From lars.nooden at gmx.com Mon Sep 1 09:13:26 2025 From: lars.nooden at gmx.com (=?UTF-8?Q?Lars_Nood=C3=A9n?=) Date: Mon, 1 Sep 2025 10:13:26 +0300 Subject: [gnutls-help] Signing an x509 Certificate Signing Request (CSR) with a smart card In-Reply-To: <8e4273d5-e356-41c3-aa1e-9cfc68003c47@gmx.com> References: <7db7a075-c010-4bbe-859d-56502496382f@gmx.com> <8e4273d5-e356-41c3-aa1e-9cfc68003c47@gmx.com> Message-ID: On 8/31/25 19:57, Lars Nood?n wrote: > On 7/25/25 13:45, Zoltan Fridrich wrote: >> Hello Lars, >> >> I think you can sign a CSR with certtool, the command might look >> something >> like this: >> *$ certtool --generate-certificate --load-request= >> --load-ca-privkey= --load-ca-certificate= >> --outfile=* >> but instead of providing file paths, you can provide PKCS#11 URIs which >> would look something like this >> "pkcs11:p11-kit- >> trust;manufacturer=PKCS%2311%20Kit;serial=1;token=System%20Trust". >> You can specify the concrete cert and keys by adding type,id and label to >> the uri, so maybe something >> like: "pkcs11:p11-kit- >> trust;manufacturer=PKCS%2311%20Kit;serial=1;token=System%20Trust;type=;object=