Precondition |
CardManager Plugin Command |
Command-Description |
Parameter n) is numbering |
Param-Description n) is corresponding numbering |
Required / Optional |
||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| CardManager connected (cm>) | auth | Authenticate using the given (or default) initial key (key set version 255) according to Secure Channel Protocol (SCP). The command execution contains the following 2 commands: init-update ext-auth Execution of the command without any params will use the default keyset (you must set your keyset before with set-key). usage:auth [plain|mac|enc] [keydata] |
1) plain|mac|enc 2) keydata |
1) plain: no secure messaging (default) mac: Command MAC (C-MAC) generation enc: Command data encryption (C-ENC) and C-MAC generation. 2) keydata for authentification (only one key is accepted - the 3 card-manager keys will set to this key) |
Optional | ||||||||||
| CardManager connected (cm>) | begin-RMAC | Global Platform BEGIN R-MAC command. Prerequisites: SCP must be established (Authentication with auth). usage:begin-RMAC [-c [data]] |
1) -c 2) data |
1) Indicates that no secure messaging is expected meaning that only the END R-MAC command will contain a R-MAC.
If this option is not set all consequent APDUs are expected to include a R-MAC. 2) Data (HEX string) to be included in the command. |
|||||||||||
| CardManager connected (cm>) | card-info | Displays card information (Card Manager state/AID and registry info). Obtain information about applets and packages currently contained in the card. Also dump information
about the Global Platform lifecycle of the CardManager and the applets (Authentication required). This command use implizit the Global Platform command "get-status". Prerequisites: SCP must be established (Authentication with auth). usage: card-info [[-o|--old-format][-q|--quiet][-x|--exclude][-e|--exists][-n|--not-exists][-a|--applets][-p|--packages][AID..]] The privileges are coded as follows: S - Security Domain V - Security Domain with DAP verification E - Security Domain with delegated management L - Card Manager lock privilege T - Card Manager terminate privilege D - Implicit selectable (default applet) P - PIN change privilege M - Security Domain with mandated DAP verification AID Data syntax: HEX[|CHARS[|HEX...]] (see also Data Considerations) |
1) -o|--old-format 2) -q|--quiet 3) -x|--exclude 4) -e|--exists 5) -n|--not-exists 6) -a|--applets 7) -p|--packages 8) AID.. |
1) Chose old output format 2) Don't print anything, just setup list of AIDs as return value 3) Exclude specified AIDs from listing/return value 4) List/include in return value only specified AIDs if existing 5) List all but specified AIDs, return value are not existing AIDs 6) List only installed applets 7) List only packages (load files) 8) List of AIDs. |
|||||||||||
| CardManager connected (cm>) | change-pin | Changes the Global Platform 2.0.1' Global PIN value and it's max. false retry limit (Authentication required). Note: The Global PIN is allocated at the time this command is sent for the first time. Prior to this, the Global PIN is not available through the Global Platform API (e.g. OPSystem.verifyPIN()). Prerequisites: SCP must be established (Authentication with auth). usage: change-pin <3-15> value Note:Prerequisites also that this card loaded an installed the EMV command "pin-change-unblock". |
1) <3-15> 2) value |
1) Max. false retry limit. 2) New PIN value to be set. |
Required | ||||||||||
| CardManager connected (cm>) | cvm-block-unblock | This command allowes to block/unblock the CVM. This is an extension to the Global Platform specification. usage:cvm-block-unblock block|unblock Note:Prerequisites also that this card loaded an installed the EMV command "pin-change-unblock". |
block|unblock | Indicates whether the CVM is to be blocked (transitioned to BLOCKED state) or unblocked (transitioned to ACTIVE state). | Required | ||||||||||
| CardManager connected (cm>) | cvm-update | This command updates the CVM value and/or the CVM try limit. This is an extension to the Global Platform specification.
The command is only allowed in the context of a secure channel using SCP 02. usage:cvm-update [[-l|--limit retry-limit][-f|--format format][value]] Note:Prerequisites also that this card loaded an installed the EMV command "pin-change-unblock". |
1) -l|--limit retry-limit 2) -f|--format format 3) value |
1) Update the CVM retry limit (retry-limit --> New CVM retry limit to be set. Range 0-15, where zero indicates that the CVM state is to be set to INACTIVE.) 2) Define the format of the CVM value. If this option is not set, the default format is ASCII. The CVM value provided is interpreted accoding to this format indication (format --> CVM encoding format: BCD | HEX | ASCII). 3) The new CVM value to be set. |
|||||||||||
| CardManager connected (cm>) | delete | Delete an applet or package from the card (Authentication required). Global Platform DELETE command. Delete a uniquely identifiable object such as an Executable Load File, an Application or an Executable Load File and its related Applications. usage: delete [-r|--delete-related] AID Error: 6A88 (Reference data not found) if applet dosn't exist. |
1) -r|--delete-related 2) AID |
1) Also delete related objects (related instances of a package). 2) AID of object to be deleted. |
1) Optional / 2)Required | ||||||||||
| CardManager connected (cm>) | delete-key | Delete keys currently stored in the off-card repository. Example usage: delete-key 1/1 1/2 1/3. By default all keys are removed from the repository. usage:delete-key [keyref..] |
keyref.. | Space separated list of key references (keyref --> Key reference syntax: SET/ID see also: /set-key). | Required | ||||||||||
| CardManager connected (cm>) | end-RMAC | Global Platform END R-MAC command. usage:end-RMAC |
|||||||||||||
| CardManager connected (cm>) | extradite | Extradite an applet to another Security Domain. Corresponds with the Global Platform Install [for extradition] command. usage:extradite sdAID appAID |
1) sdAID 2) appAID |
1) AID of the Security Domain to which the applet is to be extradited. 2) AID of the applet instance to be extradited. |
Required | ||||||||||
| CardManager connected (cm>) | ext-auth | Global Platform EXTERNAL AUTHENTICATE command. Complete the authentication to the CardManager with the EXTERNAL AUTHENTICATE command. usage: ext-auth [plain|mac|enc|rmac|crmac|crmacenc] Alowed security levels:
|
plain|mac|enc|rmac|crmac|crmacenc | Desired security level for subsequent APDU's |
Optional | ||||||||||
| CardManager connected (cm>) | flush | Flush Global Platform session info (close secure channel). Flush secure channel parametes, resets the session state and flushes off-card cache of registry information. Clear applets, domains and loaded files. All keys and keysets - set before - are unchanged! usage: flush |
|||||||||||||
| CardManager connected (cm>) | get-data | Global Platform GET DATA command used to retrieve data objects. usage:get-data tag |
tag | Two byte tag value (HEX string) defining the data object to be retrieved. Example usage: get-data 9F7F. | Required | ||||||||||
| CardManager connected (cm>) | get-cplc | Get CardProductionLifeCycle information from the card (as defined in Global Platform). usage:get-cplc |
|||||||||||||
| CardManager connected (cm>) | init-update | Global Platform INITIALIZE-UPDATE command. Execute the INITIALIZE UPDATE command to begin authentication to the CardManager ( includes flush). Prerequisite is the knowledge of the appropriate keys. These keys must be set via the set-key command.usage: init-update [key-set [scp]] Valid values for Secure Channel Protocol are: SCP_UNDEFINED, SCP_01_05, SCP_01_15, SCP_02_04, SCP_02_05, SCP_02_0A, SCP_02_0B, SCP_02_14, SCP_02_15, SCP_02_1A, SCP_02_1B. SCP_UNDEFINED is the default value and means that SCP_02_15 will be used if the card indicates that it supports SCP 02. Otherwise SCP_01_05 will be used (that's the Global (Open) Platform 2.0.1' compatible protocol. Note:Not all valid SCP values are supported by a special card or simulation (mostly only one). The reply to this command contains the supported SCP (for more info see "Global Platform Specification"). Response Message: The data field of the response message shall contain the concatenation without delimiters of the following data elements:
The key information includes the Key Version Number and the Secure Channel Protocol identifier, here '01', used in initiating the Secure Channel Session. The card challenge is an internally generated random number. The card cryptogram is an authentication cryptogram. |
1) key-set 2) scp |
1) Key set version to be used. Zero is default and means that the card dictates, which key set to be used. 2) Global Platform 2.1.1 Secure Channel Protocol (SCP) to be used. |
Optional | ||||||||||
| CardManager connected (cm>) | install | Install an applet (via the Card Manager) with certain privileges and, if desired, make it selectable. Install an applet and register it under an AID (Authentication required). Be aware that the C9 tag needs to be specified manually during the passing of applet install parameters. usage: install [-e|--delegation][-l|--cm-lock][-t|--terminate][-d|--default][-p|--pin-change][-s|--security-domain][-b|--sd-dap][-m|--mandated-dap][-q|--install-param params][-i|--instance-aid AID][-o|--install-only] pkgAID appAID Install parameters in TLV format (VOP/GP) Tags:
|
1) -e|--delegation 2) -l|--cm-lock 3) -t|--terminate 4) -d|--default 5) -p|--pin-change 6) -s|--security-domain 7) -b|--sd-dap 8) -m|--mandated-dap 9) -q|--install-param params 10) -i|--instance-aid AID 11) -o|--install-only 12) pkgAID 13) appAID |
1) Security Domain with delegated management. 2) Card Manager lock permission. 3) Card terminate permission. 4) Implicit selectable (default) applet. 5) PIN change permission. 6) A Security Domain. 7) Security Domain with DAP verification. 8) Security Domain with mandated DAP verification. 9) Install parameters in TLV format (params Install parameters). 10) Desired instance AID (AID --> Instance AID). 11) Install the applet only, don't make it selectable. 12) AID of the package (Load File) to install from. 13) AID of the applet (Executable Module within the Load File) to be installed. |
1-11) Optional / 12-13)Required | ||||||||||
| CardManager connected (cm>) | install-rom-package | Install a romized package. usage:install-rom-package [-s|--sd SD-AID] PKG-AID PKGID |
1) -s|--sd SD-AID 2) PKG-AID 3) PKGID |
1) Security Domain to associate the package/application(s) with (SD-AID --> Security Domain AID). 2) Package AID of ROM package 3) Package ID - refer to the spec of your ROM mask |
1) Optional / 2-)Required | ||||||||||
| CardManager connected (cm>) | ls | Displays card information (Card Manager state/AID and registry info). This command is alias to card-info usage:ls [[-o|--old-format][-q|--quiet][-x|--exclude][-e|--exists][-n|--not-exists][-a|--applets][-p|--packages][AID..]] The privileges are coded as follows: S - Security Domain V - Security Domain with DAP verification E - Security Domain with delegated management L - Card Manager lock privilege T - Card Manager terminate privilege D - Implicit selectable (default applet) P - PIN change privilege M - Security Domain with mandated DAP verification AID Data syntax: HEX[|CHARS[|HEX...]] (see also Data Considerations) |
1) -o|--old-format 2) -q|--quiet 3) -x|--exclude 4) -e|--exists 5) -n|--not-exists 6) -a|--applets 7) -p|--packages 8) AID.. |
1) Chose old output format 2) Don't print anything, just setup list of AIDs as return value 3) Exclude specified AIDs from listing/return value 4) List/include in return value only specified AIDs if existing 5) List all but specified AIDs, return value are not existing AIDs 6) List only installed applets 7) List only packages (load files) 8) Space separated list of AIDs |
Optional | ||||||||||
| CardManager connected (cm>) | make-selectable | Make a previously installed applet selectable. Corresponds with the Global Platform Install [for make selectable] command. usage:make-selectable [-d|--default-applet] AID |
1) -d|--default-applet 2) AID |
1) Set the Implicit Selectable (default applet) privilege. 2) AID of the applet instance to be made selectable. |
1)Optional / 2)Required | ||||||||||
| CardManager connected (cm>) | personalize | Initiate that the currenlty selected Security Domain shall personalize one of its associated applets
(via subsequent STORE DATA commands). Corresponds with the Global Platform Install [for personalization] command. usage:personalize appAID |
appAID | AID of the applet instance to be personalized. | Required | ||||||||||
| CardManager connected (cm>) | print-key | Print information about keys currently stored in the off-card repository. Example usage: print-key 1/1 1/2 1/3. By default information about all keys is printed. usage:print-key [keyref..] |
keyref.. | List of key references (keyref --> Key reference syntax: SET/ID, see set-key). | Optional | ||||||||||
| CardManager connected (cm>) | put-data | Visa Global Platform PUT DATA command used to write data objects. usage:put-data tag data examples: put-data 0066 010203040506070809 => 80 DA 00 66 09 01 02 03 04 05 06 07 08 09 |
1) tag 2) data |
1) Two byte tag value (HEX string) defining the data object to be written. 2) Data (HEX string) to be written. |
Required | ||||||||||
| CardManager connected (cm>) | put-key | Load new keys or key sets into the card, possibly exchanging the currently active ones (Authentication required). Add/modify/replace one or more DES keys or add one RSA public key. If the mode option is not set the default mode is add and if add doesn't work the modify mode is tried. All keys must belong to the same key set and must be ordered (lowest index first).If the operation mode is 'replace' a replace key set must be defined. usage: put-key [-m|--mode modify|replace|add][-r|--replace-keySet key-set]keydef|keyref.. |
1) -m|--mode modify|replace|add 2) -r|--replace-keySet key-set 3) keydef|keyref.. |
1) PutKey operation mode. Defines whether the key set to which the keys belong to is to be modified, replaced or added (modify|replace|add --> Modify, replace or add key set). 2) Defines the key set to be replaced. Only applicable if the operation mode is set to 'replace' (key-set --> Key set to be replaced). 3) List of keys to be put onto the card (keydef|keyref --> Either a key reference or definition / Syntax see set-key). |
<1-2) Optional / 3) Required/td> | ||||||||||
| CardManager connected (cm>) | put-keyset | Load a complete key set into the card. The difference to the put-key command is that this command does not
allow to load single keys (Authentication required). Add/modify/replace one DES key set (keys at index 1,2 and 3). If the mode option is not set the default mode is 'add' and if 'add' doesn't work the 'modify' mode is tried. If the operation mode is 'replace' a replace key set must be defined. usage: put-keyset [-m|--mode modify|replace|add][-r|--replace-keySet key-set]key-set.. |
1) -m|--mode modify|replace|add 2) -r|--replace-keySet key-set 3) key-set.. |
1) PutKey operation mode. Defines whether the key set to which the keys belong to is to be modified, replaced or added. 2) Defines the key set to be replaced. Only applicable if the operation mode is set to 'replace' (key-set --> Key set to be replaced). 3) List of key sets to be put onto the card. Key 1,2 and 3 must be present in this key set. |
<1-2) Optional / 3) Required/td> | ||||||||||
| CardManager connected (cm>) | put-pub-key | Add a RSA public key to the desired key set at the desired key index. The specified token will be searched
for key pairs (private certs) holding public keys which can be put onto the card. usage:put-pub-key [-i|--tokenpin PIN][-d|--keyID key-ID] key-set tokenspec Possible token definitions are: "pkcs11:<dllname>" | "windows" | "<PKCS#12-file>" | "<PKCS#8-file>". The string "windows" means to search your Windows system (CAPI) for a key pair. |
1) -i|--tokenpin PIN 2) -d|--keyID key-ID 3) key-set 4) tokenspec |
1) Specify the PIN to open the token. Only used if token is PIN protected (PIN --> PIN to open the token referenced by tokenspec). 2) Define key index in the key set version of the public key to be put (default is 1) (key-ID --> Key index in the key set version). 3) Key set version to be added. 4) Specify the token holding the key pair including the public key to be put. |
|||||||||||
| CardManager connected (cm>) | select | Send select command APDU to card. usage:select Command generated APDU is: '0x00A4040008A00000000300000000' |
|||||||||||||
| CardManager connected (cm>) | send | Send APDU via secure channel, if established. usage:send apdu [pattern..] examples: send 0001000002AABB03 *9000 How must be translated APDUs in order Jcshell sends them in a secure channel (to avoid problems by missing Lc/Le identification): Case 1: Source APDU: CLA INS P1 P2 JCShell Command: send CLA INS P1 P2 00 [pattern] Case 2: Source APDU: CLA INS P1 P2 Lc Data JCShell Command: send CLA INS P1 P2 Lc Data [pattern] Case 3: Source APDU: CLA INS P1 P2 Le JCShell Command: send CLA INS P1 P2 00 Le [pattern] Case 4: Source APDU: CLA INS P1 P2 Lc Data Le JCShell Command: send CLA INS P1 P2 Lc Data Le [pattern] |
1) apdu 2) pattern.. |
1) Data syntax: HEX[|CHARS[|HEX...]] (see also Data Considerations) 2) Description of expected responses. (see also /send command) |
APDU is required / pattern is optional | ||||||||||
| CardManager connected (cm>) | session-info | Print Global Platform session (secure channel) status. usage:session-info |
|||||||||||||
| CardManager connected (cm>) | set-aid | Change the Card Manager AID via an Global Platform 2.0.1' PUT DATA command. Sets the AID of the Card Manager. If the AID is to be modified on-card, an Open Platform 2.0.1 'PUT DATA' command is sent to the card to achieve this. usage:set-aid AID examples: set-aid A000000003000000 => 80 DA 00 4F 08 A0 00 00 00 03 00 00 00 |
AID | Desired AID. | Required | ||||||||||
| CardManager connected (cm>) | set-applet | Set the Global Platform life cycle of an applet (Authentication required). usage: set-applet AID installed|selectable|personalized|locked. |
1) AID 2) installed|selectable|personalized|blocked|locked |
1) Applet AID 2) Set application life cycle state. |
Required | ||||||||||
| CardManager connected (cm>) | set-scp | Allows defining the secure channel protocol to be used in subsequent implicit channel setup.
If no secure channel exists and a SCP has been set using this command, implicit channel setup
takes place automatically as soon as an APDU is sent. usage:set-scp scp Valid values are: SCP_02_0A, SCP_02_0B, SCP_02_1A, SCP_02_1B. |
scp | Global Platform 2.1.1 Secure Channel Protocol (SCP) to be set. | Required | ||||||||||
| CardManager connected (cm>) | set-key | Registers the secret key(s) with the CardManager plugin for use in the secure messaging executed during authentication.
No interaction with card. usage: set-key keydef.. Key syntax: SET/ID/TYPE/HEX SET and ID are the key-set version and key identifier. TYPE specifies the key type is must be one of: DES, DES-ECB, DES-CBC, RSA-PRIV, RSA-PUB, RSA-CRT, DSA-PRIV, DSA-PUB. HEX is the representation of the key material. White space is allowed in HEX between pair of hex digits. Any slash can be substituted by the following chars: '.,|;: Example with 2 keys: set-key 255/1/DES-ECB/404142434445464748494a4b4c4d4e4f 255/2/DES-ECB/404142434445464748494a4b4c4d4e4f |
keydef.. | Space separated list of keys to be set in off-card repository. | Required | ||||||||||
| CardManager connected (cm>) | set-security | Sets the security level of the current secure channel. Note that this setting is only for the client (JCShell) - not for the card!
After set security to e.g. "enc" the following commands send to card will be encrypted. usage:set-security plain|mac|enc|rmac|crmac|crmacenc Desired security level:
|
plain|mac|enc|rmac|crmac|crmacenc | Desired security level. | Required | ||||||||||
| CardManager connected (cm>) | set-state | Set the CardManager life cycle state. usage: set-state ready|initialized|secured|locked|terminated. |
ready|initialized|secured|locked|terminated | CardManger life cycle state. | Required | ||||||||||
| CardManager connected (cm>) | store-aid | Change the Card Manager AID via a Global Platform 2.1.1 STORE DATA command. Sets the AID of the Card Manager. If the AID is to be modified on-card, a Global Platform 2.1.1 'STORE DATA' command is sent to the card to achieve this. usage:store-aid AID examples: store-aid A000000003000000 => 80 E2 80 00 0A 4F 08 A0 00 00 00 03 00 00 00 |
AID | Desired AID. | Required | ||||||||||
| CardManager connected (cm>) | store-dap-key | Set DAP verification public key information via a Global Platform STORE DATA command.
The public key is stored in key set version 0x73 at index 1. usage:store-dap-key [-i|--tokenpin PIN] tokenspec Possible token definitions are: "pkcs11:<dllname>" | "windows" | "<PKCS#12-file>" | "<PKCS#8-file>". The string "windows" means to search your Windows system (CAPI) for a key pair. |
1) -i|--tokenpin PIN 2) tokenspec |
1) Specify the PIN to open the token. Only used if token is PIN protected (PIN --> PIN to open the token referenced by tokenspec). 2) Specify the token holding the key pair including the public key to be stored. |
1)Optional / 2)Required | ||||||||||
| CardManager connected (cm>) | store-data | Global Platform STORE DATA command used to transfer data to an application or Security Domain. usage:store-data [-m|--more-blocks][-b|--block-number number] data |
1) -m|--more-blocks 2) -b|--block-number number 3) data |
1) Indicates that this is not the last block (more store-data commands to follow). 2) Block number in case of command chaining. Default value is zero indicating that this is the first and only block (number --> Block number (0-255)). 3) Data (HEX string) to be stored. |
1-2)Optional / 3)Required | ||||||||||
| CardManager connected (cm>) | store-keyset | Add or replace one complete key set verison (keys at index 1,2 and 3) via a Global Platform STORE DATA command. usage:store-keyset [-r|--replace-keySet replace-key-set] key-set |
1) -r|--replace-keySet replace-key-set 2) key-set |
1) Defines the key set to be replaced (value 1-111). If a new key set version is to be added this option shall not be set (replace-key-set --> Key set to be replaced). 2) New key set version to be stored. |
1)Optional / 2)Required | ||||||||||
| CardManager connected (cm>) | unblock-pin | Unblock the Global Platform 2.0.1 Global PIN (Authentication required). usage: unblock-pin Note:Prerequisites also that this card loaded an installed the EMV command "pin-change-unblock". |
|||||||||||||
| CardManager connected (cm>) | upload | Load a package onto the card via the Card Manager. Upload a package contained in a JavaCard 2.1.1/2.2.1 compliant CAP-file to the card (Authentication required). usage: upload [-p|--progress][-c|--components][-r|--random][-l|--package package-name][-s|--sd SD-AID][-m|--params parameters][-b|--block_length length][-a|--auto][-d|--load-debug] CAP-file System specific load parameters in TLV format (VOP/GP) Tags:
|
1) -p|--progress 2) -c|--components 3) -r|--random 4) -l|--package package-name 5) -s|--sd SD-AID 6) -m|--params parameters 7) -b|--block_length length 8) -a|--auto 9) -d|--load-debug 10) CAP-file |
1) Display upload progress. 2) Load CAP-file component wise. 3) Load with random APDU length. 4) Package name to look for in the CAP-file (package-name --> Java package name). 5) Security Domain to associate the package/application(s) with (SD-AID --> Security Domain AID). 6) System specific load parameters in TLV format (parameters --> Load parameters in raw (TLV) format). 7) Max. block (APDU) length sent to the card during package upload (length --> Max. block (APDU) length). 8) Auto-install/select applet. The instance AID is generated by appending 'i' to the applet AID. If the applet AID consists of 16 bytes already, the last character is replaced by 'i' (or 'x' if already equals 'i'). 9) Load descriptor/debug component if available. 10) Name of the CAP-file to be loaded. |
1-9) Optional / 10)Required |