OP-TEE Archive on lore.kernel.org
 help / color / mirror / Atom feed
* OP-TEE queries
@ 2024-12-03 20:08 murali selvaraj
  0 siblings, 0 replies; 2+ messages in thread
From: murali selvaraj @ 2024-12-03 20:08 UTC (permalink / raw)
  To: op-tee

[-- Attachment #1: Type: text/plain, Size: 1257 bytes --]

Hi All,

We are currently working on standard PKCS#11 TA and I'm new to this topic
(PKCS11, OP-TEE,TA).

Please go through and share your inputs on the following queries.

-> slot
        How do we know how many slots are supported in my device?
        Is it based on the physical interface of the device or how do we
find the list of available slots without pkcs11-tool?
        Please share the details with an example.

-> token
        Is token is a kind of virtual to hold different objects(keys, cert
and so on).
        Can one token have private, public, leaf cert, intermediate ca
cert, root ca cart and so on or any limitations on the number of objects in
a token?
        Can we have each token be specific to the object ( for example ,
token1 will have cert, token 2 will have key, token 3 will have seed/client
cert )?
        How many tokens maximum support on each slot?

->    As part of pkcs11-tool, we have been using SO-PIN, user PIN,
token/label name which are more specific to security.
       If the normal world/REE is compromised, any sensitive data it holds,
including PINs and tokens, could be exposed.
       Do we have any access control mechanism to avoid this security issue
( in PKCS11 TA, OP-TEE context).

Thanks,
Murali.S

^ permalink raw reply	[flat|nested] 2+ messages in thread

end of thread, other threads:[~2024-12-11 10:13 UTC | newest]

Thread overview: 2+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
     [not found] < <CABBtTm973zFtNDixvV-9deQVJu3OUUux1sVckuKH9uSWJcFMnQ@mail.gmail.com>
2024-12-11 10:13 ` OP-TEE queries Etienne CARRIERE - foss
2024-12-03 20:08 murali selvaraj

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox