On Thu, 3 Dec 2009 16:29:23 +0300
"Aktiv Co. Aleksey Samsonov" <samso...@guardant.ru> wrote:

> > The basic problem is that none of my PKCS#15 cards have an object for
> > the PUK (and from what I can tell the PKCS#15 standard doesn't require
> > them to). This means that we cannot do a C_Login with the PUK
> > beforehand (as we cannot figure out the reference of the PUK for the
> > VERIFY operation).
> 
> Then "alternative sheme" isn't correct in this case. But, I fear for 
> call sc_pkcs15_unblock_pin if we have a cached SO PIN (if SO PIN != PUK).
> 

Can that happen when using the API correctly though? PKCS#11 only has
two types of PIN, so SO PIN must be the PUK.

-- 
Pierre Ossman            OpenSource-based Thin Client Technology
System Developer         Telephone: +46-13-21 46 00
Cendio AB                Web: http://www.cendio.com

Attachment: signature.asc
Description: PGP signature

_______________________________________________
opensc-devel mailing list
opensc-devel@lists.opensc-project.org
http://www.opensc-project.org/mailman/listinfo/opensc-devel

Reply via email to