Smartcard help! GemPlus..

Smartcard help! GemPlus..

Secure Home | Search | About
 Microsoft Applications Security    Post an article   get this group's latest topics as an RSS feed add this group's latest topics to your My MSN content add this group's latest topics to your My Yahoo content add this group's latest topics to your Google content
Subject Author Date
Smartcard help! GemPlus.. UselessUser 04-15-2007
Posted by =?Utf-8?B?VXNlbGVzc1VzZXI=?= on April 15, 2007, 7:54 am
If you were  Registered and logged in, you could reply and use other advanced thread options
Hi all,

I am looking at trialling some smartcards primarily for logon but possibly
other users in the future, but it seems this is a very poorly documented area
(Even by the manufacturers)..

The two manufacturers I have been looking at are OmniKey and GemPlus.. I
have been reading that the GemSafe 32K Expresso cards do not seem to work
with the built in Microsoft GemPlus CSP v1.0 and that I need to obtain an
updated version from GemPlus... The only thing I have seen that offers this
is the GemPlus Libraries software??

What this actual software does seems to be extremely confusing... do I
actually need this software at all? It mentions securing email etc etc, but
surely I can do this with the Windows CA software?? In which case what is the
difference?

Also as it appears these cards need this software for the new CSP even if
not for anything else, do I need to buy licences for this software or is it
just purchase one cd?

If however this software is needed just to use the cards for logon etc why
can I not seem to find any Omnikey software?..

Please help extremely confused about this...

Posted by Brian Komar on April 15, 2007, 8:41 am
If you were  Registered and logged in, you could reply and use other advanced thread options
Answers inline...

On Sun, 15 Apr 2007 04:54:03 -0700, UselessUser wrote:

> Hi all,
>
> I am looking at trialling some smartcards primarily for logon but possibly
> other users in the future, but it seems this is a very poorly documented area
> (Even by the manufacturers)..
>
> The two manufacturers I have been looking at are OmniKey and GemPlus.. I
> have been reading that the GemSafe 32K Expresso cards do not seem to work
> with the built in Microsoft GemPlus CSP v1.0 and that I need to obtain an
> updated version from GemPlus... The only thing I have seen that offers this
> is the GemPlus Libraries software??

This is correct. You need to by the GemPlus Libraries software. As you
guess later in the thread, you must purchase one license per station where
the middleware is used.

Also, GemPlus merged with Axalto last year to form Gemalto. If you are
looking for smart cards that *just* work out of the box, start looking for
smart cards that support the Microsoft Smart Card Base CSP. The new smart
card base CSP implements a driver model similar to printers. There is a
base CSP and the vendors provide a mini-driver that provides details
regarding the specific vendor hardware.

- All vendors that are certified have their mini-drivers made available to
the community via Windows Update.
- Base Smart Card CSP is available for Windows XP through Windows Update
- Base Smart Card CSP is built in to Windows Vista
- GemAlto currently has cards available that use Base Smart Card CSP
(Axalto .NET cards)

>
> What this actual software does seems to be extremely confusing... do I
> actually need this software at all? It mentions securing email etc etc, but
> surely I can do this with the Windows CA software?? In which case what is the
> difference?

Their installer is kind of confusing. You use their admin software to
generate a "package" that only contains the items you feel you need at the
client stations. This package can then be distributed to all workstations.

>
> Also as it appears these cards need this software for the new CSP even if
> not for anything else, do I need to buy licences for this software or is it
> just purchase one cd?

One license per workstation

>
> If however this software is needed just to use the cards for logon etc why
> can I not seem to find any Omnikey software?..

Not sure where to look...
>
> Please help extremely confused about this...

Posted by =?Utf-8?B?VXNlbGVzc1VzZXI=?= on April 15, 2007, 10:38 am
If you were  Registered and logged in, you could reply and use other advanced thread options
Hi,

Thanks for the response, it certainly is helpful.. in all honesty you would
think these people would make this a tad easier to see... so just to clarify..

Is it true, that each vendor, GemAlto, OmniKey etc would need to provide
some kind of licensed software that needs to be purchased in relation to how
many machines use the software in order to use their product?

This product then basically hooks into Windows at various points (Logon,
Outlook etc) in order for them to make use of the card..?

These new .Net based systems instead allow Windows itself to create the hook
points, and the manufacturer simply supplies software (Free???) that informs
Windows of what the particular model can do?

Do these new .Net based systems require specific .Net card reader hardware,
or is it just the cards themselves that differ...?

Finally, after all that, is there any online store that I can purchase a
.Net reader (If necessary) and .Net cards for a trial?!

Thanks so much!

"Brian Komar" wrote:

> Answers inline...
>
> On Sun, 15 Apr 2007 04:54:03 -0700, UselessUser wrote:
>
> > Hi all,
> >
> > I am looking at trialling some smartcards primarily for logon but possibly
> > other users in the future, but it seems this is a very poorly documented
area
> > (Even by the manufacturers)..
> >
> > The two manufacturers I have been looking at are OmniKey and GemPlus.. I
> > have been reading that the GemSafe 32K Expresso cards do not seem to work
> > with the built in Microsoft GemPlus CSP v1.0 and that I need to obtain an
> > updated version from GemPlus... The only thing I have seen that offers this
> > is the GemPlus Libraries software??
>
> This is correct. You need to by the GemPlus Libraries software. As you
> guess later in the thread, you must purchase one license per station where
> the middleware is used.
>
> Also, GemPlus merged with Axalto last year to form Gemalto. If you are
> looking for smart cards that *just* work out of the box, start looking for
> smart cards that support the Microsoft Smart Card Base CSP. The new smart
> card base CSP implements a driver model similar to printers. There is a
> base CSP and the vendors provide a mini-driver that provides details
> regarding the specific vendor hardware.
>
> - All vendors that are certified have their mini-drivers made available to
> the community via Windows Update.
> - Base Smart Card CSP is available for Windows XP through Windows Update
> - Base Smart Card CSP is built in to Windows Vista
> - GemAlto currently has cards available that use Base Smart Card CSP
> (Axalto .NET cards)
>
> >
> > What this actual software does seems to be extremely confusing... do I
> > actually need this software at all? It mentions securing email etc etc, but
> > surely I can do this with the Windows CA software?? In which case what is
the
> > difference?
>
> Their installer is kind of confusing. You use their admin software to
> generate a "package" that only contains the items you feel you need at the
> client stations. This package can then be distributed to all workstations.
>
> >
> > Also as it appears these cards need this software for the new CSP even if
> > not for anything else, do I need to buy licences for this software or is it
> > just purchase one cd?
>
> One license per workstation
>
> >
> > If however this software is needed just to use the cards for logon etc why
> > can I not seem to find any Omnikey software?..
>
> Not sure where to look...
> >
> > Please help extremely confused about this...
>

Posted by Brian Komar on April 15, 2007, 12:06 pm
If you were  Registered and logged in, you could reply and use other advanced thread options
Some more answers and comments inline.

On Sun, 15 Apr 2007 07:38:02 -0700, UselessUser wrote:

> Hi,
>
> Thanks for the response, it certainly is helpful.. in all honesty you would
> think these people would make this a tad easier to see... so just to clarify..
>
> Is it true, that each vendor, GemAlto, OmniKey etc would need to provide
> some kind of licensed software that needs to be purchased in relation to how
> many machines use the software in order to use their product?
That is pretty much the case if you use smart cards that are *not* relying
on the Microsoft Base Smart Card CSP. In this case, you need to purchase
the middleware, CSP, and potentially PKCS#11 libraries (depending on your
application needs. These are typically bundled together and require 1
license per workstation where the software is installed.

>
> This product then basically hooks into Windows at various points (Logon,
> Outlook etc) in order for them to make use of the card..?
Yes

>
> These new .Net based systems instead allow Windows itself to create the hook
> points, and the manufacturer simply supplies software (Free???) that informs
> Windows of what the particular model can do?

First of all, they are not .NET cards, they are Microsoft Base Smart Card
CSP cards. The .Net branding is the name used by Axalto. They really have
nothing to do with Microsoft .NET. The only software provided by the vendor
is a mini-driver (sometimes referred to as a card module in earlier
documentation). To be certified, the mini-driver is sent in for evaluation.
Once certified, the mini-driver is made available through Windows Update.
But, some vendors may choose to not have their mini-driver evaluated. In
this case, you would need to acquire the mini-driver from the vendor.
>
> Do these new .Net based systems require specific .Net card reader hardware,
> or is it just the cards themselves that differ...?
No. This question is one of the most frequently asked. Let me answer it
with a question. If you have a Verbatim 1.44" Floppy drive, can you read it
in a Maxto floppy drive. Of course you can! The reader is simply a
reader/writer that follows standards. The only factor is that you must load
the necessary drivers for the reader at each workstation.
>
> Finally, after all that, is there any online store that I can purchase a
> .Net reader (If necessary) and .Net cards for a trial?!

The gemalto store Web site is
http://www.market.axalto.com/is-bin/INTERSHOP.enfinity/eCS/Store/en/-/-/Storefront-Start

>
> Thanks so much!
<snip>


Posted by Michael Meiners on May 13, 2007, 10:39 pm
If you were  Registered and logged in, you could reply and use other advanced thread options

. This package can then be distributed to all workstations.
>
>>
>> Also as it appears these cards need this software for the new CSP even if
>> not for anything else, do I need to buy licences for this software or is
>> it
>> just purchase one cd?
>
> One license per workstation
>
Sicrypt CSPs are already included in windows


Similar ThreadsPosted
smartcard , IE August 28, 2006, 9:52 am
SmartCard and Key Archival March 28, 2006, 9:41 am
ANN: Smartcard component for VS.NET May 26, 2006, 9:31 am
OCSP and smartcard logon October 21, 2005, 7:20 am
how to authenticate via IE with a smartcard certificate November 28, 2005, 5:42 pm
SmartCard logons to domain November 30, 2005, 9:17 am
Signing email using SmartCard CSP December 28, 2005, 6:56 am
DRA certificate on smartcard - vista May 1, 2007, 3:20 pm
Digital Signature with SmartCard October 20, 2007, 4:16 am
Can smartcard for logon be disabled? January 30, 2008, 1:06 pm

The site map in XML format XML site map

Contact Us | Privacy Policy