> > > > dnssec-keyfromlabel -a RSASHA1 -l pkcs11:foobar foobar > This assumes you have already created a RSA key called "foobar" in the HSM. Thanks Mark, So, can I assume that the "out of memory" error really means it just can't find the key? Regards, Greg