04.01.2013 Views

DoD Implementation Guide for CAC PIV End-Point - Common ...

DoD Implementation Guide for CAC PIV End-Point - Common ...

DoD Implementation Guide for CAC PIV End-Point - Common ...

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

<strong>DoD</strong> <strong>Implementation</strong> <strong>Guide</strong> <strong>for</strong> <strong>CAC</strong> <strong>PIV</strong> <strong>End</strong>-<strong>Point</strong><br />

• Printed In<strong>for</strong>mation Buffer<br />

Figure 3. <strong>CAC</strong> <strong>PIV</strong> <strong>End</strong>-<strong>Point</strong> Data Model 5<br />

Sign/<br />

Encr<br />

7<br />

Get Data Verify/Change Pin<br />

SP 800-73-1 permits default applets 6 . In this profile the default selected applet and<br />

container <strong>for</strong> both contact and contactless are the <strong>PIV</strong> Transitional Applet and the CHUID<br />

container. To use <strong>PIV</strong> defined GET DATA commands after a cold or warm reset a SELECT<br />

<strong>PIV</strong> <strong>End</strong>-<strong>Point</strong> Applet command is required. The CCC is shared between <strong>PIV</strong> <strong>End</strong>-<strong>Point</strong> and<br />

the Transitional data model.<br />

Note: To access the <strong>PIV</strong> Auth Certificate from the <strong>End</strong>-<strong>Point</strong> card edge, implementers first<br />

select the <strong>PIV</strong> EP applet and then issue a GET_DATA request as per SP800-73. To access<br />

the <strong>PIV</strong> Auth Certificate from the <strong>PIV</strong> Transitional card edge (<strong>PIV</strong> Auth Activated mode),<br />

implementers use OID 0xA001.<br />

4.1 Access Control Rule Definition<br />

The following table lists the Access Control Rules supported by <strong>PIV</strong> <strong>End</strong>-<strong>Point</strong> applet during<br />

the Card Usage of the lifecycle phase of card 7 .<br />

5 When using a <strong>PIV</strong> <strong>End</strong>-<strong>Point</strong> card with the <strong>PIV</strong> Auth activated mode, the <strong>PIV</strong> Auth<br />

Certificate OID at the <strong>PIV</strong> Transitional card edge will read 0xA001 as opposed to 0x0101.<br />

6 SP800-73-1 section 3.4.2, pg 19 does not mandate a specific selected application.<br />

7 These are not applicable at the Card Issuance lifecycle phase.

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!