Return-Path: Delivered-To: apmail-xml-security-dev-archive@www.apache.org Received: (qmail 30294 invoked from network); 31 Jan 2006 20:38:25 -0000 Received: from hermes.apache.org (HELO mail.apache.org) (209.237.227.199) by minotaur.apache.org with SMTP; 31 Jan 2006 20:38:25 -0000 Received: (qmail 41634 invoked by uid 500); 31 Jan 2006 20:38:24 -0000 Delivered-To: apmail-xml-security-dev-archive@xml.apache.org Received: (qmail 41255 invoked by uid 500); 31 Jan 2006 20:38:23 -0000 Mailing-List: contact security-dev-help@xml.apache.org; run by ezmlm Precedence: bulk List-Post: List-Help: List-Unsubscribe: Reply-To: security-dev@xml.apache.org List-Id: Delivered-To: mailing list security-dev@xml.apache.org Received: (qmail 41244 invoked by uid 99); 31 Jan 2006 20:38:23 -0000 Received: from asf.osuosl.org (HELO asf.osuosl.org) (140.211.166.49) by apache.org (qpsmtpd/0.29) with ESMTP; Tue, 31 Jan 2006 12:38:23 -0800 X-ASF-Spam-Status: No, hits=0.0 required=10.0 tests= X-Spam-Check-By: apache.org Received-SPF: pass (asf.osuosl.org: local policy) Received: from [217.72.192.242] (HELO fmmailgate04.web.de) (217.72.192.242) by apache.org (qpsmtpd/0.29) with ESMTP; Tue, 31 Jan 2006 12:38:22 -0800 Received: by fmmailgate04.web.de (8.12.10/8.12.10/webde Linux 0.7) with SMTP id k0VKc0bw026374 for ; Tue, 31 Jan 2006 21:38:00 +0100 Received: from [84.189.55.58] by freemailng1201.web.de with HTTP; Tue, 31 Jan 2006 21:38:00 +0100 Date: Tue, 31 Jan 2006 21:38:00 +0100 Message-Id: <1261811897@web.de> MIME-Version: 1.0 From: Ulrich Ackermann To: security-dev@xml.apache.org Subject: RE: Examples for XMLSignature with private key on a Smartcard Organization: http://freemail.web.de/ Content-Type: text/plain; charset=iso-8859-1 Content-Transfer-Encoding: 7bit X-Virus-Checked: Checked by ClamAV on apache.org X-Spam-Rating: minotaur.apache.org 1.6.2 0/1000/N Hi, the hint I got from Sean did (probably) solve my problem. Probably means, that I still have a problem with namespaces, but I hopefully will get to handle that, too. I haven't used JSS so far. I am accessing the smartcard through the PKCS11Wrapper from IAIK and the PKCS#11 driver of the smartcard. I'm sorry that I cannot give you any help in using JSS. Ulrich security-dev@xml.apache.org schrieb am 30.01.06 09:07:25: Hi, Did you by any chance happen to solve this problem? Are you accessing the certificate on the smartcard using JSS? It so, the problem is in the providers that register when you initialize the jss, which causes different signaturevalues. I have no idea why they calculate different values, but they do, even if the data that gets sent in is the same. miha -----Original Message----- From: Ulrich Ackermann [mailto:ulrich.ackermann@web.de] Sent: Tuesday, January 24, 2006 2:02 PM To: security-dev@xml.apache.org Subject: Re: Examples for XMLSignature with private key on a Smartcard Hi Sean, Thank you for your response. It seems that my question wasn't as clear as I thought it would be. I Haven't got any problems in using a Smartcard. I DO have got problems in getting the right hash, that has to be encrypted with the private key on the Smartcard (or on any other hardware crypto device). I have used the example class which is included in the XML Security download. But it gets me a different SignatureValue, when I calculate the digest of the SignedInfo element outside the framework and encrypt it on a smartcard (or for testing purposes with a software key as I did). So, maybe I should narrow my question down to "How do I get the bytes, that the XML security framework uses for hashing?" or "Is there a way, to get the hash of the SignedInfo element from the XML security framework?" Thank you very much and sorry for the misleading question, Ulrich security-dev@xml.apache.org schrieb am 23.01.06 23:13:40: Does the card support PKCS#11? If so, have you tried using it with a PKCS#11 JCE provider, such as the one in Sun's JDK 5.0? : http://java.sun.com/j2se/1.5.0/docs/guide/security/p11guide.html --Sean Ulrich Ackermann wrote: > Hi, > > I've been looking quit a while without any luck for any advice or > examples for getting an XMLSignature done with the constraint, that > the private key can't be offered the XML Security framework (because > he is on a Smartcard, e.g.). All attempts getting or creating the > "right" digest and encrypting it with the private key outside didn't > lead to any result either. > > Has anybody anywhere accomplished this task (which shouldn't be too > extraordinary...)? Any help (links, example code etc.) is much > appreciated! > > Thanks in advance, Ulrich > ______________________________________________________________ > Verschicken Sie romantische, coole und witzige Bilder per SMS! Jetzt > bei WEB.DE FreeMail: http://f.web.de/?mc=021193 > __________________________________________________________________________ Erweitern Sie FreeMail zu einem noch leistungsstarkeren E-Mail-Postfach! Mehr Infos unter http://freemail.web.de/home/landingpad/?mc=021131 ______________________________________________________________ Verschicken Sie romantische, coole und witzige Bilder per SMS! Jetzt bei WEB.DE FreeMail: http://f.web.de/?mc=021193