PKCS#11 Function Coverage
Every Cryptoki 3.2 function, mechanism and attribute in the DuoKey PKCS#11 library, and its exact status.
The library implements the single-part subset of Cryptoki needed to manage and use keys through the DuoKey Cockpit. Every slot in the function table is a valid pointer: implemented functions do the work, and the rest return a clear error (CKR_FUNCTION_NOT_SUPPORTED or CKR_FUNCTION_NOT_PARALLEL).
Implemented functions
General purpose
| Function | Behaviour |
|---|---|
C_GetFunctionList | Returns the function table (the only exported symbol). |
C_Initialize | Loads configuration, builds the proxy client, initializes global state. |
C_Finalize | Tears down global state. |
C_GetInfo | Reports Cryptoki 3.2, library 0.1, manufacturer "DuoKey". |
Slot & token management
| Function | Behaviour |
|---|---|
C_GetSlotList | Presents exactly one virtual slot (slot_id from config). |
C_GetSlotInfo | Static "DKE Cockpit Virtual HSM Slot", flags CKF_TOKEN_PRESENT | CKF_HW_SLOT. |
C_GetTokenInfo | Token flags and metadata (best-effort from the proxy, with an offline fallback). |
C_GetMechanismList | Returns the advertised mechanism list (see below). |
C_GetMechanismInfo | Key-size range and flags per mechanism; OR-s CKF_HW into the flags. |
Session management
| Function | Behaviour |
|---|---|
C_OpenSession | Serial sessions only; parallel rejected with CKR_SESSION_PARALLEL_NOT_SUPPORTED. |
C_CloseSession | Closes a session. |
C_CloseAllSessions | Closes all sessions for the slot. |
C_GetSessionInfo | Derives the RO/RW × public/user state. |
C_Login | Moves the session to the user state. No PIN is transmitted; only CKU_USER / CKU_CONTEXT_SPECIFIC are accepted. |
C_Logout | Clears the logged-in flag. |
Object management
| Function | Behaviour |
|---|---|
C_FindObjectsInit / C_FindObjects / C_FindObjectsFinal | Queries the Cockpit with the template filter, interns and pages the results. |
C_GetAttributeValue | Answers attributes from the cached descriptor (buffer-length protocol supported). |
C_DestroyObject | Deletes the object at the Cockpit and forgets the handle. |
Encryption & decryption (single-part)
| Function | Behaviour |
|---|---|
C_EncryptInit / C_Encrypt | Single-part encrypt; for AES-GCM the tag is appended to the ciphertext. |
C_DecryptInit / C_Decrypt | Single-part decrypt. |
Signing, verification & digest (single-part)
| Function | Behaviour |
|---|---|
C_SignInit / C_Sign | Single-part sign. |
C_VerifyInit / C_Verify | Single-part verify; CKR_SIGNATURE_INVALID when the backend reports invalid. |
C_DigestInit / C_Digest | Keyless single-part digest (computed at the Cockpit). |
Key management
| Function | Behaviour |
|---|---|
C_GenerateKey | Generates a symmetric key (requires login). |
C_GenerateKeyPair | Generates an asymmetric key pair (requires login). |
C_WrapKey | Wraps a key under a wrapping key. |
C_UnwrapKey | Unwraps a blob into a new key object. |
Random
| Function | Behaviour |
|---|---|
C_GenerateRandom | Requests N random bytes from the backend. |
C_SeedRandom | Accepted and ignored — the backend RNG cannot be seeded by the client. |
Not supported
- Token / PIN administration —
C_InitToken,C_InitPIN,C_SetPIN - Operation state —
C_GetOperationState,C_SetOperationState - Object create / copy / size / set-attribute —
C_CreateObject,C_CopyObject,C_GetObjectSize,C_SetAttributeValue - Multi-part encrypt / decrypt —
C_EncryptUpdate,C_EncryptFinal,C_DecryptUpdate,C_DecryptFinal - Multi-part digest —
C_DigestUpdate,C_DigestKey,C_DigestFinal - Multi-part / recover sign & verify —
C_SignUpdate,C_SignFinal,C_SignRecoverInit,C_SignRecover,C_VerifyUpdate,C_VerifyFinal,C_VerifyRecoverInit,C_VerifyRecover - Dual-function —
C_DigestEncryptUpdate,C_DecryptDigestUpdate,C_SignEncryptUpdate,C_DecryptVerifyUpdate - Key derivation —
C_DeriveKey - Slot events —
C_WaitForSlotEvent
C_GetFunctionStatus, C_CancelFunction (legacy parallel-function management).
These operations are not used by the supported key workflows, which are single-part by construction.
Mechanisms
C_GetMechanismList advertises the mechanisms below. C_GetMechanismInfo returns the key-size range and flags and also sets CKF_HW. Key-size units follow the mechanism: AES in bytes, RSA/EC in bits.
| Mechanism | Min | Max | Operations |
|---|---|---|---|
CKM_AES_KEY_GEN | 16 | 32 | generate |
CKM_AES_CBC, CKM_AES_CBC_PAD | 16 | 32 | encrypt, decrypt, wrap, unwrap |
CKM_AES_GCM | 16 | 32 | encrypt, decrypt |
CKM_AES_KEY_WRAP, CKM_AES_KEY_WRAP_PAD | 16 | 32 | wrap, unwrap |
CKM_GENERIC_SECRET_KEY_GEN | 1 | 512 | generate |
CKM_RSA_PKCS_KEY_PAIR_GEN | 2048 | 4096 | generate key pair |
CKM_RSA_PKCS | 2048 | 4096 | encrypt, decrypt, sign, verify, wrap, unwrap |
CKM_RSA_PKCS_OAEP | 2048 | 4096 | encrypt, decrypt, wrap, unwrap |
CKM_RSA_PKCS_PSS, CKM_SHA256_RSA_PKCS, CKM_SHA384_RSA_PKCS, CKM_SHA512_RSA_PKCS | 2048 | 4096 | sign, verify |
CKM_EC_KEY_PAIR_GEN | 256 | 521 | generate key pair |
CKM_ECDSA, CKM_ECDSA_SHA256, CKM_ECDSA_SHA384 | 256 | 521 | sign, verify |
CKM_SHA_1, CKM_SHA256, CKM_SHA384, CKM_SHA512 | — | — | digest |
CKM_SHA256_HMAC, CKM_SHA384_HMAC, CKM_SHA512_HMAC | 1 | 512 | sign, verify |
CKM_ML_DSA_KEY_PAIR_GEN, CKM_SLH_DSA_KEY_PAIR_GEN, CKM_ML_KEM_KEY_PAIR_GEN | — | — | generate key pair |
CKM_ML_DSA, CKM_SLH_DSA | — | — | sign, verify |
The concrete parameter set (e.g. ML-DSA-65, SLH-DSA-128s) is selected per key via CKA_PARAMETER_SET, not a bit-length key size, so these mechanisms report no min/max key size. CKM_ML_KEM_KEY_PAIR_GEN generates a key pair only — the v3.2 encapsulation mechanism itself is not yet advertised.
Digest is computed at the Cockpit and currently supports SHA-256 / 384 / 512. CKM_SHA_1 is advertised but a SHA-1 digest is rejected by the backend (CKR_MECHANISM_INVALID).
Objects & attributes
Object classes: CKO_DATA, CKO_CERTIFICATE, CKO_PUBLIC_KEY, CKO_PRIVATE_KEY, CKO_SECRET_KEY, CKO_DOMAIN_PARAMETERS.
Key types: CKK_AES, CKK_RSA, CKK_EC, CKK_GENERIC_SECRET, CKK_DSA, CKK_DH, CKK_SHA256_HMAC, CKK_SHA384_HMAC, CKK_SHA512_HMAC, CKK_ML_DSA, CKK_SLH_DSA, CKK_ML_KEM.
C_GetAttributeValue returns, from the cached descriptor: CKA_CLASS, CKA_KEY_TYPE, CKA_LABEL, CKA_ID, CKA_VALUE_LEN, CKA_MODULUS, CKA_PUBLIC_EXPONENT, CKA_MODULUS_BITS, CKA_EC_PARAMS, CKA_EC_POINT, and the boolean capability flags (CKA_TOKEN, CKA_PRIVATE, CKA_SENSITIVE, CKA_EXTRACTABLE, CKA_ENCRYPT, CKA_DECRYPT, CKA_WRAP, CKA_UNWRAP, CKA_SIGN, CKA_VERIFY, CKA_DERIVE, …).
CKA_VALUE always returns CKR_ATTRIBUTE_SENSITIVE — raw key material lives only in the backend and never crosses the PKCS#11 boundary. Keys report CKA_EXTRACTABLE = false, CKA_SENSITIVE = true, CKA_NEVER_EXTRACTABLE = true. Any unrecognized attribute type returns CKR_ATTRIBUTE_TYPE_INVALID.