everything up to a Java 11 baseline for some time, and we'll therefore be bringing out an XMLSecTool V3 for that environment and to fix this issue. I'd like to make sure that anyone affected has an opportunity to test before that happens. Hence the request for contact.
Cheers,
-- Ian, lead XMLSecTool guy
-------------- next part --------------
A non-text attachment was scrubbed...
Name: smime.p7s
Type: application/pkcs7-signature
Size: 3883 bytes
Desc: not available
URL: <http://shibboleth.net/pipermail/users/attachments/20200916/c713a168/attachment.p7s>
More information about the users
mailing list