pkcs11 private key for EAP-TLS (inbuilt RADIUS)

tom tomschuring at
Tue Sep 22 03:42:01 EDT 2020


I see some code in tls_connection_set_params that checks if the
private key starts with a pkcs11: and then tries to load the private
key from the engine.

however if i specify a private _key as:


it fails because it is expecting a file in this location inside

How can I specify a pkcs11 private key to be used for a EAP-TLS AP connection ?

Or am I reading the code wrong and is the tls_connection_set_paramter
only used inside the supplicant side ?


More information about the Hostap mailing list