> > I think, in PKCS11 environment, if the keys are not created internally > in xmlSec, the problem will arise. So how about my previous sugegstion: transform (AES encryption, for example) gets slot from a key. If it is not available, then it calls "GetBestSlot". Aleksey