On 30 jun 2009, at 07.33, Rickard Bondesson wrote: > We should do the hashing in the host and not via an HSM. What do you > think of that? Then we would only need to do signing and key > generation in the hsm. are there any HSM that does not support signing only (and thus MUST do the hashing itself)? jakob