<?xml version="1.0" encoding="utf-8"?>
<feed xmlns="http://www.w3.org/2005/Atom">
	<id>tag:old.nabble.com,2006:forum-973</id>
	<title>Nabble - OpenSC</title>
	<updated>2009-12-05T09:27:03Z</updated>
	<link rel="self" type="application/atom+xml" href="http://old.nabble.com/OpenSC-f973.xml" />
	<link rel="alternate" type="text/html" href="http://old.nabble.com/OpenSC-f973.html" />
	<subtitle type="html">SmartCard library and applications with support for PKCS #15 compatible cards. OpenSC home is &lt;a href=&quot;http://www.opensc.org/&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;here&lt;/a&gt;.</subtitle>
	
<entry>
	<id>tag:old.nabble.com,2006:post-26657864</id>
	<title>Re: smartcard supported by opensc</title>
	<published>2009-12-05T09:27:03Z</published>
	<updated>2009-12-05T09:27:03Z</updated>
	<author>
		<name>Kevin Oberman</name>
	</author>
	<content type="html">&lt;div class='shrinkable-quote'&gt;&amp;gt; From: Andreas Jellinghaus &amp;lt;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26657864&amp;i=0&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;aj@...&lt;/a&gt;&amp;gt;
&lt;br&gt;&amp;gt; Date: Sat, 5 Dec 2009 11:04:26 +0100
&lt;br&gt;&amp;gt; Sender: &lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26657864&amp;i=1&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;opensc-user-bounces@...&lt;/a&gt;
&lt;br&gt;&amp;gt; 
&lt;br&gt;&amp;gt; Am Freitag 04 Dezember 2009 15:57:26 schrieb rainbow:
&lt;br&gt;&amp;gt; &amp;gt; My system is linux ,debian lenny 5.0,so Aladdin eToken PRO USB 64K(4.2B)
&lt;br&gt;&amp;gt; &amp;gt; &amp;nbsp;may not be supported 
&lt;br&gt;&amp;gt; 
&lt;br&gt;&amp;gt; hu? aladdin etoken should work fine on that system.
&lt;br&gt;&amp;gt; 
&lt;br&gt;&amp;gt; but: aladdin initializes the software in their own format, opensc uses
&lt;br&gt;&amp;gt; pkcs#15. so the normal thing to do is: format the token and then use
&lt;br&gt;&amp;gt; either only opensc with it, or only the aladdin software with it.
&lt;br&gt;&amp;gt; 
&lt;br&gt;&amp;gt; you can have both formats side by side, but each software will only
&lt;br&gt;&amp;gt; be able to access it's format, and if you format the token, everything
&lt;br&gt;&amp;gt; is gone (so normaly noone does that).
&lt;/div&gt;&lt;br&gt;Andreas,
&lt;br&gt;&lt;br&gt;Thanks for the nice summary of SmartCard support issues (in a previous
&lt;br&gt;message).
&lt;br&gt;&lt;br&gt;As far as the eToken PRO 64K(4.2B), we have had great success with this
&lt;br&gt;token. We use it for Unix, MacOS, and Windows and do run it with Aladdin
&lt;br&gt;PKCS11 and OpenSC PKCS15 formats &amp;quot;side by side&amp;quot;. It's annoying in that
&lt;br&gt;it requires two separate certs and ends up containing two sets of ssh
&lt;br&gt;keys, but the annoyance is only during the initialization and loading of
&lt;br&gt;the certs.
&lt;br&gt;&lt;br&gt;Once set up, they just work for most every OS we have tried, though
&lt;br&gt;MacOS support is a bit clunky.
&lt;br&gt;&lt;br&gt;One caveat. Many Unix desktop environments include keyring managers
&lt;br&gt;(e.g. seahorse for Gnome) that don't support the PINs for the tokens, so
&lt;br&gt;the system most be configured to not use the manager for ssh or whatever
&lt;br&gt;application you need to work with the token. For Gnome, the command is:
&lt;br&gt;gconftool-2 --set -t bool /apps/gnome-keyring/daemon-components/ssh false
&lt;br&gt;-- 
&lt;br&gt;R. Kevin Oberman, Network Engineer
&lt;br&gt;Energy Sciences Network (ESnet)
&lt;br&gt;Ernest O. Lawrence Berkeley National Laboratory (Berkeley Lab)
&lt;br&gt;E-mail: &lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26657864&amp;i=2&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;oberman@...&lt;/a&gt;			Phone: +1 510 486-8634
&lt;br&gt;Key fingerprint:059B 2DDF 031C 9BA3 14A4 &amp;nbsp;EADA 927D EBB3 987B 3751
&lt;br&gt;_______________________________________________
&lt;br&gt;opensc-user mailing list
&lt;br&gt;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26657864&amp;i=3&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;opensc-user@...&lt;/a&gt;
&lt;br&gt;&lt;a href=&quot;http://www.opensc-project.org/mailman/listinfo/opensc-user&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.opensc-project.org/mailman/listinfo/opensc-user&lt;/a&gt;&lt;br&gt;&lt;p&gt;From forum: &lt;a href=&quot;http://old.nabble.com/OpenSC---User-f976.html&quot; embed=&quot;fixTarget[976]&quot; target=&quot;_top&quot; &gt;OpenSC - User&lt;/a&gt;&lt;/p&gt;</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/smartcard-supported-by-opensc-tp26643319p26657864.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-26655286</id>
	<title>Re: Setcos 4.4.1 cards</title>
	<published>2009-12-05T04:32:11Z</published>
	<updated>2009-12-05T04:32:11Z</updated>
	<author>
		<name>Martin Paljak-2</name>
	</author>
	<content type="html">2009/12/5 Andreas Jellinghaus &amp;lt;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26655286&amp;i=0&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;aj@...&lt;/a&gt;&amp;gt;:
&lt;br&gt;&amp;gt; Am Samstag 05 Dezember 2009 10:24:42 schrieb rainbow:
&lt;br&gt;&amp;gt;&amp;gt; yes,I know, so if I want to use opensc with smart card, what smart  cards
&lt;br&gt;&amp;gt;&amp;gt; should I buy? I find there is few cards can get from the market support
&lt;br&gt;&amp;gt;&amp;gt; opensc.
&lt;br&gt;&amp;gt; or maybe javacards with the muscle applet, but I would buy only one
&lt;br&gt;&amp;gt; or two cards and experiment with them first, to see if that it works
&lt;br&gt;&amp;gt; out for you, as I got mixed results.
&lt;br&gt;&lt;br&gt;There's also JavaCardSign for JavaCards.
&lt;br&gt;&lt;a href=&quot;http://javacardsign.sourceforge.net/&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://javacardsign.sourceforge.net/&lt;/a&gt;&amp;nbsp;a PKCS#15 compatible open source
&lt;br&gt;applet. I have not tried it yet but João whoi has worked with
&lt;br&gt;JavaCards said it looks promising (== minor tweaks necessary to make
&lt;br&gt;it work with the rest of OpenSC, including pkcs15-init).
&lt;br&gt;&lt;br&gt;Martin.
&lt;br&gt;_______________________________________________
&lt;br&gt;opensc-user mailing list
&lt;br&gt;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26655286&amp;i=1&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;opensc-user@...&lt;/a&gt;
&lt;br&gt;&lt;a href=&quot;http://www.opensc-project.org/mailman/listinfo/opensc-user&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.opensc-project.org/mailman/listinfo/opensc-user&lt;/a&gt;&lt;p&gt;From forum: &lt;a href=&quot;http://old.nabble.com/OpenSC---User-f976.html&quot; embed=&quot;fixTarget[976]&quot; target=&quot;_top&quot; &gt;OpenSC - User&lt;/a&gt;&lt;/p&gt;</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/Setcos-4.4.1-cards-tp26652156p26655286.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-26654393</id>
	<title>Re: Setcos 4.4.1 cards</title>
	<published>2009-12-05T02:20:45Z</published>
	<updated>2009-12-05T02:20:45Z</updated>
	<author>
		<name>Andreas Jellinghaus-2</name>
	</author>
	<content type="html">Am Samstag 05 Dezember 2009 10:24:42 schrieb rainbow:
&lt;br&gt;&amp;gt; yes,I know, so if I want to use opensc with smart card, what smart &amp;nbsp;cards
&lt;br&gt;&amp;gt; should I buy? I find there is few cards can get from the market support
&lt;br&gt;&amp;gt; opensc.
&lt;br&gt;&lt;br&gt;JP corrected me, setec 4.4.1 should work very well, if you can buy them.
&lt;br&gt;also cardos 4.3B work well.
&lt;br&gt;&lt;br&gt;or maybe javacards with the muscle applet, but I would buy only one
&lt;br&gt;or two cards and experiment with them first, to see if that it works
&lt;br&gt;out for you, as I got mixed results.
&lt;br&gt;&lt;br&gt;Regards, Andreas
&lt;br&gt;_______________________________________________
&lt;br&gt;opensc-user mailing list
&lt;br&gt;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26654393&amp;i=0&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;opensc-user@...&lt;/a&gt;
&lt;br&gt;&lt;a href=&quot;http://www.opensc-project.org/mailman/listinfo/opensc-user&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.opensc-project.org/mailman/listinfo/opensc-user&lt;/a&gt;&lt;br&gt;&lt;p&gt;From forum: &lt;a href=&quot;http://old.nabble.com/OpenSC---User-f976.html&quot; embed=&quot;fixTarget[976]&quot; target=&quot;_top&quot; &gt;OpenSC - User&lt;/a&gt;&lt;/p&gt;</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/Setcos-4.4.1-cards-tp26652156p26654393.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-26654382</id>
	<title>Re: Setcos 4.4.1 cards</title>
	<published>2009-12-05T02:17:58Z</published>
	<updated>2009-12-05T02:17:58Z</updated>
	<author>
		<name>Andreas Jellinghaus-2</name>
	</author>
	<content type="html">Am Samstag 05 Dezember 2009 09:34:44 schrieb rainbow:
&lt;br&gt;&amp;gt; so,what the common smart card is well supported by opensc?
&lt;br&gt;&lt;br&gt;you found the biggest problem we have with opensc.
&lt;br&gt;everytime there is a nice card and it works fine with opensc,
&lt;br&gt;the production of the card is stopped :(
&lt;br&gt;&lt;br&gt;cardos 4.2B or 4.3B work (but you need to format them once
&lt;br&gt;with some windows software I guess).
&lt;br&gt;&lt;br&gt;I have little experience with java cards and using the muscle
&lt;br&gt;applet. it seems to work somehow, the experience is mixed,
&lt;br&gt;some say it works very good, some ran into problems like
&lt;br&gt;I did.
&lt;br&gt;&lt;br&gt;note sure if the oberthur cards with that specific authentic
&lt;br&gt;applet are available.
&lt;br&gt;&lt;br&gt;if someone writes a driver acos5 could be interesting,
&lt;br&gt;or working on an improved javacard applet and a driver for
&lt;br&gt;it in opensc.
&lt;br&gt;&lt;br&gt;any other card I forgot?
&lt;br&gt;&lt;br&gt;Regards, Andreas
&lt;br&gt;_______________________________________________
&lt;br&gt;opensc-user mailing list
&lt;br&gt;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26654382&amp;i=0&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;opensc-user@...&lt;/a&gt;
&lt;br&gt;&lt;a href=&quot;http://www.opensc-project.org/mailman/listinfo/opensc-user&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.opensc-project.org/mailman/listinfo/opensc-user&lt;/a&gt;&lt;br&gt;&lt;p&gt;From forum: &lt;a href=&quot;http://old.nabble.com/OpenSC---User-f976.html&quot; embed=&quot;fixTarget[976]&quot; target=&quot;_top&quot; &gt;OpenSC - User&lt;/a&gt;&lt;/p&gt;</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/Setcos-4.4.1-cards-tp26652156p26654382.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-26654351</id>
	<title>Re: smartcard supported by opensc</title>
	<published>2009-12-05T02:11:41Z</published>
	<updated>2009-12-05T02:11:41Z</updated>
	<author>
		<name>Andreas Jellinghaus-2</name>
	</author>
	<content type="html">Am Freitag 04 Dezember 2009 17:49:25 schrieb John R Pierce:
&lt;br&gt;&amp;gt; Martin Paljak wrote:
&lt;br&gt;&amp;gt; &amp;gt; The RightWay of adding smart card support is via PKCS#11 which is
&lt;br&gt;&amp;gt; &amp;gt; available from hre:
&lt;br&gt;&amp;gt; &amp;gt;
&lt;br&gt;&amp;gt; &amp;gt; &lt;a href=&quot;http://sites.google.com/site/alonbarlev/openssh-pkcs11&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://sites.google.com/site/alonbarlev/openssh-pkcs11&lt;/a&gt;&lt;br&gt;&amp;gt; 
&lt;br&gt;&amp;gt; what about &lt;a href=&quot;http://www.opensc-project.org/engine_pkcs11&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.opensc-project.org/engine_pkcs11&lt;/a&gt;&amp;nbsp;?
&lt;br&gt;&lt;br&gt;that works for openssl, but applications need to explicit
&lt;br&gt;use it. for example wpa_supplicant does it.
&lt;br&gt;&lt;br&gt;openssh could be changed to use pkcs#11 not directly but
&lt;br&gt;via some engine, sure. but I don't think anyone wrote a
&lt;br&gt;patch for that so far. but a good idea still.
&lt;br&gt;&lt;br&gt;however I think the openssh developers strive to keep
&lt;br&gt;the software as simple as possible to avoid security
&lt;br&gt;issues. thus I'm not sure what code they would accept
&lt;br&gt;anyway. after all they didn't accept our patch for
&lt;br&gt;bug 608 in many, many years, nor could tell us how we
&lt;br&gt;can aim for a better patch that would be acceptable.
&lt;br&gt;so my hopes to get any new code for smart card support
&lt;br&gt;into openssh are not very high.
&lt;br&gt;&lt;br&gt;Regards, Andreas
&lt;br&gt;_______________________________________________
&lt;br&gt;opensc-user mailing list
&lt;br&gt;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26654351&amp;i=0&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;opensc-user@...&lt;/a&gt;
&lt;br&gt;&lt;a href=&quot;http://www.opensc-project.org/mailman/listinfo/opensc-user&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.opensc-project.org/mailman/listinfo/opensc-user&lt;/a&gt;&lt;br&gt;&lt;p&gt;From forum: &lt;a href=&quot;http://old.nabble.com/OpenSC---User-f976.html&quot; embed=&quot;fixTarget[976]&quot; target=&quot;_top&quot; &gt;OpenSC - User&lt;/a&gt;&lt;/p&gt;</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/smartcard-supported-by-opensc-tp26643319p26654351.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-26654335</id>
	<title>Re: smartcard supported by opensc</title>
	<published>2009-12-05T02:08:30Z</published>
	<updated>2009-12-05T02:08:30Z</updated>
	<author>
		<name>Andreas Jellinghaus-2</name>
	</author>
	<content type="html">Am Freitag 04 Dezember 2009 17:28:23 schrieb Martin Paljak:
&lt;br&gt;&amp;gt; The RightWay of adding smart card support is via PKCS#11 which is available
&lt;br&gt;&amp;gt; &amp;nbsp;from hre:
&lt;br&gt;&amp;gt; 
&lt;br&gt;&amp;gt; &lt;a href=&quot;http://sites.google.com/site/alonbarlev/openssh-pkcs11&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://sites.google.com/site/alonbarlev/openssh-pkcs11&lt;/a&gt;&lt;br&gt;&lt;br&gt;thats the most flexible way and works with many different software.
&lt;br&gt;&lt;br&gt;but recompiling openssh with &amp;quot;--enable-opensc&amp;quot; and applying the
&lt;br&gt;patch for bug 608 to openssh is working fine as well.
&lt;br&gt;(yes, it uses the old opensc api, we don't prefer that any more,
&lt;br&gt;but it still works fine...)
&lt;br&gt;&lt;br&gt;the patch is in src/openssh/ask-for-pin.diff or see here:
&lt;br&gt;&lt;a href=&quot;http://www.opensc-project.org/svn/opensc/trunk/src/openssh/&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.opensc-project.org/svn/opensc/trunk/src/openssh/&lt;/a&gt;&lt;br&gt;&lt;br&gt;Regards, Andreas
&lt;br&gt;_______________________________________________
&lt;br&gt;opensc-user mailing list
&lt;br&gt;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26654335&amp;i=0&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;opensc-user@...&lt;/a&gt;
&lt;br&gt;&lt;a href=&quot;http://www.opensc-project.org/mailman/listinfo/opensc-user&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.opensc-project.org/mailman/listinfo/opensc-user&lt;/a&gt;&lt;br&gt;&lt;p&gt;From forum: &lt;a href=&quot;http://old.nabble.com/OpenSC---User-f976.html&quot; embed=&quot;fixTarget[976]&quot; target=&quot;_top&quot; &gt;OpenSC - User&lt;/a&gt;&lt;/p&gt;</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/smartcard-supported-by-opensc-tp26643319p26654335.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-26654305</id>
	<title>Re: smartcard supported by opensc</title>
	<published>2009-12-05T02:04:26Z</published>
	<updated>2009-12-05T02:04:26Z</updated>
	<author>
		<name>Andreas Jellinghaus-2</name>
	</author>
	<content type="html">Am Freitag 04 Dezember 2009 15:57:26 schrieb rainbow:
&lt;br&gt;&amp;gt; My system is linux ,debian lenny 5.0,so Aladdin eToken PRO USB 64K(4.2B)
&lt;br&gt;&amp;gt; &amp;nbsp;may not be supported 
&lt;br&gt;&lt;br&gt;hu? aladdin etoken should work fine on that system.
&lt;br&gt;&lt;br&gt;but: aladdin initializes the software in their own format, opensc uses
&lt;br&gt;pkcs#15. so the normal thing to do is: format the token and then use
&lt;br&gt;either only opensc with it, or only the aladdin software with it.
&lt;br&gt;&lt;br&gt;you can have both formats side by side, but each software will only
&lt;br&gt;be able to access it's format, and if you format the token, everything
&lt;br&gt;is gone (so normaly noone does that).
&lt;br&gt;&lt;br&gt;Regards, Andreas
&lt;br&gt;_______________________________________________
&lt;br&gt;opensc-user mailing list
&lt;br&gt;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26654305&amp;i=0&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;opensc-user@...&lt;/a&gt;
&lt;br&gt;&lt;a href=&quot;http://www.opensc-project.org/mailman/listinfo/opensc-user&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.opensc-project.org/mailman/listinfo/opensc-user&lt;/a&gt;&lt;br&gt;&lt;p&gt;From forum: &lt;a href=&quot;http://old.nabble.com/OpenSC---User-f976.html&quot; embed=&quot;fixTarget[976]&quot; target=&quot;_top&quot; &gt;OpenSC - User&lt;/a&gt;&lt;/p&gt;</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/smartcard-supported-by-opensc-tp26643319p26654305.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-26654210</id>
	<title>Re: smartcard supported by opensc</title>
	<published>2009-12-05T01:48:56Z</published>
	<updated>2009-12-05T01:48:56Z</updated>
	<author>
		<name>Andreas Jellinghaus-2</name>
	</author>
	<content type="html">Am Freitag 04 Dezember 2009 15:45:35 schrieb Peter Keller:
&lt;br&gt;&amp;gt; &amp;nbsp; &amp;nbsp;(2) The Aladdin eToken PRO USB 72K(JC) has been reported NOT to work on
&lt;br&gt;&amp;gt; Linux with the Aladdin PKI client here:
&lt;br&gt;&amp;gt; &lt;a href=&quot;http://www.etokenonlinux.org/et/FAQ#eTokenhardwareandsoftware&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.etokenonlinux.org/et/FAQ#eTokenhardwareandsoftware&lt;/a&gt;&lt;br&gt;&lt;br&gt;but some people managed to install muscle applet on those tokens
&lt;br&gt;and thus get them to work with opensc.
&lt;br&gt;&lt;br&gt;Regards, Andreas
&lt;br&gt;_______________________________________________
&lt;br&gt;opensc-user mailing list
&lt;br&gt;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26654210&amp;i=0&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;opensc-user@...&lt;/a&gt;
&lt;br&gt;&lt;a href=&quot;http://www.opensc-project.org/mailman/listinfo/opensc-user&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.opensc-project.org/mailman/listinfo/opensc-user&lt;/a&gt;&lt;br&gt;&lt;p&gt;From forum: &lt;a href=&quot;http://old.nabble.com/OpenSC---User-f976.html&quot; embed=&quot;fixTarget[976]&quot; target=&quot;_top&quot; &gt;OpenSC - User&lt;/a&gt;&lt;/p&gt;</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/smartcard-supported-by-opensc-tp26643319p26654210.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-26654165</id>
	<title>Re: smartcard supported by opensc</title>
	<published>2009-12-05T01:42:50Z</published>
	<updated>2009-12-05T01:42:50Z</updated>
	<author>
		<name>Andreas Jellinghaus-2</name>
	</author>
	<content type="html">Am Freitag 04 Dezember 2009 15:29:31 schrieb rainbow:
&lt;br&gt;&amp;gt; hi, I do not understand the smartcard very much,I see from opensc that AKIS
&lt;br&gt;&amp;gt; card not support the pkcs15-init , so is there any thing impact the use of
&lt;br&gt;&amp;gt; opensc ,such as write data to card or create keys, or is there a card full
&lt;br&gt;&amp;gt; supported by opensc,thanks.
&lt;br&gt;&lt;br&gt;opensc has three kinds of supports
&lt;br&gt;* basic functionality only
&lt;br&gt;* emulation functionality
&lt;br&gt;* full initialization functionality
&lt;br&gt;&lt;br&gt;basic means you can play with it and issue a few commands for testing, but
&lt;br&gt;it is not usefull for real work environments.
&lt;br&gt;&lt;br&gt;emulation functionality means you can't change the card (maybe change PIN
&lt;br&gt;or the content of an already existing file), but use the card (i.e. read
&lt;br&gt;data, use rsa keys for signing/encryption, etc.). this is common for
&lt;br&gt;a) national ID cards (you can't change anything with them usualy, but only
&lt;br&gt;&amp;nbsp; &amp;nbsp;use them)
&lt;br&gt;b) cards initialized with some other software (if they use a different format
&lt;br&gt;than PKCS#15 and thus we can only guess which informtion is where on the card)
&lt;br&gt;&lt;br&gt;full initialization functionality means you can buy a blank card, initialize
&lt;br&gt;it with opensc - thus create a PKCS#15 structure - and change it in all
&lt;br&gt;the normal ways, for example create keys, store keys and certificates, create
&lt;br&gt;and manage PIN, reset PIN, store public or private data objects, change those,
&lt;br&gt;with most cards also delete objects/keys/certiticates. details still depend on
&lt;br&gt;the card in questions, some cards have special situations (e.g. the cardos
&lt;br&gt;cards with the secret commands to get them going).
&lt;br&gt;&lt;br&gt;still with full initialization: if the same card was initialized with some
&lt;br&gt;other software in PKCS#15 format, then opensc can use it (similar to emulated
&lt;br&gt;cards), but altering the card will most likely not work (maybe change/unblock
&lt;br&gt;a PIN or change existing DATA files, but not store or create new certificates
&lt;br&gt;or keys, as that requires a compatible profile, which is software specific).
&lt;br&gt;&lt;br&gt;but cards in &amp;quot;full initialization&amp;quot; support should work (read, sign, decrypt)
&lt;br&gt;with other software, and also work if other software initialized them in
&lt;br&gt;PKCS#15 format.
&lt;br&gt;&lt;br&gt;does this explanation help?
&lt;br&gt;&lt;br&gt;Regards, Andreas
&lt;br&gt;_______________________________________________
&lt;br&gt;opensc-user mailing list
&lt;br&gt;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26654165&amp;i=0&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;opensc-user@...&lt;/a&gt;
&lt;br&gt;&lt;a href=&quot;http://www.opensc-project.org/mailman/listinfo/opensc-user&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.opensc-project.org/mailman/listinfo/opensc-user&lt;/a&gt;&lt;br&gt;&lt;p&gt;From forum: &lt;a href=&quot;http://old.nabble.com/OpenSC---User-f976.html&quot; embed=&quot;fixTarget[976]&quot; target=&quot;_top&quot; &gt;OpenSC - User&lt;/a&gt;&lt;/p&gt;</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/smartcard-supported-by-opensc-tp26643319p26654165.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-26654054</id>
	<title>Re: problem</title>
	<published>2009-12-05T01:25:21Z</published>
	<updated>2009-12-05T01:25:21Z</updated>
	<author>
		<name>Andreas Jellinghaus-2</name>
	</author>
	<content type="html">Am Samstag 05 Dezember 2009 01:20:23 schrieb Thorsten Sprenger:
&lt;br&gt;&amp;gt; Hello Andreas and Sebastian,
&lt;br&gt;&amp;gt; 
&lt;br&gt;&amp;gt; my answer might come a little late, but I just spent quite a long time to
&lt;br&gt;&amp;gt; &amp;nbsp;solve the mentioned problem with Firefox / Windows.
&lt;br&gt;&amp;gt; 
&lt;br&gt;&amp;gt; It is quite simple:
&lt;br&gt;&amp;gt; Just put OpenSC's 'bin' directory to the environment variable 'Path'.
&lt;br&gt;&amp;gt; That's all.
&lt;br&gt;&lt;br&gt;Ah, sure, firefox needs to find the dll's. the alternative is to put
&lt;br&gt;the dlls into system32, which is of course the path into library hell.
&lt;br&gt;but at least if gina with a CSP wants to use opensc, there might be
&lt;br&gt;no alternative (not sure if the path for GINA can be set somehow).
&lt;br&gt;&lt;br&gt;&lt;br&gt;&amp;gt; PS: Andreas, could you give me a hint, how to bring a CardOS 4.3B card from
&lt;br&gt;&amp;gt; &amp;nbsp;'manufacturing' state into a useful one ?
&lt;br&gt;&lt;br&gt;sure. run cardos-tool --info (or the old cardos-info): if the
&lt;br&gt;startkey is version &amp;quot;00&amp;quot;, then you need to change it to &amp;quot;ff&amp;quot; first.
&lt;br&gt;once it is &amp;quot;ff&amp;quot; (and the valus is really 16 bytes 0xff), then you 
&lt;br&gt;can format the card (that creates the main folder and puts the
&lt;br&gt;card in admin mode), and after that is done you can run
&lt;br&gt;pkcs15-init --create-pkcs15.
&lt;br&gt;&lt;br&gt;to change the startkey from 0x00 to 0xff you need to know and
&lt;br&gt;use the secret APDU command from siemens. latest opensc trunk
&lt;br&gt;has code in cardos-tool to check you use the right APDU (but
&lt;br&gt;you still need to pass it), with older opensc versions you
&lt;br&gt;can run &amp;quot;opensc-tool -s APDU&amp;quot; to do that.
&lt;br&gt;&lt;br&gt;to format the card you can run cardos-tool --format
&lt;br&gt;(if you have an older opensc version and know the APDU you
&lt;br&gt;can of course use &amp;quot;opensc-tool -s APDU&amp;quot; to do that).
&lt;br&gt;&lt;br&gt;the APDU commands might be copyrighted by siemens so I can't
&lt;br&gt;post them here.
&lt;br&gt;&lt;br&gt;alternative: use some official software to change startkey
&lt;br&gt;and format the cards once. costs 20€ or so. (but I have
&lt;br&gt;no experience with that, except for aladdin etokens and
&lt;br&gt;the aladdin software...)
&lt;br&gt;&lt;br&gt;Regards, Andreas
&lt;br&gt;_______________________________________________
&lt;br&gt;opensc-user mailing list
&lt;br&gt;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26654054&amp;i=0&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;opensc-user@...&lt;/a&gt;
&lt;br&gt;&lt;a href=&quot;http://www.opensc-project.org/mailman/listinfo/opensc-user&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.opensc-project.org/mailman/listinfo/opensc-user&lt;/a&gt;&lt;p&gt;From forum: &lt;a href=&quot;http://old.nabble.com/OpenSC---User-f976.html&quot; embed=&quot;fixTarget[976]&quot; target=&quot;_top&quot; &gt;OpenSC - User&lt;/a&gt;&lt;/p&gt;</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/problem-tp26652001p26654054.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-26654050</id>
	<title>Re: Setcos 4.4.1 cards</title>
	<published>2009-12-05T01:24:42Z</published>
	<updated>2009-12-05T01:24:42Z</updated>
	<author>
		<name>rainbow-7</name>
	</author>
	<content type="html">yes,I know, so if I want to use opensc with smart card, what smart  cards should I buy? I find there is few cards can get from the market support opensc.&lt;br&gt;&lt;br&gt;&lt;div class=&quot;gmail_quote&quot;&gt;2009/12/5 Andreas Jellinghaus &lt;span dir=&quot;ltr&quot;&gt;&amp;lt;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26654050&amp;i=0&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;aj@...&lt;/a&gt;&amp;gt;&lt;/span&gt;&lt;br&gt;
&lt;blockquote class=&quot;gmail_quote&quot; style=&quot;border-left: 1px solid rgb(204, 204, 204); margin: 0pt 0pt 0pt 0.8ex; padding-left: 1ex;&quot;&gt;Am Samstag 05 Dezember 2009 02:46:23 schrieb rainbow:&lt;br&gt;
&lt;div class=&quot;im&quot;&gt;&amp;gt; hi, if I buy an  Setcos 4.4.1 card, can I use the pkcs15-init to the card?&lt;br&gt;
&amp;gt;&lt;br&gt;
&lt;/div&gt;I don&amp;#39;t remember anyone using a setcos card in years, so I&amp;#39;m pretty sure&lt;br&gt;
the answer is: no.&lt;br&gt;
&lt;br&gt;
Regards, Andreas&lt;br&gt;
&lt;/blockquote&gt;&lt;/div&gt;&lt;br&gt;&lt;br clear=&quot;all&quot;&gt;&lt;br&gt;-- &lt;br&gt;Qingquan Lv&lt;br&gt;School of Information Science &amp;amp; Engineering , Lanzhou University.&lt;br&gt;mail: &lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26654050&amp;i=1&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;lvqq05@...&lt;/a&gt;&lt;br&gt;Do what you like,&lt;br&gt;
Enjoy your life.&lt;br&gt;
&lt;br /&gt;_______________________________________________
&lt;br&gt;opensc-user mailing list
&lt;br&gt;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26654050&amp;i=2&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;opensc-user@...&lt;/a&gt;
&lt;br&gt;&lt;a href=&quot;http://www.opensc-project.org/mailman/listinfo/opensc-user&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.opensc-project.org/mailman/listinfo/opensc-user&lt;/a&gt;&lt;p&gt;From forum: &lt;a href=&quot;http://old.nabble.com/OpenSC---User-f976.html&quot; embed=&quot;fixTarget[976]&quot; target=&quot;_top&quot; &gt;OpenSC - User&lt;/a&gt;&lt;/p&gt;</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/Setcos-4.4.1-cards-tp26652156p26654050.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-26654010</id>
	<title>Re: Setcos 4.4.1 cards</title>
	<published>2009-12-05T01:18:46Z</published>
	<updated>2009-12-05T01:18:46Z</updated>
	<author>
		<name>Andreas Jellinghaus-2</name>
	</author>
	<content type="html">Am Samstag 05 Dezember 2009 02:46:23 schrieb rainbow:
&lt;br&gt;&amp;gt; hi, if I buy an &amp;nbsp;Setcos 4.4.1 card, can I use the pkcs15-init to the card?
&lt;br&gt;&amp;gt; 
&lt;br&gt;I don't remember anyone using a setcos card in years, so I'm pretty sure
&lt;br&gt;the answer is: no.
&lt;br&gt;&lt;br&gt;Regards, Andreas
&lt;br&gt;_______________________________________________
&lt;br&gt;opensc-user mailing list
&lt;br&gt;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26654010&amp;i=0&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;opensc-user@...&lt;/a&gt;
&lt;br&gt;&lt;a href=&quot;http://www.opensc-project.org/mailman/listinfo/opensc-user&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.opensc-project.org/mailman/listinfo/opensc-user&lt;/a&gt;&lt;br&gt;&lt;p&gt;From forum: &lt;a href=&quot;http://old.nabble.com/OpenSC---User-f976.html&quot; embed=&quot;fixTarget[976]&quot; target=&quot;_top&quot; &gt;OpenSC - User&lt;/a&gt;&lt;/p&gt;</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/Setcos-4.4.1-cards-tp26652156p26654010.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-26653786</id>
	<title>Re: Setcos 4.4.1 cards</title>
	<published>2009-12-05T00:34:44Z</published>
	<updated>2009-12-05T00:34:44Z</updated>
	<author>
		<name>rainbow-7</name>
	</author>
	<content type="html">so,what the common smart card is well supported by opensc?&lt;br&gt;&lt;br&gt;&lt;div class=&quot;gmail_quote&quot;&gt;2009/12/5 Jean-Pierre Szikora &lt;span dir=&quot;ltr&quot;&gt;&amp;lt;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26653786&amp;i=0&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;jean-pierre.szikora@...&lt;/a&gt;&amp;gt;&lt;/span&gt;&lt;br&gt;
&lt;blockquote class=&quot;gmail_quote&quot; style=&quot;border-left: 1px solid rgb(204, 204, 204); margin: 0pt 0pt 0pt 0.8ex; padding-left: 1ex;&quot;&gt;&lt;br&gt;
Le 05-déc.-09 à 02:46, rainbow a écrit :&lt;div class=&quot;im&quot;&gt;&lt;br&gt;
&lt;br&gt;
&lt;blockquote class=&quot;gmail_quote&quot; style=&quot;border-left: 1px solid rgb(204, 204, 204); margin: 0pt 0pt 0pt 0.8ex; padding-left: 1ex;&quot;&gt;
hi, if I buy an  Setcos 4.4.1 card, can I use the pkcs15-init to the card?&lt;br&gt;
&lt;br&gt;
&lt;/blockquote&gt;
&lt;br&gt;&lt;/div&gt;
Hi,&lt;br&gt;
&lt;br&gt;
I&amp;#39;m surprised that the card is still for sale, Setec (a finish company acquired by Gemalto) stopped the production of this chip 3 years ago. And yes, the card is well supported by OpenSC.&lt;br&gt;
&lt;br&gt;
Cheers,&lt;br&gt;&lt;font color=&quot;#888888&quot;&gt;
&lt;br&gt;
Jean-Pierre&lt;/font&gt;&lt;/blockquote&gt;&lt;/div&gt;&lt;br&gt;&lt;br clear=&quot;all&quot;&gt;&lt;br&gt;-- &lt;br&gt;Qingquan Lv&lt;br&gt;School of Information Science &amp;amp; Engineering , Lanzhou University.&lt;br&gt;mail: &lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26653786&amp;i=1&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;lvqq05@...&lt;/a&gt;&lt;br&gt;
Do what you like,&lt;br&gt;Enjoy your life.&lt;br&gt;
&lt;br /&gt;_______________________________________________
&lt;br&gt;opensc-user mailing list
&lt;br&gt;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26653786&amp;i=2&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;opensc-user@...&lt;/a&gt;
&lt;br&gt;&lt;a href=&quot;http://www.opensc-project.org/mailman/listinfo/opensc-user&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.opensc-project.org/mailman/listinfo/opensc-user&lt;/a&gt;&lt;p&gt;From forum: &lt;a href=&quot;http://old.nabble.com/OpenSC---User-f976.html&quot; embed=&quot;fixTarget[976]&quot; target=&quot;_top&quot; &gt;OpenSC - User&lt;/a&gt;&lt;/p&gt;</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/Setcos-4.4.1-cards-tp26652156p26653786.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-26653804</id>
	<title>Re: Setcos 4.4.1 cards</title>
	<published>2009-12-05T00:27:50Z</published>
	<updated>2009-12-05T00:27:50Z</updated>
	<author>
		<name>JP Szikora-2</name>
	</author>
	<content type="html">&lt;br&gt;Le 05-déc.-09 à 02:46, rainbow a écrit :
&lt;br&gt;&lt;br&gt;&amp;gt; hi, if I buy an &amp;nbsp;Setcos 4.4.1 card, can I use the pkcs15-init to the &amp;nbsp;
&lt;br&gt;&amp;gt; card?
&lt;br&gt;&amp;gt;
&lt;br&gt;&lt;br&gt;Hi,
&lt;br&gt;&lt;br&gt;I'm surprised that the card is still for sale, Setec (a finish company &amp;nbsp;
&lt;br&gt;acquired by Gemalto) stopped the production of this chip 3 years ago. &amp;nbsp;
&lt;br&gt;And yes, the card is well supported by OpenSC.
&lt;br&gt;&lt;br&gt;Cheers,
&lt;br&gt;&lt;br&gt;Jean-Pierre
&lt;br&gt;_______________________________________________
&lt;br&gt;opensc-user mailing list
&lt;br&gt;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26653804&amp;i=0&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;opensc-user@...&lt;/a&gt;
&lt;br&gt;&lt;a href=&quot;http://www.opensc-project.org/mailman/listinfo/opensc-user&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.opensc-project.org/mailman/listinfo/opensc-user&lt;/a&gt;&lt;br&gt;&lt;p&gt;From forum: &lt;a href=&quot;http://old.nabble.com/OpenSC---User-f976.html&quot; embed=&quot;fixTarget[976]&quot; target=&quot;_top&quot; &gt;OpenSC - User&lt;/a&gt;&lt;/p&gt;</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/Setcos-4.4.1-cards-tp26652156p26653804.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-26652156</id>
	<title>Setcos 4.4.1 cards</title>
	<published>2009-12-04T17:46:23Z</published>
	<updated>2009-12-04T17:46:23Z</updated>
	<author>
		<name>rainbow-7</name>
	</author>
	<content type="html">hi, if I buy an  Setcos 4.4.1 card, can I use the pkcs15-init to the card?&lt;br clear=&quot;all&quot;&gt;&lt;br&gt;-- &lt;br&gt;Qingquan Lv&lt;br&gt;School of Information Science &amp;amp; Engineering , Lanzhou University.&lt;br&gt;mail: &lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26652156&amp;i=0&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;lvqq05@...&lt;/a&gt;&lt;br&gt;
Do what you like,&lt;br&gt;Enjoy your life.&lt;br&gt;
&lt;br /&gt;_______________________________________________
&lt;br&gt;opensc-user mailing list
&lt;br&gt;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26652156&amp;i=1&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;opensc-user@...&lt;/a&gt;
&lt;br&gt;&lt;a href=&quot;http://www.opensc-project.org/mailman/listinfo/opensc-user&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.opensc-project.org/mailman/listinfo/opensc-user&lt;/a&gt;&lt;p&gt;From forum: &lt;a href=&quot;http://old.nabble.com/OpenSC---User-f976.html&quot; embed=&quot;fixTarget[976]&quot; target=&quot;_top&quot; &gt;OpenSC - User&lt;/a&gt;&lt;/p&gt;</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/Setcos-4.4.1-cards-tp26652156p26652156.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-26652001</id>
	<title>problem</title>
	<published>2009-12-04T16:20:23Z</published>
	<updated>2009-12-04T16:20:23Z</updated>
	<author>
		<name>Thorsten Sprenger</name>
	</author>
	<content type="html">Hello Andreas and Sebastian,
&lt;br&gt;&lt;br&gt;my answer might come a little late, but I just spent quite a long time to solve the mentioned problem with Firefox / Windows.
&lt;br&gt;&lt;br&gt;It is quite simple:
&lt;br&gt;Just put OpenSC's 'bin' directory to the environment variable 'Path'.
&lt;br&gt;That's all.
&lt;br&gt;&lt;br&gt;Hope I could help you !
&lt;br&gt;Regards,
&lt;br&gt;Thorsten
&lt;br&gt;&lt;br&gt;PS: Andreas, could you give me a hint, how to bring a CardOS 4.3B card from 'manufacturing' state into a useful one ?
&lt;br&gt;&lt;br&gt;_______________________________________________
&lt;br&gt;opensc-user mailing list
&lt;br&gt;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26652001&amp;i=0&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;opensc-user@...&lt;/a&gt;
&lt;br&gt;&lt;a href=&quot;http://www.opensc-project.org/mailman/listinfo/opensc-user&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.opensc-project.org/mailman/listinfo/opensc-user&lt;/a&gt;&lt;br&gt;&lt;p&gt;From forum: &lt;a href=&quot;http://old.nabble.com/OpenSC---User-f976.html&quot; embed=&quot;fixTarget[976]&quot; target=&quot;_top&quot; &gt;OpenSC - User&lt;/a&gt;&lt;/p&gt;</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/problem-tp26652001p26652001.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-26646654</id>
	<title>Re: smartcard supported by opensc</title>
	<published>2009-12-04T10:06:46Z</published>
	<updated>2009-12-04T10:06:46Z</updated>
	<author>
		<name>John R Pierce</name>
	</author>
	<content type="html">&lt;div class='shrinkable-quote'&gt;&lt;br&gt;&amp;gt;&amp;gt;&amp;gt; The RightWay of adding smart card support is via PKCS#11 which is available from hre:
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt; &lt;a href=&quot;http://sites.google.com/site/alonbarlev/openssh-pkcs11&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://sites.google.com/site/alonbarlev/openssh-pkcs11&lt;/a&gt;&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt; &amp;nbsp; &amp;nbsp; &amp;nbsp; 
&lt;br&gt;&amp;gt;&amp;gt; what about &lt;a href=&quot;http://www.opensc-project.org/engine_pkcs11&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.opensc-project.org/engine_pkcs11&lt;/a&gt;&amp;nbsp;?
&lt;br&gt;&amp;gt;&amp;gt; &amp;nbsp; &amp;nbsp; 
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; I don't see any reference to &amp;quot;engine&amp;quot; in OpenSSH documentation. 
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; In theory it could do as well but nlike the direct PKCS#11 interface, to my knowledge there is no implementation for an engine based approach.
&lt;br&gt;&amp;gt; &amp;nbsp; 
&lt;/div&gt;&lt;br&gt;&lt;br&gt;ooops, my eyes crossed. &amp;nbsp;you wrote ssh and I read ssl.
&lt;br&gt;&lt;br&gt;_______________________________________________
&lt;br&gt;opensc-user mailing list
&lt;br&gt;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26646654&amp;i=0&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;opensc-user@...&lt;/a&gt;
&lt;br&gt;&lt;a href=&quot;http://www.opensc-project.org/mailman/listinfo/opensc-user&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.opensc-project.org/mailman/listinfo/opensc-user&lt;/a&gt;&lt;br&gt;&lt;p&gt;From forum: &lt;a href=&quot;http://old.nabble.com/OpenSC---User-f976.html&quot; embed=&quot;fixTarget[976]&quot; target=&quot;_top&quot; &gt;OpenSC - User&lt;/a&gt;&lt;/p&gt;</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/smartcard-supported-by-opensc-tp26643319p26646654.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-26646294</id>
	<title>Re: smartcard supported by opensc</title>
	<published>2009-12-04T09:43:21Z</published>
	<updated>2009-12-04T09:43:21Z</updated>
	<author>
		<name>Martin Paljak-2</name>
	</author>
	<content type="html">&lt;br&gt;On 04.12.2009, at 18:49, John R Pierce wrote:
&lt;br&gt;&lt;br&gt;&amp;gt; Martin Paljak wrote:
&lt;br&gt;&amp;gt;&amp;gt; The RightWay of adding smart card support is via PKCS#11 which is available from hre:
&lt;br&gt;&amp;gt;&amp;gt; 
&lt;br&gt;&amp;gt;&amp;gt; &lt;a href=&quot;http://sites.google.com/site/alonbarlev/openssh-pkcs11&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://sites.google.com/site/alonbarlev/openssh-pkcs11&lt;/a&gt;&lt;br&gt;&amp;gt;&amp;gt; 
&lt;br&gt;&amp;gt; 
&lt;br&gt;&amp;gt; what about &lt;a href=&quot;http://www.opensc-project.org/engine_pkcs11&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.opensc-project.org/engine_pkcs11&lt;/a&gt;&amp;nbsp;?
&lt;br&gt;&lt;br&gt;I don't see any reference to &amp;quot;engine&amp;quot; in OpenSSH documentation. 
&lt;br&gt;&lt;br&gt;In theory it could do as well but nlike the direct PKCS#11 interface, to my knowledge there is no implementation for an engine based approach.
&lt;br&gt;&lt;br&gt;&lt;br&gt;-- 
&lt;br&gt;Martin Paljak
&lt;br&gt;&lt;a href=&quot;http://martin.paljak.pri.ee&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://martin.paljak.pri.ee&lt;/a&gt;&lt;br&gt;+372.515.6495
&lt;br&gt;&lt;br&gt;&lt;br&gt;&lt;br&gt;&lt;br&gt;_______________________________________________
&lt;br&gt;opensc-user mailing list
&lt;br&gt;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26646294&amp;i=0&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;opensc-user@...&lt;/a&gt;
&lt;br&gt;&lt;a href=&quot;http://www.opensc-project.org/mailman/listinfo/opensc-user&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.opensc-project.org/mailman/listinfo/opensc-user&lt;/a&gt;&lt;br&gt;&lt;p&gt;From forum: &lt;a href=&quot;http://old.nabble.com/OpenSC---User-f976.html&quot; embed=&quot;fixTarget[976]&quot; target=&quot;_top&quot; &gt;OpenSC - User&lt;/a&gt;&lt;/p&gt;</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/smartcard-supported-by-opensc-tp26643319p26646294.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-26645588</id>
	<title>Re: smartcard supported by opensc</title>
	<published>2009-12-04T08:49:25Z</published>
	<updated>2009-12-04T08:49:25Z</updated>
	<author>
		<name>John R Pierce</name>
	</author>
	<content type="html">Martin Paljak wrote:
&lt;br&gt;&amp;gt; The RightWay of adding smart card support is via PKCS#11 which is available from hre:
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; &lt;a href=&quot;http://sites.google.com/site/alonbarlev/openssh-pkcs11&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://sites.google.com/site/alonbarlev/openssh-pkcs11&lt;/a&gt;&lt;br&gt;&amp;gt; &amp;nbsp; 
&lt;br&gt;&lt;br&gt;what about &lt;a href=&quot;http://www.opensc-project.org/engine_pkcs11&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.opensc-project.org/engine_pkcs11&lt;/a&gt;&amp;nbsp;?
&lt;br&gt;&lt;br&gt;&lt;br&gt;_______________________________________________
&lt;br&gt;opensc-user mailing list
&lt;br&gt;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26645588&amp;i=0&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;opensc-user@...&lt;/a&gt;
&lt;br&gt;&lt;a href=&quot;http://www.opensc-project.org/mailman/listinfo/opensc-user&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.opensc-project.org/mailman/listinfo/opensc-user&lt;/a&gt;&lt;br&gt;&lt;p&gt;From forum: &lt;a href=&quot;http://old.nabble.com/OpenSC---User-f976.html&quot; embed=&quot;fixTarget[976]&quot; target=&quot;_top&quot; &gt;OpenSC - User&lt;/a&gt;&lt;/p&gt;</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/smartcard-supported-by-opensc-tp26643319p26645588.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-26645262</id>
	<title>Re: smartcard supported by opensc</title>
	<published>2009-12-04T08:28:23Z</published>
	<updated>2009-12-04T08:28:23Z</updated>
	<author>
		<name>Martin Paljak-2</name>
	</author>
	<content type="html">&lt;br&gt;On 04.12.2009, at 18:19, Peter Keller wrote:
&lt;br&gt;&lt;div class='shrinkable-quote'&gt;&lt;br&gt;&amp;gt; On Fri, 4 Dec 2009, rainbow wrote:
&lt;br&gt;&amp;gt; 
&lt;br&gt;&amp;gt;&amp;gt; My system is linux ,debian lenny 5.0,so Aladdin eToken PRO USB 64K(4.2B) may not be supported ,do you know Athena ASEPCOS can be full supported by opensc and linux?
&lt;br&gt;&amp;gt; 
&lt;br&gt;&amp;gt; I have never seen or used any Athena cards, so I cannot answer any questions 
&lt;br&gt;&amp;gt; about them at all.
&lt;br&gt;&amp;gt; 
&lt;br&gt;&amp;gt; I forgot to say in my previous post that for the Aladdin eToken devices to 
&lt;br&gt;&amp;gt; work, you must install the Linux PKI client as well. This software should be 
&lt;br&gt;&amp;gt; either be supplied with the token or a licence code provided with the token 
&lt;br&gt;&amp;gt; that will allow you to register with Aladdin and download the software. 
&lt;br&gt;&amp;gt; However we have found that some suppliers of the hardware will not provide 
&lt;br&gt;&amp;gt; access to the software, making the cards effectively useless.
&lt;br&gt;&amp;gt; 
&lt;br&gt;&amp;gt; I rarely use debian. I can say the following though: in Ubuntu (which is 
&lt;br&gt;&amp;gt; very similar to debian), the opensc and openct packages seem to work but 
&lt;br&gt;&amp;gt; openssh is not built with smartcard support. If you want to use ssh or 
&lt;br&gt;&amp;gt; ssh-agent with a key that is stored on a smartcard, you will need to 
&lt;br&gt;&amp;gt; recompile the openssh-client package with smartcard support. This applies to 
&lt;br&gt;&amp;gt; any smartcard. I do not know anything about support for smartcards in Linux 
&lt;br&gt;&amp;gt; for applications other than openssh.
&lt;/div&gt;&lt;br&gt;The RightWay of adding smart card support is via PKCS#11 which is available from hre:
&lt;br&gt;&lt;br&gt;&lt;a href=&quot;http://sites.google.com/site/alonbarlev/openssh-pkcs11&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://sites.google.com/site/alonbarlev/openssh-pkcs11&lt;/a&gt;&lt;br&gt;&lt;br&gt;-- 
&lt;br&gt;Martin Paljak
&lt;br&gt;&lt;a href=&quot;http://martin.paljak.pri.ee&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://martin.paljak.pri.ee&lt;/a&gt;&lt;br&gt;+372.515.6495
&lt;br&gt;&lt;br&gt;&lt;br&gt;&lt;br&gt;&lt;br&gt;_______________________________________________
&lt;br&gt;opensc-user mailing list
&lt;br&gt;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26645262&amp;i=0&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;opensc-user@...&lt;/a&gt;
&lt;br&gt;&lt;a href=&quot;http://www.opensc-project.org/mailman/listinfo/opensc-user&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.opensc-project.org/mailman/listinfo/opensc-user&lt;/a&gt;&lt;br&gt;&lt;p&gt;From forum: &lt;a href=&quot;http://old.nabble.com/OpenSC---User-f976.html&quot; embed=&quot;fixTarget[976]&quot; target=&quot;_top&quot; &gt;OpenSC - User&lt;/a&gt;&lt;/p&gt;</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/smartcard-supported-by-opensc-tp26643319p26645262.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-26644980</id>
	<title>Re: smartcard supported by opensc</title>
	<published>2009-12-04T08:19:03Z</published>
	<updated>2009-12-04T08:19:03Z</updated>
	<author>
		<name>Peter Keller-2</name>
	</author>
	<content type="html">On Fri, 4 Dec 2009, rainbow wrote:
&lt;br&gt;&lt;br&gt;&amp;gt; My system is linux ,debian lenny 5.0,so Aladdin eToken PRO USB 64K(4.2B) may not be supported ,do you know Athena ASEPCOS can be full supported by opensc and linux?
&lt;br&gt;&lt;br&gt;I have never seen or used any Athena cards, so I cannot answer any questions 
&lt;br&gt;about them at all.
&lt;br&gt;&lt;br&gt;I forgot to say in my previous post that for the Aladdin eToken devices to 
&lt;br&gt;work, you must install the Linux PKI client as well. This software should be 
&lt;br&gt;either be supplied with the token or a licence code provided with the token 
&lt;br&gt;that will allow you to register with Aladdin and download the software. 
&lt;br&gt;However we have found that some suppliers of the hardware will not provide 
&lt;br&gt;access to the software, making the cards effectively useless.
&lt;br&gt;&lt;br&gt;I rarely use debian. I can say the following though: in Ubuntu (which is 
&lt;br&gt;very similar to debian), the opensc and openct packages seem to work but 
&lt;br&gt;openssh is not built with smartcard support. If you want to use ssh or 
&lt;br&gt;ssh-agent with a key that is stored on a smartcard, you will need to 
&lt;br&gt;recompile the openssh-client package with smartcard support. This applies to 
&lt;br&gt;any smartcard. I do not know anything about support for smartcards in Linux 
&lt;br&gt;for applications other than openssh.
&lt;br&gt;&lt;br&gt;If you need to recompile openssh-client, help should be available from the 
&lt;br&gt;debian community.
&lt;br&gt;&lt;br&gt;Regards,
&lt;br&gt;Peter.
&lt;br&gt;&lt;br&gt;-- 
&lt;br&gt;Peter Keller &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Tel.: +44 (0)1223 353033
&lt;br&gt;Global Phasing Ltd., &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Fax.: +44 (0)1223 366889
&lt;br&gt;Sheraton House,
&lt;br&gt;Castle Park,
&lt;br&gt;Cambridge CB3 0AX
&lt;br&gt;United Kingdom
&lt;br&gt;_______________________________________________
&lt;br&gt;opensc-user mailing list
&lt;br&gt;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26644980&amp;i=0&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;opensc-user@...&lt;/a&gt;
&lt;br&gt;&lt;a href=&quot;http://www.opensc-project.org/mailman/listinfo/opensc-user&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.opensc-project.org/mailman/listinfo/opensc-user&lt;/a&gt;&lt;br&gt;&lt;p&gt;From forum: &lt;a href=&quot;http://old.nabble.com/OpenSC---User-f976.html&quot; embed=&quot;fixTarget[976]&quot; target=&quot;_top&quot; &gt;OpenSC - User&lt;/a&gt;&lt;/p&gt;</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/smartcard-supported-by-opensc-tp26643319p26644980.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-26643709</id>
	<title>Re: smartcard supported by opensc</title>
	<published>2009-12-04T06:57:26Z</published>
	<updated>2009-12-04T06:57:26Z</updated>
	<author>
		<name>rainbow-7</name>
	</author>
	<content type="html">My system is linux ,debian lenny 5.0,so Aladdin eToken PRO USB 64K(4.2B) may not be supported ,do you know Athena ASEPCOS can be full supported by opensc and linux?&lt;br&gt;&lt;br&gt;&lt;div class=&quot;gmail_quote&quot;&gt;2009/12/4 Peter Keller &lt;span dir=&quot;ltr&quot;&gt;&amp;lt;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26643709&amp;i=0&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;pkeller@...&lt;/a&gt;&amp;gt;&lt;/span&gt;&lt;br&gt;
&lt;blockquote class=&quot;gmail_quote&quot; style=&quot;border-left: 1px solid rgb(204, 204, 204); margin: 0pt 0pt 0pt 0.8ex; padding-left: 1ex;&quot;&gt;&lt;div class=&quot;im&quot;&gt;On Fri, 4 Dec 2009, rainbow wrote:&lt;br&gt;
&lt;br&gt;
&amp;gt; hi, I do not understand the smartcard very much,I see from opensc that AKIS card not support the pkcs15-init , so is there any thing impact the use of opensc ,such as write data to card or create keys, or is&lt;br&gt;
&amp;gt; there a card full supported by opensc,thanks.&lt;br&gt;
&lt;br&gt;
&lt;/div&gt;We have successfully used the Aladdin eToken PRO USB 64K(4.2B) cards with&lt;br&gt;
opensc, on the following systems:&lt;br&gt;
&lt;br&gt;
    OpenSUSE 11.1 (distribution default openssh, opensc and openct packages)&lt;br&gt;
&lt;br&gt;
    OS X 10.5.8 (OpenSC installed separately: only the OpenSC scssh-agent is&lt;br&gt;
actually required, the other system-provided ssh-tools and pcscd work fine).&lt;br&gt;
Please be aware that:&lt;br&gt;
&lt;br&gt;
   (1) These cards will NOT work on Windows 7 or OS X 10.6.x systems until&lt;br&gt;
Aladdin release compatible middleware&lt;br&gt;
&lt;br&gt;
   (2) The Aladdin eToken PRO USB 72K(JC) has been reported NOT to work on&lt;br&gt;
Linux with the Aladdin PKI client here:&lt;br&gt;
&lt;a href=&quot;http://www.etokenonlinux.org/et/FAQ#eTokenhardwareandsoftware&quot; target=&quot;_blank&quot; rel=&quot;nofollow&quot;&gt;http://www.etokenonlinux.org/et/FAQ#eTokenhardwareandsoftware&lt;/a&gt;&lt;br&gt;
&lt;br&gt;
Good luck,&lt;br&gt;
Peter.&lt;br&gt;
&lt;br&gt;
--&lt;br&gt;
Peter Keller                                     Tel.: +44 (0)1223 353033&lt;br&gt;
Global Phasing Ltd.,                             Fax.: +44 (0)1223 366889&lt;br&gt;
Sheraton House,&lt;br&gt;
Castle Park,&lt;br&gt;
Cambridge CB3 0AX&lt;br&gt;
United Kingdom&lt;br&gt;
_______________________________________________&lt;br&gt;
opensc-user mailing list&lt;br&gt;
&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26643709&amp;i=1&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;opensc-user@...&lt;/a&gt;&lt;br&gt;
&lt;a href=&quot;http://www.opensc-project.org/mailman/listinfo/opensc-user&quot; target=&quot;_blank&quot; rel=&quot;nofollow&quot;&gt;http://www.opensc-project.org/mailman/listinfo/opensc-user&lt;/a&gt;&lt;br&gt;
&lt;/blockquote&gt;&lt;/div&gt;&lt;br&gt;&lt;br clear=&quot;all&quot;&gt;&lt;br&gt;-- &lt;br&gt;Qingquan Lv&lt;br&gt;School of Information Science &amp;amp; Engineering , Lanzhou University.&lt;br&gt;mail: &lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26643709&amp;i=2&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;lvqq05@...&lt;/a&gt;&lt;br&gt;Do what you like,&lt;br&gt;
Enjoy your life.&lt;br&gt;
&lt;br /&gt;_______________________________________________
&lt;br&gt;opensc-user mailing list
&lt;br&gt;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26643709&amp;i=3&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;opensc-user@...&lt;/a&gt;
&lt;br&gt;&lt;a href=&quot;http://www.opensc-project.org/mailman/listinfo/opensc-user&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.opensc-project.org/mailman/listinfo/opensc-user&lt;/a&gt;&lt;p&gt;From forum: &lt;a href=&quot;http://old.nabble.com/OpenSC---User-f976.html&quot; embed=&quot;fixTarget[976]&quot; target=&quot;_top&quot; &gt;OpenSC - User&lt;/a&gt;&lt;/p&gt;</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/smartcard-supported-by-opensc-tp26643319p26643709.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-26643544</id>
	<title>Re: smartcard supported by opensc</title>
	<published>2009-12-04T06:45:35Z</published>
	<updated>2009-12-04T06:45:35Z</updated>
	<author>
		<name>Peter Keller-2</name>
	</author>
	<content type="html">On Fri, 4 Dec 2009, rainbow wrote:
&lt;br&gt;&lt;br&gt;&amp;gt; hi, I do not understand the smartcard very much,I see from opensc that AKIS card not support the pkcs15-init , so is there any thing impact the use of opensc ,such as write data to card or create keys, or is
&lt;br&gt;&amp;gt; there a card full supported by opensc,thanks.
&lt;br&gt;&lt;br&gt;We have successfully used the Aladdin eToken PRO USB 64K(4.2B) cards with 
&lt;br&gt;opensc, on the following systems:
&lt;br&gt;&lt;br&gt;&amp;nbsp; &amp;nbsp; OpenSUSE 11.1 (distribution default openssh, opensc and openct packages)
&lt;br&gt;&lt;br&gt;&amp;nbsp; &amp;nbsp; OS X 10.5.8 (OpenSC installed separately: only the OpenSC scssh-agent is 
&lt;br&gt;actually required, the other system-provided ssh-tools and pcscd work fine). 
&lt;br&gt;Please be aware that:
&lt;br&gt;&lt;br&gt;&amp;nbsp; &amp;nbsp;(1) These cards will NOT work on Windows 7 or OS X 10.6.x systems until 
&lt;br&gt;Aladdin release compatible middleware
&lt;br&gt;&lt;br&gt;&amp;nbsp; &amp;nbsp;(2) The Aladdin eToken PRO USB 72K(JC) has been reported NOT to work on 
&lt;br&gt;Linux with the Aladdin PKI client here: 
&lt;br&gt;&lt;a href=&quot;http://www.etokenonlinux.org/et/FAQ#eTokenhardwareandsoftware&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.etokenonlinux.org/et/FAQ#eTokenhardwareandsoftware&lt;/a&gt;&lt;br&gt;&lt;br&gt;Good luck,
&lt;br&gt;Peter.
&lt;br&gt;&lt;br&gt;-- 
&lt;br&gt;Peter Keller &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Tel.: +44 (0)1223 353033
&lt;br&gt;Global Phasing Ltd., &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Fax.: +44 (0)1223 366889
&lt;br&gt;Sheraton House,
&lt;br&gt;Castle Park,
&lt;br&gt;Cambridge CB3 0AX
&lt;br&gt;United Kingdom
&lt;br&gt;_______________________________________________
&lt;br&gt;opensc-user mailing list
&lt;br&gt;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26643544&amp;i=0&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;opensc-user@...&lt;/a&gt;
&lt;br&gt;&lt;a href=&quot;http://www.opensc-project.org/mailman/listinfo/opensc-user&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.opensc-project.org/mailman/listinfo/opensc-user&lt;/a&gt;&lt;br&gt;&lt;p&gt;From forum: &lt;a href=&quot;http://old.nabble.com/OpenSC---User-f976.html&quot; embed=&quot;fixTarget[976]&quot; target=&quot;_top&quot; &gt;OpenSC - User&lt;/a&gt;&lt;/p&gt;</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/smartcard-supported-by-opensc-tp26643319p26643544.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-26643319</id>
	<title>smartcard supported by opensc</title>
	<published>2009-12-04T06:29:31Z</published>
	<updated>2009-12-04T06:29:31Z</updated>
	<author>
		<name>rainbow-7</name>
	</author>
	<content type="html">hi, I do not understand the smartcard very much,I see from opensc that AKIS card not support the pkcs15-init , so is there any thing impact the use of opensc ,such as write data to card or create keys, or is there a card full supported by opensc,thanks.&lt;br&gt;
-- &lt;br&gt;Qingquan Lv&lt;br&gt;School of Information Science &amp;amp; Engineering , Lanzhou University.&lt;br&gt;mail: &lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26643319&amp;i=0&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;lvqq05@...&lt;/a&gt;&lt;br&gt;Do what you like,&lt;br&gt;Enjoy your life.&lt;br&gt;
&lt;br /&gt;_______________________________________________
&lt;br&gt;opensc-user mailing list
&lt;br&gt;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26643319&amp;i=1&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;opensc-user@...&lt;/a&gt;
&lt;br&gt;&lt;a href=&quot;http://www.opensc-project.org/mailman/listinfo/opensc-user&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.opensc-project.org/mailman/listinfo/opensc-user&lt;/a&gt;&lt;p&gt;From forum: &lt;a href=&quot;http://old.nabble.com/OpenSC---User-f976.html&quot; embed=&quot;fixTarget[976]&quot; target=&quot;_top&quot; &gt;OpenSC - User&lt;/a&gt;&lt;/p&gt;</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/smartcard-supported-by-opensc-tp26643319p26643319.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-26642947</id>
	<title>Re: Gemplus GPK 16k cards are fully supported by OpenSC and regularly tested</title>
	<published>2009-12-04T06:01:54Z</published>
	<updated>2009-12-04T06:01:54Z</updated>
	<author>
		<name>Andreas Jellinghaus-2</name>
	</author>
	<content type="html">Am Freitag 04 Dezember 2009 14:53:33 schrieb rainbow:
&lt;br&gt;&amp;gt; &amp;quot; Gemplus GPK 16k cards are fully supported by OpenSC and regularly tested&amp;quot;
&lt;br&gt;&amp;gt; does that means I can execute all pkcs15-init &amp;nbsp;commands and opensc-explorer
&lt;br&gt;&amp;gt; commands and so on?
&lt;br&gt;&lt;br&gt;as far as I know: yes. but those card are very, very old. I guess gemplus
&lt;br&gt;stopped producing them 5 or 10 years ago, so I doubt you can still buy them.
&lt;br&gt;&lt;br&gt;Current Gemalto cards are all unsupported, as far as I know, except for
&lt;br&gt;the cryptoflex card which can be used with the muscle applet (see current
&lt;br&gt;discussion on this list, haven't tested it myself). And there is some kind
&lt;br&gt;of emulation for gemplus v1 card format in opensc - i.e. you can use a few
&lt;br&gt;functions of those cards. and Gemplus v1 format is quite old too, I think
&lt;br&gt;they introduced a new format years ago, and that isn't supported by opensc.
&lt;br&gt;&lt;br&gt;Regards, Andreas
&lt;br&gt;_______________________________________________
&lt;br&gt;opensc-user mailing list
&lt;br&gt;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26642947&amp;i=0&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;opensc-user@...&lt;/a&gt;
&lt;br&gt;&lt;a href=&quot;http://www.opensc-project.org/mailman/listinfo/opensc-user&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.opensc-project.org/mailman/listinfo/opensc-user&lt;/a&gt;&lt;br&gt;&lt;p&gt;From forum: &lt;a href=&quot;http://old.nabble.com/OpenSC---User-f976.html&quot; embed=&quot;fixTarget[976]&quot; target=&quot;_top&quot; &gt;OpenSC - User&lt;/a&gt;&lt;/p&gt;</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/Gemplus-GPK-16k-cards-are-fully-supported-by-OpenSC-and-regularly-tested-tp26642826p26642947.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-26642826</id>
	<title>Gemplus GPK 16k cards are fully supported by OpenSC and regularly tested</title>
	<published>2009-12-04T05:53:33Z</published>
	<updated>2009-12-04T05:53:33Z</updated>
	<author>
		<name>rainbow-7</name>
	</author>
	<content type="html">&lt;br clear=&quot;all&quot;&gt;&amp;quot;
Gemplus GPK 16k cards are fully supported by OpenSC and regularly tested&amp;quot; does that means I can execute all pkcs15-init  commands and opensc-explorer commands and so on?&lt;br&gt;-- &lt;br&gt;Qingquan Lv&lt;br&gt;School of Information Science &amp;amp; Engineering , Lanzhou University.&lt;br&gt;
mail: &lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26642826&amp;i=0&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;lvqq05@...&lt;/a&gt;&lt;br&gt;Do what you like,&lt;br&gt;Enjoy your life.&lt;br&gt;
&lt;br /&gt;_______________________________________________
&lt;br&gt;opensc-user mailing list
&lt;br&gt;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26642826&amp;i=1&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;opensc-user@...&lt;/a&gt;
&lt;br&gt;&lt;a href=&quot;http://www.opensc-project.org/mailman/listinfo/opensc-user&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.opensc-project.org/mailman/listinfo/opensc-user&lt;/a&gt;&lt;p&gt;From forum: &lt;a href=&quot;http://old.nabble.com/OpenSC---User-f976.html&quot; embed=&quot;fixTarget[976]&quot; target=&quot;_top&quot; &gt;OpenSC - User&lt;/a&gt;&lt;/p&gt;</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/Gemplus-GPK-16k-cards-are-fully-supported-by-OpenSC-and-regularly-tested-tp26642826p26642826.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-26642581</id>
	<title>Re: no pkcs15-init in my opensc</title>
	<published>2009-12-04T05:35:12Z</published>
	<updated>2009-12-04T05:35:12Z</updated>
	<author>
		<name>Andreas Jellinghaus-2</name>
	</author>
	<content type="html">Am Freitag 04 Dezember 2009 13:21:19 schrieb rainbow:
&lt;br&gt;&amp;gt; my card is acs03,maybe it is not supported by opensc now.
&lt;br&gt;&lt;br&gt;acos3 is not supported, and never will be (opensc is for
&lt;br&gt;crypto cards, acos3 doesn't have rsa crypto as far as I know).
&lt;br&gt;&lt;br&gt;acos5 is a crypto card, but we don't have a drive for it,
&lt;br&gt;so it can't be used with opensc either.
&lt;br&gt;&lt;br&gt;Regards, Andreas
&lt;br&gt;_______________________________________________
&lt;br&gt;opensc-user mailing list
&lt;br&gt;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26642581&amp;i=0&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;opensc-user@...&lt;/a&gt;
&lt;br&gt;&lt;a href=&quot;http://www.opensc-project.org/mailman/listinfo/opensc-user&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.opensc-project.org/mailman/listinfo/opensc-user&lt;/a&gt;&lt;br&gt;&lt;p&gt;From forum: &lt;a href=&quot;http://old.nabble.com/OpenSC---User-f976.html&quot; embed=&quot;fixTarget[976]&quot; target=&quot;_top&quot; &gt;OpenSC - User&lt;/a&gt;&lt;/p&gt;</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/no-pkcs15-init-in-my-opensc-tp26641781p26642581.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-26642564</id>
	<title>Re: pkcs15-init and openct</title>
	<published>2009-12-04T05:33:37Z</published>
	<updated>2009-12-04T05:33:37Z</updated>
	<author>
		<name>Andreas Jellinghaus-2</name>
	</author>
	<content type="html">if you want to use opensc with pcsc, then edit
&lt;br&gt;opensc.conf and set reader_drivers = pcsc;
&lt;br&gt;&lt;br&gt;if you want to use opensc with openct, then edit
&lt;br&gt;opensc.conf and set reader_drivers = openct;
&lt;br&gt;&lt;br&gt;the default is both drivers, but you don't need that
&lt;br&gt;(unless you absolutely know what you are doing).
&lt;br&gt;&lt;br&gt;&amp;gt; &amp;nbsp;should I have to install openct ? There is no such indication on the
&lt;br&gt;&amp;gt; &amp;nbsp;opensc project? anybody know why?
&lt;br&gt;&lt;br&gt;please have a look at the documentation (e.g. FAQ on the website,
&lt;br&gt;QuickStart of each project), and help us to improve it.
&lt;br&gt;&lt;br&gt;Thanks, Andreas
&lt;br&gt;_______________________________________________
&lt;br&gt;opensc-user mailing list
&lt;br&gt;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26642564&amp;i=0&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;opensc-user@...&lt;/a&gt;
&lt;br&gt;&lt;a href=&quot;http://www.opensc-project.org/mailman/listinfo/opensc-user&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.opensc-project.org/mailman/listinfo/opensc-user&lt;/a&gt;&lt;br&gt;&lt;p&gt;From forum: &lt;a href=&quot;http://old.nabble.com/OpenSC---User-f976.html&quot; embed=&quot;fixTarget[976]&quot; target=&quot;_top&quot; &gt;OpenSC - User&lt;/a&gt;&lt;/p&gt;</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/pkcs15-init-and-openct-tp26642196p26642564.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-26642196</id>
	<title>pkcs15-init and openct</title>
	<published>2009-12-04T04:59:29Z</published>
	<updated>2009-12-04T04:59:29Z</updated>
	<author>
		<name>rainbow-7</name>
	</author>
	<content type="html">hi, I have install opensc and pc/sc driver for smart card, i do not install openct,but when I &lt;br&gt;   #pkcs15-init --create-pkcs15&lt;br&gt;   Error: can&amp;#39;t open /var/run/openct/status: No such file or directory&lt;br&gt;   Error: can&amp;#39;t open /var/run/openct/status: No such file or directory&lt;br&gt;
   Error: can&amp;#39;t open /var/run/openct/status: No such file or directory&lt;br&gt;   Error: can&amp;#39;t open /var/run/openct/status: No such file or directory&lt;br&gt;   Error: can&amp;#39;t open /var/run/openct/status: No such file or directory&lt;br&gt;
 should I have to install openct ? There is no such indication on the opensc project? anybody know why?&lt;br&gt;&lt;br clear=&quot;all&quot;&gt;&lt;br&gt;-- &lt;br&gt;Qingquan Lv&lt;br&gt;School of Information Science &amp;amp; Engineering , Lanzhou University.&lt;br&gt;
mail: &lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26642196&amp;i=0&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;lvqq05@...&lt;/a&gt;&lt;br&gt;Do what you like,&lt;br&gt;Enjoy your life.&lt;br&gt;
&lt;br /&gt;_______________________________________________
&lt;br&gt;opensc-user mailing list
&lt;br&gt;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26642196&amp;i=1&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;opensc-user@...&lt;/a&gt;
&lt;br&gt;&lt;a href=&quot;http://www.opensc-project.org/mailman/listinfo/opensc-user&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.opensc-project.org/mailman/listinfo/opensc-user&lt;/a&gt;&lt;p&gt;From forum: &lt;a href=&quot;http://old.nabble.com/OpenSC---User-f976.html&quot; embed=&quot;fixTarget[976]&quot; target=&quot;_top&quot; &gt;OpenSC - User&lt;/a&gt;&lt;/p&gt;</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/pkcs15-init-and-openct-tp26642196p26642196.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-26641781</id>
	<title>no pkcs15-init in my opensc</title>
	<published>2009-12-04T04:21:19Z</published>
	<updated>2009-12-04T04:21:19Z</updated>
	<author>
		<name>rainbow-7</name>
	</author>
	<content type="html">hi,&lt;br&gt;    I have installed opensc on my computer,my os is debian 5.0 and gcc is 3.4,after installing it according to the method on the official webpage, but I find there is no pkcs15-init command,and when i execute command :&lt;br&gt;
&lt;pre class=&quot;wiki&quot;&gt;#opensc-tool --atr&lt;br&gt;Using reader with a card: ACS ACR38U 00 00&lt;br&gt;[opensc-tool] card-default.c:113:default_init: unable to determine the right class byte&lt;br&gt;[opensc-tool] card.c:202:sc_connect_card: driver &amp;#39;Default driver for unknown cards&amp;#39; init() failed: Card is invalid or cannot be handled&lt;br&gt;
[opensc-tool] card.c:213:sc_connect_card: unable to find driver for inserted card&lt;br&gt;[opensc-tool] card.c:228:sc_connect_card: returning with: Card is invalid or cannot be handled&lt;br&gt;Failed to connect to card: Card is invalid or cannot be handled&lt;br&gt;
&lt;br&gt;&lt;/pre&gt;my card is acs03,maybe it is not supported by opensc now. If I have pkcs15-init tool, is it the best for me to buy an empty card or it may limit the opensc tool?  Hope your reples,thanks!&lt;br&gt; &lt;br&gt;Qingquan Lv&lt;br&gt;
School of Information Science &amp;amp; Engineering , Lanzhou University.&lt;br&gt;mail: &lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26641781&amp;i=0&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;lvqq05@...&lt;/a&gt;&lt;br&gt;Do what you like,&lt;br&gt;Enjoy your life.&lt;br&gt;
&lt;br /&gt;_______________________________________________
&lt;br&gt;opensc-user mailing list
&lt;br&gt;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26641781&amp;i=1&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;opensc-user@...&lt;/a&gt;
&lt;br&gt;&lt;a href=&quot;http://www.opensc-project.org/mailman/listinfo/opensc-user&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.opensc-project.org/mailman/listinfo/opensc-user&lt;/a&gt;&lt;p&gt;From forum: &lt;a href=&quot;http://old.nabble.com/OpenSC---User-f976.html&quot; embed=&quot;fixTarget[976]&quot; target=&quot;_top&quot; &gt;OpenSC - User&lt;/a&gt;&lt;/p&gt;</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/no-pkcs15-init-in-my-opensc-tp26641781p26641781.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-26639883</id>
	<title>Re: Unblocking PIN via PKCS#11?</title>
	<published>2009-12-04T01:31:53Z</published>
	<updated>2009-12-04T01:31:53Z</updated>
	<author>
		<name>Viktor TARASOV-2</name>
	</author>
	<content type="html">&lt;!DOCTYPE html PUBLIC &quot;-//W3C//DTD HTML 4.01 Transitional//EN&quot;&gt;
&lt;html&gt;
&lt;head&gt;
  &lt;meta content=&quot;text/html;charset=ISO-8859-1&quot; http-equiv=&quot;Content-Type&quot;&gt;
&lt;/head&gt;
&lt;body bgcolor=&quot;#ffffff&quot; text=&quot;#000000&quot;&gt;
Pierre Ossman wrote:
&lt;blockquote cite=&quot;mid:20091204091920.032b9f97@ossman.lkpg.cendio.se&quot; type=&quot;cite&quot;&gt;
  &lt;pre wrap=&quot;&quot;&gt;On Thu, 03 Dec 2009 16:32:01 +0100
Viktor TARASOV &lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26639883&amp;i=0&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;viktor.tarasov@...&lt;/a&gt; wrote:

  &lt;/pre&gt;
  &lt;blockquote type=&quot;cite&quot;&gt;
    &lt;pre wrap=&quot;&quot;&gt;As for me, for the cards (rather 'pkcs15 contents') that do not have 
SOPIN or the only useful SOPIN function is 'unblock_user_pin' it's 
acceptable to use PUK as SOPIN and to use 'sc_pkcs15_unblock_pin' in 
C_InitPIN() .

    &lt;/pre&gt;
  &lt;/blockquote&gt;
  &lt;pre wrap=&quot;&quot;&gt;&lt;!----&gt;
Could you elaborate on what other SO PINs there are out there
  &lt;/pre&gt;
&lt;/blockquote&gt;
According to standard the SO-PIN is not PUK - the role of SO is to
initialize token &lt;br&gt;
and create User PIN .&lt;br&gt;
So, it's natural that our colleagues can oppose the idea to consider
PUK==SOPIN . &lt;br&gt;
(As I've told above, it's not my case. )&lt;br&gt;
&lt;br&gt;
There is no &quot;PUK&quot; notion in the standard. &lt;br&gt;
From my point of view, the most 'standard' manner to do User 'PIN
unblock' &lt;br&gt;
is with the C_SetPIN() in the unlogged session.&lt;br&gt;
&lt;br&gt;
&lt;br&gt;
&lt;blockquote cite=&quot;mid:20091204091920.032b9f97@ossman.lkpg.cendio.se&quot; type=&quot;cite&quot;&gt;
  &lt;pre wrap=&quot;&quot;&gt;how my patch would cause problems in those cases.
  &lt;/pre&gt;
&lt;/blockquote&gt;
I need to look it more closely.&lt;br&gt;
&lt;br&gt;
&lt;blockquote cite=&quot;mid:20091204091920.032b9f97@ossman.lkpg.cendio.se&quot; type=&quot;cite&quot;&gt;
  &lt;pre wrap=&quot;&quot;&gt;All the cards I have
experience with only have the PIN and PUK.
  &lt;/pre&gt;
&lt;/blockquote&gt;
&lt;br&gt;
There are the cases when at the card level SOPIN != PUK .&lt;br&gt;
Another question if this difference is exported by the driver to the
upper level.&lt;br&gt;
&lt;br&gt;
&lt;br&gt;
&lt;blockquote cite=&quot;mid:20091204091920.032b9f97@ossman.lkpg.cendio.se&quot; type=&quot;cite&quot;&gt;
  &lt;pre wrap=&quot;&quot;&gt;
Rgds
  &lt;/pre&gt;
&lt;/blockquote&gt;
&lt;br&gt;
Kind wishes,&lt;br&gt;
&lt;br&gt;
&lt;br&gt;
&lt;pre class=&quot;moz-signature&quot; cols=&quot;128&quot;&gt;-- 
Viktor Tarasov	&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26639883&amp;i=1&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;viktor.tarasov@...&lt;/a&gt;
&lt;/pre&gt;
&lt;/body&gt;
&lt;/html&gt;
&lt;br /&gt;_______________________________________________
&lt;br&gt;opensc-devel mailing list
&lt;br&gt;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26639883&amp;i=2&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;opensc-devel@...&lt;/a&gt;
&lt;br&gt;&lt;a href=&quot;http://www.opensc-project.org/mailman/listinfo/opensc-devel&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.opensc-project.org/mailman/listinfo/opensc-devel&lt;/a&gt;&lt;p&gt;From forum: &lt;a href=&quot;http://old.nabble.com/OpenSC---Dev-f975.html&quot; embed=&quot;fixTarget[975]&quot; target=&quot;_top&quot; &gt;OpenSC - Dev&lt;/a&gt;&lt;/p&gt;</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/Unblocking-PIN-via-PKCS-11--tp26288636p26639883.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-26639362</id>
	<title>Re: Unblocking PIN via PKCS#11?</title>
	<published>2009-12-04T00:44:36Z</published>
	<updated>2009-12-04T00:44:36Z</updated>
	<author>
		<name>Viktor TARASOV-2</name>
	</author>
	<content type="html">&lt;!DOCTYPE html PUBLIC &quot;-//W3C//DTD HTML 4.01 Transitional//EN&quot;&gt;
&lt;html&gt;
&lt;head&gt;
  &lt;meta content=&quot;text/html;charset=ISO-8859-1&quot; http-equiv=&quot;Content-Type&quot;&gt;
&lt;/head&gt;
&lt;body bgcolor=&quot;#ffffff&quot; text=&quot;#000000&quot;&gt;
Pierre Ossman wrote:
&lt;blockquote cite=&quot;mid:20091204091704.5fdbf4f1@ossman.lkpg.cendio.se&quot; type=&quot;cite&quot;&gt;
  &lt;pre wrap=&quot;&quot;&gt;On Thu, 03 Dec 2009 16:57:55 +0100
Viktor TARASOV &lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26639362&amp;i=0&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;viktor.tarasov@...&lt;/a&gt; wrote:

  &lt;/pre&gt;
  &lt;blockquote type=&quot;cite&quot;&gt;
    &lt;pre wrap=&quot;&quot;&gt;In fact, reading the pkcs11.v2.20 pp 116:

C_SetPIN modifies the PIN of the user that is currently logged in, or 
the CKU_USER PIN if the session is not logged in.

So, C_Login(CKU_SO) + C_InitPIN() is not the only PIN unblocking scheme.

    &lt;/pre&gt;
  &lt;/blockquote&gt;
  &lt;pre wrap=&quot;&quot;&gt;&lt;!----&gt;
But C_SetPIN requires knowledge of the existing PIN, which the user
most likely doesn't have if they've managed to lock themselves out.

And even if they know the correct PIN, how would OpenSC go about
verifying this since the card will refuse to validate the PIN now that
it is locked?
  &lt;/pre&gt;
&lt;/blockquote&gt;
&lt;br&gt;
I understood this phrase in the following way:&lt;br&gt;
-- if C_SetPIN() is preceded by C_Login(CKU_XX), then C_SetPIN will
change the XX PIN.&lt;br&gt;
&amp;nbsp;&amp;nbsp; In this case the 'pOldPin' argument is the current PIN value &lt;br&gt;
&amp;nbsp;&amp;nbsp; or empty (if P1=01 mode of the ISO 'Change Reference Data' command
is used &lt;br&gt;
&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;nbsp;&amp;nbsp;&amp;nbsp; or PIN is already cached during the C_Login());&lt;br&gt;
&lt;br&gt;
-- if C_SetPIN() is not preceded by C_Login then it's implicitly the
User PIN is going to be changed. &lt;br&gt;
&amp;nbsp;&amp;nbsp; In this case the 'pOldPin' argument is the unblocking code. &lt;br&gt;
&amp;nbsp;&amp;nbsp; For me it's quite logical, because, as you've told, &lt;br&gt;
&amp;nbsp;&amp;nbsp; we do not have or cannot use the actual PIN value.&lt;br&gt;
&lt;br&gt;
&lt;br&gt;
The standard uses term 'modify' - for me it can be the both - 'change'
and 'unlock'.&lt;br&gt;
To make 'PIN change' there is the C_Login()+C_SetPIN() mode. &lt;br&gt;
So, the other mode is for 'PIN unlock', and, IMHO, this mode fits quite
well to 'PIN unlock'.&lt;br&gt;
&lt;br&gt;
&lt;br&gt;
&lt;br&gt;
&lt;blockquote cite=&quot;mid:20091204091704.5fdbf4f1@ossman.lkpg.cendio.se&quot; type=&quot;cite&quot;&gt;
  &lt;pre wrap=&quot;&quot;&gt;
Rgds
  &lt;/pre&gt;
&lt;/blockquote&gt;
&lt;br&gt;
Kind wishes,&lt;br&gt;
&lt;br&gt;
&lt;br&gt;
&lt;pre class=&quot;moz-signature&quot; cols=&quot;128&quot;&gt;-- 
Viktor Tarasov	&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26639362&amp;i=1&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;viktor.tarasov@...&lt;/a&gt;
&lt;/pre&gt;
&lt;/body&gt;
&lt;/html&gt;
&lt;br /&gt;_______________________________________________
&lt;br&gt;opensc-devel mailing list
&lt;br&gt;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26639362&amp;i=2&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;opensc-devel@...&lt;/a&gt;
&lt;br&gt;&lt;a href=&quot;http://www.opensc-project.org/mailman/listinfo/opensc-devel&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.opensc-project.org/mailman/listinfo/opensc-devel&lt;/a&gt;&lt;p&gt;From forum: &lt;a href=&quot;http://old.nabble.com/OpenSC---Dev-f975.html&quot; embed=&quot;fixTarget[975]&quot; target=&quot;_top&quot; &gt;OpenSC - Dev&lt;/a&gt;&lt;/p&gt;</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/Unblocking-PIN-via-PKCS-11--tp26288636p26639362.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-26639126</id>
	<title>Re: Unblocking PIN via PKCS#11?</title>
	<published>2009-12-04T00:19:20Z</published>
	<updated>2009-12-04T00:19:20Z</updated>
	<author>
		<name>Pierre Ossman-3</name>
	</author>
	<content type="html">On Thu, 03 Dec 2009 16:32:01 +0100
&lt;br&gt;Viktor TARASOV &amp;lt;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26639126&amp;i=0&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;viktor.tarasov@...&lt;/a&gt;&amp;gt; wrote:
&lt;br&gt;&lt;br&gt;&amp;gt; 
&lt;br&gt;&amp;gt; As for me, for the cards (rather 'pkcs15 contents') that do not have 
&lt;br&gt;&amp;gt; SOPIN or the only useful SOPIN function is 'unblock_user_pin' it's 
&lt;br&gt;&amp;gt; acceptable to use PUK as SOPIN and to use 'sc_pkcs15_unblock_pin' in 
&lt;br&gt;&amp;gt; C_InitPIN() .
&lt;br&gt;&amp;gt; 
&lt;br&gt;&lt;br&gt;Could you elaborate on what other SO PINs there are out there and how
&lt;br&gt;my patch would cause problems in those cases. All the cards I have
&lt;br&gt;experience with only have the PIN and PUK.
&lt;br&gt;&lt;br&gt;Rgds
&lt;br&gt;-- 
&lt;br&gt;Pierre Ossman &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;OpenSource-based Thin Client Technology
&lt;br&gt;System Developer &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Telephone: +46-13-21 46 00
&lt;br&gt;Cendio AB &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;Web: &lt;a href=&quot;http://www.cendio.com&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.cendio.com&lt;/a&gt;&lt;br&gt;&lt;br /&gt; &lt;br /&gt;_______________________________________________
&lt;br&gt;opensc-devel mailing list
&lt;br&gt;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26639126&amp;i=1&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;opensc-devel@...&lt;/a&gt;
&lt;br&gt;&lt;a href=&quot;http://www.opensc-project.org/mailman/listinfo/opensc-devel&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.opensc-project.org/mailman/listinfo/opensc-devel&lt;/a&gt;&lt;div class=&quot;small&quot;&gt;&lt;br/&gt;&lt;img src=&quot;http://old.nabble.com/images/icon_attachment.gif&quot; &gt; &lt;strong&gt;signature.asc&lt;/strong&gt; (205 bytes) &lt;a href=&quot;http://old.nabble.com/attachment/26639126/0/signature.asc&quot; target=&quot;_top&quot;&gt;Download Attachment&lt;/a&gt;&lt;/div&gt;&lt;p&gt;From forum: &lt;a href=&quot;http://old.nabble.com/OpenSC---Dev-f975.html&quot; embed=&quot;fixTarget[975]&quot; target=&quot;_top&quot; &gt;OpenSC - Dev&lt;/a&gt;&lt;/p&gt;</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/Unblocking-PIN-via-PKCS-11--tp26288636p26639126.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-26639106</id>
	<title>Re: Unblocking PIN via PKCS#11?</title>
	<published>2009-12-04T00:17:04Z</published>
	<updated>2009-12-04T00:17:04Z</updated>
	<author>
		<name>Pierre Ossman-3</name>
	</author>
	<content type="html">On Thu, 03 Dec 2009 16:57:55 +0100
&lt;br&gt;Viktor TARASOV &amp;lt;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26639106&amp;i=0&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;viktor.tarasov@...&lt;/a&gt;&amp;gt; wrote:
&lt;br&gt;&lt;br&gt;&amp;gt; 
&lt;br&gt;&amp;gt; In fact, reading the pkcs11.v2.20 pp 116:
&lt;br&gt;&amp;gt; 
&lt;br&gt;&amp;gt; C_SetPIN modifies the PIN of the user that is currently logged in, or 
&lt;br&gt;&amp;gt; the CKU_USER PIN if the session is not logged in.
&lt;br&gt;&amp;gt; 
&lt;br&gt;&amp;gt; So, C_Login(CKU_SO) + C_InitPIN() is not the only PIN unblocking scheme.
&lt;br&gt;&amp;gt; 
&lt;br&gt;&lt;br&gt;But C_SetPIN requires knowledge of the existing PIN, which the user
&lt;br&gt;most likely doesn't have if they've managed to lock themselves out.
&lt;br&gt;&lt;br&gt;And even if they know the correct PIN, how would OpenSC go about
&lt;br&gt;verifying this since the card will refuse to validate the PIN now that
&lt;br&gt;it is locked?
&lt;br&gt;&lt;br&gt;Rgds
&lt;br&gt;-- 
&lt;br&gt;Pierre Ossman &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;OpenSource-based Thin Client Technology
&lt;br&gt;System Developer &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Telephone: +46-13-21 46 00
&lt;br&gt;Cendio AB &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;Web: &lt;a href=&quot;http://www.cendio.com&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.cendio.com&lt;/a&gt;&lt;br&gt;&lt;br /&gt; &lt;br /&gt;_______________________________________________
&lt;br&gt;opensc-devel mailing list
&lt;br&gt;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26639106&amp;i=1&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;opensc-devel@...&lt;/a&gt;
&lt;br&gt;&lt;a href=&quot;http://www.opensc-project.org/mailman/listinfo/opensc-devel&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.opensc-project.org/mailman/listinfo/opensc-devel&lt;/a&gt;&lt;div class=&quot;small&quot;&gt;&lt;br/&gt;&lt;img src=&quot;http://old.nabble.com/images/icon_attachment.gif&quot; &gt; &lt;strong&gt;signature.asc&lt;/strong&gt; (205 bytes) &lt;a href=&quot;http://old.nabble.com/attachment/26639106/0/signature.asc&quot; target=&quot;_top&quot;&gt;Download Attachment&lt;/a&gt;&lt;/div&gt;&lt;p&gt;From forum: &lt;a href=&quot;http://old.nabble.com/OpenSC---Dev-f975.html&quot; embed=&quot;fixTarget[975]&quot; target=&quot;_top&quot; &gt;OpenSC - Dev&lt;/a&gt;&lt;/p&gt;</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/Unblocking-PIN-via-PKCS-11--tp26288636p26639106.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-26629927</id>
	<title>Re: SCardConnect(), dwPreferredProtocols and detecting 	Pinpad</title>
	<published>2009-12-03T09:34:12Z</published>
	<updated>2009-12-03T09:34:12Z</updated>
	<author>
		<name>Ludovic Rousseau</name>
	</author>
	<content type="html">2009/12/3 Viktor TARASOV &amp;lt;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26629927&amp;i=0&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;viktor.tarasov@...&lt;/a&gt;&amp;gt;:
&lt;br&gt;&amp;gt; Hi,
&lt;br&gt;&lt;br&gt;Hello,
&lt;br&gt;&lt;br&gt;&amp;gt; for me, PinPad is not detected with dwPreferredProtocols=0
&lt;br&gt;&amp;gt; in the preceding SCardConnect() call (src/libopensc/reader-pcsc.c +917).
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; With dwPreferredProtocols=SCARD_PROTOCOL_ANY it's detected normally.
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; Is it question of version of PCSC(1.4.3-16) or CCID(1.3.0-15)?
&lt;br&gt;&lt;br&gt;Exact. This bug has been corrected in revision 2957 [1] of pcsc-lite.
&lt;br&gt;The correction appeared in version pcsc-lite 1.5.0.
&lt;br&gt;&lt;br&gt;The Apple version of pcsc-lite still have the bug.
&lt;br&gt;&lt;br&gt;Bye
&lt;br&gt;&lt;br&gt;[1] &lt;a href=&quot;http://lists.alioth.debian.org/pipermail/pcsclite-cvs-commit/2008-May/003131.html&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://lists.alioth.debian.org/pipermail/pcsclite-cvs-commit/2008-May/003131.html&lt;/a&gt;&lt;br&gt;&lt;br&gt;-- 
&lt;br&gt;&amp;nbsp;Dr. Ludovic Rousseau
&lt;br&gt;_______________________________________________
&lt;br&gt;opensc-devel mailing list
&lt;br&gt;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26629927&amp;i=1&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;opensc-devel@...&lt;/a&gt;
&lt;br&gt;&lt;a href=&quot;http://www.opensc-project.org/mailman/listinfo/opensc-devel&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.opensc-project.org/mailman/listinfo/opensc-devel&lt;/a&gt;&lt;br&gt;&lt;p&gt;From forum: &lt;a href=&quot;http://old.nabble.com/OpenSC---Dev-f975.html&quot; embed=&quot;fixTarget[975]&quot; target=&quot;_top&quot; &gt;OpenSC - Dev&lt;/a&gt;&lt;/p&gt;</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/SCardConnect%28%29%2C-dwPreferredProtocols-and-detecting-Pinpad-tp26623501p26629927.html" />
</entry>

</feed>
