Li Yao wrote: > Hi guys, > > basically, I'm trying to use smart card(with muscle Applet) to generate > a RSA key pair and export public key to construct a certificate Request. > Since a certificate request needs the corresponding private key to sign > it, I'm thinking to form a certRequestInfo and send it to card to get > the signature and then construct the certRequest with the signature. > Does this method make any sense? > > And I have examined the CardEdge.java code and the computeCrypt function > confused me. In javacard2.1.1 Spec: TYPE_RSA_PRIVATE = 5; > TYPE_RSA_CRT_PRIVATE = 6; In the CardEdge.java: > "private static final byte KEY_RSA_PUBLIC = 1; > private static final byte KEY_RSA_PRIVATE = 2; > private static final byte KEY_RSA_PRIVATE_CRT = 3; > private static final byte KEY_DSA_PUBLIC = 4; > private static final byte KEY_DSA_PRIVATE = 5; > private static final byte KEY_DES = 6; > private static final byte KEY_3DES = 7; > private static final byte KEY_3DES3 = 8;" > Under computeCrypt method, under OP_INIT case, and in ciph_dir under > "CD_SIGN CD_VERIFY" case, the RSA_CRT_PRIVATE keyType 6 should be the > same as KEY_DES, which the program should throw a SW_INCORRECT_ALG.
No, because the Java Card key type are mapped to the correct CardEdge keyType ...2JCKeyType or something like this the method is called. > > But in MuscleTool, the doCrypt function has: > > "cryptInit.keyNum = keyNum; > cryptInit.cipherMode = MSC_MODE_RSA_NOPAD; > cryptInit.cipherDirection = MSC_DIR_SIGN; > cryptInit.optParams = 0; > cryptInit.optParamsSize = 0; > > padData(inCryptData, inDataSize, keySize); > inDataSize = outDataSize = keySize; > > binToHex(inCryptData, inDataSize, outCryptData); > > rv = MSCComputeCrypt( pConnection, &cryptInit, > inCryptData, inDataSize, > outCryptData, &outDataSize);" > If I input the keyNum as 0 which is my RSA_CRT_PRIVATE key, with some > input, the program will return me 256 bytes of data not a > SW_INCORRECT_ALG. Did I miss anything? Yes, see above. > > And suppose I use RSA_PRIVATE key which has the same value > as KEY_DSA_PRIVATE in CardEdge, under OP_INIT case, and in ciph_dir > under "CD_SIGN CD_VERIFY" case it will goto: > "case KEY_DSA_PUBLIC: > case KEY_DSA_PRIVATE: > ciph_alg_id = Cipher.ALG_RSA_ISO9796; > ISOException.throwIt((short)SW_UNSUPPORTED_FEATURE); > break;" > Cipher.ALG_RSA_ISO9796 = 11, same as the Signature ALG: > ALG_RSA_MD5_PKCS1; Does that mean there is only one supported Signature > algorithm i.e. ALG_RSA_MD5_PKCS1? > > BTW why CardEdge use these confused names as the condition? Don't know. Maybe this is due to the history. > > If there is anything wrong please forgive my ignorance and kindly > correct me. I hope, this is done. > Thank you in advance. De nada. > > Li Karsten _______________________________________________ Muscle mailing list [email protected] http://lists.drizzle.com/mailman/listinfo/muscle
