opendnssec / SoftHSMv2

SoftHSM version 2
http://www.softhsm.org/
Other
767 stars 339 forks source link

PIN is not asked during delete of a slot #754

Open sharathbu opened 1 month ago

sharathbu commented 1 month ago

While trying to delete a slot, it is not mandated to use PIN ? Isn't this a security loophole. During slot initialisation, PIN and SO_PIN is asked and it serves as a purpose of Authentication. The same should be mandated during deletion as well. For import, PIN is being asked.