PUT KEY works only without C-MAC and C-DEC secure channel

HI!
I would like to know why the PUT KEY command to set a new key set only works if a secure channel is opend without secure messaging. My smartcard is GP 2.1.1 compatible.
This is a problem because I'm not allowed to open a secure channel without secure messaging when the smartcard state is SECURED. I even don't know why this is not allowed. Visa Platform 2.0.1 defines this behavior but I can't find it in the GP 2.1.1 spec.
Best regards, globalplayer.

Are you saying that the PUT-KEY command works only in the card life cycle state SECURED?
I can show you that for JCOP it also works in OP_READY, security level '00' --> authentication only, no secure messaging expected:
- /terminal "winscard:4|OMNIKEY CardMan 5x21 0"
--Opening terminal
/card -a a000000003000000 -c com.ibm.jc.CardManagerresetCard with timeout: 0 (ms)
--Waiting for card...
ATR=3B FA 13 00 00 81 31 FE 45 4A 43 4F 50 34 31 56 ;.....1.EJCOP41V
32 33 31 97 231.
ATR: T=1, FI=1/DI=3 (93clk/etu), N=0, IFSC=254, BWI=4/CWI=5, Hist="JCOP41V231"
=> 00 A4 04 00 08 A0 00 00 00 03 00 00 00 00 ..............
(54923 usec)
<= 6F 65 84 08 A0 00 00 00 03 00 00 00 A5 59 9F 65 oe...........Y.e
01 FF 9F 6E 06 40 51 63 45 29 00 73 4A 06 07 2A ...n.@QcE).sJ..*
86 48 86 FC 6B 01 60 0C 06 0A 2A 86 48 86 FC 6B .H..k.`...*.H..k
02 02 01 01 63 09 06 07 2A 86 48 86 FC 6B 03 64 ....c...*.H..k.d
0B 06 09 2A 86 48 86 FC 6B 04 02 15 65 0B 06 09 ...*.H..k...e...
2B 85 10 86 48 64 02 01 03 66 0C 06 0A 2B 06 01 +...Hd...f...+..
04 01 2A 02 6E 01 02 90 00 ..*.n....
Status: No Error
cm> set-key 255/1/DES-ECB/404142434445464748494a4b4c4d4e4f 255/2/DES-ECB/404142434445464748494a4b4c4d4e4f 255/3/DES-ECB/404142434445464748494a4b4c4d4e4f
cm> init-update 255
=> 80 50 00 00 08 AE 78 53 3B 25 42 AC 42 00 .P....xS;%B.B.
(75418 usec)
<= 00 00 70 15 00 05 94 91 11 07 FF 02 00 38 5C 1F ..p..........8\.
9C 9B 00 3A 3D 5D F1 31 A0 12 7A 35 90 00 ...:=].1..z5..
Status: No Error
cm> ext-auth plain
=> 84 82 *00* 00 10 59 65 45 89 C1 15 42 BD DB 6D CF .....YeE...B..m.
CA 0D 8E E3 C7 .....
(179029 usec)
<= 90 00 ..
Status: No Error
cm> card-info
Card Manager AID : A000000003000000
Card Manager state : OP_READY
cm> set-key 1/1/DES-ECB/404142434445464748494a4b4c4d4e4f 1/2/DES-ECB/404142434445464748494a4b4c4d4e4f 1/3/DES-ECB/404142434445464748494a4b4c4d4e4f
cm> put-keyset 1
=> 80 D8 00 81 43 01 80 10 F1 D3 F6 3B 73 F8 EF 6C ....C......;s..l
0A CE B0 23 2A 26 D0 98 03 8B AF 47 80 10 F1 D3 ...#*&.....G....
F6 3B 73 F8 EF 6C 0A CE B0 23 2A 26 D0 98 03 8B .;s..l...#*&....
AF 47 80 10 F1 D3 F6 3B 73 F8 EF 6C 0A CE B0 23 .G.....;s..l...#
2A 26 D0 98 03 8B AF 47 00 *&.....G.
(214587 usec)
<= 01 8B AF 47 8B AF 47 8B AF 47 90 00 ...G..G..G..
Status: No Error

Similar Messages

  • Foreing keys works only when created as CAPITAL?

    Hello,
    When working with HTML DB tutorial, I have noticed that foreign keys works only when I do create them as CAPITAL. I did create some foreign keys manually, and when I was trying "query by example" it did not work correctly unles I did re-create the foreign keys using all captials in their name. Why is it that?
    Thank you,
    DanielD

    I let it dry out more and it started working. It still has a quirk or two but I can live with it.

  • Why GWt suggest box is not working in the latest versions of Firefox ? It was working only in Firefox 3 and not other versions. could you please assist in this regards.,

    Why GWt suggest box is not working in the latest versions of Firefox ?
    It was working only in Firefox 3 and not other versions. could you please assist in this regards.,

    jbren wrote:
    I repeatedly have problems with playback on my STB's. Go thru all the motions, inhouse agent, fix multi room dvr problems. Unplug unit, unplug dvr, etc. etc. etc.  The DVR'd show will play on the DVR but not on the STB's. What's up with that?
    Sorry to hear the auto fix suggested early did not fix your problem. So we can get more information from you, I have copied your post to our private support board. Please refer all correspondences to there from here on out. You can easily get to the private support one of two ways. In the email you signed up for the forums with, you will receive a link to click on. Make sure you are already signed into the forums before clicking on this link. Another way of getting there is by clicking on your username anywhere you see it in the forums. This brings you to your account profile. Scroll down to the section labeled "My Support Cases" . In there you will see the link to your case.
    Anthony_VZ
    **If someones post has helped you, please acknowledge their assistance by clicking the red thumbs up button to give them Kudos. If you are the original poster and any response gave you your answer, please mark the post that had the answer as the solution**
    Notice: Content posted by Verizon employees is meant to be informational and does not supersede or change the Verizon Forums User Guidelines or Terms or Service, or your Customer Agreement Terms and Conditions or plan

  • I am trying to connect to apple support and it keeps asking me to put in the SN of my MAC and when i do it says that the SN is invalid I am putting in the SN from under about this mac and it is the same as the one one the bottom of the MAC any ideas ?

    I am trying to connect to apple support and it keeps asking me to put in the SN of my MAC and when i do it says that the SN is invalid I am putting in the SN from about this mac and it is the same as the one on the bottom of the MAC any ideas ?

    Did you purchase this product direct from Apple online, in an Apple Store, or through a third-party authorized reseller? Or did you buy it from an original owner whose Applecare plan was supposed to be transitioned to a new owner, by them?
    Do you have an original shipping carton the unit arrived in?
    If the product was a retail 'open carton' purchase and no
    back-track is possible, contact the reseller.
    And if the computer had seen a major service with logic
    board replaced, etc, it may have other issues with serial
    number vs one they may have assigned it. Usually a
    new logic board may have the SN flashed or if a unit
    was determined to be a reman, a new # assigned. But
    that would appear in System Profiler, if officially reman.
    If you registered a product anywhere with Apple, it would show on a web page along with its serial numbers, going back several years, at this page after you log in there.
    https://getsupport.apple.com/GetproductgroupList.action
    A blue text with triangle See all products and services opens an Apple ID
    sign-in window, then the page changes to show your items & info about them.
    If you run the serial number through online Lookup, what appears?
    http://www.powerbookmedic.com/identify-mac-serial.php
    Not sure if this helps, 'your product' should appear - if registered.
    Good luck & happy computing!

  • I burnt a dvd from a file I exported from quicktime using the share with apple and pc option.  It was burnt directly from the finder. The dvd works perfectly on my mac, and also runs in my windows, but the sound in my windows pc is stammered.

    This is file I created in SnapzPro (which was saved as a Quicktime mov - Animation) of a Powerpoint Presentation.

    Jon, how do I re-compress the Snapz data for dvd playback?
    That depends on your specific work flow strategy. I normally perform the processing in two stages if editing is involved or in a single stage if I don't plan to trim, title, add a narration track, add special effects, and/or add filters to the Snapz Pro X captured screen data.
    In the two-stage process you export the captured data to an intermediate low-compression, high-quality fomat. (This can be the default settings for Snaps Pro X or a more modern editing specific format like ProRes 422/Linear PCM depending on the codec components for which your system is configured and your personal editing preferences.) The Snapz Pro X intermediate file is then edited in the application of your choice and the results are re-compressed to your final target compression format.
    In any case, whether you are re-compressing the data using QT 7 Pro, iMovie, GarageBand, MPEG Streamclip, Snapz Pro X, or similar third-party app that accesses the built-in OS X QT routines, the export process is essentially the same. Whether you use a "Movie to MPEG-4" or "Movie to QT Movie" export, you must export to a data rate limited, multi-pass H.264/AAC compression combination to take advantage of the "Optimize of CD/DVD" option. Specific data rate limits depend on the playback dimensions of the file you are creating, the minimum level of quality you will accept, and the playback speed of the hardware to be used. (I normally target 4X-8X settings for SD content but if you know the recipient has a higher rated optical drive and your content is HD, then you can use higher encode settings for improved quality.)
    I captured the slideshow again in Snapz, and saved it as H264/AAC. Is this good enough?
    If you did not specifically use the "Optimize for..." feature, then the file is automatically targeted for "Computer" playback which assumes playback is from an hard drive which has greater bandwidth/faster throughput than an optical media player. If the target display dimensions are resonably small, the the contextual nature of the H.264 video encoder may or may not be within the playback limitations of an optical drive usually depending on the encode matrix dimensions, graphic complexity of the source data, overall brightness of the scenes, and limitations you may have place on the target file—i.e., the larger the encoding dimensions, the faster the data date and the less likely the file will be compatible with optical drive playback without having to constantly interrupt playback to cache/rebuffer additional data. However, you can always tell the recipient that if this happens, he or she should simply copy the movie file from the CD/DVD to their hard drive for playback.
    What now? Do I open it in Quicktime and use the "share for mac and pc", then right-click on it in the finder and "burn to disc?"
    What you do next depends on how you plan to burn the file. The steps explained above allows you to create a file that is compatible with playback from an optical drive in a QT Player app but is not authored for playback from a commercial DVD Player. Your next step is to burn that file to an optical disc that can be read by your recipient's computer. I my case, I normally burn the disc using a hybrid (HFS Plus/ISO 9660) format which supports HFS Plus, ISO-9660, Rock Ridge, and Joliet with Rock Ridge file systems. How you do this is up to you. You can, for instance, use a third-party app like Toast or Dragon Burn to create a data disc; create/burn an image file with your Disk Utility app (this is a good option if you plan to burn several discs now and/or in the future); create a named "Burn" folder, drop the file to it, and press the burn button; or simply insert a blank optical media disc into you optical drive, change the default disc name to whatever you want, drop your file to the blank media's Finder window, and press the "Burn" button. (NOTE: Burn options may differ depending on the software installed on your system and/or the version of OS X under which you may be operating.)
    Dont see any specs re playback from an optical disc drive? The slideshow is only 3 min long, and I want to avoid turning it into a video DVD using iDVD, iMovie etc, as the quality of the pictures and type degrades badly. Thanks for the help. Been struggling with this for weeks.
    As noted above, this is an encode setting that only becomes active when you are targeting your H.264/AAC encode for multi-pass/data rate limited compression. When active, the "Optimize for..." pop-up allows you to select "computer" (targets playback from a hard drive), "CD/DVD" (targets playback from optical media), or "Streaming" (targets playback from a realtime streaming server) options. This option prevents data rate excursions from exceeding limits normally associated with each of the named types of playback. This option has nothing to do with the file system used to burn the media disc which determines which platforms/OS can read the disc and the file it contains.

  • Function keys - Boot Camp switching between Mac and PC mode

    My question pertains to running Windows on a Mac computer using Boot Camp and following the instructions, listed below, to enable the function keys while running Windows.
    If I have set the keyboard to "use all F1 etc..." do I have to continually reset the keyboard function from Windows to Mac and visa versa each time I launch the computer in Windows or Mac OS. Or is the setting only applied to the keyboard when I am running Boot Camp as a Windows system?
    While running on the Windows side, right click the Boot Camp icon in the lower right hand corner of the task bar
    Select Boot Camp Control Panel
    Click on the Keyboard tab at the top of the dialog box
    Make sure there is a check mark in the box that says, “Use all F1, F2, etc. keys as standard function keys”
    When finished, click OK
    Thanks

    Thanks Bob,
    So if I may confirm, Windows setting will not effect Mac settings because the two sides completely independent?
    Sorry I can't test it because I'm working on a uni lab computer.
    m

  • I have an SD card that my husband uses for a trail camera. The camera does not have a delete function for the pics, so I put the SD card in our MAC and we can view the pics but when I go to delete them it says that the files cant be deleted. What can i do

    My husband has an SD card he  uses for his trail camera. We put it in our mac book pro and can look at the pictures but when I go to move them to the trash it tells me that the files can't be moved to the trash because they cant be deleted. I have Nikon camera software on my mac and it pics up and asks if you want to import the pics and if you want them deleted from the devices afterwards. I tried that but I get a message afterwards that says that some files were not able to be deleted. When I go to check, none of them were deleted. How can I clean of the SD Card? I do have a camera I could stick it in, it would just be nice to know how to do it from my mac. Also, the files are jpg. if that matters.

    AFAIK cameras offer their own built-in format utility for inserted SD cards.  You should use that.  Otherwise, refer to the manual that came with your camera to determine precisely how your SD cards need to be formatted to work properly.  Personally, I'd suggest Partition Scheme: MBR, and Filesystem: FAT32.
    Try to limit the number of formats you perform on the SD cards, though, as you're reducing their lifespan.  I believe formatting causes re-writes to a portion of the SD card that has fewer read/write cycles than the rest of the card as a whole.

  • Where should I tell PE 12 to put its working copies on my Mac

    When I initially set up PE on my Mac, I set the following for the working directories:
    Capture Video : Same as Project
    Capture Audio : Same as Project
    Video Previews: Same as Project
    Audio Previews: Same as Project
    Media Cache: Custom
    Disc Encoding: Same as Project
    Actually…I don’t remember setting Media Cache differently, so maybe it is the default.
    Anyway, this all seemed reasonable so I could tell how much was in each project and when I was done with  the project, make sure everything got cleaned out.  This worked pretty well since I manually move the media source files off to an external drive and if I need to work on the project again, bring them back to the same location.  The project files are all under one set of directories and the media source files are all under a different set.  Project directory stays small and grows slowly (as long as I make sure intermediate files are deleted), media directory expands and contracts in big increments based on what I manually do to bring media files into the SSD on my Mac or move off to slower NAS disks.
    Then I turned on Time Machine on my Mac.  I backup to an external USB 3.0 drive I periodically connect to my Mac (every couple of days).  I keep it disconnected and in a fireproof box for safety. I looked on my Mac after a couple of days of not doing backups and was short 70 GB on my drive.  Finder said I was using 226 GB out of 499 GB while adding up the directories only got me to 155 GB.  Did some searches on Mac support and found out that Time Machine keeps local copies on my Mac (one an hour, then one a day).  Also, it appears there is no way to disable the local copies or limit how much disk it uses.  I know all the Mac guys will say to “just let it be, it manages it for you”.  But since I want to be moving content on and off the SSD, that is not what I want.  But that is how it is.
    That brings me back to the PE working directories.  When I set up Time Machine, I excluded the large media folders when I set up Time Machine since I knew I was going to be moving stuff in and out of there.  Also I only read these files and have them already backed up elsewhere.  However, I did have it back up the directory structure where my PE project files since there is the bulk of my work.  I think that the Mac is backing up all the working files PE creates and deletes. 
    My plan now is to set all the working directories that are defined as “Same as Project” to new directory that I am going to create just for the Adobe working files and then exclude it from the Time Machine backup.  I will also point Media Cache to that same directory.
    My question is will it cause problems having a single location for all the projects?  I can create separate subdirectories for each of the types of files (i.e. AdobeWorkingArea/CaptureVideo, AdobeWorkingArea/CaptureAudio, etc.).   Also, is losing any of the data in these working directories an issue?  Is there one that I should keep with the project data and backed up?

    You can set  your working files to be saved to wherever you want.
    Although most people prefer to same them Same as Project, and save each new project in its own unique folder, just as a matter of housekeeping.

  • Trying to format a new USB flash drive so it will work on both a Mac and PC

    I have a brand new Sandisk USB flash drive that I am trying to copy movie files onto from my Mac's hard drive.  For some reason I can copy one of the movie files but not the other, even though they are both Quicktime (.mov) files.  In doing some research, it seems the one file will not copy/paste likely because it is over 4 GB in size and the FAT32 filing system on the USB drive prevents files in excess of this size to be copied and pasted.
    My question to anyone who can help me is:  How can I get files over 4 GB onto and off of this USB drive AND be able to use it for both Mac and PC computers?
    Thanks for any advice.
    Shaun

    If I format the USB stick on my Mac as exFAT, will my client who´s most likely using a PC be able to screen it tomorrow morning...??
    exFAT would only be an issue if they were running a version of Windows older than XP. If it is XP, they would need to install the free exFAT update before being able to access the drive.

  • Does DML error logging work only on local DB and not remote DB?

    (A) does not log the errors but (B) does log the errors.
    Does the LOG clause work only on a local database and not a remote database?
    A)
    begin
    INSERT
    INTO
    "PRISM"."TARGET"@"DBLINK"
    (INVOICE_NUM
    ,INVOICE_AMOUNT)
    VALUES
    ('GHI'
    ,'GI')
    LOG ERRORS INTO "PRISM"."ERR$_TARGET"@"DBLINK" (1000) REJECT LIMIT unlimited
    end;
    B)
    begin
    INSERT
    INTO
    "PEER_TARGET"
    ("INVOICE_NUM",
    "INVOICE_AMOUNT")
    VALUES
    ('GHI'
    ,'GI')
    LOG ERRORS INTO "ERR$_PEER_TARGET" (1000) REJECT LIMIT unlimited
    end;

    Oracle has come back to us saying that
    "DML error logging feature is not supported for distributed DML."

  • MAGNIFYER WORKS ONLY IN LOW POWER AND 250% POWER BUT NOT IN ANY OTHER % POWER, ,WHY

    Fire fox magnifier works only in 100% and 250% power but can not select 125, or 150% power, or any other % power, why?

    Are you referring to '''Page Zoom'''? <br />
    https://support.mozilla.com/en-US/kb/Page+Zoom
    Default is 33% to 300% in 14 increments. <br />
    .3,.5,.67,.8,.9,1,1.1,1.2,1.33,1.5,1.7,2,2.4,3
    Or is that something that you installed?

  • Why do I receive some text messages ONLY on my mac and NOT on both my phone AND mac?

    I have my iPhone linked to my messages app on my macbook pro. Often times incoming messages are only sent to my mac and NOT my phone. When I turn on my mac I see that I have missed several text messages. This didn't happen before I upgraded to the latest software for my phone.

    Have you checked to see which accounts are active on your Mac?

  • Shell authorization works only on vty lines and not on console

    Why does command authorization only works for the vty line and NOT for the consoles?
    I use ACS for Win 3.3.(1)
    any input are very welcome
    Configuration
    aaa new-model
    aaa authentication login VTY group tacacs+ local
    aaa authentication login CONSOLE group tacacs+ local
    aaa authentication enable default group tacacs+ enable
    aaa authorization exec default group tacacs+ none
    aaa authorization commands 15 default group tacacs+ none
    line con 0
    login authentication CONSOLE
    line vty 0 4
    login authentication VTY

    By default, console authorization is turned off, even with all the standard authorization commands in your configuration. This was done deliberately to leave the console connection as a "back door" to get into the router in case you lock yourself out (which is easy to do with authorization). The theory is that if someone has access to your console port, you have a lot more to worry about than command authorization :-)
    If you really, really want to do this, make sure it works fine first on the VTY's, and then issue the hidden command:
    aaa authorization console

  • How do I tell itunes (on a Windows XP PC) to start adding downloaded files to an external drive ? Starting itunes while pressing the shift key and then choosing works only for a MAC, I think. I only need this one final step. All is copied already

    How do I tell itunes on a Windows XP PC to start downloading new songs to my external drive ? The whole library has already been moved. I am just one final step away. Everything I`m downloading still lands on C: Relaunching itunes while pressing "shift" and then getting prompted to choose library might work for a Mac, it doesn't for Windows.

    In iTunes click on 'Edit', then 'Preferances', Click on the 'Advanced' button, change the entry in the 'iTunes media folder location' to point to your external drive.

  • Working folder & template questions (Mac and Win)

    I'm using Captivate for Mac (both 5.5 and 6). In the recording preferences (Project Info) there is a field for "Working folder" for FMR in Captivate 5.5 or Video Demo in Captivate 6.
    For new blank projects, it appears that the Working folder is automatically generated to have a path name:
    /private/var/folders/.....
    Question #1: Where is this location on a Mac? (I can't find it.)
    Question #2: Is this location different from the "Adobe Captivate Cached Projects" folder in my Documents folder on a Mac?
    On a related topic, a client has provided me with a template that currently has this path for the Working folder:
    C:\Users\JaneSmith\AppData\Local\Temp\CP344026233798Session\ForFMR344026233908
    Obviously, this path is valid only on Jane Smith's Win PC and is useless for any other Captivate user, whether on Windows or Mac. In fact, when I modify certain default preferences for this template, I get an error message: "The specified working folder could not be created. Please enter a valid location to continue." So I have to change it to a local Mac path.
    Question #3: Which location do I use for the Working folder? Do I use the "/private/var/folders/" location (wherever that is). Do I create any old folder? Or do I use the "Adobe Captivate Cached Projects" folder?
    Question #4: I need to share this modified template with several Captivate users working on this project (could be using either Mac or Windows). If a template contains a working folder specific to my computer, must every user re-modify the template and re-set the working folder location for his/her specific computer?
    Question #5: If I'm not mistaken, temp/working folders for similar software are usually set at the application level, not the project/document level. Is there a good reason why that convention isn't followed in Captivate?

    organic_othman wrote:
    Hi,
    I want to get the default system folder on any OS .
    for windows it should be"My Documents" and for Mac it should be "Pictures"
    however OS folders names depend on OS current language (English, French, Spanish etc..)
    I vaguely remember reading somewhere that the English version of those folders will find the correct folders in the localised versions.
    Quick google gives me:
    http://developer.apple.com/documentation/MacOSX/Conceptual/BPFileSystem/Articles/DisplayNames.html

Maybe you are looking for