[Opendnssec-maintainers] Fwd: SoftHSM v2 status?

Rickard Bellgrim rickard at opendnssec.org
Thu Jun 19 07:11:21 UTC 2014


Some useful information when migrating between SoftHSMv1 and SoftHSMv2.

---------- Forwarded message ----------
From: Rickard Bellgrim <rickard at opendnssec.org>
Date: Thu, Jun 19, 2014 at 8:48 AM
Subject: Re: [Opendnssec-user] SoftHSM v2 status?
To: Paul Wouters <paul at nohats.ca>
Cc: Petr Spacek <pspacek at redhat.com>, Jaap Akkerhuis <jaap at nlnetlabs.nl>, "
Opendnssec-user at lists.opendnssec.org List" <
opendnssec-user at lists.opendnssec.org>


On Thu, Jun 19, 2014 at 5:28 AM, Paul Wouters <paul at nohats.ca> wrote:

> - Does softhsm2 change the API/ABI ?
>

The library is using the same version of PKCS#11, but have implemented more
functions.

The support tools have been changed, e.g. softhsm -> softhsm2-util

New configuration file: softhsm2.conf


> - Is softhsm2 able to read/convert softhsm1 stores/files ?
>

softhsm2-migrate

- Is there a migration method for going from softhsm1 to softhsm2 that
>   we can do for known softhsm stores on package update?
>   (eg the stores in /var/softhsm)


Read token/file paths from softhsm.conf, initiate equal numbers of tokens
in SoftHSMv2, migrate old token databases using the command above.

// Rickard
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://lists.opendnssec.org/pipermail/opendnssec-maintainers/attachments/20140619/d3d793f8/attachment.htm>


More information about the Opendnssec-maintainers mailing list