Re: PIN-counter

Douglas E Engert <[email protected]> Tue, 18 Apr 2023 10:36:35 -0500
Newsgroups gmane.comp.encryption.opensc.devel
Message-ID <[email protected]>
This is a multi-part message in MIME format.
--===============8807776369376546853==
Content-Type: multipart/alternative;
 boundary="------------0zUmH71rcazYIqRkeaZQaSXG"
Content-Language: en-US

This is a multi-part message in MIME format.
--------------0zUmH71rcazYIqRkeaZQaSXG
Content-Type: text/plain; charset=UTF-8; format=flowed
Content-Transfer-Encoding: 8bit

`pkcs15-tool -s --list-pins`  might work.

https://github.com/OpenSC/OpenSC/blob/master/src/tools/pkcs15-tool.c#L1529-L1530

But it does not look like it will force the query of the token  ans id not working for PIV card. May work for others.

On 4/18/2023 8:44 AM, Hans via Opensc-devel wrote:
>
> Thanks Frank,
>
> A dedicated CLI wouldn’t be needed,
>
> I hoped that it would be visible via pkcs11-tool –T
>
> Regards, Hans
>
> *From:*Frank Morgner <[email protected]>
> *Sent:* Tuesday, April 18, 2023 3:09 PM
> *To:* [email protected]
> *Subject:* Re: [Opensc-devel] PIN-counter
>
> Depending on the card you can send an empty VERIFY command (without PIN) and it will return the tries left. However, I don't think we have a dedicated CLI for this.
>
> Regards, Frank.
>
> Am 18.04.23 um 14:49 schrieb Hans via Opensc-devel:
>
>     Hi all,
>
>     Excuse me for troubling with a trivial question…
>
>     I remember seeing many months ago in the release notes that it was possible to check the PIN-retry count.
>
>     But, looking for it, (man-pages google) I fail to find it. (pkcs11-tools / pkcs15-tools / opensc)
>
>     Is my mind playing tricks with me.
>
>     From very long time ago, I remember when doing a PIN-verification by sending an APDU, you get the PIN-count (and tries-left) back.
>
>     Though that seems a very crude way to do it.
>
>     Met vriendelijke groet,
>
>     *Hans Witvliet, J, Ing., DMO/OPS/I&S/APH, Kennis Team Opensource
>     Coldenhovelaan 1 Maasland 3531RC Coldehovelaan 1, kamer B213*
>
>
>     Dit bericht kan informatie bevatten die niet voor u is bestemd. Indien u niet de geadresseerde bent of dit bericht abusievelijk aan u is toegezonden, wordt u verzocht dat aan de afzender te
>     melden en het bericht te verwijderen. De Staat aanvaardt geen aansprakelijkheid voor schade, van welke aard ook, die verband houdt met risico's verbonden aan het elektronisch verzenden van
>     berichten.
>
>     This message may contain information that is not intended for you. If you are not the addressee or if this message was sent to you by mistake, you are requested to inform the sender and delete
>     the message. The State accepts no liability for damage of any kind resulting from the risks inherent in the electronic transmission of messages.
>
>
>     _______________________________________________
>
>     Opensc-devel mailing list
>
>     [email protected]
>
>     https://lists.sourceforge.net/lists/listinfo/opensc-devel
>
>
> Dit bericht kan informatie bevatten die niet voor u is bestemd. Indien u niet de geadresseerde bent of dit bericht abusievelijk aan u is toegezonden, wordt u verzocht dat aan de afzender te melden 
> en het bericht te verwijderen. De Staat aanvaardt geen aansprakelijkheid voor schade, van welke aard ook, die verband houdt met risico's verbonden aan het elektronisch verzenden van berichten.
>
> This message may contain information that is not intended for you. If you are not the addressee or if this message was sent to you by mistake, you are requested to inform the sender and delete the 
> message. The State accepts no liability for damage of any kind resulting from the risks inherent in the electronic transmission of messages.
>
>
> _______________________________________________
> Opensc-devel mailing list
> [email protected]
> https://lists.sourceforge.net/lists/listinfo/opensc-devel

-- 

  Douglas E. Engert<[email protected]>
  

--------------0zUmH71rcazYIqRkeaZQaSXG
Content-Type: text/html; charset=UTF-8
Content-Transfer-Encoding: 8bit

<html>
  <head>
    <meta http-equiv="Content-Type" content="text/html; charset=UTF-8">
  </head>
  <body>
    `pkcs15-tool -s --list-pins`  might work.  <br>
    <br>
<a class="moz-txt-link-freetext" href="https://github.com/OpenSC/OpenSC/blob/master/src/tools/pkcs15-tool.c#L1529-L1530">https://github.com/OpenSC/OpenSC/blob/master/src/tools/pkcs15-tool.c#L1529-L1530</a><br>
    <br>
    But it does not look like it will force the query of the token  ans
    id not working for PIV card. May work for others.<br>
    <br>
    <div class="moz-cite-prefix">On 4/18/2023 8:44 AM, Hans via
      Opensc-devel wrote:<br>
    </div>
    <blockquote type="cite"
      cite="mid:[email protected]">
      <meta http-equiv="Content-Type" content="text/html; charset=UTF-8">
      <meta name="Generator" content="Microsoft Word 15 (filtered
        medium)">
      <style>@font-face
	{font-family:"Cambria Math";
	panose-1:2 4 5 3 5 4 6 3 2 4;}@font-face
	{font-family:Calibri;
	panose-1:2 15 5 2 2 2 4 3 2 4;}@font-face
	{font-family:Verdana;
	panose-1:2 11 6 4 3 5 4 4 2 4;}@font-face
	{font-family:Consolas;
	panose-1:2 11 6 9 2 2 4 3 2 4;}p.MsoNormal, li.MsoNormal, div.MsoNormal
	{margin:0in;
	margin-bottom:.0001pt;
	font-size:12.0pt;
	font-family:"Times New Roman",serif;}a:link, span.MsoHyperlink
	{mso-style-priority:99;
	color:blue;
	text-decoration:underline;}a:visited, span.MsoHyperlinkFollowed
	{mso-style-priority:99;
	color:purple;
	text-decoration:underline;}p
	{mso-style-priority:99;
	mso-margin-top-alt:auto;
	margin-right:0in;
	mso-margin-bottom-alt:auto;
	margin-left:0in;
	font-size:12.0pt;
	font-family:"Times New Roman",serif;}pre
	{mso-style-priority:99;
	mso-style-link:"HTML Preformatted Char";
	margin:0in;
	margin-bottom:.0001pt;
	font-size:10.0pt;
	font-family:"Courier New";}p.msonormal0, li.msonormal0, div.msonormal0
	{mso-style-name:msonormal;
	mso-margin-top-alt:auto;
	margin-right:0in;
	mso-margin-bottom-alt:auto;
	margin-left:0in;
	font-size:12.0pt;
	font-family:"Times New Roman",serif;}span.HTMLPreformattedChar
	{mso-style-name:"HTML Preformatted Char";
	mso-style-priority:99;
	mso-style-link:"HTML Preformatted";
	font-family:Consolas;}span.EmailStyle21
	{mso-style-type:personal-reply;
	font-family:"Verdana",sans-serif;
	color:#1F497D;
	font-weight:normal;
	font-style:normal;}.MsoChpDefault
	{mso-style-type:export-only;
	font-size:10.0pt;}div.WordSection1
	{page:WordSection1;}</style><!--[if gte mso 9]><xml>
<o:shapedefaults v:ext="edit" spidmax="1026" />
</xml><![endif]--><!--[if gte mso 9]><xml>
<o:shapelayout v:ext="edit">
<o:idmap v:ext="edit" data="1" />
</o:shapelayout></xml><![endif]-->
      <div class="WordSection1">
        <p class="MsoNormal"><span
style="font-size:10.0pt;font-family:&quot;Verdana&quot;,sans-serif;color:#1F497D;mso-fareast-language:EN-US">Thanks
            Frank,<o:p></o:p></span></p>
        <p class="MsoNormal"><span
style="font-size:10.0pt;font-family:&quot;Verdana&quot;,sans-serif;color:#1F497D;mso-fareast-language:EN-US"><o:p> </o:p></span></p>
        <p class="MsoNormal"><span
style="font-size:10.0pt;font-family:&quot;Verdana&quot;,sans-serif;color:#1F497D;mso-fareast-language:EN-US"
            lang="EN-US">A dedicated CLI wouldn’t be needed,<o:p></o:p></span></p>
        <p class="MsoNormal"><span
style="font-size:10.0pt;font-family:&quot;Verdana&quot;,sans-serif;color:#1F497D;mso-fareast-language:EN-US"
            lang="EN-US">I hoped that it would be visible via
            pkcs11-tool –T<o:p></o:p></span></p>
        <p class="MsoNormal"><span
style="font-size:10.0pt;font-family:&quot;Verdana&quot;,sans-serif;color:#1F497D;mso-fareast-language:EN-US"
            lang="EN-US"><o:p> </o:p></span></p>
        <p class="MsoNormal"><span
style="font-size:10.0pt;font-family:&quot;Verdana&quot;,sans-serif;color:#1F497D;mso-fareast-language:EN-US"
            lang="EN-US">Regards, Hans<o:p></o:p></span></p>
        <p class="MsoNormal"><span
style="font-size:10.0pt;font-family:&quot;Verdana&quot;,sans-serif;color:#1F497D;mso-fareast-language:EN-US"
            lang="EN-US"><o:p> </o:p></span></p>
        <div>
          <div style="border:none;border-top:solid #E1E1E1
            1.0pt;padding:3.0pt 0in 0in 0in">
            <p class="MsoNormal"><b><span
                  style="font-size:11.0pt;font-family:&quot;Calibri&quot;,sans-serif"
                  lang="EN-US">From:</span></b><span
                style="font-size:11.0pt;font-family:&quot;Calibri&quot;,sans-serif"
                lang="EN-US"> Frank Morgner
                <a class="moz-txt-link-rfc2396E" href="mailto:[email protected]">&lt;[email protected]&gt;</a>
                <br>
                <b>Sent:</b> Tuesday, April 18, 2023 3:09 PM<br>
                <b>To:</b> <a class="moz-txt-link-abbreviated" href="mailto:[email protected]">[email protected]</a><br>
                <b>Subject:</b> Re: [Opensc-devel] PIN-counter<o:p></o:p></span></p>
          </div>
        </div>
        <p class="MsoNormal"><o:p> </o:p></p>
        <p>Depending on the card you can send an empty VERIFY command
          (without PIN) and it will return the tries left. However, I
          don't think we have a dedicated CLI for this.<o:p></o:p></p>
        <p>Regards, Frank.<o:p></o:p></p>
        <div>
          <p class="MsoNormal">Am 18.04.23 um 14:49 schrieb Hans via
            Opensc-devel:<o:p></o:p></p>
        </div>
        <blockquote style="margin-top:5.0pt;margin-bottom:5.0pt">
          <div>
            <p class="MsoNormal"
              style="mso-margin-top-alt:auto;mso-margin-bottom-alt:auto">Hi
              all,<o:p></o:p></p>
            <p class="MsoNormal"
              style="mso-margin-top-alt:auto;mso-margin-bottom-alt:auto"> <o:p></o:p></p>
            <p class="MsoNormal"
              style="mso-margin-top-alt:auto;mso-margin-bottom-alt:auto"><span
                lang="EN-US">Excuse me for troubling with a trivial
                question…</span><o:p></o:p></p>
            <p class="MsoNormal"
              style="mso-margin-top-alt:auto;mso-margin-bottom-alt:auto"><span
                lang="EN-US"> </span><o:p></o:p></p>
            <p class="MsoNormal"
              style="mso-margin-top-alt:auto;mso-margin-bottom-alt:auto"><span
                lang="EN-US">I remember seeing many months ago in the
                release notes that it was possible to check the
                PIN-retry count.</span><o:p></o:p></p>
            <p class="MsoNormal"
              style="mso-margin-top-alt:auto;mso-margin-bottom-alt:auto"><span
                lang="EN-US"> </span><o:p></o:p></p>
            <p class="MsoNormal"
              style="mso-margin-top-alt:auto;mso-margin-bottom-alt:auto"><span
                lang="EN-US">But, looking for it, (man-pages google) I
                fail to find it. (pkcs11-tools / pkcs15-tools / opensc)</span><o:p></o:p></p>
            <p class="MsoNormal"
              style="mso-margin-top-alt:auto;mso-margin-bottom-alt:auto"><span
                lang="EN-US">Is my mind playing tricks with me.</span><o:p></o:p></p>
            <p class="MsoNormal"
              style="mso-margin-top-alt:auto;mso-margin-bottom-alt:auto"><span
                lang="EN-US"> </span><o:p></o:p></p>
            <p class="MsoNormal"
              style="mso-margin-top-alt:auto;mso-margin-bottom-alt:auto"><span
                lang="EN-US">From very long time ago, I remember when
                doing a PIN-verification by sending an APDU, you get the
                PIN-count (and tries-left) back.</span><o:p></o:p></p>
            <p class="MsoNormal"
              style="mso-margin-top-alt:auto;mso-margin-bottom-alt:auto"><span
                lang="EN-US">Though that seems a very crude way to do
                it.</span><o:p></o:p></p>
            <p class="MsoNormal"
              style="mso-margin-top-alt:auto;mso-margin-bottom-alt:auto"><span
                lang="EN-US"> </span><o:p></o:p></p>
            <div>
              <p class="MsoNormal"
                style="mso-margin-top-alt:auto;mso-margin-bottom-alt:auto"><span
                  lang="EN-US"> </span><o:p></o:p></p>
            </div>
            <p class="MsoNormal"
              style="mso-margin-top-alt:auto;mso-margin-bottom-alt:auto">Met
              vriendelijke groet,<o:p></o:p></p>
            <p class="MsoNormal"
              style="mso-margin-top-alt:auto;mso-margin-bottom-alt:auto"><b>Hans
                Witvliet, J, Ing., DMO/OPS/I&amp;S/APH, Kennis Team
                Opensource<br>
                Coldenhovelaan 1 Maasland 3531RC Coldehovelaan 1, kamer
                B213</b><o:p></o:p></p>
            <p class="MsoNormal"
              style="mso-margin-top-alt:auto;mso-margin-bottom-alt:auto"> <o:p></o:p></p>
          </div>
          <p class="MsoNormal"><br>
            Dit bericht kan informatie bevatten die niet voor u is
            bestemd. Indien u niet de geadresseerde bent of dit bericht
            abusievelijk aan u is toegezonden, wordt u verzocht dat aan
            de afzender te melden en het bericht te verwijderen. De
            Staat aanvaardt geen aansprakelijkheid voor schade, van
            welke aard ook, die verband houdt met risico's verbonden aan
            het elektronisch verzenden van berichten.
            <br>
            <br>
            This message may contain information that is not intended
            for you. If you are not the addressee or if this message was
            sent to you by mistake, you are requested to inform the
            sender and delete the message. The State accepts no
            liability for damage of any kind resulting from the risks
            inherent in the electronic transmission of messages. <br>
            <br>
            <br>
            <o:p></o:p></p>
          <pre>_______________________________________________<o:p></o:p></pre>
          <pre>Opensc-devel mailing list<o:p></o:p></pre>
          <pre><a href="mailto:[email protected]" moz-do-not-send="true" class="moz-txt-link-freetext">[email protected]</a><o:p></o:p></pre>
          <pre><a href="https://lists.sourceforge.net/lists/listinfo/opensc-devel" moz-do-not-send="true" class="moz-txt-link-freetext">https://lists.sourceforge.net/lists/listinfo/opensc-devel</a><o:p></o:p></pre>
        </blockquote>
      </div>
      <br>
      Dit bericht kan informatie bevatten die niet voor u is bestemd.
      Indien u niet de geadresseerde bent of dit bericht abusievelijk
      aan u is toegezonden, wordt u verzocht dat aan de afzender te
      melden en het bericht te verwijderen. De Staat aanvaardt geen
      aansprakelijkheid voor schade, van welke aard ook, die verband
      houdt met risico's verbonden aan het elektronisch verzenden van
      berichten.
      <br>
      <br>
      This message may contain information that is not intended for you.
      If you are not the addressee or if this message was sent to you by
      mistake, you are requested to inform the sender and delete the
      message. The State accepts no liability for damage of any kind
      resulting from the risks inherent in the electronic transmission
      of messages.
      <br>
      <fieldset class="moz-mime-attachment-header"></fieldset>
      <br>
      <fieldset class="moz-mime-attachment-header"></fieldset>
      <pre class="moz-quote-pre" wrap="">_______________________________________________
Opensc-devel mailing list
<a class="moz-txt-link-abbreviated" href="mailto:[email protected]">[email protected]</a>
<a class="moz-txt-link-freetext" href="https://lists.sourceforge.net/lists/listinfo/opensc-devel">https://lists.sourceforge.net/lists/listinfo/opensc-devel</a>
</pre>
    </blockquote>
    <br>
    <pre class="moz-signature" cols="200">-- 

 Douglas E. Engert  <a class="moz-txt-link-rfc2396E" href="mailto:[email protected]">&lt;[email protected]&gt;</a>
 
</pre>
  </body>
</html>

--------------0zUmH71rcazYIqRkeaZQaSXG--


--===============8807776369376546853==
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
Content-Disposition: inline


--===============8807776369376546853==
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
Content-Disposition: inline

_______________________________________________
Opensc-devel mailing list
[email protected]
https://lists.sourceforge.net/lists/listinfo/opensc-devel

--===============8807776369376546853==--