Dear Maintainer, in Fedora PKCS#11 modules configured in the system's p11-kit will be automatically registered to be visible to NSS applications. https://fedoraproject.org/wiki/Changes/NSSLoadP11KitModules In Debian (I am currently testing on Debian 10) this mechanism does not seem to work. I created /etc/crypto-policies/local.d/nss-p11-kit.config as follows: