+--On 23 août 2016 14:26:48 +0000 Mathieu Arnold via RT wrote: | | Ok, so I was kinda leaning toward what you are telling me. | | The OP says that stuff does not work, I'm going to see if there really is | something that does not work and get back to you. | | Thanks, So, the OP says that if the BIND9 port is built with the native-pkcs11 option, it fails with: root@freebsd:~ # dnssec-keyfromlabel -l 'pkcs11:object=sample_ksk;pin-source=/etc/token_pin' -a RSASHA256 -f KSK -v3 -E /usr/local/lib/softhsm/libsofthsm2.so example.com dnssec-keyfromlabel: fatal: failed to get key example.com/RSASHA256: built with no crypto support -- Mathieu Arnold