They sometimes leak in so we should be prepared to return -EINVAL.
Fixed in r27619.
Done several tests: * Login to Apoteket using BankID+Fribid * Init PKCS15 card using my pkcs15-selfsigned.sh * Basic test with NetID for Linux Tested these combinations: server client ======================= 4.1.0 4.1.1win ok 4.1.0 4.1.1lin ok 4.1.1 4.1.0win ok 4.1.1 4.1.0lin ok 4.1.1 4.1.1win ok 4.1.1 4.1.1lin ok