Better not even think about saying anything about normalization, right? PKCS#11 nowadays supports UTF-8 for the strings we care about, but says nothing about normalization. I suppose you could say that matching should be (lowercase) normalization-insensitive. In practice it will never matter (which is why the lowercase). Nico --