List Info

Thread: PKCS#15 / ISO7816-15 Question




PKCS#15 / ISO7816-15 Question
country flaguser name
Austria
2007-10-11 07:46:03
Hi all,

i am playing around with an Austrian e-Card (health care card), and i came across a characteristic of the card which i'm a bit confused about.

The card does have a EF(DIR) in the MF, which perfectly contains the aid's of the card applications.

Problem ist - all the application DF's do not contain EF(ODF) files. In my understanding, the EF(ODF) should be mandatory. At least it is in PKCS#15. Did this change in ISO7816-15 ? Or do those cards have an incomplete PKCS#15 / ISO7816-15 structure ???

Best regards
Brandy


Connect to the next generation of MSN Messenger  Get it now!
Re: PKCS#15 / ISO7816-15 Question
country flaguser name
Turkey
2007-10-11 10:00:41
On Thursday 11 October 2007 15:46:03 Franz Brandl wrote:

> The card does have a EF(DIR) in the MF, which perfectly
contains the aid's
> of the card applications.
>
> Problem ist - all the application DF's do not contain
EF(ODF) files. In my
> understanding, the EF(ODF) should be mandatory. At
least it is in PKCS#15.

Only PKCS-15 applications are supposed to contain EF(ODF),
other applications 
are free to use any structure they want.

In Turkey for example, national CA uses pkcs-15 for digital
signatures, so you 
can use them for signing and login, etc with all pkcs-15
software (like 
pam_p11, firefox, thunderbird, etc). But health care is a
property 
application and uses their own data structures.
_______________________________________________
opensc-devel mailing list
opensc-devellists.opensc-project.org
http://www.opensc-project.org/mailman/listinfo/opensc
-devel

Re: PKCS#15 / ISO7816-15 Question
country flaguser name
Austria
2007-10-11 10:54:37

> From: gurerpardus.org.tr
> To: opensc-devellists.opensc-project.org
> Date: Thu, 11 Oct 2007 18:00:41 +0300
> Subject: Re: [opensc-devel] PKCS#15 / ISO7816-15 Question
>
> On Thursday 11 October 2007 15:46:03 Franz Brandl wrote:
>;
> > The card does have a EF(DIR) in the MF, which perfectly contains the aid's
> > of the card applications.
> >
> > Problem ist - all the application DF's do not contain EF(ODF) files. In my
> > understanding, the EF(ODF) should be mandatory. At least it is in PKCS#15.
>
> Only PKCS-15 applications are supposed to contain EF(ODF), other applications
> are free to use any structure they want.
>
> In Turkey for example, national CA uses pkcs-15 for digital signatures, so you
> can use them for signing and login, etc with all pkcs-15 software (like
> pam_p11, firefox, thunderbird, etc). But health care is a property
> application and uses their own data structures.
> _______________________________________________

hi,

i should have been more specific.

the card contains a EF(DIR) in the MF which points to a couple of applications. So these applications are supposed to be PKCS#15 applications, otherwise they should not appear in EF(DIR), i guess. some of them do contain an EF(ODF), but some don't, and that seems strange to me. the rest of their file structure also seems like PKCS#15, there are EF(DCOD) ..., but no EF(ODF).

Regards,
Brandy


Connect to the next generation of MSN Messenger  Get it now!
Re: PKCS#15 / ISO7816-15 Question
country flaguser name
Turkey
2007-10-11 11:22:00
On Thursday 11 October 2007 18:54:37 Franz Brandl wrote:

> the card contains a EF(DIR) in the MF which points to a
couple of
> applications. So these applications are supposed to be
PKCS#15
> applications, otherwise they should not appear in
EF(DIR), i guess.

Nope, EF(DIR) is defined in ISO 7816 rather than PKCS. A
PKCS15 application is 
something in the EF(DIR) with A000000063504B43532D3135 as
application id, and 
if there are multiple PKCS15 apps, they are distinguished by
OID or label 
values in the EF(DIR). If app ID is not PKCS-15, you
shouldn't expect proper 
PKCS-15 structures inside the app path.

> some of them do contain an EF(ODF), but some don't, and
that seems
> strange to me. the rest of their file structure also
seems like
> PKCS#15, there are EF(DCOD) ..., but no EF(ODF).

Probably they used a simplified version of PKCS-15?
_______________________________________________
opensc-devel mailing list
opensc-devellists.opensc-project.org
http://www.opensc-project.org/mailman/listinfo/opensc
-devel

[1-4]

about | contact  Other archives ( Real Estate discussion Medical topics )