git-svn-id: https://vsmartcard.svn.sourceforge.net/svnroot/vsmartcard@368 96b47cad-a561-4643-ad3b-153ac7d7599c
57 lines
2.2 KiB
Plaintext
57 lines
2.2 KiB
Plaintext
/** @mainpage
|
|
|
|
Welcome to npa. The purpose of npa is to offer an easy to use API for the new
|
|
German identity card (neuer Personalausweis, nPA). The library also implements
|
|
secure messaging, which could also be used for other cards.
|
|
|
|
npa is implemented using OpenPACE (http://sourceforge.net/projects/openpace/).
|
|
Some fragments of the source code are on the source code of the OpenSC tools.
|
|
|
|
The included pace-tool has support for Password Authenticated Connection
|
|
Establishment (PACE). pace-tool can be used for PIN management or to encrypt
|
|
APDUs inside a secure messaging channel established with PACE.
|
|
|
|
|
|
@section i INSTALLATION
|
|
|
|
See file INSTALL.
|
|
|
|
|
|
@subsection o HINTS ON OPENSC
|
|
|
|
npa links against libopensc, which is discouraged and hindered since
|
|
opensc>=0.12. We really need to get rid of this dependency. But since this is a
|
|
lot of work, you will have to use older versions of opensc.
|
|
|
|
OpenSC older than r4244 will yield something like this error:
|
|
|
|
[default] apdu.c:341:sc_check_apdu: Invalid Case 4 short APDU:
|
|
cse=04 cla=10 ins=86 p1=00 p2=00 lc=2 le=0
|
|
resp=0x10353c0 resplen=256 data=0x1034a30 datalen=2
|
|
[default] pace.c:1110:EstablishPACEChannel: Could not get encrypted nonce from card (General Authenticate step 1 failed).
|
|
|
|
This requires the following patch:
|
|
http://www.opensc-project.org/opensc/raw-attachment/ticket/209/le0.patch
|
|
|
|
The following patch makes the hex dumped output more readable:
|
|
http://www.opensc-project.org/opensc/raw-attachment/ticket/263/hex_dump_align.2.patch
|
|
|
|
|
|
@section u USAGE
|
|
|
|
When testing PACE with either PIN, CAN, MRZ or PUK run pace-tool. Here you can
|
|
enter APDUs which are to be converted according to the secure messaging
|
|
parameter and to be sent to the card. Herefor insert the APDU in hex (upper or
|
|
lower case) with a colon to separate the bytes or without it. Example APDUs can
|
|
be found in the file apdus.
|
|
To pass a secret to pace-tool, the command line parameters or the environment
|
|
variables PIN/CAN/MRZ/PUK/NEWPIN can be used. If none of these options is used,
|
|
pace-tool will show a password prompt.
|
|
|
|
|
|
@section q QUESTIONS
|
|
For questions, please use http://sourceforge.net/projects/vsmartcard/support
|
|
|
|
@author Frank Morgner <morgner@informatik.hu-berlin.de>
|
|
*/
|