<html><head><meta http-equiv="Content-Type" content="text/html charset=us-ascii"></head><body style="word-wrap: break-word; -webkit-nbsp-mode: space; -webkit-line-break: after-white-space;" class=""><br class=""><div><blockquote type="cite" class=""><div class="">On 19 Sep 2017, at 16:45, Rainer Hoerbe <<a href="mailto:rainer@hoerbe.at" class="">rainer@hoerbe.at</a>> wrote:</div><br class="Apple-interchange-newline"><div class=""><span style="font-family: Monaco; font-size: 13px; font-style: normal; font-variant-caps: normal; font-weight: normal; letter-spacing: normal; text-align: start; text-indent: 0px; text-transform: none; white-space: normal; word-spacing: 0px; -webkit-text-stroke-width: 0px; float: none; display: inline !important;" class="">Do you use some legacy syntax for the -key option?<span class="Apple-converted-space"> </span></span></div></blockquote></div><div class=""><br class=""></div>No, the format of the -key option to openssl req depends on the engine, I think. In this case 0:10 represents slotid 0 keyid 10.<div class=""><br class=""></div><div class="">This is the article I used to get my token working:</div><div class=""><br class=""></div><div class=""><a href="https://raymii.org/s/articles/Get_Started_With_The_Nitrokey_HSM.html" class="">https://raymii.org/s/articles/Get_Started_With_The_Nitrokey_HSM.html</a></div><div class=""><br class=""></div><div class="">I don't have the same token you do, and as I implied before one of the problems with this area is that every single token in the world seems to work in a slightly different way. So it's hard for me to make practical suggestions as to how to configure your token. In particular, I have no knowledge of the PKCS11-URIs you're using. So what you're doing may be equivalent to what I'm doing, or it may not be, I can't tell.</div><div class=""><br class=""></div><div class="">You've hit the limit of my knowledge, I'm afraid. If you wanted to buy a Nitrokey HSM, I am pretty sure we could get you running, but I can't debug what I can't replicate (and I think we're agreed that this actually isn't an XMLSecTool problem, so in terms of configuring the token the OpenSC lists might have more people who understand your token at this level).<br class=""><div class="">
<span class="Apple-style-span" style="border-collapse: separate; font-variant-ligatures: normal; font-variant-east-asian: normal; font-variant-position: normal; line-height: normal; border-spacing: 0px;"><div style="word-wrap: break-word; -webkit-nbsp-mode: space; -webkit-line-break: after-white-space;" class=""><span class="Apple-style-span" style="border-collapse: separate; color: rgb(0, 0, 0); font-family: Helvetica; font-size: 12px; font-style: normal; font-variant: normal; font-weight: normal; letter-spacing: normal; line-height: normal; orphans: 2; text-indent: 0px; text-transform: none; white-space: normal; widows: 2; word-spacing: 0px; border-spacing: 0px; -webkit-text-decorations-in-effect: none; -webkit-text-stroke-width: 0px;"><div class=""><span class="Apple-tab-span" style="white-space: pre;"><br class="Apple-interchange-newline"></span>    -- Ian<br class=""></div><div class=""><span class="Apple-style-span" style="font-size: medium;"><br class=""></span></div></span></div></span><br class="Apple-interchange-newline"><br class="Apple-interchange-newline">
</div>
<br class=""></div></body></html>