|
Re: root certs on smart cards: msg#00232encryption.opensc.devel
Justin Karneges wrote: Hi folks, it's certainly possible but whether it makes sense depends on your scenario (can you trust the cert from the card, and as smartcards are very slow: do you actually want to read it from the card if possible). I ask because if I'm validating a certificate I wonder if my app should try to read some roots off of an inserted smart card, to use for validation (either in place of, or in addition to, the usual roots on the host system). Note that the systems validating the smartcard must know who it can trust, but I would normally use own copies root certificates for the validating system I'm not talking about secondary issuers, as I know those can be on a smart card. this describtion matchs every computer so it's true It might be that any x.509 question is beyond the scope of what smart cards actually do, and so instead I'm supposed to follow some unwritten "best practices". Any websites about this would be great. if you are unsure you might consider following the designs of some other big id card project (Belgian, Italian, Spanish (ceres) and Estonian Id card projects (sorry no link at hand, ask google)) but as I don't know what you want to do I'm not sure if this really helps. Cheers, Nils |
|
| <Prev in Thread] | Current Thread | [Next in Thread> |
|---|---|---|
| Previous by Date: | Re: Various small changes to OpenSC: 00232, Nils Larsch |
|---|---|
| Next by Date: | PIN pad support for Kobil Kaan Pro?: 00232, Andreas Steffen |
| Previous by Thread: | root certs on smart cardsi: 00232, Justin Karneges |
| Next by Thread: | Re: root certs on smart cards: 00232, Justin Karneges |
| Indexes: | [Date] [Thread] [Top] [All Lists] |
| News | FAQ | advertise |