documentation

git-svn-id: https://vsmartcard.svn.sourceforge.net/svnroot/vsmartcard@586 96b47cad-a561-4643-ad3b-153ac7d7599c
This commit is contained in:
frankmorgner
2011-10-27 15:23:06 +00:00
parent 61519f1da0
commit ebfb023658
4 changed files with 93 additions and 47 deletions

View File

@@ -1,6 +1,9 @@
.. highlight:: sh .. highlight:: sh
.. _OpenSC: http://www.opensc-project.org/opensc .. _OpenSC: http://www.opensc-project.org/opensc
.. _GadgetFS: http://www.linux-usb.org/gadget/
.. _libccid: http://pcsclite.alioth.debian.org/ccid.html
************* *************
ccid-emulator ccid-emulator
@@ -21,9 +24,9 @@ reader to the host system. ccid-emulator has support for Password
Authenticated Connection Establishment (PACE) using OpenPACE Authenticated Connection Establishment (PACE) using OpenPACE
(http://sourceforge.net/projects/openpace/). (http://sourceforge.net/projects/openpace/).
ccid-emulator is implemented using GadgetFS. Some fragments of the source code ccid-emulator is implemented using GadgetFS_. Some fragments of the source code
are based on the GadgetFS example at http://www.linux-usb.org/gadget/ and on the are based on the GadgetFS_ example and on the source code of the OpenSC_ tools.
source code of the OpenSC tools.
============= =============
Installation Installation
@@ -32,33 +35,36 @@ Installation
ccid uses the GNU Build System to compile and install. If you are unfamiliar ccid uses the GNU Build System to compile and install. If you are unfamiliar
with it, please have a look at the file ``INSTALL``. If you have a look around with it, please have a look at the file ``INSTALL``. If you have a look around
and can not find it, you are probably working bleeding edge in the repository. and can not find it, you are probably working bleeding edge in the repository.
Run the following command in the npa direcotry to get the missing standard Run the following command in the npa directory to get the missing standard
auxiliary files:: auxiliary files::
autoreconf -i autoreconf -i
ccid as the following dependencies: ccid as the following dependencies:
- OpenSC_ - Linux Kernel with GadgetFS_
- libnpa - OpenSC_
- libnpa
------------------
Hints of GadgetFS -----------------
------------------ Hints on GadgetFS
-----------------
To create an USB Gadget in both USB host and USB client mode, you need to load To create an USB Gadget in both USB host and USB client mode, you need to load
the kernel module gadgetfs. A guide focused on Debian based systems to run and the kernel module ``gadgetfs``. A guide focused on Debian based systems to run
compile gadgetfs, you can find here: and compile gadgetfs, you can find `here
http://wiki.openmoko.org/wiki/Building_Gadget_USB_Module <http://wiki.openmoko.org/wiki/Building_Gadget_USB_Module>`_.
On OpenMoko it is likely that you need to patch your kernel (see On OpenMoko it is likely that you need to `patch your kernel
http://docs.openmoko.org/trac/ticket/2206). If you also want to switch multiple <http://docs.openmoko.org/trac/ticket/2206>`_. If you also want to switch
times between gadgetfs and g_ether, another patch is needed (see multiple times between ``gadgetfs`` and ``g_ether``, `another patch is needed
https://docs.openmoko.org/trac/ticket/2240). <http://docs.openmoko.org/trac/ticket/2240)>`_.
If you are using a more recent version of ``dummy_hcd`` and get an error
loading the module, you maybe want to check out `this patch
<http://comments.gmane.org/gmane.linux.usb.general/47440>`_.
If you are using a more recent version of dummy_hcd, you maybe want to check
out this patch:
http://comments.gmane.org/gmane.linux.usb.general/47440
--------------- ---------------
Hints on OpenSC Hints on OpenSC
@@ -90,15 +96,16 @@ Usage
===== =====
ccid-emulator has various command line options to customize the appearance on ccid-emulator has various command line options to customize the appearance on
the USB host. In order to run ccid-emulator GadgetFS must be loaded and mounted. the USB host. In order to run ccid-emulator GadgetFS_ must be loaded and
ccid-emulator is compatible with the unix driver libccid and the windows smart mounted. ccid-emulator is compatible with the unix driver libccid_ and the
card driver. To initialize PACE using the PC/SC API you need to patch libccid windows smart card driver. To initialize PACE using the PC/SC API you need to
and pcsc-lite (see directory patches). patch libccid and pcsc-lite (see directory patches).
cats-test can be used to test the PACE capabilities of a smart card reader with cats-test can be used to test the PACE capabilities of a smart card reader with
PACE support (such as ccid-emulator or any other "Standardleser" CAT-S or PACE support (such as ccid-emulator or any other "Standardleser" CAT-S or
"Komfortleser" CAT-C) via PC/SC. "Komfortleser" CAT-C) via PC/SC.
========= =========
Questions Questions
========= =========

View File

@@ -3,11 +3,11 @@
.. _OpenSC: http://www.opensc-project.org/opensc .. _OpenSC: http://www.opensc-project.org/opensc
.. _OpenPACE: http://sourceforge.net/projects/openpace/ .. _OpenPACE: http://sourceforge.net/projects/openpace/
*** ***
npa npa
*** ***
:Author: :Author:
Frank Morgner <morgner@informatik.hu-berlin.de> Frank Morgner <morgner@informatik.hu-berlin.de>
:License: :License:
@@ -26,6 +26,7 @@ The included npa-tool has support for Password Authenticated Connection
Establishment (PACE). npa-tool can be used for PIN management or to encrypt Establishment (PACE). npa-tool can be used for PIN management or to encrypt
APDUs inside a secure messaging channel established with PACE. APDUs inside a secure messaging channel established with PACE.
.. _npa-install: .. _npa-install:
============ ============
@@ -35,7 +36,7 @@ Installation
npa uses the GNU Build System to compile and install. If you are unfamiliar npa uses the GNU Build System to compile and install. If you are unfamiliar
with it, please have a look at the file ``INSTALL``. If you have a look around with it, please have a look at the file ``INSTALL``. If you have a look around
and can not find it, you are probably working bleeding edge in the repository. and can not find it, you are probably working bleeding edge in the repository.
Run the following command in the npa direcotry to get the missing standard Run the following command in the npa directory to get the missing standard
auxiliary files:: auxiliary files::
autoreconf -i autoreconf -i
@@ -45,6 +46,7 @@ npa has the following dependencies:
- OpenSC_ - OpenSC_
- OpenSSL with OpenPACE_ - OpenSSL with OpenPACE_
------------------------------ ------------------------------
Hints on OpenSSL with OpenPACE Hints on OpenSSL with OpenPACE
------------------------------ ------------------------------
@@ -69,6 +71,7 @@ to configure npa to use it::
./configure PKG_CONFIG_PATH=$PREFIX/lib/pkgconfig ./configure PKG_CONFIG_PATH=$PREFIX/lib/pkgconfig
--------------- ---------------
Hints on OpenSC Hints on OpenSC
--------------- ---------------

View File

@@ -3,14 +3,18 @@
.. _libnfc: http://www.libnfc.org/ .. _libnfc: http://www.libnfc.org/
.. _PCSC-lite: http://pcsclite.alioth.debian.org/ .. _PCSC-lite: http://pcsclite.alioth.debian.org/
********** **********
pcsc-relay pcsc-relay
********** **********
.. Authors : Dominik Oepen <oepen@informatik.hu-berlin.de> :Authors:
.. Frank Morgner <morgner@informatik.hu-berlin.de> - Dominik Oepen <oepen@informatik.hu-berlin.de>
.. License : See file COPYING - Frank Morgner <morgner@informatik.hu-berlin.de>
.. Tested Platforms : Linux 2.6 (Debian, Ubuntu, Om 2008) :License:
GPL version 3
:Tested Platforms:
Linux (Debian, Ubuntu, OpenMoko)
Welcome to pcsc-relay. The purpose of pcsc-relay is to forward APDUs from the Welcome to pcsc-relay. The purpose of pcsc-relay is to forward APDUs from the
OpenPICC or from a libnfc device to a smart card via the PCSC middleware. You OpenPICC or from a libnfc device to a smart card via the PCSC middleware. You
@@ -25,7 +29,7 @@ Installation
pcsc-relay uses the GNU Build System to compile and install. If you are pcsc-relay uses the GNU Build System to compile and install. If you are
unfamiliar with it, please have a look at the file ``INSTALL``. If you have a unfamiliar with it, please have a look at the file ``INSTALL``. If you have a
look around and can not find it, you are probably working bleeding edge in the look around and can not find it, you are probably working bleeding edge in the
repository. Run the following command in the pcsc-relay direcotry to get the repository. Run the following command in the pcsc-relay directory to get the
missing standard auxiliary files:: missing standard auxiliary files::
autoreconf -i autoreconf -i
@@ -35,6 +39,7 @@ pcsc-relay has the following dependencies:
- PC/SC middleware - PC/SC middleware
- libnfc_ - libnfc_
--------------- ---------------
Hints on libnfc Hints on libnfc
--------------- ---------------
@@ -57,6 +62,7 @@ configure pcsc-relay to use it::
./configure PKG_CONFIG_PATH=$PREFIX/lib/pkgconfig ./configure PKG_CONFIG_PATH=$PREFIX/lib/pkgconfig
------------------------- -------------------------
Hints on PC/SC middleware Hints on PC/SC middleware
------------------------- -------------------------
@@ -68,6 +74,7 @@ distribution. Windows also ships with a PC/SC middleware in form of the
Winscard module. Microsoft's developement environment Visual Studio includes Winscard module. Microsoft's developement environment Visual Studio includes
all necessary data for building pcsc-relay. all necessary data for building pcsc-relay.
========= =========
Questions Questions
========= =========

View File

@@ -1,3 +1,15 @@
.. highlight:: sh
.. _PBKDF2: https://www.dlitz.net/software/python-pbkdf2/
.. _PCSC-lite: http://pcsclite.alioth.debian.org/
.. _PCSC-lite: http://pcsclite.alioth.debian.org/
.. _PIP: http://www.pythonware.com/products/pil/
.. _PyCrypto: http://pycrypto.org/
.. _Python: http://www.python.org/
.. _cyberflex-shell: https://github.com/henryk/cyberflex-shell
.. _pyscard: http://pyscard.sourceforge.net/
****************** ******************
Virtual Smart Card Virtual Smart Card
****************** ******************
@@ -16,38 +28,55 @@ smart card and make it accessible through PCSC. Currently the virtual smart
card supports almost all commands of ISO-7816 including secure messaging. card supports almost all commands of ISO-7816 including secure messaging.
Besides a plain ISO-7816 smart card it is also possible to emulate a German Besides a plain ISO-7816 smart card it is also possible to emulate a German
ePass (only basic access control) and a rudimentary Cryptoflex smart card. The ePass (only basic access control) and a rudimentary Cryptoflex smart card. The
virtual smart card can be accessed through the virtual smart card reader which virtual smart card (vpicc) can be accessed through the virtual smart card
is a driver for pcscd of PCSC-Lite. reader (vpcd) which is a driver for ``pcscd`` of PCSC-Lite_.
By default the virtual smart card communicates with the virtual smart card By default the vicc communicates with the vpcd through a socket on localhost
reader through a socket on localhost port 35963. The file utils.py was taken port 35963. The file ``utils.py`` was taken from Henryk Plötz's
from `Henryk Plötz's cyberflex-shell <https://github.com/henryk/cyberflex-shell/>`_. cyberflex-shell_.
------------
Installation Installation
------------ ------------
::
autoconf -vsi virtualsmartcard uses the GNU Build System to compile and install. If you are
./configure unfamiliar with it, please have a look at the file ``INSTALL``. If you have a
make look around and can not find it, you are probably working bleeding edge in the
make install repository. Run the following command in the virtualsmartcard directory to get
the missing standard auxiliary files::
autoreconf -i
Depending on your usage of the vpicc you might or might not need
the following:
- Python_
- pyscard_
- PyCrypto_
- PBKDF2_
- PIP_
The vpcd has the following dependencies:
- PCSC-Lite_
------------------------
Running virtualsmartcard Running virtualsmartcard
------------------------ ------------------------
First you need to make sure that pcscd loads the virtual smart card driver. You First you need to make sure that pcscd loads the vpcd. You might need to run
might run ``update-reader.conf`` to update pcscd's configuration file. Then ``update-reader.conf`` to update pcscd's configuration file. Then ``pcscd -f
``pcscd -f -d`` should say something like -d`` should say something like ``Attempting startup of Virtual PCD``
readerfactory.c:1024:RFInitializeReader() Attempting startup of Virtual PCD 00 00 using /usr/lib/pcsc/drivers/serial/libvpcd.so
Now you can run ``vicc`` which connects to the virtual reader. The Now you can run ``vicc`` which connects to the virtual reader. The
command ``vicc --help`` gives an overview about the command line command ``vicc --help`` gives an overview about the command line
options. options.
You should now be able to access the virtual smart card through the system's You should now be able to access the vpicc through the system's
PC/SC API. You can use the opensc-explorer or pcsc_scan to test that. PC/SC API via vpcd/pcscd. You can use the opensc-explorer or pcsc_scan to test
that.
Question Question