CardManager Plugin detailed command description

Command overview

Precondition
CardManager
Plugin
Command
Command-Description
Parameter
n) is numbering
Param-Description
n) is corresponding numbering
Required / Optional
CardManager connected (cm>) auth Authenticate using the given (or default) initial key (key set version 255) according to Secure Channel Protocol (SCP).
The command execution contains the following 2 commands:
init-update
ext-auth
Execution of the command without any params will use the default keyset (you must set your keyset before with set-key). usage:auth [plain|mac|enc] [keydata]
1) plain|mac|enc
2) keydata
1) plain: no secure messaging (default)
mac: Command MAC (C-MAC) generation
enc: Command data encryption (C-ENC) and C-MAC generation.
2) keydata for authentification (only one key is accepted - the 3 card-manager keys will set to this key)
Optional
CardManager connected (cm>) begin-RMAC Global Platform BEGIN R-MAC command.
Prerequisites: SCP must be established (Authentication with auth).
usage:begin-RMAC [-c [data]]
1) -c
2) data
1) Indicates that no secure messaging is expected meaning that only the END R-MAC command will contain a R-MAC. If this option is not set all consequent APDUs are expected to include a R-MAC.
2) Data (HEX string) to be included in the command.
CardManager connected (cm>) card-info Displays card information (Card Manager state/AID and registry info). Obtain information about applets and packages currently contained in the card. Also dump information about the Global Platform lifecycle of the CardManager and the applets (Authentication required).
This command use implizit the Global Platform command "get-status".
Prerequisites: SCP must be established (Authentication with auth).
usage: card-info [[-o|--old-format][-q|--quiet][-x|--exclude][-e|--exists][-n|--not-exists][-a|--applets][-p|--packages][AID..]]

The privileges are coded as follows:
S - Security Domain
V - Security Domain with DAP verification
E - Security Domain with delegated management
L - Card Manager lock privilege
T - Card Manager terminate privilege
D - Implicit selectable (default applet)
P - PIN change privilege
M - Security Domain with mandated DAP verification

AID Data syntax: HEX[|CHARS[|HEX...]] (see also Data Considerations)
1) -o|--old-format
2) -q|--quiet
3) -x|--exclude
4) -e|--exists
5) -n|--not-exists
6) -a|--applets
7) -p|--packages
8) AID..
1) Chose old output format
2) Don't print anything, just setup list of AIDs as return value
3) Exclude specified AIDs from listing/return value
4) List/include in return value only specified AIDs if existing
5) List all but specified AIDs, return value are not existing AIDs
6) List only installed applets
7) List only packages (load files)
8) List of AIDs.
CardManager connected (cm>) change-pin Changes the Global Platform 2.0.1' Global PIN value and it's max. false retry limit (Authentication required).
Note: The Global PIN is allocated at the time this command is sent for the first time. Prior to this, the Global PIN is not available through the Global Platform API (e.g. OPSystem.verifyPIN()).
Prerequisites: SCP must be established (Authentication with auth).
usage: change-pin <3-15> value
Note:Prerequisites also that this card loaded an installed the EMV command "pin-change-unblock".
1) <3-15>
2) value
1) Max. false retry limit.
2) New PIN value to be set.
Required
CardManager connected (cm>) cvm-block-unblock This command allowes to block/unblock the CVM. This is an extension to the Global Platform specification.
usage:cvm-block-unblock block|unblock
Note:Prerequisites also that this card loaded an installed the EMV command "pin-change-unblock".
block|unblock Indicates whether the CVM is to be blocked (transitioned to BLOCKED state) or unblocked (transitioned to ACTIVE state). Required
CardManager connected (cm>) cvm-update This command updates the CVM value and/or the CVM try limit. This is an extension to the Global Platform specification. The command is only allowed in the context of a secure channel using SCP 02.
usage:cvm-update [[-l|--limit retry-limit][-f|--format format][value]]
Note:Prerequisites also that this card loaded an installed the EMV command "pin-change-unblock".
1) -l|--limit retry-limit
2) -f|--format format
3) value
1) Update the CVM retry limit (retry-limit --> New CVM retry limit to be set. Range 0-15, where zero indicates that the CVM state is to be set to INACTIVE.)
2) Define the format of the CVM value. If this option is not set, the default format is ASCII. The CVM value provided is interpreted accoding to this format indication (format --> CVM encoding format: BCD | HEX | ASCII).
3) The new CVM value to be set.
CardManager connected (cm>) delete Delete an applet or package from the card (Authentication required).
Global Platform DELETE command. Delete a uniquely identifiable object such as an Executable Load File, an Application or an Executable Load File and its related Applications.
usage: delete [-r|--delete-related] AID
Error: 6A88 (Reference data not found) if applet dosn't exist.
1) -r|--delete-related
2) AID
1) Also delete related objects (related instances of a package).
2) AID of object to be deleted.
1) Optional / 2)Required
CardManager connected (cm>) delete-key Delete keys currently stored in the off-card repository.
Example usage: delete-key 1/1 1/2 1/3.
By default all keys are removed from the repository.
usage:delete-key [keyref..]
keyref.. Space separated list of key references (keyref --> Key reference syntax: SET/ID see also: /set-key). Required
CardManager connected (cm>) end-RMAC Global Platform END R-MAC command.
usage:end-RMAC
CardManager connected (cm>) extradite Extradite an applet to another Security Domain. Corresponds with the Global Platform Install [for extradition] command.
usage:extradite sdAID appAID
1) sdAID
2) appAID
1) AID of the Security Domain to which the applet is to be extradited.
2) AID of the applet instance to be extradited.
Required
CardManager connected (cm>) ext-auth Global Platform EXTERNAL AUTHENTICATE command.
Complete the authentication to the CardManager with the EXTERNAL AUTHENTICATE command.
usage: ext-auth [plain|mac|enc|rmac|crmac|crmacenc]

Alowed security levels:
plain
no secure messaging (default)
mac
Command MAC (C-MAC) generation
enc
Command data encryption (C-ENC) and C-MAC generation
rmac
Response MAC (R-MAC) generation
crmac
C-MAC and R-MAC generation
crmacenc
C-MAC, R-MAC and C-ENC
plain|mac|enc|rmac|crmac|crmacenc Desired security level for subsequent APDU's
Optional
CardManager connected (cm>) flush Flush Global Platform session info (close secure channel).
Flush secure channel parametes, resets the session state and flushes off-card cache of registry information. Clear applets, domains and loaded files.
All keys and keysets - set before - are unchanged!
usage: flush
CardManager connected (cm>) get-data Global Platform GET DATA command used to retrieve data objects.
usage:get-data tag
tag Two byte tag value (HEX string) defining the data object to be retrieved. Example usage: get-data 9F7F. Required
CardManager connected (cm>) get-cplc Get CardProductionLifeCycle information from the card (as defined in Global Platform).
usage:get-cplc
CardManager connected (cm>) init-update Global Platform INITIALIZE-UPDATE command.
Execute the INITIALIZE UPDATE command to begin authentication to the CardManager ( includes flush). Prerequisite is the knowledge of the appropriate keys. These keys must be set via the set-key command.
usage: init-update [key-set [scp]]

Valid values for Secure Channel Protocol are:
SCP_UNDEFINED, SCP_01_05, SCP_01_15, SCP_02_04, SCP_02_05, SCP_02_0A, SCP_02_0B, SCP_02_14, SCP_02_15, SCP_02_1A, SCP_02_1B. SCP_UNDEFINED is the default value and means that SCP_02_15 will be used if the card indicates that it supports SCP 02. Otherwise SCP_01_05 will be used (that's the Global (Open) Platform 2.0.1' compatible protocol.

Note:Not all valid SCP values are supported by a special card or simulation (mostly only one). The reply to this command contains the supported SCP (for more info see "Global Platform Specification").

Response Message: The data field of the response message shall contain the concatenation without delimiters of the following data elements:
Name
Length
Key diversification data 10 bytes
Key information 2 bytes
Card challenge 8 bytes
Card cryptogram 8 bytes
The key diversification data is data typically used by a backend system to derive the card static keys.
The key information includes the Key Version Number and the Secure Channel Protocol identifier, here '01', used in initiating the Secure Channel Session.
The card challenge is an internally generated random number.
The card cryptogram is an authentication cryptogram.
1) key-set
2) scp
1) Key set version to be used. Zero is default and means that the card dictates, which key set to be used.
2) Global Platform 2.1.1 Secure Channel Protocol (SCP) to be used.
Optional
CardManager connected (cm>) install Install an applet (via the Card Manager) with certain privileges and, if desired, make it selectable.
Install an applet and register it under an AID (Authentication required). Be aware that the C9 tag needs to be specified manually during the passing of applet install parameters.
usage: install [-e|--delegation][-l|--cm-lock][-t|--terminate][-d|--default][-p|--pin-change][-s|--security-domain][-b|--sd-dap][-m|--mandated-dap][-q|--install-param params][-i|--instance-aid AID][-o|--install-only] pkgAID appAID

Install parameters in TLV format (VOP/GP) Tags:
0xC9
application specific parameters
0xEF
system specific parameters:
0xC6
non volatile code space limit
0xC7
volatile data space limit
0xC8
non volatile data space limit
Install parameters in TLV format (GSM 03.48) Tags:
0xEF
system parameters
0xC8
non volatile memory required for installation
0xC7
volatile memory required for installation
0xCA
GSM applet specific parameters
0xC9
applet specific parameters
GSM applet specific parameters are:
1 byte
Length of Access Domain field
1-n bytes
Access Domain:
Either one or three bytes! Possible values:
1 byte
0x00 - Full access to the GSM file system
1 byte
0xFF - No access to the GSM file system
3 bytes
0x01 - APDU access mechanism (combinations of these bits are allowed!)
0x0000
No access
0x0001
ALWAYS
0x0002
CHV1
0x0004
CHV2
0x0010
ADM
1 byte
Priority level of the Toolkit applet instance
1 byte
Maximum number of timers allowed
1 byte
Maximum text length for a menu entry
1 byte
Maximum number of menu entries
1 byte
Position of the first menu entry ('00' means last)
1 byte
Identifier of the first menu entry ('00' means don't care)
1 byte
Position of the last menu entry ('00' means last)
1 byte
Identifier of the last menu entry ('00' means don't care)
1) -e|--delegation
2) -l|--cm-lock
3) -t|--terminate
4) -d|--default
5) -p|--pin-change
6) -s|--security-domain
7) -b|--sd-dap
8) -m|--mandated-dap
9) -q|--install-param params
10) -i|--instance-aid AID
11) -o|--install-only
12) pkgAID
13) appAID
1) Security Domain with delegated management.
2) Card Manager lock permission.
3) Card terminate permission.
4) Implicit selectable (default) applet.
5) PIN change permission.
6) A Security Domain.
7) Security Domain with DAP verification.
8) Security Domain with mandated DAP verification.
9) Install parameters in TLV format (params Install parameters).
10) Desired instance AID (AID --> Instance AID).
11) Install the applet only, don't make it selectable.
12) AID of the package (Load File) to install from.
13) AID of the applet (Executable Module within the Load File) to be installed.
1-11) Optional / 12-13)Required
CardManager connected (cm>) install-rom-package Install a romized package.
usage:install-rom-package [-s|--sd SD-AID] PKG-AID PKGID
1) -s|--sd SD-AID
2) PKG-AID
3) PKGID
1) Security Domain to associate the package/application(s) with (SD-AID --> Security Domain AID).
2) Package AID of ROM package
3) Package ID - refer to the spec of your ROM mask
1) Optional / 2-)Required
CardManager connected (cm>) ls Displays card information (Card Manager state/AID and registry info).
This command is alias to card-info
usage:ls [[-o|--old-format][-q|--quiet][-x|--exclude][-e|--exists][-n|--not-exists][-a|--applets][-p|--packages][AID..]]

The privileges are coded as follows:
S - Security Domain
V - Security Domain with DAP verification
E - Security Domain with delegated management
L - Card Manager lock privilege
T - Card Manager terminate privilege
D - Implicit selectable (default applet)
P - PIN change privilege
M - Security Domain with mandated DAP verification

AID Data syntax: HEX[|CHARS[|HEX...]] (see also Data Considerations)
1) -o|--old-format
2) -q|--quiet
3) -x|--exclude
4) -e|--exists
5) -n|--not-exists
6) -a|--applets
7) -p|--packages
8) AID..
1) Chose old output format
2) Don't print anything, just setup list of AIDs as return value
3) Exclude specified AIDs from listing/return value
4) List/include in return value only specified AIDs if existing
5) List all but specified AIDs, return value are not existing AIDs
6) List only installed applets
7) List only packages (load files)
8) Space separated list of AIDs
Optional
CardManager connected (cm>) make-selectable Make a previously installed applet selectable. Corresponds with the Global Platform Install [for make selectable] command.
usage:make-selectable [-d|--default-applet] AID
1) -d|--default-applet
2) AID
1) Set the Implicit Selectable (default applet) privilege.
2) AID of the applet instance to be made selectable.
1)Optional / 2)Required
CardManager connected (cm>) personalize Initiate that the currenlty selected Security Domain shall personalize one of its associated applets (via subsequent STORE DATA commands). Corresponds with the Global Platform Install [for personalization] command.
usage:personalize appAID
appAID AID of the applet instance to be personalized. Required
CardManager connected (cm>) Print information about keys currently stored in the off-card repository.
Example usage: print-key 1/1 1/2 1/3.
By default information about all keys is printed.
usage:print-key [keyref..]
keyref.. List of key references (keyref --> Key reference syntax: SET/ID, see set-key). Optional
CardManager connected (cm>) put-data Visa Global Platform PUT DATA command used to write data objects.
usage:put-data tag data
examples:
put-data 0066 010203040506070809
=> 80 DA 00 66 09 01 02 03 04 05 06 07 08 09
1) tag
2) data
1) Two byte tag value (HEX string) defining the data object to be written.
2) Data (HEX string) to be written.
Required
CardManager connected (cm>) put-key Load new keys or key sets into the card, possibly exchanging the currently active ones (Authentication required).
Add/modify/replace one or more DES keys or add one RSA public key. If the mode option is not set the default mode is add and if add doesn't work the modify mode is tried. All keys must belong to the same key set and must be ordered (lowest index first).If the operation mode is 'replace' a replace key set must be defined.
usage: put-key [-m|--mode modify|replace|add][-r|--replace-keySet key-set]keydef|keyref..
1) -m|--mode modify|replace|add
2) -r|--replace-keySet key-set
3) keydef|keyref..
1) PutKey operation mode. Defines whether the key set to which the keys belong to is to be modified, replaced or added (modify|replace|add --> Modify, replace or add key set).
2) Defines the key set to be replaced. Only applicable if the operation mode is set to 'replace' (key-set --> Key set to be replaced).
3) List of keys to be put onto the card (keydef|keyref --> Either a key reference or definition / Syntax see set-key).
<1-2) Optional / 3) Required/td>
CardManager connected (cm>) put-keyset Load a complete key set into the card. The difference to the put-key command is that this command does not allow to load single keys (Authentication required).
Add/modify/replace one DES key set (keys at index 1,2 and 3). If the mode option is not set the default mode is 'add' and if 'add' doesn't work the 'modify' mode is tried. If the operation mode is 'replace' a replace key set must be defined.
usage: put-keyset [-m|--mode modify|replace|add][-r|--replace-keySet key-set]key-set..
1) -m|--mode modify|replace|add
2) -r|--replace-keySet key-set
3) key-set..
1) PutKey operation mode. Defines whether the key set to which the keys belong to is to be modified, replaced or added.
2) Defines the key set to be replaced. Only applicable if the operation mode is set to 'replace' (key-set --> Key set to be replaced).
3) List of key sets to be put onto the card. Key 1,2 and 3 must be present in this key set.
<1-2) Optional / 3) Required/td>
CardManager connected (cm>) put-pub-key Add a RSA public key to the desired key set at the desired key index. The specified token will be searched for key pairs (private certs) holding public keys which can be put onto the card.
usage:put-pub-key [-i|--tokenpin PIN][-d|--keyID key-ID] key-set tokenspec

Possible token definitions are: "pkcs11:<dllname>" | "windows" | "<PKCS#12-file>" | "<PKCS#8-file>".
The string "windows" means to search your Windows system (CAPI) for a key pair.
1) -i|--tokenpin PIN
2) -d|--keyID key-ID
3) key-set
4) tokenspec
1) Specify the PIN to open the token. Only used if token is PIN protected (PIN --> PIN to open the token referenced by tokenspec).
2) Define key index in the key set version of the public key to be put (default is 1) (key-ID --> Key index in the key set version).
3) Key set version to be added.
4) Specify the token holding the key pair including the public key to be put.
CardManager connected (cm>) select Send select command APDU to card.
usage:select
Command generated APDU is: '0x00A4040008A00000000300000000'
CardManager connected (cm>) send Send APDU via secure channel, if established.
usage:send apdu [pattern..]

examples:
send 0001000002AABB03 *9000

How must be translated APDUs in order Jcshell sends them in a secure channel (to avoid problems by missing Lc/Le identification):
Case 1:

	Source APDU: 			CLA INS P1 P2
	JCShell Command:	send	CLA INS P1 P2 00 [pattern]

Case 2:

	Source APDU: 			CLA INS P1 P2 Lc Data
	JCShell Command:	send	CLA INS P1 P2 Lc Data [pattern]

Case 3:

	Source APDU: 			CLA INS P1 P2 Le
	JCShell Command:	send	CLA INS P1 P2 00 Le [pattern]

Case 4:

	Source APDU: 			CLA INS P1 P2 Lc Data Le
	JCShell Command:	send	CLA INS P1 P2 Lc Data Le [pattern]
			
1) apdu
2) pattern..
1) Data syntax: HEX[|CHARS[|HEX...]] (see also Data Considerations)
2) Description of expected responses. (see also /send command)
APDU is required / pattern is optional
CardManager connected (cm>) session-info Print Global Platform session (secure channel) status.
usage:session-info
CardManager connected (cm>) set-aid Change the Card Manager AID via an Global Platform 2.0.1' PUT DATA command.
Sets the AID of the Card Manager. If the AID is to be modified on-card, an Open Platform 2.0.1 'PUT DATA' command is sent to the card to achieve this.
usage:set-aid AID
examples:
set-aid A000000003000000
=> 80 DA 00 4F 08 A0 00 00 00 03 00 00 00
AID Desired AID. Required
CardManager connected (cm>) set-applet Set the Global Platform life cycle of an applet (Authentication required).
usage: set-applet AID installed|selectable|personalized|locked.
1) AID
2) installed|selectable|personalized|blocked|locked
1) Applet AID
2) Set application life cycle state.
Required
CardManager connected (cm>) set-scp Allows defining the secure channel protocol to be used in subsequent implicit channel setup. If no secure channel exists and a SCP has been set using this command, implicit channel setup takes place automatically as soon as an APDU is sent.
usage:set-scp scp

Valid values are: SCP_02_0A, SCP_02_0B, SCP_02_1A, SCP_02_1B.
scp Global Platform 2.1.1 Secure Channel Protocol (SCP) to be set. Required
CardManager connected (cm>) set-key Registers the secret key(s) with the CardManager plugin for use in the secure messaging executed during authentication. No interaction with card.
usage: set-key keydef..

Key syntax: SET/ID/TYPE/HEX
SET and ID are the key-set version and key identifier.
TYPE specifies the key type is must be one of: DES, DES-ECB, DES-CBC, RSA-PRIV, RSA-PUB, RSA-CRT, DSA-PRIV, DSA-PUB.
HEX is the representation of the key material. White space is allowed in HEX between pair of hex digits. Any slash can be substituted by the following chars: '.,|;:
Example with 2 keys:
set-key 255/1/DES-ECB/404142434445464748494a4b4c4d4e4f 255/2/DES-ECB/404142434445464748494a4b4c4d4e4f
keydef.. Space separated list of keys to be set in off-card repository. Required
CardManager connected (cm>) set-security Sets the security level of the current secure channel. Note that this setting is only for the client (JCShell) - not for the card! After set security to e.g. "enc" the following commands send to card will be encrypted.
usage:set-security plain|mac|enc|rmac|crmac|crmacenc

Desired security level:
plain
no secure messaging
mac
Command MAC (C-MAC) generation
enc
Command data encryption (C-ENC) and C-MAC generation
rmac
Response MAC (R-MAC) generation
crmac
C-MAC and R-MAC generation
crmacenc
C-MAC, R-MAC and C-ENC
plain|mac|enc|rmac|crmac|crmacenc Desired security level. Required
CardManager connected (cm>) set-state Set the CardManager life cycle state.
usage: set-state ready|initialized|secured|locked|terminated.
ready|initialized|secured|locked|terminated CardManger life cycle state. Required
CardManager connected (cm>) store-aid Change the Card Manager AID via a Global Platform 2.1.1 STORE DATA command.
Sets the AID of the Card Manager. If the AID is to be modified on-card, a Global Platform 2.1.1 'STORE DATA' command is sent to the card to achieve this.
usage:store-aid AID
examples:
store-aid A000000003000000
=> 80 E2 80 00 0A 4F 08 A0 00 00 00 03 00 00 00
AID Desired AID. Required
CardManager connected (cm>) store-dap-key Set DAP verification public key information via a Global Platform STORE DATA command. The public key is stored in key set version 0x73 at index 1.
usage:store-dap-key [-i|--tokenpin PIN] tokenspec

Possible token definitions are: "pkcs11:<dllname>" | "windows" | "<PKCS#12-file>" | "<PKCS#8-file>".
The string "windows" means to search your Windows system (CAPI) for a key pair.
1) -i|--tokenpin PIN
2) tokenspec
1) Specify the PIN to open the token. Only used if token is PIN protected (PIN --> PIN to open the token referenced by tokenspec).
2) Specify the token holding the key pair including the public key to be stored.
1)Optional / 2)Required
CardManager connected (cm>) store-data Global Platform STORE DATA command used to transfer data to an application or Security Domain.
usage:store-data [-m|--more-blocks][-b|--block-number number] data
1) -m|--more-blocks
2) -b|--block-number number
3) data
1) Indicates that this is not the last block (more store-data commands to follow).
2) Block number in case of command chaining. Default value is zero indicating that this is the first and only block (number --> Block number (0-255)).
3) Data (HEX string) to be stored.
1-2)Optional / 3)Required
CardManager connected (cm>) store-keyset Add or replace one complete key set verison (keys at index 1,2 and 3) via a Global Platform STORE DATA command.
usage:store-keyset [-r|--replace-keySet replace-key-set] key-set
1) -r|--replace-keySet replace-key-set
2) key-set
1) Defines the key set to be replaced (value 1-111). If a new key set version is to be added this option shall not be set (replace-key-set --> Key set to be replaced).
2) New key set version to be stored.
1)Optional / 2)Required
CardManager connected (cm>) unblock-pin Unblock the Global Platform 2.0.1 Global PIN (Authentication required).
usage: unblock-pin
Note:Prerequisites also that this card loaded an installed the EMV command "pin-change-unblock".
CardManager connected (cm>) upload Load a package onto the card via the Card Manager.
Upload a package contained in a JavaCard 2.1.1/2.2.1 compliant CAP-file to the card (Authentication required).
usage: upload [-p|--progress][-c|--components][-r|--random][-l|--package package-name][-s|--sd SD-AID][-m|--params parameters][-b|--block_length length][-a|--auto][-d|--load-debug] CAP-file

System specific load parameters in TLV format (VOP/GP) Tags:
0xEF
system specific parameters
0xC6
non volatile code space limi
0xC7
volatile data space limi
0xC8
non volatile data space limit
System specific load parameters in TLV format (GSM 03.48) Tags:
0xEF
system specific parameters
0xC6
non volatile memory space required for package loadin
0xC8
non volatile memory requirements for installatio
0xC7
volatile memory requirements for installatio
1) -p|--progress
2) -c|--components
3) -r|--random
4) -l|--package package-name
5) -s|--sd SD-AID
6) -m|--params parameters
7) -b|--block_length length
8) -a|--auto
9) -d|--load-debug
10) CAP-file
1) Display upload progress.
2) Load CAP-file component wise.
3) Load with random APDU length.
4) Package name to look for in the CAP-file (package-name --> Java package name).
5) Security Domain to associate the package/application(s) with (SD-AID --> Security Domain AID).
6) System specific load parameters in TLV format (parameters --> Load parameters in raw (TLV) format).
7) Max. block (APDU) length sent to the card during package upload (length --> Max. block (APDU) length).
8) Auto-install/select applet. The instance AID is generated by appending 'i' to the applet AID. If the applet AID consists of 16 bytes already, the last character is replaced by 'i' (or 'x' if already equals 'i').
9) Load descriptor/debug component if available.
10) Name of the CAP-file to be loaded.
1-9) Optional / 10)Required