Re: Unable to read PKCS#8 file generated using OpenSSL command linetool

2008-10-01 Thread Julien R Pierre - Sun Microsystems
David, David Stutzman wrote: >> If you are only trying to protect the private key from being >> extracted, >> then the answer is obvious - don't use a software token, use >> an HSM that >> stores the key in such a way that it cannot be extracted. > > And when Julien says HSM, a USB crypto tok

RE: Unable to read PKCS#8 file generated using OpenSSL command linetool

2008-10-01 Thread David Stutzman
> If you are only trying to protect the private key from being > extracted, > then the answer is obvious - don't use a software token, use > an HSM that > stores the key in such a way that it cannot be extracted. And when Julien says HSM, a USB crypto token would provide security vastly superi