package certproof import ( "crypto/sha256" "encoding/binary" "errors" "sync" ) // errPINRejectedBefore is returned instead of logging in with a PIN the token already // refused: every failed login counts towards the token's lockout, which for a TPM is // shared with everything else on the machine, and proofs are collected on every sync. var errPINRejectedBefore = errors.New("PKCS#11 token rejected this PIN before, not trying it again") // errPINNeedsToken refuses a PIN that names no token to log in to. var errPINNeedsToken = errors.New("a PKCS#11 PIN needs the token named in NB_CERT_PKCS11_URI, as token=