gpg frontend support to setup KDF DO
Closed, ResolvedPublic


Now, scdaemon supports KDF DO, if the card support is available.
It should be supported by gpg command line, somehow.

gniibe created this task.Mar 5 2018, 8:49 AM
gniibe added a comment.Mar 6 2018, 7:16 AM

Something like this script should be implemented by gpg frontend:

gniibe added a comment.Mar 7 2018, 8:02 AM

It doesn't work because I did mistake for the salt of reset code, it should be 8-byte instead of 4-byte.
Here is a fixed version, which I tested with Gnuk 1.2.8:

gniibe added a comment.Mar 8 2018, 3:44 AM

Sorry again. My script was still wrong (didn't work).

Here is a final script, which works for my Gnuk Token version 1.2.8.
I confirmed it's working well.
The fix are (1) a typo of hex value: 02->82, (2) s2k count should be in hex.

gniibe added a comment.EditedMar 8 2018, 3:45 AM

I realized that: once KDF-DO is written to smartcard/token, factory-reset command won't work because it assumes standard PIN format than hashed.

gniibe added a comment.Mar 8 2018, 9:06 AM
This comment was removed by gniibe.
gniibe changed the task status from Open to Testing.Mar 22 2018, 7:59 AM

2.2.6 will have this feature in --card-edit, as kdf-setup. Please test.

Arnaud added a subscriber: Arnaud.Apr 3 2018, 11:08 AM
gniibe closed this task as Resolved.Jun 6 2018, 3:41 AM