Hi, I am currently trying to get the Italian CNS Card working. Except the qualified certificate I can use everything fine.
The following problem I do have. The card uses secure messaging with 3DES/MAC3 (ISV = Nullvector) for the qualified signature. Since a Null Vector is used the implementation should not be a big problem. Still so it seems I do something wrong. Here is a sniff of a real communication 1. Get Challenge send to the card -> 00 84 00 00 08 <- A1 AF E2 DB D5 68 36 16 90 00 2. First secret = A1 AF E2 DB D5 68 36 16 3. Give Random send to the card with random number FE E6 29 53 B2 33 F0 E5 -> 80 86 00 00 08 FE E6 29 53 B2 33 F0 E5 4. Second secret = FE E6 29 53 B2 33 F0 E5 5.The following secure ADPU is sent to the card to calculate the signature: -> 0C 2A 9E 9A 35 87 29 01 E9 7F A1 E8 F3 C0 6A 0F 32 B4 E8 A4 6F 58 63 3C AC 6D A2 DC 23 FB 07 24 B4 EE CF 39 46 4E 7E 48 23 10 7E F3 67 B9 1E 8B E9 7F A1 E8 F3 C0 6A 0F 32 B4 E8 A4 6F 58 63 3C AC 6D A2 DC 23 FB 07 24 B4 EE CF 39 46 4E 7E 48 23 10 7E F3 67 B9 1E 8B 8E 08 49 5E F4 D7 2B 9A 3F AD 00 6. "Nicely" written that is: 0C 2A 9E 9A 35 87 29 01 Encrypted part: E9 7F A1 E8 F3 C0 6A 0F 32 B4 E8 A4 6F 58 63 3C AC 6D A2 DC 23 FB 07 24 B4 EE CF 39 46 4E 7E 48 23 10 7E F3 67 B9 1E 8B MAC: 8E 08 49 5E F4 D7 2B 9A 3F AD LE: 00 7. Now I should be able to decrypt the Encrypted part using secret1 and 2 (3DES startvector is null) Unfortunatly I never get a decrypted string which would make sense. I tried already several things like using secret 1 as 2 and 2 as 1 etc. There must be a transformation of secret 1 and 2 to something different before using them. Is here anyone who has an idea? For example how other cards are doing it? Thanks a lot in advance for all your answers. Heribert
_______________________________________________ opensc-devel mailing list [email protected] http://www.opensc-project.org/mailman/listinfo/opensc-devel
