After much struggling, I finally changed SE Linux settings to
"permissive" and the HSM is now visible and usable. The PKCS11
config file from Utimaco (cs2_pkcs11.ini) also needed to be in
the /etc folder for JSS+NSS to see the HSM.
While this got the CA installed, I've run into an issue that
seems to be unresolved from a thread back in Nov 2009:
https://www.redhat.com/archives/pki-users/2009-November/msg00017.html
Bugzilla apparently has the fix and the server.xml has the right
values for clientAuth, but the bad MAC error keeps appearing for
every HTTPS page in my test installation.
Is there any resolution to John Dorovski's problem? His last
message remains unanswered.
Thanks.
Arshad Noor
StrongAuth, Inc.