I think a hybrid approach(APDU & Card Service) will solve the problem for now.
Ofcourse, it might defeat the purpose of using card services..
----------
The Vice Presidency is like the last cookie on the plate.
Everybody insists he won't take it, but somebody always does.
- Bill Vaughan
>-----Original Message-----
>From: Karl Scheibelhofer [mailto:[EMAIL PROTECTED]]
>Sent: Wednesday, July 12, 2000 9:21 PM
>To: OpenCard Mailingliste
>Subject: FW: [OCF] RSA/DSA key & secret codes
>
>
>-----Original Message-----
>From: Karl Scheibelhofer [mailto:[EMAIL PROTECTED]]
>Sent: Wednesday, July 12, 2000 12:38 PM
>To: Bartek Paszkowski
>Subject: RE: [OCF] RSA/DSA key & secret codes
>
>
>> I got stuck with a little problem: how to protect RSA/DSA keys by
>> a secret code? I use:
>>
>> kms.createGeneratedPublicKeyFile(generatedKeyFile, ef_PINFile);
>> kgs.generateKeyPair(null, generatedKeyFile, -1, null);
>>
>> where:
>> -> generatedKeyFile = new GPKSignatureUnwrapKeyFile(ef_RSAKey,
>> 1024, GPKRSAKeyFile.CERTIFIED_KEY);
>> ->ef_RSAKey & ef_PINFile = new CardFilePath(``:0200 : ...``);
>>
>> and it doesn't work (the key is not even created, there are no
>> any exceptions!).
>
>i have the same problem. the reason is:
>the GPK card services do not implement this feature. you cannot protect
>public key files with a secret code using the current GPK services. i
>suggested this improvement to gemplus serveral weeks ago.
>the development of the GPK card services did not make any progress for
>several months. i had contact to a developer there, but he
>switched to an
>other department. i tried to contact the people responsible now.
>unfortunately they didn't even answer my mails.
>the GPK services would really need several improvements and
>i'd like to make
>several suggestions. perhaps someone of the people from
>gemplus follows this
>mailing list.
>
>best regards
>
> Karl Scheibelhofer
>
>--
>
>Karl Scheibelhofer, <mailto:[EMAIL PROTECTED]>
>Institute for Applied Information Processing and Communications (IAIK)
>at Technical University of Graz, Austria, http://www.iaik.at
>Phone: (+43) (316) 873-5540
>
>
>
>---
>> Visit the OpenCard web site at http://www.opencard.org/ for more
>> information on OpenCard---binaries, source code, documents.
>> This list is being archived at
http://www.opencard.org/archive/opencard/
! To unsubscribe from the [EMAIL PROTECTED] mailing list send an email
! to
! [EMAIL PROTECTED]
! containing the word
! unsubscribe
! in the body.
---
> Visit the OpenCard web site at http://www.opencard.org/ for more
> information on OpenCard---binaries, source code, documents.
> This list is being archived at http://www.opencard.org/archive/opencard/
! To unsubscribe from the [EMAIL PROTECTED] mailing list send an email
! to
! [EMAIL PROTECTED]
! containing the word
! unsubscribe
! in the body.