Doug Engert

Results 472 comments of Doug Engert

@asalkhanbadr What tool are you using to send the APDU? Looks like the reader, applet or java card 3 has a problem returning a response to the "47" command with...

> PyApduTool. According to the data sheet, it supports 115 kb/s data transmission. Where is the data sheet? What system are you using? Best I can tell HID OMNI 3111...

Get a different reader. A USB CCID compliant reader.

You may be misinterpreting the Yubico-piv-tool command. PIV standards allow a vendor to provision a token using their own commands, and this does not appear to be a PIV standard...

Please disregard previous comment. Too many 82 and 81 used for both tags and length.

> PIV as specified in NIST card specs actually does support key generation and certificate loading. So from the card edge point of view, this should work just fine. But...

You are close.. But need to look at piv ATR cache. Will elaborate later. On Fri, May 27, 2022, 9:11 AM Rayan BOULARES ***@***.***> wrote: > I'm still struggling with...

The ATR cache for PIV is there to take a short cut to bet to device driver. It maybe there because you did not have a minidriver entry for your...

https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-73-4.pdf says: > 3.1.4 X.509 Certificate for Card Authentication FIPS 201 specifies the mandatory asymmetric Card Authentication key (CAK) as a private key that may be used to support physical...

Another point to consider for: "where only 9E can be done over contactless". The card knows it is using contact or contactless but an attacker could switch a the reader...