[xmlsec] Mscrypto patch 2, for cvs XMLSEC_MSCRYPTO_083103 branch

Edward Shallow ed.shallow at rogers.com
Thu Sep 4 07:15:41 PDT 2003


Wouter,

    If one if using MS CAPI or CAPICOM, it is a foregone comclusion one is
working keys/certificates from the MS Crypto Store. Building support for
PKCS12 outside of the CAPI library makes no sense, since the test will not
be exercising the real MS Crypto and Key Store access built into CAPI.

    The test suite will have to change somewhat, or as a test pre-step, one
imports all the P12s into the MS Crypto Store and works with them from that
CAPI-centric location.

    Importing is supported bacl to Win98 no problem.

    We have been doing the reverse (while waiting for Wouter), that is:
exporting from the MS Crypto Store when the user session starts out to a
P12, and then using the an XMLSec/OpenSSL build on the exported key/cert. 

Ed  


-----Original Message-----
From: xmlsec-admin at aleksey.com [mailto:xmlsec-admin at aleksey.com] On Behalf
Of Roumen Petrov
Sent: September 4, 2003 3:28 AM
To: Wouter
Cc: Aleksey Sanin; xmlsec at aleksey.com

  Wouter wrote:

><SNIP>
>Great that you added the mscrypto option for the tests :)
>
>The tests indeed fail since importing of keys is nit supported at this 
>time. Iwas planning to implement pkcs12 support anyway. The only 
>disadvantage is that pkcs 12 import is only supported in windows XP, as 
>far as I know.
>
No Import of PKCS12 files *.{p12|.pfx} should work with NTx (nt4/w2k/xp) and
95x (+ME). Realy I cannot remember for w95, but for 98 works. When ms os has
instaled IE >= 5.x it should work fine.


_______________________________________________
xmlsec mailing list
xmlsec at aleksey.com
http://www.aleksey.com/mailman/listinfo/xmlsec





More information about the xmlsec mailing list