Skip to content

Read card facts without authenticating - #25

Merged
mmlado merged 1 commit into
mainfrom
feat/keyless-card-facts
Oct 9, 2026
Merged

mmlado merged 1 commit into
mainfrom
feat/keyless-card-facts

Conversation

@mmlado

@mmlado mmlado commented Oct 9, 2026

Copy link
Copy Markdown
Collaborator
  • New piv inventory: the applet's key objects, verifiers, containers and config flags with their access rules, read from the vendor GET DATA 2F47xx identifiers (4B keys, 50 verifiers, 44 containers, 43 config, 56 version, 53 status; P2 is the index, 6A82 ends a listing). No authentication. An applet with restrict-enumeration set answers 6986; the command reports the structure as withheld and still shows version, state and config.
  • Finalized (SECURED) state now comes from the applet's status object (2F4753, tag 80 = GP content state, 0F = secured). It is a separate flag (piv_secured, JSON secured) beside the personalization ladder, because finalize locks the structure only. piv status, info, report and factory piv preperso status show it; finalize gates on it. PivState.SECURED is removed; CONTEXT.md amended.
  • piv admin status and factory piv preperso status read the admin security domain's SCP version and key versions from its key information template (SELECT the PIV SSD, ISD fallback, then 80 CA 00 E0). They no longer send INITIALIZE UPDATE, which this chip counts as a failed authentication when not followed by EXTERNAL AUTHENTICATE. The SSD's FCI carries no SCP OID on the D600, so the version is inferred from the key type (DES = SCP02, AES = SCP03). piv admin status --key-version is removed and PivAdmin.initialize_update_probe deleted. JSON of preperso status gains security_domain; scp03_available and scp_version stay.
  • Applet facts the decoders rely on: access mode low five bits are the cardholder condition with 1F = ALWAYS, 40 = SM, 60 = VCI, 80 = user-admin; the applet's TRUE byte is A5, FALSE is 5A.

Tests use response bytes captured from a D600 card with the cryptnox-default structure. Ruff, 505 pytest, Sphinx -W all green.

Follow-up once #24 merges: point step 1 of the key-rotation section at piv admin status.

🤖 Generated with Claude Code

Add `piv inventory`: the applet's key objects, verifiers, containers and
config flags with their access rules, from the vendor GET DATA 2F47xx
identifiers. Read the finalized (SECURED) state from the applet's status
object and report it beside the personalization ladder in `piv status`,
`info`, `report` and `factory piv preperso status`; the finalize gate uses
it. Read the admin security domain's SCP version and key versions from
its key information template instead of sending INITIALIZE UPDATE, which
this chip counts as a failed authentication; `piv admin status
--key-version` is removed and `initialize_update_probe` deleted.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
@mmlado mmlado self-assigned this Oct 9, 2026
@mmlado
mmlado merged commit 141b8c1 into main Oct 9, 2026
12 checks passed
@mmlado
mmlado deleted the feat/keyless-card-facts branch October 9, 2026 10:17
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant