I've managed to locate (somewhat incredibly) 5 virgen USB tokens that - presumably as they are in their original static-proof bags - still have the manufacturer's app security domain applet on the card - in addition of the card issuers SD. (Typically, during post-manufacturing we removed the app SD , to free up space to load and init the muscle applet.)

What I do not have is any technical documentation and all the my people contacts have long since left the javacard startup company for greener pastures.

Anyone want to play with some of them, to test GPShell and ensure its 2.01 era delegated loading (via RSA) is solid?

--------------------------------------------------
From: "Karsten Ohme" <[EMAIL PROTECTED]>
Sent: Saturday, April 05, 2008 4:43 AM
To: "MUSCLE" <muscle@lists.musclecard.com>
Subject: Re: [Muscle] load file DAP

Peter Williams schrieb:
1. Has anyone used GPShell to load an RSA public key into an _issuer's_ security domain of a 201 card, so one can use the GPShell to send a DAP hash and signature for the load file?

I think this does not work. I have tried a lot with different cards, but I had no success. So, there might be compatibility problems, the cards do to support it after all or the specification is not clear enough. You can play with the code base, would be very interesting to me, if you get it working.

Karsten
 2. has anyone tested the use of SHA1 by itself for a LOAD DAP?
3 If I half remember right, only a security domain OTHER than the card manager SD can verify either a DESCBC or an RSA DAP (given its knows the verification key, and knowledge that the signature is either RSA or DESCBC).
 ------------------------------------------------------------------------

_______________________________________________
Muscle mailing list
Muscle@lists.musclecard.com
http://lists.drizzle.com/mailman/listinfo/muscle

_______________________________________________
Muscle mailing list
Muscle@lists.musclecard.com
http://lists.drizzle.com/mailman/listinfo/muscle

_______________________________________________
Muscle mailing list
Muscle@lists.musclecard.com
http://lists.drizzle.com/mailman/listinfo/muscle

Reply via email to