This will be used by toolbox(1) to ensure that the certificates from certificate authorities (or CAs) that are available inside a Toolbx container are kept synchronized with the host operating system [1]. Any program that uses PKCS #11 to access CA certificates should see the same ones both inside the container and on the host. This is the same approach taken by Flatpak [2]. [1] https://github.com/containers/toolbox/issues/626 [2] Flatpak commit 66b2ff40f7caf3a7 https://github.com/flatpak/flatpak/commit/66b2ff40f7caf3a7 https://github.com/flatpak/flatpak/pull/1757 https://github.com/p11-glue/p11-kit/issues/68 https://pagure.io/fedora-kiwi-descriptions/pull-request/189