To use nCipher PKCS#11 devices with the CA EEM Server or the CA EEM SDK, configure the nCipher device and set the following property is set as follows:
CKNFAST_OVERRIDE_SECURITY_ASSURANCES=all
Note: For more information about how to configure the nCipher device with a hard token, see the nCipher documentation.
To configure the CA EEM Server to use certificates stored in a PKCS#11 devices, do the following:
Defines the type of certificate to be used. Supported certificate types are p12, pem, and p11.
Default: pem
Type: Childnode
<pkcs11Lib/>—Path to PKCS11 library provided by token
<token/>—Token id
<userpin/>—Munged user pin
<id/>—Certificate and private key id
<sensitive/>—Private key is sensitive. Sensitive keys are not converted as software keys and crypto operation are performed using the cryptopki hardware (nonsensitive key can be treated as sensitive, but sensitive keys cannot be converted or treated as nonsensitive key)
Default: False
| Copyright © 2011 CA. All rights reserved. | Email CA Technologies about this topic |