Peter, This has been mentioned in the IETF-PKIX list but I believe I have seen it in some other lists as well (I have subscribed to too many..)
However, there is one thing missing and that is that there is no support in current browsers for more advanced schemes (that more or less do card personalization things). For example a CA cannot define -PIN-code policies - key export policies (encryption keys may be exported in some regimes) In addition the existing methods are much too complex for real world users which have made all banks in Scandinavia abandon the browser schemes (keygen + xenroll) for entirely proprietary code. These look great as a comparison but you are not even allowed to get the spec. without an NDA. I'm trying to raise interest in a new on-line key-gen cert-download scheme as the thing we have today does not support my "pet", the TPM, in any useful way. Anders ----- Original Message ----- From: "Peter Tomlinson" <[EMAIL PROTECTED]> To: "MUSCLE" <[email protected]> Cc: "Henry Ryan" <[EMAIL PROTECTED]> Sent: Thursday, August 11, 2005 09:40 Subject: Re: [Muscle] Vendor keys in smart cards - How/where? As a natural consequence of work done under the eEurope Smart Cards umbrella, the following should be implemented: - secure the silicon chip at the wafer level, before it is sawn (inject a certificate into each individual cell that will eventually go into a smart card as soon as that cell is tested good) - secure the card OS with a certificate - secure the JavaCard interpreter with a certificate - secure each relevant on-card application (applet) with a certificate, including the structure into which data will be loaded. The eESC group was hoping to further develop security topics, but the EC refused further funding for a secretariat and a small number of editors. Short-sighted of them. (Anders: can you identify the security lists, please?) Peter Anders Rundgren wrote: > There has been several suggestions in various security lists that a > HW token during a CSR (Certificate Signing Request) should be able to > counter- sign the request with a key and cert identifying the > container itself. > > The reason for this is that certain CA policies require that the > users only have store (and use) keys in "strong cases". > > Pardon my ignorance, but is there any kind of standard practice for > deploying vendor keys? Links would be higly appreciated. > > In addition I would like to know how one could handle such keys from > a PKCS #11 interface. > > thanx, Anders Rundgren > _______________________________________________ Muscle mailing list > [email protected] > http://lists.drizzle.com/mailman/listinfo/muscle > _______________________________________________ Muscle mailing list [email protected] http://lists.drizzle.com/mailman/listinfo/muscle _______________________________________________ Muscle mailing list [email protected] http://lists.drizzle.com/mailman/listinfo/muscle
