Hello, Peter:
Who signs all these certificates? To what do they attest? And why should I
believe a word they have to say?
Cheers, Scott
-----Original Message-----
From: [EMAIL PROTECTED] on behalf of Peter Tomlinson
Sent: Thu 8/11/2005 3:40 AM
To: MUSCLE
Cc: Henry Ryan
Subject: Re: [Muscle] Vendor keys in smart cards - How/where?
As a natural consequence of work done under the eEurope Smart Cards
umbrella, the following should be implemented:
- secure the silicon chip at the wafer level, before it is sawn (inject
a certificate into each individual cell that will eventually go into a
smart card as soon as that cell is tested good)
- secure the card OS with a certificate
- secure the JavaCard interpreter with a certificate
- secure each relevant on-card application (applet) with a certificate,
including the structure into which data will be loaded.
The eESC group was hoping to further develop security topics, but the EC
refused further funding for a secretariat and a small number of editors.
Short-sighted of them.
(Anders: can you identify the security lists, please?)
Peter
Anders Rundgren wrote:
> There has been several suggestions in various security lists that a
> HW token during a CSR (Certificate Signing Request) should be able to
> counter- sign the request with a key and cert identifying the
> container itself.
>
> The reason for this is that certain CA policies require that the
> users only have store (and use) keys in "strong cases".
>
> Pardon my ignorance, but is there any kind of standard practice for
> deploying vendor keys? Links would be higly appreciated.
>
> In addition I would like to know how one could handle such keys from
> a PKCS #11 interface.
>
> thanx, Anders Rundgren
> _______________________________________________ Muscle mailing list
> [email protected]
> http://lists.drizzle.com/mailman/listinfo/muscle
>
_______________________________________________
Muscle mailing list
[email protected]
http://lists.drizzle.com/mailman/listinfo/muscle
_______________________________________________
Muscle mailing list
[email protected]
http://lists.drizzle.com/mailman/listinfo/muscle