[15510] in Kerberos_V5_Development
Re: pkinit prompting behavior issue
daemon@ATHENA.MIT.EDU (Jeffrey Hutzelman)
Tue Feb 23 11:38:09 2010
Date: Tue, 23 Feb 2010 11:38:05 -0500
From: Jeffrey Hutzelman <jhutz@cmu.edu>
To: Nicolas Williams <Nicolas.Williams@sun.com>
Message-ID: <B0602D2396F9BEB709E9B886@minbar.fac.cs.cmu.edu>
In-Reply-To: <20100223162150.GV1061@Sun.COM>
MIME-Version: 1.0
Content-Disposition: inline
Cc: Sam Hartman <hartmans@mit.edu>, MIT Kerberos Dev List <krbdev@mit.edu>,
jhutz@cmu.edu
Content-Type: text/plain; charset="us-ascii"
Content-Transfer-Encoding: 7bit
Errors-To: krbdev-bounces@mit.edu
--On Tuesday, February 23, 2010 10:21:50 AM -0600 Nicolas Williams
<Nicolas.Williams@sun.com> wrote:
> As for PKCS#11 softtokens on USB drives... I believe that a softtoken
> implementation should present N virtual slots, all empty, and when
> removable media becomes available (mounted) it should search the
> top-level for softtoken files, then pick the first available virtual
> slot and pretend that there is now a token in that slot (and
> C_Wait4Slot() should allow you to wait on a virtual slot). Of course,
> having virtual softtoken slots means that one could not skip an "insert
> token" prompt on the basis of there being no slots.
We're not talking only about USB softtokens. We're also talking about real
tokens, which present as a USB-connected smartcard "reader" containing a
"card" which is an integral part of the device. Until you insert the USB
token, the reader is not present in the system. Of course, there are
non-smartcard devices that behave the same way.
_______________________________________________
krbdev mailing list krbdev@mit.edu
https://mailman.mit.edu/mailman/listinfo/krbdev