SmardCard Delete Key Problem / Decrypt Message ambiguity

Hello,

we’ve integerated our own smartcard into notes.

First i do a “Move Private Key to SmartCard”

We can authenticate and sign messages without problems.

However, when i want to delete the key through “Delete Certificate from ID” - the private key is still on the smartcard - i know it is stated like that in the Admin HELP - BUT !

When I import the certificate (with private key) again, the option “Move Private Key to SmartCard” is disabled - that means i cannot put the private key again on the smardcard - because notes seems to cache your settings within the ID file.

The same thing applies when i manually delete the private key from the smart card - it doesnt work either, cant move private key to smartcard again - once i did it, and delete it again - i cannot do it again - i have to use an older copy of my ID file which never had that key.

Second Problem, Encrypted Messages do not use the private key on the smartcard for decrytion - i do not know how this is possibile - i can manually delete the private key from the smartcard and notes is still able to decrypt, after deletion however - signing is not possibile (the way it should).

So it seems that for signing, notes uses the private key on the smartcard, but for decrytion it uses a copy of a private key in the ID file ? OR is it possibile that notes does not use internet certificates for encryption and uses the notes public keys instead of the x509 certs ?

Subject: SmardCard Delete Key Problem / Decrypt Message ambiguity

When I import the certificate (with private key) again, the option “Move Private Key to SmartCard” is disabled - that means i cannot put the private key again on the smardcard - because notes seems to cache your settings within the ID file.

Leaf certificates (with private keys) aren’t actually deleted from the ID file, because then you would lose access to mail that was encrypted to that certificate – they are just no longer displayed, and cannot be “actively” used. When you re-add the same certificate chain again, and the certificate becomes active once more, you will probably find that the private key on the token is being used.

The same thing applies when i manually delete the private key from the smart card - it doesnt work either, cant move private key to smartcard again - once i did it, and delete it again - i cannot do it again - i have to use an older copy of my ID file which never had that key.

Notes doesn’t currently cleanly handle having objects on the token that it needs being deleted out from under it. I’ve written an SPR (DKEN5V2PRT) to add a few more checks to the “move private key to smartcard” process.

Second Problem, Encrypted Messages do not use the private key on the smartcard for decrytion - i do not know how this is possibile - i can manually delete the private key from the smartcard and notes is still able to decrypt, after deletion however - signing is not possibile (the way it should).

Your default signing certificate is configured in the ID file, but the default encryption certificate is configured in the public directory. Check your person record in the public directory that the sender is using and confirm that your “exported” certificate is the default encryption certificate. Once the sender is encrypting with the correct key, that particular problem should go away. When you export a private key to the token, the copy of the key in the ID file is deleted, so it’s definitely not decrypting with a copy of the key in the ID file.

Good luck, and let us know how it turns out.

dave

Subject: RE: SmardCard Delete Key Problem / Decrypt Message ambiguity

Hi Dave,

thanks for the answers - a few clarifcations please :

Leaf certificates (with private keys) aren’t actually deleted

from the ID file, because then you would lose access to mail that was encrypted

to that certificate – they are just no longer displayed, and cannot be

“actively” used. When you re-add the same certificate chain again, and the

certificate becomes active once more, you will probably find that the private

key on the token is being used.

So, notes is smart enough to sign my documents ones again ? This seemed not to

work @ Version 6.02 - i double check.

Notes doesn’t currently cleanly handle having objects on the token that it

needs being deleted out from under it. I’ve written an SPR (DKEN5V2PRT) to add

a few more checks to the “move private key to smartcard” process.

Could you supply my a download link ? Ive searched the download section and

didnt find it - or do i need business partner access ? Furthermore - when will

this SPR be applied to an official release ?

Your default signing certificate is configured in the ID file, but the default

encryption certificate is configured in the public directory. Check your person

record in the public directory that the sender is using and confirm that your

“exported” certificate is the default encryption certificate. Once the sender

is encrypting with the correct key, that particular problem should go away.

When you export a private key to the token, the copy of the key in the ID file

is deleted, so it’s definitely not decrypting with a copy of the key in the ID

file.

Well, i guess you are right - the problem was the notes client didnt use x509

encryption but notes encryption. AFAIK i can only supply public keys from

signed emails - i cannot import them directly into my NAB or is there a way to

change that programmatically… i mean you were talking about the encryption

certificate settings - but arent these taken from the Domino Server NAB and not

from the Personal ?

Lastly, another issue ive got so far - how do i switch back from the smartcard

usage of an ID - currently i make a backup copy of the ID file - if i dont want

to use the smartcard anymore i just overwrite my ID file and use it instead of

the other ones… There is a menu “Enable Smartcard Login” … shouldnt there

be an option “Disable Smartcard Login” ?

Thanks for the heads up

Regards

René

BTW : How do you color the text within an response ? My font tags get always parsed out even tho i use brackets

Subject: RE: SmardCard Delete Key Problem / Decrypt Message ambiguity

Snippets from my post in blue, René’s responses to my post in red, and my responses to those responses in black. :slight_smile: Leaf certificates (with private keys) aren’t actually deleted from the ID file, because then you would lose access to mail that was encrypted to that certificate – they are just no longer displayed, and cannot be “actively” used. When you re-add the same certificate chain again, and the certificate becomes active once more, you will probably find that the private key on the token is being used.

So, notes is smart enough to sign my documents ones again ? This seemed not to work @ Version 6.02 - i double check.

You don’t need to re-sign anything. The original signatures were never removed. Adding the exact same certificate again just re-activates the deleted cert and private key.

Notes doesn’t currently cleanly handle having objects on the token that it needs being deleted out from under it. I’ve written an SPR (DKEN5V2PRT) to add a few more checks to the “move private key to smartcard” process.

Could you supply my a download link ? Ive searched the download section and didnt find it - or do i need business partner access ? Furthermore - when will this SPR be applied to an official release ?

Since I only wrote the SPR last Friday, a fix is definitely not downloadable yet. If you want a fix RSN, you should open a support incident, especially since the workaround – don’t delete objects that are in use from the token – is fairly simple.

Your default signing certificate is configured in the ID file, but the default encryption certificate is configured in the public directory. Check your person record in the public directory that the sender is using and confirm that your “exported” certificate is the default encryption certificate. Once the sender is encrypting with the correct key, that particular problem should go away. When you export a private key to the token, the copy of the key in the ID file is deleted, so it’s definitely not decrypting with a copy of the key in the ID file.

Well, i guess you are right - the problem was the notes client didnt use x509 encryption but notes encryption. AFAIK i can only supply public keys from signed emails - i cannot import them directly into my NAB or is there a way to change that programmatically… i mean you were talking about the encryption certificate settings - but arent these taken from the Domino Server NAB and not from the Personal ?

By the “public directory” I was referring to the public NAB on the server, not the personal NAB on the client.

There are several ways to make the client use S/MIME instead of Notes mail. In your location record, you can set “Format for messages addressed to internet addresses” to “MIME Format”, and then address the message to “foo@bar.com” instead of Foo/Bar. In the recipient’s person record on the server’s NAB, you can set “Format preference for incoming mail” to “Prefers MIME”.

You can set the default X.509 encryption cert in the server’s directory by going to the Certificates/Internet Certificates pane in the person record, selecting “Examine Internet Certificates”, and then selecting a certificate from the list box and pressing the “Set as default for encryption” button.

Once the mail being sent is MIME and encrypted and the recipient has an Internet cert in the directory and the cert corresponding to the private key on the smartcard is the default encryption cert, you’ll start seeing the smartcard used for decryption.

And there is an Action for “Import Internet Certificates” that you can use to import X.509 certs from a PKCS#12 file directly into the server’s NAB.

Lastly, another issue ive got so far - how do i switch back from the smartcard usage of an ID - currently i make a backup copy of the ID file - if i dont want to use the smartcard anymore i just overwrite my ID file and use it instead of the other ones… There is a menu “Enable Smartcard Login” … shouldnt there be an option “Disable Smartcard Login” ?

A menu option to “Disable Smartcard Login” would potentially allow users to over-ride administrator policy… if an administrator issues a smartcard to a user, it is expected that the admin wouldn’t want the user to be able to disable smartcard login and keep using his password-protected ID file.

The only supported means of switching back from the smartcard usage of an ID is to use the ID File Recovery feature. But, as you pointed out, just keeping a pre-smartcard copy of the ID around works as well, although keeping password-protected backup copies of the ID file around in a production environment could be considered a security risk.

BTW : How do you color the text within an response ? My font tags get always parsed out even tho i use brackets

I don’t read this forum through a web browser, but it’s fairly trivial to do in the Notes Client. Try asking that to the forum as a whole – odds are that someone here knows. :slight_smile:

Hope that helps,

dave

Subject: RE: SmardCard Delete Key Problem / Decrypt Message ambiguity

Thanks for the answers dave,

lastly - is it possible to create an automatic install for smartcard logins ? I mean, just imagine a company with 1000+ users, the administrator would have to go to every client - select the dll - and enable smartcard login.

Is it possible to write an agent that just ask for the DLL of the smartcard provider and if the dll is valid - the current id is automatically smartcard enabled ?

Regards

René

Subject: Smartcard-enabling an ID file through the C API

The path to the DLL is stored in the PKCS11_Library notes.ini variable, and after setting that you can programatically smartcard-enable an ID file by using the SECManipulateSC API function in a manner similar to the pseudocode below. The full functionality of SECManipulateSC is documented along with the rest of the C API.

SCMCTX Context = NULLSCMCTX;

error = SECManipulateSC (SC_manip_GetVersion,

                         NULLSCMCTX,

			 NULL,

			 &Version,

			 NULL);

/* Initialize the PKCS#11 context.

*/

error = SECManipulateSC (SC_manip_InitializeContext,

			&Context,

			NULL, NULL, NULL);

/* Set up the ID file

*/

error = SECManipulateSC (SC_manip_EnterIDFile,

			&Context,

			 NULL, 

			&dwIDLen,

			IDPath);

/* Unlock the smartcard

*/

error = SECManipulateSC (SC_manip_EnterPIN,

			&Context,

			NULL,

			&dwPINLen,

			PIN);

/* Note – SC_manip_EnterPIN will use an external authentication path if it exists. If the token doesn’t support a protected authentcation path, SC_manip_EnterPIN will use the supplied PIN if one exists or generate a prompt if a NULL or zero-length PIN was used. */

/* Smartcard-enable the ID file

*/

error = SECManipulateSC (SC_manip_SCEnableID,

			&Context,

			NULL,

			&dwNotesIDPasswordLen,

			pNotesIDPassword);

/* Note – SC_manip_SCEnableID will prompt for the password to the ID file if it is not

given as a parameter */

/* Clean up

*/

SECManipulateSC (SC_manip_TerminateContext,

	   &Context, 

             NULL, NULL, NULL);