Intelligent hardware token processors (5) are capable of sending and
receiving encrypted messages. Generic initialization with
non-user-specific certificates comprising public and private keys allows
a certificate authority (210) to securely communicate with the hardware
token. New users enrolling with the certificate server (210) have their
hardware tokens securely reprogrammed with user specific certificates.