• tal@olio.cafeOP
    link
    fedilink
    English
    arrow-up
    1
    ·
    4 天前

    I’m pretty sure that you can use something like a YubiKey as a PKCS#11 certificate store, if the issue is just the card reader form factor.

    kagis

    Yeah:

    https://developers.yubico.com/yubico-piv-tool/YKCS11/

    This is a PKCS#11 module that allows external applications to communicate with the PIV application running on a YubiKey.

    • boonhet@sopuli.xyz
      link
      fedilink
      English
      arrow-up
      3
      ·
      4 天前

      That solves one issue, the other being how buggy it can be to use in the browser. The file signing feature is separate software (which has an official Linux port!), but to log into your bank, etc, browsers often pre-decide for you which certificate you want to use and then complain that it’s not present. Perhaps it’s changed now, I haven’t used it much in quite a few years now because Mobiil-ID and Smart-ID have just worked 99% of time.