>
> >>
> >>>However from the user point of view,
> >>>it is password, so min/max length and other password attributes still
> >>
> >>take place.
> >>
> >>of course you can misuse a pin a object for this, but I don't think
> >>there's an elegant solution for this (using pkcs15, not to mention
> >>pkcs11 ;-)
> >
> > [Vladimir Beker] Regarding to PKCS#15 - it is not elegant (it would be
> > better to have missing attributes in auth. key object instead, just to
> > make them OPTIONAL. So, presence of these attributes (such as min.
> length)
> > would mean that it is actually password derived.
>
> of course you would need to specify the alg and parameters to derive
> the key as well ...
[Vladimir Beker] Agree with you. There are 2 issues here. One is derivation
mechanism, another one is that many attributes of pin apply here.
Probably the solution would be:
To define new kind of object: derived_auth_key, which is the same as auth_key +
derivation mechanism + the same id as auth. pin to be derived.
So actually we have 2 records but define 1 real object. It is a bit dirty
trick, but it allows not mixing attributes of key and pin
>
> that's not allowed. to quote pkcs15:
>
> CommonObjectAttributes ::= SEQUENCE {
> ...
> authId Identifier OPTIONAL, ...,
> ...
> } (CONSTRAINED BY {
> -- authId should be present in the IC card case if flags.private is
> set.
> -- It must equal an authID in one AuthRecord in the AODF -- })
>
> but I don't that many libraries stumble over this.
[Vladimir Beker] Strictly speaking you are right. But I would consider such
thing as the least evil.
>
> > Or it may be
> > something that the card will not accept in VERIFY command (such as
> 0xFF).
>
> id != reference
[Vladimir Beker] Agree.
**************************************************************************************************
The contents of this email and any attachments are confidential.
It is intended for the named recipient(s) only.
If you have received this email in error please notify the system manager or
the
sender immediately and do not disclose the contents to anyone or make copies.
** eSafe scanned this email for viruses, vandals and malicious content **
**************************************************************************************************
_______________________________________________
Muscle mailing list
[email protected]
http://lists.drizzle.com/mailman/listinfo/muscle