Skip to content

Add PKCS#11 / p11-kit verifier for Linuxย #157

@zecakeh

Description

@zecakeh

As mentioned in several places, the current problems with Linux are that the certificates are loaded only once and there are no trust decisions available.

Several distributions use p11-kit as a way to list certificates on the system and to list other PKCS#11 modules, and expose them via its API or a PKCS#11 proxy module. By interacting with it, we get an up-to-date list of certificates, and each certificate has a trust decision.

There is support for this in other TLS libraries:

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions