PKCS #11 Compatibility Mode

This mode allows full compatibility with all cryptographic mechanisms provided by the PKCS#11 v2.20 standard, including those mechanisms subsequently found to have security flaws. The following affected mechanisms are available when this policy is set:

CKM_CONCATENATE_BASE_AND_KEY
CKM_CONCATENATE_BASE_AND_DATA
CKM_CONCATENATE_DATA_AND_BASE
CKM_EXTRACT_KEY_FROM_KEY

**WARNING**   Use of this security policy compromises security. A skilled attacker may be able to exploit vulnerabilities in certain mechanisms when this policy is set.

Command:

ctconf –fp