Token Owner (User)

Many users may be assigned this role. There will be one per user slot. The user has these abilities:

>Exercise cryptographic services with Public objects

>Exercise cryptographic services with Private objects

>Create, destroy, import, export, generate and derive Public objects

>Create, destroy, import, export, generate and derive Private objects

>May change his/her own PIN