Li Yao wrote:
> Hi guys,
>  
> basically, I'm trying to use smart card(with muscle Applet) to generate 
> a RSA key pair and export public key to construct a certificate Request. 
> Since a certificate request needs the corresponding private key to sign 
> it, I'm thinking to form a certRequestInfo and send it to card to get 
> the signature and then construct the certRequest with the signature. 
> Does this method make any sense?
>  
> And I have examined the CardEdge.java code and the computeCrypt function 
> confused me. In javacard2.1.1 Spec: TYPE_RSA_PRIVATE = 5; 
> TYPE_RSA_CRT_PRIVATE = 6; In the CardEdge.java:    
>     "private static final byte KEY_RSA_PUBLIC = 1;
>     private static final byte KEY_RSA_PRIVATE = 2;
>     private static final byte KEY_RSA_PRIVATE_CRT = 3;
>     private static final byte KEY_DSA_PUBLIC = 4;
>     private static final byte KEY_DSA_PRIVATE = 5;
>     private static final byte KEY_DES = 6;
>     private static final byte KEY_3DES = 7;
>     private static final byte KEY_3DES3 = 8;"
> Under computeCrypt method, under OP_INIT case, and in ciph_dir under 
> "CD_SIGN CD_VERIFY" case, the RSA_CRT_PRIVATE keyType 6 should be the 
> same as KEY_DES, which the program should throw a SW_INCORRECT_ALG.

No, because the Java Card key type are mapped to the correct CardEdge
keyType ...2JCKeyType or something like this the method is called.

>  
> But in MuscleTool, the doCrypt function has:
>  
>   "cryptInit.keyNum = keyNum;
>   cryptInit.cipherMode = MSC_MODE_RSA_NOPAD;
>   cryptInit.cipherDirection = MSC_DIR_SIGN;
>   cryptInit.optParams = 0;
>   cryptInit.optParamsSize = 0;
>  
>   padData(inCryptData, inDataSize, keySize);
>   inDataSize = outDataSize = keySize;
>  
>   binToHex(inCryptData, inDataSize, outCryptData);
>  
>   rv = MSCComputeCrypt( pConnection, &cryptInit,
>    inCryptData, inDataSize,
>    outCryptData, &outDataSize);"
> If I input the keyNum as 0 which is my RSA_CRT_PRIVATE key, with some 
> input, the program will return me 256 bytes of data not a 
> SW_INCORRECT_ALG. Did I miss anything?

Yes, see above.

>  
> And suppose I use RSA_PRIVATE key which has the same value 
> as KEY_DSA_PRIVATE in CardEdge, under OP_INIT case, and in ciph_dir 
> under "CD_SIGN CD_VERIFY" case it will goto:                
>                 "case KEY_DSA_PUBLIC:
>                 case KEY_DSA_PRIVATE:
>                     ciph_alg_id = Cipher.ALG_RSA_ISO9796;
>                     ISOException.throwIt((short)SW_UNSUPPORTED_FEATURE);
>                     break;"
> Cipher.ALG_RSA_ISO9796 = 11, same as the Signature ALG: 
> ALG_RSA_MD5_PKCS1; Does that mean there is only one supported Signature 
> algorithm i.e. ALG_RSA_MD5_PKCS1?
>  
> BTW why CardEdge use these confused names as the condition?

Don't know. Maybe this is due to the history.

>  
> If there is anything wrong please forgive my ignorance and kindly 
> correct me.

I hope, this is done.

> Thank you in advance.

De nada.

>  
> Li

Karsten
_______________________________________________
Muscle mailing list
[email protected]
http://lists.drizzle.com/mailman/listinfo/muscle

Reply via email to