What is 'CA fingerprint 1' on Smartcard

NIIBE Yutaka gniibe at fsij.org
Thu Apr 2 04:40:39 CEST 2015

On 04/01/2015 01:50 AM, Daniel Krebs wrote:
> What is the CA fingerprint on FSFE-Smartcard?
> A gpg2 --car-status gave the information:
> CA fingerprint 1 .: C485 A6CD 7EC6 6E9E EC33  65F2 70F2 75E4 C32F 6CA5

Well, I can't find a key with this fingerprint on key servers.

> This is a smartcard issued by the FSFE. After reseting the card this
> information is gone, so it must be applied by FSFE. I read the
> openpgp-card-2.0 specification but I'm still not sure what this CA
> data object is used for and what specific CA it points to. Maybe you
> can help...

It seems that it's intended to be hold a fingerprint of OpenPGP, but
it is not clear what/how this fingerprint is used for.

>From a view point of scdaemon developer, I don't have any experience
using these data objects.  Even, I couldn't imagine valid usage of
these data objects.

Besides, I don't understand the reason why this data object was filled
by a specific value when shipped.

Sorry for not useful information, but, those are all I could say.

Still, it would make sense to share this info.

More information about the Gnupg-users mailing list