As a natural consequence of work done under the eEurope Smart Cards
umbrella, the following should be implemented:
- secure the silicon chip at the wafer level, before it is sawn (inject
a certificate into each individual cell that will eventually go into a
smart card as soon as that cell is tested good)
- secure the card OS with a certificate
- secure the JavaCard interpreter with a certificate
- secure each relevant on-card application (applet) with a certificate,
including the structure into which data will be loaded.
The eESC group was hoping to further develop security topics, but the EC
refused further funding for a secretariat and a small number of editors.
Short-sighted of them.
(Anders: can you identify the security lists, please?)
Peter
Anders Rundgren wrote:
There has been several suggestions in various security lists that a
HW token during a CSR (Certificate Signing Request) should be able to
counter- sign the request with a key and cert identifying the
container itself.
The reason for this is that certain CA policies require that the
users only have store (and use) keys in "strong cases".
Pardon my ignorance, but is there any kind of standard practice for
deploying vendor keys? Links would be higly appreciated.
In addition I would like to know how one could handle such keys from
a PKCS #11 interface.
thanx, Anders Rundgren
_______________________________________________ Muscle mailing list
[email protected]
http://lists.drizzle.com/mailman/listinfo/muscle
_______________________________________________
Muscle mailing list
[email protected]
http://lists.drizzle.com/mailman/listinfo/muscle