Il 28/04/2011 09:05, Toni Sjoblom - Aventra ha scritto:

> I think that this feature is just missing from the drivers code.
> Can you Martin say which card you have used the --insecure option with?
> This could help find the missing code
Yup!

> (for us that that are not that
> familiar with the OpenSC code structure and all that :).
Present! :)

> I agree. Also a very common scenario is to have 3 PINs, one for normal use,
> one for signatures (PIN is reset after every use, so user need to enter PIN
> explicitly for every signature) and one for administration.
How can you tell that a PIN is actually a "signature PIN" that must not
be cached? Really enorcing "re-enter PIN" policy could be done only if
keyboard was on card (seen some prototypes online, w/ a display, too...
but never seen 'em in shops :( ), but making card "forget" it +
"hinting" driver not to cache it could often work well enough.

BYtE,
 Diego.
_______________________________________________
opensc-devel mailing list
opensc-devel@lists.opensc-project.org
http://www.opensc-project.org/mailman/listinfo/opensc-devel

Reply via email to