> Next great thing would be for ISC to support the Soft-HSM that > OpenDNSSEC uses. I believe that this would make the step of moving to a > real hardware HSM a lot easier (if necessary). BIND has supported the PKCS#11 interface (./configure --with-pkcs11) since 9.6 IIRC, so it ought to be possible to integrate. -JP