3 ms·
I'd say it's not a bad idea - oddly enough I've tried to do it the other way around (using a physical PKCS#11-compatible token on iOS devices). There are CAC-ty
by nickf 14y ago
I'd say it's not a bad idea - oddly enough I've tried to do it the other way around (using a physical PKCS#11-compatible token on iOS devices). There are CAC-type smartcard readers that operate over Bluetooth, but they're big and expensive.
A couple of thoughts:
Is there a reason you wouldn't use a 'real' hard-token like an eToken or similar? Yes, they need USB - but they're small and resilient. I generally have my keys on my all the time!
There's a project out there called LSM-PKCS11 that basically has encrypted storage 'boxes' (files) that are accessed via PKCS#11 via a daemon-client system over TCP. It might not be too hard to port the daemon to iOS. Somewhere to start, maybe?
http://www.clizio.com/lsmpkcs11.html http://www.clizio.com/lsmpkcs11.html