Terminating and reactivating an OpenPGPCard and/or CryptoStick

Werner Koch wk at gnupg.org
Fri Jul 30 08:56:01 CEST 2010


On Thu, 29 Jul 2010 20:35, pk at opensc-project.org said:

> According to the handbook this should be easy. Just a TERMINATE DF
> followed by an ACTIVATE FILE.

However terminate is only allowed if PW1 and PW3 are blocked.  Thus I
use these commands with gpg-connect-agent:

  scd serialno
  scd apdu 00 20 00 81 08 40 40 40 40 40 40 40 40
  scd apdu 00 20 00 81 08 40 40 40 40 40 40 40 40
  scd apdu 00 20 00 81 08 40 40 40 40 40 40 40 40
  scd apdu 00 20 00 81 08 40 40 40 40 40 40 40 40
  scd apdu 00 20 00 83 08 40 40 40 40 40 40 40 40
  scd apdu 00 20 00 83 08 40 40 40 40 40 40 40 40
  scd apdu 00 20 00 83 08 40 40 40 40 40 40 40 40
  scd apdu 00 20 00 83 08 40 40 40 40 40 40 40 40
  scd apdu 00 44 00 00
  scd apdu 00 e6 00 00
  /echo card has been reset to factory defaults
  
> So should I nevertheless block all my PINs and give it a try??

I can't tell you my cards show

   Status Indicator: 05

abd thus the life cycle management is supported.  I have no crypt strick
to test it out.


Shalom-Salam,

   Werner


-- 
Die Gedanken sind frei.  Ausnahmen regelt ein Bundesgesetz.




More information about the Gnupg-devel mailing list