[opensc-devel] OpenSC @ FOSDEM 2012 & resurrection of security-devroom list

2011-11-01 Thread Martin Paljak
Hello,

1. I filed for a security devroom again, I hope it will be accepted
(hey, they even resurrected the mailing list). The theme of the devroom
is "(hardware) security / crypto"
2. The scheme is the same as last year, except there should be a
(different) room for two days, where the second day will be pure hands
on hacking. I plan to bring a bunch of different hardware and I hope to
see many people from different projects and hopefully we can even have a
short hackathon there.
3. Please distribute at relevant lists/forums/groups links
 - to the mailing list at [1]
 - to the wiki [2]
4. If you have a talk proposal, please send a short description of it to
the same list or add it to the currently empty wiki page [2] following
basically the same CFP as last year [3]. Also, feel free to voice your
interests either on the list or in the wiki. For example, I'm personally
interested in hearing something about CESECORE [4] and Android(/smart
cards, like [5]), hopefully this helps to send the word around that we
actually could see people associated with such efforts.


Best,
Martin

[1] https://lists.fosdem.org/mailman/listinfo/security-devroom
[2] http://www.opensc-project.org/opensc/wiki/FOSDEM2012
[3] https://www.opensc-project.org/opensc/wiki/FOSDEM2011/CFP
[4] https://www.cesecore.eu/
[5] http://code.google.com/p/seek-for-android/
-- 
@MartinPaljak
+3725156495
___
opensc-devel mailing list
opensc-devel@lists.opensc-project.org
http://www.opensc-project.org/mailman/listinfo/opensc-devel


Re: [opensc-devel] ACS pinpad support

2011-11-01 Thread Martin Paljak
Hello,
On 11/1/11 12:07 , Jean-Michel Pouré - GOOZE wrote:
> We bought some SPR532.
They are old but good (in fact, the reference reader when I was working
on pinpad support in pcsc-lite/ccid). Make sure that the firmware is the
right version, they changed things back and forth several times.

> About ACS, did you try libacsccid? It is supposed to fill the gab. 
> 
> My opinion is that CCID is a loose standard. pcscd is modulal enough for
> vendors to provide their own CCID library. Event SCM does that, even it
> is not yet in Debian.
Vendors are free to distribtue what they want.

There are 193 readers in *the* CCID driver list of supported readers
[1], including some from ACS. This shows, that hardware can be made in a
compliant way and that ACS can do that as well. But a few readers from
ACS don't. I try to stick to readers that are compliant and there are
plenty to choose from.

Compare:
Claiming support for HTTP after requiring a proprietary handshake is as
good as claiming just the proprietary support. It means that you can
only use software already implementing the proprietary handshake. Or
hint, that it should be relatively simple to tweak existing software
that already talks HTTP to also do the proprietary handshake.

But it is definitely not HTTP as the rest of the world knows it.

Nevertheless, I might try out the driver as I really like the form
factor of ACS ACR83.

I had the reader before the hacked driver was available, so it has been
sitting uselessly in a box ever since.

[1] http://pcsclite.alioth.debian.org/ccid/section.html
-- 
@MartinPaljak
+3725156495
___
opensc-devel mailing list
opensc-devel@lists.opensc-project.org
http://www.opensc-project.org/mailman/listinfo/opensc-devel

Re: [opensc-devel] ACS pinpad support

2011-11-01 Thread Jean-Michel Pouré - GOOZE
Dear Martin,

> I gave up bothering with APG8201 [1]. What kind of SCM pinpad readers
> do you have, if not SPR532?

We bought some SPR532.

About ACS, did you try libacsccid? It is supposed to fill the gab. 

My opinion is that CCID is a loose standard. pcscd is modulal enough for
vendors to provide their own CCID library. Event SCM does that, even it
is not yet in Debian.

> But the standard log of a failed transaction with for example PKCS#11
> would be needed [2]

OK, thanks.

> [1] http://www.opensc-project.org/opensc/wiki/CardReaders#CCID
> [2] http://www.opensc-project.org/opensc/wiki/ReportingBugs 

I will provide logs tonight.

Kind regards,
-- 
  Jean-Michel Pouré - Gooze - http://www.gooze.eu


smime.p7s
Description: S/MIME cryptographic signature
___
opensc-devel mailing list
opensc-devel@lists.opensc-project.org
http://www.opensc-project.org/mailman/listinfo/opensc-devel