We should make a note somewhere that for production purposes, OpenDNSSEC should statically link the SoftHSM libraries, to avoid snooping by rogue pkcs11 library proxies. Regards, Roy Arends Sr. Researcher Nominet UK