CardMan

Introduction

CardMan is a standalone command-line tool to perform basic OpenPlatform compliant card management operations on sample cards. It has no dependencies on other components and is intended to be fail-safe. ;-)

System Requirements
CardMan is completely self-contained and requires no installation or configuration. It consists just of one binary executable for the Win32 platform and works with any installed PC/SC smartcard readers.

Restrictions
Since CardMan is supposed to be as simple as possible, it has a set of hard-coded default settings which cannot be changed. The most noticable restriction is the built-in initial CardManager key which is set to "0x404142434445464748494A4B4C4D4E4F" (keyset FF). Furthermore CardMan can only deal with cards which are in the "OP_READY" or "INITIALIZED" life cycle state.

Using CardMan

With CardMan you can perform basic operations to maintain your OpenPlatform JavaCard. The currently supported commands let you:

Only one operation can be performed at a single invocation of CardMan. The operation is specified by a command name, followed by command-specific (optional) arguments. Without specifying a command name, CardMan displays its usage message:

C:\> cardman

usage: cardman <command> [<arguments>]...
    commands:
        capinfo <capfile>
        cplc
        list
        upload  <capfile>
        install <pkg-AID> <app-AID> [-i <inst-AID>] [-SVELTDPM] [-q <param>]
        delete  <AID>
        send    <APDU> [<APDU>] ...
        server  [<port>]

Some commands require one or more AID or APDU arguments, which have to be specified as hexadecimal or ASCII strings. The special characters quote ('), bar (|) or slash (/) can be used to switch between HEX and ASCII input. The default format is HEX. For example the string "112233|Test|AABBCC" can be used to specify the byte sequence "11223354657374AABBCC".
Note: since most non-alpha-numeric characters are somehow interpreted by the command-line shell, these special characters have to be used carefully and may have to be quoted!

CardMan Commands

Each command and its specific arguments are explained in detail in the respective section below.

CPLC command
Description: Query the card's CPLC (Card Production Life Cycle) data.
Syntax: cardman cplc
C:\> cardman cplc

CPLC data:
  IC Fabricator                   : 5048
  IC Type                         : 6017
  Operating System ID             : 4A5A
  Operating System release date   : 1074
  Operating System release level  : 0107
  IC Fabrication Date             : 1026
  IC Serial Number                : 00001862
  IC Batch Identifier             : 023A
  IC Module Fabricator            : 5048
  IC Module Packaging Date        : 0360
  ICC Manufacturer                : 5048
  IC Embedding Date               : 1010
  IC Pre-Personalizer             : 1A34
  IC Pre-Perso. Equipment Date    : 3030
  IC Pre-Perso. Equipment ID      : 31383632
  IC Personalizer                 : 0000
  IC Personalization Date         : 0000
  IC Perso. Equipment ID          : 00000000

LIST command
Description: List packages and applets on the card.
Syntax: cardman list
C:\> cardman list

Card Manager AID   :  A0000000030000
Card Manager state :  OP_READY

  Application:   SELECTABLE (-----D--) "APDUTestInst"
  Load File  :       LOADED (--------) "APDUTEST"
  Load File  :       LOADED (--------) A0000000620101  (javacard.framework)
  Load File  :       LOADED (--------) A0000000620001  (java.lang)
  Load File  :       LOADED (--------) A0000000620102  (javacard.framework)
  Load File  :       LOADED (--------) A0000000620201  (javacardx.crypto)
  Load File  :       LOADED (--------) A0000000030000  (visa.openplatform)
  Load File  :       LOADED (--------) "system"
  Load File  :       LOADED (--------) "1PAY."         (PSE)
  Load File  :       LOADED (--------) A00000000310    (VSDC)
  Load File  :       LOADED (--------) A0000000036010  (VisaCash)
  Load File  :       LOADED (--------) A00000009820

For every applet or package one line is displayed in the format type : state (flags) AID (nickname).
The flags field is a combination of the following attributes (SVELTDPM):

  • S - security domain
  • V - security domain with DAP verification
  • E - security domain with delegated management
  • L - CardManager-lock privilege
  • T - CardManager-terminate privilege
  • D - implicitly selectable (default applet)
  • P - PIN-change privilege
  • M - security domain with mandated DAP verification

CAPINFO command
Description: Display info on CAP file components.
Syntax: cardman capinfo <capfile>
C:\> cardman capinfo apdutest.cap

CAP file 'apdutest.cap':
  Header.cap (21 bytes)
    CAP version 2.1, flags 0x04, package AID "APDUTEST" version 1.0
  Directory.cap (34 bytes)
  Import.cap (14 bytes)
    import AID A0000000620101 (javacard.framework) version 1.0
  Applet.cap (15 bytes)
    applet AID "APDUTest"
  Class.cap (24 bytes)
  Method.cap (1039 bytes)
  StaticField.cap (13 bytes)
    image size 0
  ConstantPool.cap (137 bytes)
  RefLocation.cap (124 bytes)

UPLOAD command
Description: Upload a package contained in a CAP file to the card.
Syntax: cardman upload <capfile>
C:\> cardman upload apdutest.cap

loading package "APDUTEST"........done.

INSTALL command
Description: Install an applet from a loaded package.
Syntax: cardman install <pkg-AID> <app-AID> [-i <inst-AID>] [-SVELTDPM] [-q <param>]
C:\> cardman install "|APDUTEST" "|APDUTest" -i "|APDUTestInst" -d

Applet "APDUTestInst" installed.

The install command installs the specified applet <app-AID> from the package <pkg-AID>. If the -i option is given, the new applet instance will have the AID <inst-AID>. With the -SVELTDPM options (one or more occurrences), the applet's privileges can be specified (see the list command for description of the flags). If the -q option is given, the new applet instance will receive the specified install parameters <param>. Be aware that the C9 tag needs to be specified manually: Please check the accompanying FAQ if you encounter problems in passing the installation parameters to the applet.

DELETE command
Description: Delete an applet or package on the card.
Syntax: cardman delete <AID>
C:\> cardman delete "|APDUTestInst"

"APDUTestInst" deleted.

SEND command
Description: Send arbitrary APDU commands to the card.
Syntax: cardman send <APDU> [<APDU>] ...
C:\> cardman send 00A4040007A000000003000000 (SELECT CardManager)

--> [ 13] 00 A4 04 00 07 A0 00 00 00 03 00 00 00
<-- [ 28] 6F 18 84 07 A0 00 00 00 03 00 00 A5 0D 9F 6E 06 4A 5A 10 74 01 07 9F 65 01 FE 90 00

The specified command APDUs are sent as-is to the card and the corresponding response APDUs (including status) are displayed. Care has to be taken that the command APDUs comply with ISO 7816.

SERVER command
Description: Run server for remote diagnostics.
Syntax: cardman server [<port>]
C:\> cardman server

listening on port 8050 (9.4.2.4)...
accepted connection from www.zurich.ibm.com
.......