On 4/27/2010 11:04 PM, Arshad Noor wrote:
 All it seems to be doing is adding the PKCS11 library to the
 secmod.db for the new instance it is creating - something one
 can do manually even after the instance has been created. 
Right - but if you modify
both of these files and use the same "name" 
for the module for both then this gets picked up in the Supported Module 
section of the page.  Alternately, run the unmodified pkicreate, modify 
CS.cfg, stop the server, add the module manually and restart the 
server.  Make sure you use the same name.....
Mike
 You do have to restart the service so the servlet sees the new
 module in secmod.db, but I don't think it does anything else.
 Arshad Noor
 StrongAuth, Inc.
 P.S. How I miss the old Java installation wizard CS had; it
 was simple, elegant and allowed for significant configuration
 in the wizard.  You could have an instance of a CA up and
 running in less than 5 minutes.  Between rpm, perl scripts,
 HTML and servlets, the new installation process appears to
 have made installation one of the most complex parts of
 setting up a DogTag PKI.  What a pity.