Package opencryptoki

Implementation of the PKCS#11 (Cryptoki) specification v3.0 and partially v3.1

https://github.com/opencryptoki/opencryptoki

Opencryptoki implements the PKCS#11 specification v3.0 and partially v3.1
for a set of cryptographic hardware, such as IBM 4767, 4768, 4769 and 4770
crypto cards, and the Trusted Platform Module (TPM) chip. Opencryptoki also
brings a software token implementation that can be used without any cryptographic
hardware.
This package contains the Slot Daemon (pkcsslotd) and general utilities.

Version: 3.25.0

See also: opencryptoki-ccatok, opencryptoki-icsftok.

General Commands

p11kmip Transfer cryptographic keys between PKCS #11 and KMIP.
p11sak Manage token keys in a PKCS #11 token repository.
pkcsconf configuration utility for the pkcsslotd daemon
pkcshsm_mk_change utility to manage and control the re-enciphering of secure keys for a concurrent HSM master key change for openCryptoki.
pkcsstats utility to display mechanism usage statistics for openCryptoki.
pkcstok_admin utility to administrate token directories of the Opencryptoki token repository.
pkcstok_migrate utility to migrate an ICA, CCA, Soft, or EP11 token repository to the FIPS compliant format introduced with openCryptoki 3.12.

File Formats

opencryptoki.conf Configuration file for pkcsslotd.
p11kmip.conf Configuration file for the p11kmip command.
p11sak_defined_attrs.conf Configuration file for p11sak list-key command.
policy.conf Configuration file for openCryptoki policies.
strength.conf Configuration file for openCryptoki strength configuration.

Miscellanea

opencryptoki A PKCS#11 implementation.

System Administration

pkcsslotd shared memory manager for opencryptoki