PKCS11 debugging
Hi - hope this is the right place for this and my question is not going to be to vague. Oh and someone answers it would be good. We have a number of Sun-Fire-T1000 and Sun-Fire-T2000 web servers. All run IBM IHS (Apache HTTP) and all make use of the on chip cryptographic capabilities to offload the SSL functions. Without doing this the servers simply become overloaded in less than a minute. So whatever this clever on chip functionality is it certainly works, well mostly.
We've recently started to get some generic SSL handshake errors in our web servers logs and although I've pursued this extensively with IBM they've come back and stated that they would need to see some PKCS11 traces - I believe they are referring to this particular library file as this is defined in the web servers configuration files as - SSLPKCSDriver /usr/lib/libpkcs11.so.1