Repository navigation
Read card facts without authenticating - #25
Merged
Merged
Conversation
Add `piv inventory`: the applet's key objects, verifiers, containers and config flags with their access rules, from the vendor GET DATA 2F47xx identifiers. Read the finalized (SECURED) state from the applet's status object and report it beside the personalization ladder in `piv status`, `info`, `report` and `factory piv preperso status`; the finalize gate uses it. Read the admin security domain's SCP version and key versions from its key information template instead of sending INITIALIZE UPDATE, which this chip counts as a failed authentication; `piv admin status --key-version` is removed and `initialize_update_probe` deleted. Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
piv inventory: the applet's key objects, verifiers, containers and config flags with their access rules, read from the vendorGET DATA 2F47xxidentifiers (4Bkeys,50verifiers,44containers,43config,56version,53status; P2 is the index,6A82ends a listing). No authentication. An applet withrestrict-enumerationset answers6986; the command reports the structure as withheld and still shows version, state and config.2F4753, tag 80 = GP content state,0F= secured). It is a separate flag (piv_secured, JSONsecured) beside the personalization ladder, because finalize locks the structure only.piv status,info,reportandfactory piv preperso statusshow it;finalizegates on it.PivState.SECUREDis removed; CONTEXT.md amended.piv admin statusandfactory piv preperso statusread the admin security domain's SCP version and key versions from its key information template (SELECT the PIV SSD, ISD fallback, then80 CA 00 E0). They no longer send INITIALIZE UPDATE, which this chip counts as a failed authentication when not followed by EXTERNAL AUTHENTICATE. The SSD's FCI carries no SCP OID on the D600, so the version is inferred from the key type (DES = SCP02, AES = SCP03).piv admin status --key-versionis removed andPivAdmin.initialize_update_probedeleted. JSON ofpreperso statusgainssecurity_domain;scp03_availableandscp_versionstay.1F= ALWAYS,40= SM,60= VCI,80= user-admin; the applet's TRUE byte isA5, FALSE is5A.Tests use response bytes captured from a D600 card with the
cryptnox-defaultstructure. Ruff, 505 pytest, Sphinx-Wall green.Follow-up once #24 merges: point step 1 of the key-rotation section at
piv admin status.🤖 Generated with Claude Code