Opensc: epass 2003 - Failed to erase card

Created on 27 May 2016  路  15Comments  路  Source: OpenSC/OpenSC

Expected behaviour

What should happen?

epass 2003 should be erased

Actual behaviour

What happens instead?

pkcs15-init -E gives the following error:

root@ubuntu:~# pkcs15-init -E
Using reader with a card: Feitian ePass2003 00 00
Failed to erase card: Security status not satisfied

Steps to reproduce

  1. connect epass 2003
  2. pkcs15-init -E

    Logs

pkcs15-init -E -vvv logs

Most helpful comment

Source code for Fix_tool is needed, otherwise we cannot know whether the Fix_tool do something other than fixing the token.

All 15 comments

Please contact @FeitianSmartcardReader, they can provide you a tool to fix that problem.
Still on my todo list to update the Wiki.

@jursonovicst Please send mail to [email protected], he will give you a tool, thanks

Thank you...

@FeitianSmartcardReader it would be convenient if you could post the tool here. I also have the same problem, and I request you to send me the tool. I've sent you a mail already (from mail at aurabindo dot in). kindly respond to that.

Also having this issue with two different devices. @FeitianSmartcardReader dropped the address above an email.

did you send mail to us? We didn't receive your mail, please send mail to us, thanks
[email protected] and copy [email protected]

@FeitianSmartcardReader Have sent again to both addresses. Should be coming from --removed--

@alistairmackenzie We finish linux tool, check and download from below:
Fix_tool
After running fix-tool by root, please do re-plug token/card

Source code for Fix_tool is needed, otherwise we cannot know whether the Fix_tool do something other than fixing the token.

Hey ;)
I am trying to run:

sudo pkcs15-init --store-certificate cs.pem --auth-id 01 --id 01 --format pem -vvv

but it gives me the following output...

00 20 00 F4 08 31 32 33 34 35 36 37 38 . ...12345678
0x7f16f2344700 16:24:07.848 [pkcs15-init] reader-pcsc.c:212:pcsc_internal_transmit: called
0x7f16f2344700 16:24:07.860 [pkcs15-init] reader-pcsc.c:293:pcsc_transmit: 
Incoming APDU (2 bytes):
6A 81 j.
0x7f16f2344700 16:24:07.860 [pkcs15-init] apdu.c:390:sc_single_transmit: returning with: 0 (Success)
0x7f16f2344700 16:24:07.860 [pkcs15-init] apdu.c:543:sc_transmit: returning with: 0 (Success)
0x7f16f2344700 16:24:07.860 [pkcs15-init] card.c:459:sc_unlock: called
0x7f16f2344700 16:24:07.860 [pkcs15-init] card-cardos.c:313:cardos_check_sw: function/mode not supported
0x7f16f2344700 16:24:07.860 [pkcs15-init] card-cardos.c:1232:cardos_pin_cmd: returning with: -1408 (Not supported)
0x7f16f2344700 16:24:07.860 [pkcs15-init] sec.c:216:sc_pin_cmd: returning with: -1408 (Not supported)
0x7f16f2344700 16:24:07.860 [pkcs15-init] pkcs15-lib.c:3754:sc_pkcs15init_verify_secret: 'VERIFY' pin cmd failed: -1408 (Not supported)
0x7f16f2344700 16:24:07.860 [pkcs15-init] pkcs15-lib.c:3816:sc_pkcs15init_authenticate: returning with: -1408 (Not supported)
0x7f16f2344700 16:24:07.860 [pkcs15-init] pkcs15-lib.c:3884:sc_pkcs15init_create_file: Cannot create file: 'CREATE' authentication failed: -1408 (Not supported)
0x7f16f2344700 16:24:07.860 [pkcs15-init] pkcs15-lib.c:3929:sc_pkcs15init_update_file: Failed to create file: -1408 (Not supported)
0x7f16f2344700 16:24:07.860 [pkcs15-init] pkcs15-lib.c:2245:sc_pkcs15init_store_data: returning with: -1408 (Not supported)
0x7f16f2344700 16:24:07.860 [pkcs15-init] pkcs15-lib.c:2042:sc_pkcs15init_store_certificate: returning with: -1408 (Not supported)
0x7f16f2344700 16:24:07.860 [pkcs15-init] card.c:459:sc_unlock: called
0x7f16f2344700 16:24:07.860 [pkcs15-init] reader-pcsc.c:662:pcsc_unlock: called
Failed to store certificate: Not supported
0x7f16f2344700 16:24:07.868 [pkcs15-init] pkcs15-lib.c:430:sc_pkcs15init_unbind: called
0x7f16f2344700 16:24:07.868 [pkcs15-init] pkcs15-lib.c:431:sc_pkcs15init_unbind: Pksc15init Unbind: 1:0x2466660:1
0x7f16f2344700 16:24:07.868 [pkcs15-init] pkcs15-lib.c:3012:sc_pkcs15init_update_lastupdate: called
0x7f16f2344700 16:24:07.868 [pkcs15-init] pkcs15-lib.c:2978:sc_pkcs15init_update_tokeninfo: called
0x7f16f2344700 16:24:07.868 [pkcs15-init] pkcs15-lib.c:3913:sc_pkcs15init_update_file: called
0x7f16f2344700 16:24:07.868 [pkcs15-init] pkcs15-lib.c:3917:sc_pkcs15init_update_file: path:3f0050155032; datalen:297
0x7f16f2344700 16:24:07.868 [pkcs15-init] card.c:748:sc_select_file: called; type=2, path=3f0050155032
0x7f16f2344700 16:24:07.868 [pkcs15-init] card-cardos.c:484:cardos_select_file: called
0x7f16f2344700 16:24:07.868 [pkcs15-init] apdu.c:554:sc_transmit_apdu: called
0x7f16f2344700 16:24:07.868 [pkcs15-init] card.c:407:sc_lock: called
0x7f16f2344700 16:24:07.868 [pkcs15-init] reader-pcsc.c:612:pcsc_lock: called
0x7f16f2344700 16:24:07.868 [pkcs15-init] card.c:449:sc_lock: returning with: 0 (Success)
0x7f16f2344700 16:24:07.868 [pkcs15-init] apdu.c:521:sc_transmit: called
0x7f16f2344700 16:24:07.868 [pkcs15-init] apdu.c:371:sc_single_transmit: called
0x7f16f2344700 16:24:07.868 [pkcs15-init] apdu.c:378:sc_single_transmit: CLA:0, INS:A4, P1:8, P2:0, data(4) 0x7ffee684a302
0x7f16f2344700 16:24:07.868 [pkcs15-init] reader-pcsc.c:283:pcsc_transmit: reader 'Gemalto PC Twin Reader (FFACA692) 00 00'
0x7f16f2344700 16:24:07.868 [pkcs15-init] reader-pcsc.c:284:pcsc_transmit: 

Dont know where the error failed to store certificate: not supported come from
Maybe can you guys help me? I would be very thankful!

Greetings

I'm trying to overcome this problem:

$ pkcs15-init --create-pkcs15 --profile pkcs15+openpin --label 'test'
Using reader with a card: Feitian ePass2003 00 00
New User PIN.
Please enter User PIN: 
Please type again to verify: 
Unblock Code for New User PIN (Optional - press return for no PIN).
Please enter User unblocking PIN (PUK): 
Please type again to verify: 
Failed to create PKCS #15 meta structure: Not allowed

When running the fix-tool posted above it pretends to be working:

# ./FIX_TOOL 
[]===================================================[]
 |              FIX_TOOL_ePass2003/2003Auto         |
 |                                      FT V2.0     |
[]===================================================[]

Fixing.............

Done................

However the problem remains even after replugging the epass2003 usb key. I am able to do a pkcs15-init --erase-card after the fix-tool but the pkcs15-init --create-pkcs15 still fails.

I'm trying to overcome this problem:

$ pkcs15-init --create-pkcs15 --profile pkcs15+openpin --label 'test'
Using reader with a card: Feitian ePass2003 00 00
New User PIN.
Please enter User PIN: 
Please type again to verify: 
Unblock Code for New User PIN (Optional - press return for no PIN).
Please enter User unblocking PIN (PUK): 
Please type again to verify: 
Failed to create PKCS #15 meta structure: Not allowed

When running the fix-tool posted above it pretends to be working:

# ./FIX_TOOL 
[]===================================================[]
 |              FIX_TOOL_ePass2003/2003Auto         |
 |                                      FT V2.0     |
[]===================================================[]

Fixing.............

Done................

However the problem remains even after replugging the epass2003 usb key. I am able to do a pkcs15-init --erase-card after the fix-tool but the pkcs15-init --create-pkcs15 still fails.

I am working with R&D check, we may back to you next Monday or Tuesday, thanks

@RichieB2B can please share your pcsc log for our engineer to check? or is possible to have a remote session to have a look? thanks and looking forward to your reply,

my mail [email protected]

@FeitianSmartcardReader I was all set to record the pcscd logs, but I can't seem to reproduce the issue. pkcs15-init --create-pkcs15 is working again.

Was this page helpful?
0 / 5 - 0 ratings