JJ
Jakub Jelen
— On the schedule —
What shall we do with two PKCS#11 providers?
We started working on PKCS#11 provider for OpenSSL in 2022 and it was moved under openssl-projects last year. While we explored an opportunity to reuse the existing libp11's backend of pkcs11 engine, it was turned down due to various reasons. But the libp11 developers decided to implement the provider interface in early 2025 too, which puts us into the world where we have two different implementation of the same thing and users end up being confused how these can be used. OTOH, in the spirit of open source, these two can benefit from each other bugs (and fixes), compatibility testing or in other unexpected ways. In this talk, I would like to dive into these two projects, their similarities, differences and limitations to help users and developers to understand the difference and help to improve both of them.
— Compositor's note —
Software Engineer in Red Hat, working on Security technologies related to cryptograhy, Smart Cards, PKCS#11, SSH and everything that is connected to these.