Classic Client Linux User Guide
Classic Client Linux User Guide
1 for Linux
User Guide
All information herein is either public information or is the property of and owned solely by Gemalto NV. and/or its subsidiaries
who shall have and keep the sole right to file patent applications or any other kind of intellectual property protection in
connection with such information.
Nothing herein shall be construed as implying or granting to you any rights, by license, grant or otherwise, under any
intellectual and/or industrial property rights of or concerning any of Gemalto’s information.
This document can be used for informational, non-commercial, internal and personal use only provided that:
• The copyright notice below, the confidentiality and proprietary legend and this full warning notice appear in all copies.
• This document shall not be posted on any network computer or broadcast in any media and no modification of any part of
this document shall be made.
Use for any other purpose is expressly prohibited and may result in severe civil and criminal liabilities.
The information contained in this document is provided “AS IS” without any warranty of any kind. Unless otherwise expressly
agreed in writing, Gemalto makes no warranty as to the value or accuracy of information contained herein.
The document could include technical inaccuracies or typographical errors. Changes are periodically added to the information
herein. Furthermore, Gemalto reserves the right to make any change or improvement in the specifications data, information,
and the like described herein, at any time.
Gemalto hereby disclaims all warranties and conditions with regard to the information contained herein, including all
implied warranties of merchantability, fitness for a particular purpose, title and non-infringement. In no event shall
Gemalto be liable, whether in contract, tort or otherwise, for any indirect, special or consequential damages or any
damages whatsoever including but not limited to damages resulting from loss of use, data, profits, revenues, or
customers, arising out of or in connection with the use or performance of information contained in this document.
Gemalto does not and shall not warrant that this product will be resistant to all possible attacks and shall not incur,
and disclaims, any liability in this respect. Even if each product is compliant with current security standards in force
on the date of their design, security mechanisms' resistance necessarily evolves according to the state of the art in
security and notably under the emergence of new attacks. Under no circumstances, shall Gemalto be held liable for
any third party actions and in particular in case of any successful attack against systems or equipment
incorporating Gemalto products. Gemalto disclaims any liability with respect to security for direct, indirect,
incidental or consequential damages that result from any use of its products. It is further stressed that independent
testing and verification by the person using the product is particularly encouraged, especially in any application in
which defective, incorrect or insecure functioning could result in damage to persons or property, denial of service or
loss of privacy.
© Copyright 2008 Gemalto N.V. All rights reserved. Gemalto and the Gemalto logo are trademarks and service marks of
Gemalto N.V. and/or its subsidiaries and are registered in certain countries. All other trademarks and service marks, whether
registered or not in specific countries, are the property of their respective owners.
GEMALTO, B.P. 100, 13881 GEMENOS CEDEX, FRANCE.
Tel: +33 (0)[Link].00 Fax: +33 (0)[Link].90
[Link]
Contents
Introduction v
Classic Client . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . v
Who Should Read This Book . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . v
Documentation . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . v
Conventions . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . vi
Typographical Conventions . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . vi
Additional Resources . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . vi
Contact Our Hotline . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . vi
Chapter 1 Installation 1
System Requirements . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 1
Computer . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 1
Operating Systems . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 1
Applications . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 2
Peripherals . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 2
Installing Classic Client 5.1 for Linux . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 3
Installing the Classic Client 5.1 for Linux Software . . . . . . . . . . . . . . . . . . . . . . . . 3
Connecting the Smart Card Reader . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 4
Configuring Gemalto Cryptographic Security Modules . . . . . . . . . . . . . . . . . . . . . 4
Chapter 3 Tasks 13
How to Get a Certificate . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 13
How to Use E-mail Securely . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 14
About Secure E-mail . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 14
Working with Mozilla Thunderbird or Icedove. . . . . . . . . . . . . . . . . . . . . . . . . . . 15
How to View Secure Web Sites . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 21
Choosing a Certificate Used to View Web Sites . . . . . . . . . . . . . . . . . . . . . . . . . 21
Terminology 43
Abbreviations . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 43
Glossary . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 44
List of Figures
Figure 1 - Encryption Tab in Advanced Dialog . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 4
Figure 2 - Device Manager . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 5
Figure 3 - The Load PKCS#11 Device Dialog Box . . . . . . . . . . . . . . . . . . . . . . . . . . . 5
Figure 4 - Confirm Dialog . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 5
Figure 5 - Alert Dialog . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 6
Figure 6 - Cryptographic Modules Available . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 6
Figure 7 - Selecting a Smart Card Reader for the PIN Management Tool . . . . . . . . . 9
Figure 8 - Classic Client PIN Management - Change PIN Function . . . . . . . . . . . . . . 9
Figure 9 - Classic Client PIN Management - Unblock PIN Function . . . . . . . . . . . . . 11
Figure 10 - Classic Client PIN Management - Remote Unblock PIN Function . . . . . 11
Figure 11 - Remote Unblock PIN - Information for Help Desk . . . . . . . . . . . . . . . . . . 12
Figure 12 - Icedove - Certificates Tab . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 15
Figure 13 - Icedove – Encrypt This Message . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 16
Figure 14 - Icedove – Security Account Settings . . . . . . . . . . . . . . . . . . . . . . . . . . . . 17
Figure 15 - Icedove - Enter Password . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 17
Figure 16 - Icedove - Details of Selected Certificate . . . . . . . . . . . . . . . . . . . . . . . . . 17
Figure 17 - Icedove – “Use Same Certificate” Message . . . . . . . . . . . . . . . . . . . . . . 18
Figure 18 - Icedove – Security Account Settings (2) . . . . . . . . . . . . . . . . . . . . . . . . . 18
Figure 19 - Icedove New Msg Composition Window . . . . . . . . . . . . . . . . . . . . . . . . . 19
Figure 20 - Icedove Message Security Info Window . . . . . . . . . . . . . . . . . . . . . . . . . 20
Figure 21 - Mozilla Firefox Options Dialog . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 21
Figure 22 - Password Required . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 22
Figure 23 - Certificate Manager Window . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 22
Introduction
Welcome to Gemalto Classic Client for Linux.
You have made a wise investment by purchasing Classic Client as a safeguard for
secure network services.
This chapter presents an overview of Classic Client, the documentation provided with
it, and additional resources available for working with Classic Client.
Classic Client
Classic Client is for individual users, who want to use a smart card/token to protect
information and transactions made via computers, including stand-alone workstations
and Citrix client-server environments.
Note: A token is in fact a smart card embedded in a device that can be plugged into
the USB port of a PC. In this document, “connecting a device” can mean inserting a
card in a reader or PC or plugging a token in the USB port of a PC.
With Classic Client you can use a digital certificate stored on a smart card/token to:
■ Sign electronic documents.
■ Open and verify signed documents.
■ Send and receive secure e-mail using Mozilla e-mail software.
■ Connect securely with a Web server.
Classic Client also includes features for managing certificates and smart card/token
security.
This guide introduces you to Classic Client and provides easy-to-follow instructions.
Read the entire guide for assistance in the installation, configuration, and use of
Classic Client.
Documentation
Classic Client is delivered with the following documentation:
■ Classic Client 5.1 for Linux (this document). The file for this document is located on
the Classic Client 5.1 CD and in the Classic Client installation folder.
■ A Readme file. This contains any relevant information about the installation and the
complete version history.
vi Introduction
This document is best viewed with Adobe Acrobat Reader, version 7.0 or later. You
can download Adobe Acrobat Reader from Adobe’s Web site at: [Link].
Conventions
The following conventions are used in this document:
Typographical Conventions
Classic Client documentation uses the following typographical conventions to assist
the reader of this document.
> Select File > Open Indicates a menu selection. In this example you are
instructed to select the “Open” option from the
“File” menu.
Note: Example screen shots of the Classic Client for Linux software are provided
throughout this document to illustrate the various procedures and descriptions. These
screen shots were produced with Classic Client running on Debian.
Additional Resources
For further information or more detailed use of Classic Client, additional resources and
documentation are available by contacting Gemalto technical support.
This chapter discusses information related to the installation of Classic Client 5.1 for
Linux.
The installation requirements are outlined below.
This chapter describes:
■ The hardware and software you need to use Classic Client 5.1 for Linux.
■ How to install Classic Client 5.1 on your computer.
System Requirements
The following sections describe the hardware, operating systems, peripherals and
software you need to use Classic Client 5.1. You must have administrator rights to the
computer on which you are installing Classic Client.
Computer
The workstation must have at least 15 MB of available hard disk space and meet the
normal system requirements to run the version of Linux installed.
Operating Systems
Classic Client for Linux supports the following operating systems:
■ Debian Etch
■ RHEL 5 (Red Hat Enterprise Linux)
Gemalto recommends that your machine has a RAM at least equal to that normally
recommended for the OS. If this RAM requirement is met, Classic Client for Linux
should run normally.
2 Installation
Applications
Classic Client 5.1 is compliant with:
Browsers
To view secure Web sites from your computer with Classic Client 5.1 for Linux, you can
use any of the following Web browsers:
■ Mozilla Firefox version 2.0/3.0
You can download the latest version, free of charge, from [Link].
■ Iceweasel (Iceweasel is the Debian version of Firefox)
You can download the latest version, free of charge, from various sites on the
internet. Further information is available in [Link]
■ Netscape Navigator 9
You can download the latest version, free of charge, from
[Link]
E-mail Applications
Classic Client 5.1. supports Mozilla Thunderbird version 2.0.
Note: You can download the latest version of Thunderbird, free of charge, from
[Link].
Peripherals
Classic Client 5.1 for Linux requires the following peripherals:
■ A CD ROM drive.
■ An available USB port.
Smart Cards
Gemalto has recently renamed many of its products. “Table 1” gives the full list of smart
cards supported by Classic Client and gives their previous names.
Note: The cards actually supported by your Classic Client for Linux, depends on the
package you have bought. For example, one package supports cards with the Classic
Applet V1 only, another supports cards with Classic Applet V2 or Classic Applet V3
Classic TPC IXS (Classic Applet V1) GemSafeXpresso 16K (GemSafe v1.11 applet)
Classic TPC IS (Classic Applet V1) GemSafeXpresso 32K (GemSafe v1.11 applet)
Caution: Before installing the software make sure that your system has the latest
version of the PC/SC Lite and CCID drivers.
Note: You can do this without going to the installation directory first, but if you do, you
must type the full path for the file name.
Note: The screen shots in this section were taken on a PC running the Debian OS. In
Debian, the Firefox browser is called Iceweasel, and its appearance is slightly different
although its functionality is the same.
3 Click Security Devices to display the Device Manager window. This displays the
modules currently available as shown in “Figure 2” on page 5.
Installation 5
4 Click the Load button to the right in the dialog. This displays the Load PKCS#11
Device window, as shown in “Figure 3”.
8 Click OK.
A brief progress dialog appears indicating that the module is being loaded.
6 Installation
When this is completed the following Alert indicates that the module has been
installed.
This chapter discusses the Classic Client PIN Management tool, the dedicated tool for
managing PINs and the tasks it can be used to perform.
About PINs
PIN Types
Classic Client recognizes two types of PIN that may be in a smart card/token:
■ Admin PIN – the PIN that is necessary to unblock the card/token (for example after
too many consecutive incorrect presentations of the User PIN).
■ User PIN – the standard PIN used by a user to access the card/token.
Caution: Once an administration PIN has been entered incorrectly the requisite
number of times, it becomes blocked and the card/token can never be used again.
The original Admin PIN value of a smart card/token is included in the packaging of the
card/token. If you are an administrator you may want to change the Admin PIN value of
the cards/tokens you deploy so that only you, the administrator, knows it.
8 PIN Management
Caution: Do not allow the User PIN for your card/token to be blocked. If, for example,
you forget the user PIN and enter a predetermined number of failed validation
attempts (the PIN is entered incorrectly), the card/token becomes blocked and you
cannot perform any further security operations with it. If you know the Admin PIN you
can unblock your card/token as described in “How to Unblock a User PIN” on page 10.
However most companies’ security policy does not allow this, in which case you must
ask your Classic Client system administrator to unblock the card/token using the
Administrator PIN. If you have the necessary rights, you may be able to unblock your
card/token remotely. This operation is described in “How to Remotely Unblock a
Connected Smart Card/Token” on page 11. Sometimes card/token technology or
software on-board the card/token limits the absolute number of these unblocking
operations. For more information, see your card/token technology documentation.
Figure 7 - Selecting a Smart Card Reader for the PIN Management Tool
This opens the Classic Client PIN Management Window as shown in “Figure 8”.
To change a PIN
1 Connect the smart card/token whose Admin PIN or User PIN you want to change to
the PC.
2 Open the PIN Management window as described in “How to Access the Classic
Client PIN Management Tool” on page 9.
3 If it is not already selected, click Change PIN at the top of the window (see “Figure
8” on page 9).
4 Select the PIN whose value you want to change from the list, Admin PIN or User
PIN.
5 Enter the current value of the PIN in Old PIN Code, and the new value in New PIN
Code and again in Confirm PIN Code.
6 Click the Apply button at the bottom of the window. A pop-up window appears to
confirm a successful PIN change or to display an error message if unsuccessful.
If you know the Admin PIN for your card/token, you can unblock your User PIN by
using the Classic Client PIN Management tool.
In most cases, if you are not an administrator you will not know the Admin PIN – it
depends on your company’s security policy. In such cases, there are two possibilities;
■ The administrator must unblock the smart card/token for you. You must return the
smart card/token to the administrator so he or she can unblock it on his or her PC.
■ If you have been given the necessary rights, you can unblock your PIN remotely as
described in “How to Remotely Unblock a Connected Smart Card/Token” on
page 11.
4 Enter the Admin PIN in Admin PIN Code, and the new value for the User PIN in
New User PIN Code and again in Confirm User PIN.
5 For security reasons, Gemalto recommends that you check the box Force user to
change PIN. This is particularly useful if the user whose PIN is being unblocked is
not the administrator (as in most cases).
6 Click the Apply button at the bottom of the window. A pop-up window appears to
confirm a successful Unblock PIN operation or to display an error message if
unsuccessful.
4 Click Generate Info. If this button does not appear in the window, you do not have
the rights necessary to unblock your User PIN remotely. A window like the one
shown in “Figure 11” on page 12 appears.
12 PIN Management
5 Call your administrator or Help Desk at the number given in the window, and tell
him or her the CSN and Random Number that appear in the window. Click Close to
close the window.
6 The administrator or Help Desk will provide you with an encrypted value of the
Admin PIN. Enter this in Admin PIN Code.
7 Enter the new value for your User PIN in New User PIN Code and again in
Confirm User PIN.
8 Click Apply. A pop-up window appears to confirm a successful Unblock PIN
operation or to display an error message if unsuccessful.
3
Tasks
This chapter discusses information related to specific tasks that you will most often be
required to carry out when using the Classic Client 5.1 for Linux software and where to
find the information about them.
These tasks are:
■ “How to Get a Certificate” on this page.
■ “How to Use E-mail Securely” on page 14
■ “How to View Secure Web Sites” on page 21
Tasks concerning PINs are described in “Chapter 2 - PIN Management”.
Tips
When you request a certificate, you will be asked to enter information about yourself
such as your name, e-mail address, and the type of certificate you want. The type of
information required depends upon what organization is issuing the certificate, and
may include the following:
■ Key length value. The default value is 1024. Classic Client also supports 2048–bit
keys, though this ability may be restricted by the card/token used.
■ Cryptographic Module (sometimes referred to as security device). You will need
this if requesting a certificate using Mozilla Firefox or Netscape Navigator.
You must give the correct name, which is Classic Smart Card. If you give a
different name, your certificate will be stored on your hard drive instead of your
smart card/token.
14 Tasks
6 The rest of the procedure is the same as that described for Firefox. Continue from
step 3 on page 4.
This new module will be used with all e-mail you send with Thunderbird or Icedove.
16 Tasks
Note: Although selecting the certificates is mandatory, this does not mean that you
must sign and encrypt e-mails.
As the certificates in the card/token are not yet set up, the following message
appears:
6 Click Yes. This opens the security account settings window for your e-mail account
as shown in “Figure 14” on page 17.
Tasks 17
7 In Digital Signing, click Select and choose the certificate you want to use from the
list that appears.
Note: You may be prompted to enter a “master password” as shown in “Figure 15”. If
so, enter the PIN for the card and click OK.
9 If you want to use the same certificate to encrypt and decrypt messages, click OK.
This selects the certificate for you in the Encryption panel as shown in “Figure 18”.
Otherwise click Cancel.
10 If you want all of your e-mails to be digitally signed by default, check the box
Digitally sign messages (by default).
11 In Encryption, if you chose not to use the same certificate as the one used for
digital signing, click Select and choose the certificate from the list that appears. A
message similar to the one in “Figure 17” on page 18 appears, but this time asking
if you want to use the Encryption certificate for digital signing. This is just in case
you select your encryption certificate before you select your digital signature
certificate.
12 In Default encryption setting when sending messages, choose one of the
option buttons Never or Required.
13 Click OK to close the Security Account Settings window.
Note: If you want to modify the account settings at any point, open the Account
Settings window from the Tools menu by choosing Account Settings. This can be
done either from the Compose window or directly in Thunderbird or Icedove.
Tasks 19
6 From the Options menu in the Compose window choose Security > Digitally
Sign this Message in order to sign the message.
Note: You can check the security settings for your message in the Compose window
by choosing View > Message Security Info. This displays the Message Security
Info window as shown in “Figure 20” on page 20.
20 Tasks
Note: All secure Web site addresses must begin with [Link] Browsers display a lock
icon at the bottom of the browser window indicating that the site is secure. A closed
lock indicates that you are operating in secure mode. You may need to configure your
organization’s network to allow secure browsing.
When you connect to a secure Web site, your certificate must be specified in your
browser so that you can authenticate yourself to the Web server. For example, when
you bank online, your bank must be sure that you are the correct person to get account
information. Your certificate confirms your identity to the online bank.
The following sections explain how to check that your certificates are correctly
registered in your browsers when authenticating with secure web sites using Mozilla
Firefox (or the Debian equivalent Iceweasel) and Netscape.
5 In Certificates, choose one of the options for the action to take when a web site
requires a certificate:
– Select one automatically
– Ask me every time
6 To display the certificates that are on your card/token, click View Certificates. You
will be prompted for a password as shown in “Figure 22”.
8 Under Your Certificates appears the certificates that are stored on the card/token.
To display the properties of a particular certificate, select it and click View.
A
Security Basics
This chapter introduces you to the IT security standards integral to Classic Client.
Cryptography
Communicating and conducting business electronically is quickly becoming the most
convenient, effective means of transaction. An essential condition for the continued
growth toward an electronic market is security. The identities of both corporations and
individuals must be authentic. The integrity and privacy of information must be
guaranteed.
Encryption/decryption enables you to send and receive secure e-mail and documents
to protect confidential or private information. You can use the signature function to sign
your messages. By signing messages, you can prove to the recipient that you are who
you claim to be.
The IT industry uses cryptography to render information secret and known only by
authorized entities.
There are two types of cryptography:
■ Secret Key Cryptography.
■ Public Key Cryptography
Both cryptographic systems use keys to digitally sign or encrypt/decrypt data. A key is
a value in electronic format used to perform cryptographic functions on electronic data.
The differences between secret key and public key cryptography include:
■ Key management.
■ Complexity of the key structure.
Key management is central to having a successful crypto system. If keys are not
managed in a secure environment, the overall security of the crypto system is at risk.
Keys must also be convenient to use.
The complexity of a key length is determined by the degree of mathematical properties
applied to the random numbers that comprise the key.
24 Security Basics
What is S/MIME?
Secure/Multipurpose Internet Mail Extensions (S/MIME) is an open protocol standard,
that provides encryption and digital signature functionality to Internet e-mail. S/MIME
uses public key cryptography standards to define e-mail security services.
S/MIME enables you to encrypt and digitally sign Internet e-mail using Web messaging
applications such as Mozilla Thunderbird. S/MIME also enables you to authenticate
incoming messages.
S/MIME provides the following security functions:
■ Sender Authentication to verify the sender's identity. By reading the sender's
digital signature, the recipient can see who signed the message and view the
certificate for additional details.
■ Message Encryption to ensure that your messages remain private. Mozilla
Thunderbird supports domestic and export-level public key and secret key
encryption.
■ Data Integrity to guard against unauthorized manipulation of messages. S/MIME
uses a secure hashing function to detect message tampering.
■ Inter-operability to work with other S/MIME-compliant software.
What is SSL?
Secure Sockets Layer (SSL), developed by Netscape Communications, is a standard
security protocol that provides security and privacy on the Web. The protocol allows
client/server applications to communicate securely. SSL uses both public and secret
key cryptography.
The SSL protocol is application independent, which enables higher-level protocols
such as Hyper Text Transfer Protocol (HTTP) to be layered on top of it transparently.
Therefore, the client can negotiate encryption and authentication with the server before
data is exchanged by the higher-level application.
The SSL Handshake Protocol process includes two phases:
■ Server Authentication in which the client requests the server's certificate. In
response, the server returns its digital certificate and signature to the client. The
server certificate provides the server's public key. The signature proves that the
server currently has the private key corresponding to the certificate.
■ Client Authentication (optional) in which the server requests the client's
certificate. In response, the client sends the digital certificate and signature to the
server. If the SSL Server requests it, the client is prompted to enter a PIN to visit a
secure Web site.
Security Basics 27
The SSL process is repeated for every secure session you attempt to establish unless
you specify a permanent session. The SSL process will not proceed if the Web server's
certificate is expired.
Note: In some instances, the SSL Handshake takes place between the Web server
and the browser and does not require the client’s certificate.
1 Redistributions of source code must retain the above copyright notice, this list of
conditions and the following disclaimer.
2 Redistributions in binary form must reproduce the above copyright notice, this list of
conditions and the following disclaimer in the documentation and/or other materials
provided with the distribution.
3 The name of the author may not be used to endorse or promote products derived
from this software without specific prior written permission.
Changes to this license can be made only by the copyright author with explicit
written consent.
THIS SOFTWARE IS PROVIDED BY THE AUTHOR ``AS IS'' AND ANY
EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO,
THE IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A
PARTICULAR PURPOSE ARE DISCLAIMED.
IN NO EVENT SHALL THE AUTHOR BE LIABLE FOR ANY DIRECT, INDIRECT,
INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL DAMAGES
(INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE
GOODS OR SERVICES; LOSS OF USE, DATA, OR PROFITS; OR BUSINESS
INTERRUPTION) HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY,
WHETHER IN CONTRACT, STRICT LIABILITY, OR TORT (INCLUDING
NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY OUT OF THE USE OF
THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF SUCH
DAMAGE.
=============================================
This product contains code from OpenSC
[Link]
The files from OpenSC are:
./src/libopensc/asn1.c
./src/libopensc/asn1.h
./src/libopensc/card.c
./src/libopensc/cards.h
./src/libopensc/dir.c
./src/libopensc/errors.c
./src/libopensc/errors.h
./src/libopensc/internal.h
./src/libopensc/log.c
./src/libopensc/log.h
./src/libopensc/opensc.h
./src/libopensc/padding.c
./src/libopensc/pkcs15.c
./src/libopensc/pkcs15.h
./src/libopensc/pkcs15-algo.c
./src/libopensc/pkcs15-cache.c
./src/libopensc/pkcs15-cert.c
./src/libopensc/pkcs15-data.c
./src/libopensc/pkcs15-pin.c
34 End User License Agreement
./src/libopensc/pkcs15-prkey.c
./src/libopensc/pkcs15-pubkey.c
./src/libopensc/pkcs15-syn.c
./src/libopensc/pkcs15-wrap.c
./src/libopensc/sc.c
./src/libopensc/sec.c
./src/libopensc/types.h
./src/libopensc/ui.h
./src/scconf/scconf.c
./src/scconf/scconf.h
Preamble
The licenses for most software are designed to take away your freedom to share and
change it. By contrast, the GNU General Public Licenses are intended to guarantee
your freedom to share and change free software--to make sure the software is free for
all its users.
This license, the Lesser General Public License, applies to some specially designated
software packages--typically libraries--of the Free Software Foundation and other
authors who decide to use it. You can use it too, but we suggest you first think carefully
about whether this license or the ordinary General Public License is the better strategy
to use in any particular case, based on the explanations below.
When we speak of free software, we are referring to freedom of use, not price. Our
General Public Licenses are designed to make sure that you have the freedom to
distribute copies of free software (and charge for this service if you wish); that you
receive source code or can get it if you want it; that you can change the software and
use pieces of it in new free programs; and that you are informed that you can do these
things.
To protect your rights, we need to make restrictions that forbid distributors to deny you
these rights or to ask you to surrender these rights. These restrictions translate to
certain responsibilities for you if you distribute copies of the library or if you modify it.
End User License Agreement 35
For example, if you distribute copies of the library, whether gratis or for a fee, you must
give the recipients all the rights that we gave you. You must make sure that they, too,
receive or can get the source code. If you link other code with the library, you must
provide complete object files to the recipients, so that they can relink them with the
library after making changes to the library and recompiling it. And you must show them
these terms so they know their rights.
We protect your rights with a two-step method: (1) we copyright the library, and (2) we
offer you this license, which gives you legal permission to copy, distribute and/or
modify the library.
To protect each distributor, we want to make it very clear that there is no warranty for
the free library. Also, if the library is modified by someone else and passed on, the
recipients should know that what they have is not the original version, so that the
original author's reputation will not be affected by problems that might be introduced by
others.
Finally, software patents pose a constant threat to the existence of any free program.
We wish to make sure that a company cannot effectively restrict the users of a free
program by obtaining a restrictive license from a patent holder. Therefore, we insist
that any patent license obtained for a version of the library must be consistent with the
full freedom of use specified in this license.
Most GNU software, including some libraries, is covered by the ordinary GNU General
Public License. This license, the GNU Lesser General Public License, applies to
certain designated libraries, and is quite different from the ordinary General Public
License. We use this license for certain libraries in order to permit linking those
libraries into non-free programs.
When a program is linked with a library, whether statically or using a shared library, the
combination of the two is legally speaking a combined work, a derivative of the original
library. The ordinary General Public License therefore permits such linking only if the
entire combination fits its criteria of freedom. The Lesser General Public License
permits more lax criteria for linking other code with the library.
We call this license the “Lesser” General Public License because it does Less to
protect the user's freedom than the ordinary General Public License. It also provides
other free software developers Less of an advantage over competing non-free
programs. These disadvantages are the reason we use the ordinary General Public
License for many libraries. However, the Lesser license provides advantages in
certain special circumstances.
For example, on rare occasions, there may be a special need to encourage the widest
possible use of a certain library, so that it becomes a de-facto standard. To achieve
this, non-free programs must be allowed to use the library. A more frequent case is
that a free library does the same job as widely used non-free libraries. In this case,
there is little to gain by limiting the free library to free software only, so we use the
Lesser General Public License.
36 End User License Agreement
Although the Lesser General Public License is Less protective of the users' freedom, it
does ensure that the user of a program that is linked with the Library has the freedom
and the wherewithal to run that program using a modified version of the Library.
The precise terms and conditions for copying, distribution and modification follow. Pay
close attention to the difference between a “work based on the library” and a “work that
uses the library”. The former contains code derived from the library, whereas the latter
must be combined with the library in order to run.
This License Agreement applies to any software library or other program which
contains a notice placed by the copyright holder or other authorized party saying it
may be distributed under the terms of this Lesser General Public License (also
called “this License”).
Each licensee is addressed as “you”.
A “library” means a collection of software functions and/or data prepared so as to
be conveniently linked with application programs (which use some of those
functions and data) to form executables.
The “Library”, below, refers to any such software library or work which has been
distributed under these terms. A “work based on the Library” means either the
Library or any derivative work under copyright law: that is to say, a work containing
the Library or a portion of it, either verbatim or with modifications and/or translated
straightforwardly into another language. (Hereinafter, translation is included
without limitation in the term “modification”.)
“Source code” for a work means the preferred form of the work for making
modifications to it. For a library, complete source code means all the source code
for all modules it contains, plus any associated interface definition files, plus the
scripts used to control compilation and installation of the library.
Activities other than copying, distribution and modification are not covered by this
License; they are outside its scope. The act of running a program using the Library
is not restricted, and output from such a program is covered only if its contents
constitute a work based on the Library (independent of the use of the Library in a
tool for writing it). Whether that is true depends on what the Library does and what
the program that uses the Library does.
1 You may copy and distribute verbatim copies of the Library's complete source code
as you receive it, in any medium, provided that you conspicuously and
appropriately publish on each copy an appropriate copyright notice and disclaimer
of warranty; keep intact all the notices that refer to this License and to the absence
of any warranty; and distribute a copy of this License along with the Library.
End User License Agreement 37
You may charge a fee for the physical act of transferring a copy, and you may at
your option offer warranty protection in exchange for a fee.
2 You may modify your copy or copies of the Library or any portion of it, thus forming
a work based on the Library, and copy and distribute such modifications or work
under the terms of Section 1 above, provided that you also meet all of these
conditions:
a) The modified work must itself be a software library.
b) You must cause the files modified to carry prominent notices stating that you
changed the files and the date of any change.
c) You must cause the whole of the work to be licensed at no charge to all third
parties under the terms of this License.
d) If a facility in the modified Library refers to a function or a table of data to be
supplied by an application program that uses the facility, other than as an
argument passed when the facility is invoked, then you must make a good faith
effort to ensure that, in the event an application does not supply such function
or table, the facility still operates, and performs whatever part of its purpose
remains meaningful.
(For example, a function in a library to compute square roots has a purpose that is
entirely well-defined independent of the application. Therefore, Subsection 2d
requires that any application-supplied function or table used by this function must
be optional: if the application does not supply it, the square root function must still
compute square roots.)
These requirements apply to the modified work as a whole. If identifiable sections
of that work are not derived from the Library, and can be reasonably considered
independent and separate works in themselves, then this License, and its terms, do
not apply to those sections when you distribute them as separate works. But when
you distribute the same sections as part of a whole which is a work based on the
Library, the distribution of the whole must be on the terms of this License, whose
permissions for other licensees extend to the entire whole, and thus to each and
every part regardless of who wrote it.
Thus, it is not the intent of this section to claim rights or contest your rights to work
written entirely by you; rather, the intent is to exercise the right to control the
distribution of derivative or collective works based on the Library.
In addition, mere aggregation of another work not based on the Library with the
Library (or with a work based on the Library) on a volume of a storage or
distribution medium does not bring the other work under the scope of this License.
3 You may opt to apply the terms of the ordinary GNU General Public License
instead of this License to a given copy of the Library. To do this, you must alter all
the notices that refer to this License, so that they refer to the ordinary GNU General
Public License, version 2, instead of to this License. (If a newer version than
version 2 of the ordinary GNU General Public License has appeared, then you can
specify that version instead if you wish.) Do not make any other change in these
notices.
Once this change is made in a given copy, it is irreversible for that copy, so the
ordinary GNU General Public License applies to all subsequent copies and
derivative works made from that copy.
This option is useful when you wish to copy part of the code of the Library into a
program that is not a library.
4 You may copy and distribute the Library (or a portion or derivative of it, under
Section 2) in object code or executable form under the terms of Sections 1 and 2
above provided that you accompany it with the complete corresponding machine-
38 End User License Agreement
readable source code, which must be distributed under the terms of Sections 1 and
2 above on a medium customarily used for software interchange.
If distribution of object code is made by offering access to copy from a designated
place, then offering equivalent access to copy the source code from the same
place satisfies the requirement to distribute the source code, even though third
parties are not compelled to copy the source along with the object code.
5 A program that contains no derivative of any portion of the Library, but is designed
to work with the Library by being compiled or linked with it, is called a “work that
uses the Library”. Such a work, in isolation, is not a derivative work of the Library,
and therefore falls outside the scope of this License.
However, linking a “work that uses the Library” with the Library creates an
executable that is a derivative of the Library (because it contains portions of the
Library), rather than a “work that uses the library”. The executable is therefore
covered by this License.
Section 6 states terms for distribution of such executables.
When a “work that uses the Library” uses material from a header file that is part of
the Library, the object code for the work may be a derivative work of the Library
even though the source code is not.
Whether this is true is especially significant if the work can be linked without the
Library, or if the work is itself a library. The threshold for this to be true is not
precisely defined by law.
If such an object file uses only numerical parameters, data structure layouts and
accessors, and small macros and small inline functions (ten lines or less in length),
then the use of the object file is unrestricted, regardless of whether it is legally a
derivative work. (Executables containing this object code plus portions of the
Library will still fall under Section 6.)
Otherwise, if the work is a derivative of the Library, you may distribute the object
code for the work under the terms of Section 6.
Any executables containing that work also fall under Section 6, whether or not they
are linked directly with the Library itself.
6 As an exception to the Sections above, you may also combine or link a “work that
uses the Library” with the Library to produce a work containing portions of the
Library, and distribute that work under terms of your choice, provided that the terms
permit modification of the work for the customer's own use and reverse engineering
for debugging such modifications.
You must give prominent notice with each copy of the work that the Library is used
in it and that the Library and its use are covered by this License. You must supply
a copy of this License. If the work during execution displays copyright notices, you
must include the copyright notice for the Library among them, as well as a
reference directing the user to the copy of this License. Also, you must do one of
these things:
a) Accompany the work with the complete corresponding machine-readable
source code for the Library including whatever changes were used in the work
(which must be distributed under Sections 1 and 2 above); and, if the work is an
executable linked with the Library, with the complete machine-readable “work
that uses the Library”, as object code and/or source code, so that the user can
modify the Library and then relink to produce a modified executable containing
the modified Library. (It is understood that the user who changes the contents
of definitions files in the Library will not necessarily be able to recompile the
application to use the modified definitions.)
End User License Agreement 39
b) Use a suitable shared library mechanism for linking with the Library. A suitable
mechanism is one that (1) uses at run time a copy of the library already present
on the user's computer system, rather than copying library functions into the
executable, and (2) will operate properly with a modified version of the library, if
the user installs one, as long as the modified version is interface-compatible
with the version that the work was made with.
c) Accompany the work with a written offer, valid for at least three years, to give
the same user the materials specified in Subsection 6a, above, for a charge no
more than the cost of performing this distribution.
d) If distribution of the work is made by offering access to copy from a designated
place, offer equivalent access to copy the above specified materials from the
same place.
e) Verify that the user has already received a copy of these materials or that you
have already sent this user a copy.
For an executable, the required form of the “work that uses the Library” must
include any data and utility programs needed for reproducing the executable from
it. However, as a special exception, the materials to be distributed need not include
anything that is normally distributed (in either source or binary form) with the major
components (compiler, kernel, and so on) of the operating system on which the
executable runs, unless that component itself accompanies the executable.
It may happen that this requirement contradicts the license restrictions of other
proprietary libraries that do not normally accompany the operating system. Such a
contradiction means you cannot use both them and the Library together in an
executable that you distribute.
7 You may place library facilities that are a work based on the Library side-by-side in
a single library together with other library facilities not covered by this License, and
distribute such a combined library, provided that the separate distribution of the
work based on the Library and of the other library facilities is otherwise permitted,
and provided that you do these two things:
a) Accompany the combined library with a copy of the same work based on the
Library, uncombined with any other library facilities. This must be distributed
under the terms of the Sections above.
b) Give prominent notice with the combined library of the fact that part of it is a
work based on the Library, and explaining where to find the accompanying
uncombined form of the same work.
8 You may not copy, modify, sublicense, link with, or distribute the Library except as
expressly provided under this License. Any attempt otherwise to copy, modify,
sublicense, link with, or distribute the Library is void, and will automatically
terminate your rights under this License. However, parties who have received
copies, or rights, from you under this License will not have their licenses terminated
so long as such parties remain in full compliance.
9 You are not required to accept this License, since you have not signed it. However,
nothing else grants you permission to modify or distribute the Library or its
derivative works. These actions are prohibited by law if you do not accept this
License. Therefore, by modifying or distributing the Library (or any work based on
the Library), you indicate your acceptance of this License to do so, and all its terms
and conditions for copying, distributing or modifying the Library or works based on
it.
10 Each time you redistribute the Library (or any work based on the Library), the
recipient automatically receives a license from the original licensor to copy,
distribute, link with or modify the Library subject to these terms and conditions. You
40 End User License Agreement
may not impose any further restrictions on the recipients' exercise of the rights
granted herein.
You are not responsible for enforcing compliance by third parties with this License.
11 If, as a consequence of a court judgment or allegation of patent infringement or for
any other reason (not limited to patent issues), conditions are imposed on you
(whether by court order, agreement or otherwise) that contradict the conditions of
this License, they do not excuse you from the conditions of this License. If you
cannot distribute so as to satisfy simultaneously your obligations under this License
and any other pertinent obligations, then as a consequence you may not distribute
the Library at all. For example, if a patent license would not permit royalty-free
redistribution of the Library by all those who receive copies directly or indirectly
through you, then the only way you could satisfy both it and this License would be
to refrain entirely from distribution of the Library.
If any portion of this section is held invalid or unenforceable under any particular
circumstance, the balance of the section is intended to apply, and the section as a
whole is intended to apply in other circumstances.
It is not the purpose of this section to induce you to infringe any patents or other
property right claims or to contest validity of any such claims; this section has the
sole purpose of protecting the integrity of the free software distribution system
which is implemented by public license practices. Many people have made
generous contributions to the wide range of software distributed through that
system in reliance on consistent application of that system; it is up to the author/
donor to decide if he or she is willing to distribute software through any other
system and a licensee cannot impose that choice.
This section is intended to make thoroughly clear what is believed to be a
consequence of the rest of this License.
12 If the distribution and/or use of the Library is restricted in certain countries either by
patents or by copyrighted interfaces, the original copyright holder who places the
Library under this License may add an explicit geographical distribution limitation
excluding those countries, so that distribution is permitted only in or among
countries not thus excluded. In such case, this License incorporates the limitation
as if written in the body of this License.
13 The Free Software Foundation may publish revised and/or new versions of the
Lesser General Public License from time to time.
Such new versions will be similar in spirit to the present version, but may differ in
detail to address new problems or concerns.
Each version is given a distinguishing version number. If the Library specifies a
version number of this License which applies to it and “any later version”, you have
the option of following the terms and conditions either of that version or of any later
version published by the Free Software Foundation. If the Library does not specify
a license version number, you may choose any version ever published by the Free
Software Foundation.
14 If you wish to incorporate parts of the Library into other free programs whose
distribution conditions are incompatible with these, write to the author to ask for
permission. For software which is copyrighted by the Free Software Foundation,
write to the Free Software Foundation; we sometimes make exceptions for this.
Our decision will be guided by the two goals of preserving the free status of all
derivatives of our free software and of promoting the sharing and reuse of software
generally.
NO WARRANTY
End User License Agreement 41
ID Identification
OS Operating System
Glossary
Certificate An entity with the authority and methods to certify the identity
Authority of one or more parties in an exchange (an essential function in
public key crypto systems).
Digital Signature A data string produced using a Public Key Crypto system to
prove the identity of the sender and the integrity of the
message.
Key Length The number of bits forming a key. The longer the key, the
more secure the encryption. Government regulations limit the
length of cryptographic keys.
Public Key Crypto A cryptographic system that uses two different keys (public
system and private) for encrypting data. The most well-known public
key algorithm is RSA.
SSL Handshake The SSL handshake, which takes place each time you start a
secure Web session, identifies the server. This is
automatically performed by your browser.