ignoring CVCA certificate for --disable-checks
This essentially lets the terminal's DVCA certificate to be imported without being checked using the CVCA trust anchor.
This commit is contained in:
@@ -301,12 +301,14 @@ class nPA_SE(Security_Environment):
|
|||||||
|
|
||||||
result = [[0x86, len(my_token), my_token]]
|
result = [[0x86, len(my_token), my_token]]
|
||||||
if self.at.chat:
|
if self.at.chat:
|
||||||
if not pace.EAC_CTX_init_ta(self.eac_ctx, None, None, self.ca):
|
|
||||||
pace.print_ossl_err()
|
|
||||||
raise SwError(SW["WARN_NOINFO63"])
|
|
||||||
result.append([0x87, len(self.ca), self.ca])
|
result.append([0x87, len(self.ca), self.ca])
|
||||||
if (self.disable_checks):
|
if (self.disable_checks):
|
||||||
pace.TA_disable_checks(self.eac_ctx)
|
pace.TA_disable_checks(self.eac_ctx)
|
||||||
|
else:
|
||||||
|
if not pace.EAC_CTX_init_ta(self.eac_ctx, None, None, self.ca):
|
||||||
|
pace.print_ossl_err()
|
||||||
|
raise SwError(SW["WARN_NOINFO63"])
|
||||||
|
|
||||||
|
|
||||||
return 0x9000, nPA_SE.__pack_general_authenticate(result)
|
return 0x9000, nPA_SE.__pack_general_authenticate(result)
|
||||||
|
|
||||||
|
|||||||
Reference in New Issue
Block a user