Richard Kettlewell

Results 2 issues of Richard Kettlewell

It can happen that the KDF produces more data than needed. This is probably harmless, but by zeroizing it anyway, we don't need to do any analysis.

This PR adds a new `pkcs11` key store. I have tested with nShield and SoftHSM. Usage is described in `trustmanager/p11store/pkcs11.md`. # Overview - The new key store appears last in...