Peter,
This has been mentioned in the IETF-PKIX list but I believe I have seen it
in some other lists as well (I have subscribed to too many..)

However, there is one thing missing and that is that there is no
support in current browsers for more advanced schemes (that
more or less do card personalization things).  For example a CA
cannot define
-PIN-code policies
- key export policies (encryption keys may be exported in some regimes)

In addition the existing methods are much too complex for real world users
which have made all banks in Scandinavia abandon the browser schemes
(keygen + xenroll) for entirely proprietary code.  These look great as a
comparison but you are not even allowed to get the spec. without an NDA.

I'm trying to raise interest in a new on-line key-gen cert-download scheme
as the thing we have today does not support my "pet", the TPM, in any
useful way.

Anders

----- Original Message ----- 
From: "Peter Tomlinson" <[EMAIL PROTECTED]>
To: "MUSCLE" <[email protected]>
Cc: "Henry Ryan" <[EMAIL PROTECTED]>
Sent: Thursday, August 11, 2005 09:40
Subject: Re: [Muscle] Vendor keys in smart cards - How/where?


As a natural consequence of work done under the eEurope Smart Cards
umbrella, the following should be implemented:

- secure the silicon chip at the wafer level, before it is sawn (inject
a certificate into each individual cell that will eventually go into a
smart card as soon as that cell is tested good)

- secure the card OS with a certificate

- secure the JavaCard interpreter with a certificate

- secure each relevant on-card application (applet) with a certificate,
including the structure into which data will be loaded.

The eESC group was hoping to further develop security topics, but the EC 
refused further funding for a secretariat and a small number of editors. 
Short-sighted of them.

(Anders: can you identify the security lists, please?)

Peter

Anders Rundgren wrote:

> There has been several suggestions in various security lists that a
> HW token during a CSR (Certificate Signing Request) should be able to
> counter- sign the request with a key and cert identifying the
> container itself.
> 
> The reason for this is that certain CA policies require that the
> users only have store (and use) keys in "strong cases".
> 
> Pardon my ignorance, but is there any kind of standard practice for 
> deploying vendor keys?  Links would be higly appreciated.
> 
> In addition I would like to know how one could handle such keys from 
> a PKCS #11 interface.
> 
> thanx, Anders Rundgren 
> _______________________________________________ Muscle mailing list 
> [email protected] 
> http://lists.drizzle.com/mailman/listinfo/muscle
> 

_______________________________________________
Muscle mailing list
[email protected]
http://lists.drizzle.com/mailman/listinfo/muscle
_______________________________________________
Muscle mailing list
[email protected]
http://lists.drizzle.com/mailman/listinfo/muscle

Reply via email to