PKCS#11 trust module implementation

Hello,
Stef Walter has been working on designing a central key store to be
implemented on desktop systems. I was thinking this could be useful to
unbound (and possibly other implementations) to use that storage for
dnssec keys. The original document in [2] is made with certificates
(mail/web) in mind, but if you have any comments on how this could be
extended to accommodate dnssec keys it would be nice to forward them
to the author or me.

best regards,
Nikos