Files
vsmartcard/npa
frankmorgner 1e07dafbdd releasing 0.1
git-svn-id: https://vsmartcard.svn.sourceforge.net/svnroot/vsmartcard@374 96b47cad-a561-4643-ad3b-153ac7d7599c
2010-12-08 14:44:19 +00:00
..
2010-12-08 14:44:19 +00:00
2010-11-14 20:34:52 +00:00
2010-12-08 14:44:19 +00:00
2010-11-14 20:34:52 +00:00
2010-11-14 20:34:52 +00:00
2010-11-14 20:34:52 +00:00
2010-11-14 20:34:52 +00:00
2010-11-14 20:34:52 +00:00
2010-11-14 20:34:52 +00:00
2010-12-07 20:07:05 +00:00

/** @mainpage

Welcome to npa. The purpose of npa is to offer an easy to use API for the new
German identity card (neuer Personalausweis, nPA). The library also implements
secure messaging, which could also be used for other cards.

npa is implemented using OpenPACE (http://sourceforge.net/projects/openpace/).
Some fragments of the source code are on the source code of the OpenSC tools.

The included pace-tool has support for Password Authenticated Connection
Establishment (PACE). pace-tool can be used for PIN management or to encrypt
APDUs inside a secure messaging channel established with PACE.


@section i INSTALLATION

See file INSTALL.


@subsection o HINTS ON OPENSC

npa links against libopensc, which is discouraged and hindered since
opensc>=0.12. We really need to get rid of this dependency. But since this is a
lot of work, you will have to use older versions of opensc.

OpenSC older than r4244 will yield something like this error:

[default] apdu.c:341:sc_check_apdu: Invalid Case 4 short APDU:
cse=04 cla=10 ins=86 p1=00 p2=00 lc=2 le=0
resp=0x10353c0 resplen=256 data=0x1034a30 datalen=2
[default] pace.c:1110:EstablishPACEChannel: Could not get encrypted nonce from card (General Authenticate step 1 failed).

This requires the following patch:
http://www.opensc-project.org/opensc/raw-attachment/ticket/209/le0.patch

The following patch makes the hex dumped output more readable:
http://www.opensc-project.org/opensc/raw-attachment/ticket/263/hex_dump_align.2.patch


@section u USAGE

When testing PACE with either PIN, CAN, MRZ or PUK run pace-tool. Here you can
enter APDUs which are to be converted according to the secure messaging
parameter and to be sent to the card. Herefor insert the APDU in hex (upper or
lower case) with a colon to separate the bytes or without it. Example APDUs can
be found in the file apdus.
To pass a secret to pace-tool, the command line parameters or the environment
variables PIN/CAN/MRZ/PUK/NEWPIN can be used. If none of these options is used,
pace-tool will show a password prompt.


@section q QUESTIONS
For questions, please use http://sourceforge.net/projects/vsmartcard/support

@author Frank Morgner <morgner@informatik.hu-berlin.de>
*/