Skip to content

Latest commit

 

History

History
255 lines (233 loc) · 5.12 KB

File metadata and controls

255 lines (233 loc) · 5.12 KB

Behavioral differences between PC/SC native implementations

Tests made with a "Yubico YubiKey OTP+FIDO+CCID" (Vendor ID 1050, Device ID 0407) and a Gemalto IDBridge CT30 (Vendor ID 08e6, Device ID 3437). When not specified, it's implied that a YubiKey was used.

Behavioral differences can be attributed to both different PC/SC implementations and to different smartcard reader drivers.

SmartCardReader.connect()

SmartCardReader.connect MS Windows PCSClite macOS
if a transaction is ongoing:
shared mode blocks
exclusive mode fails with SCARD_E_SHARING_VIOLATION
direct mode fails with SCARD_E_SHARING_VIOLATION (behaves as exclusive) works (behaves as shared)
if another connection has exclusive mode:
shared mode SCARD_E_SHARING_VIOLATION
exclusive mode SCARD_E_SHARING_VIOLATION
direct mode SCARD_E_SHARING_VIOLATION works, but there's a protocol mismatch on transmission
direct mode, without concurrent connections:

preferredProtocols: T0|T1

activeProtocol T1 activeProtocol T0|T1 (ie, transmitting will fail)

preferredProtocols undefined

activeProtocol T1 error "invalid value given"

preferredProtocols raw

SCARD_E_NOT_READY activeProtocol raw

SmartCardConnection.startTransaction()

On Microsoft Windows, winscard automatically resets the card if a transaction is kept idle (ie, without any commands being issued) for more than 5 seconds. PCSClite has no such behavior (an idle transaction can be kept indefinitely).

SmartCardConnection.status()

Note that the status in native PC/SC APIs by flags that can be combined and have overlapping meaning (specific ⊂ powered ⊂ present ), unlike in the Web API where status is an enumeration.

This table shows the content of an SCardStatus call after a SCardConnect using the parameters specified in the leftmost column.

device connect() parameters: shared mode, preferred protocols MS Windows PCSClite macOS
YubiKey shared, T0|T1 present | powered, T1 present | powered | specific, T1
Gemalto (with card) shared, T0|T1 present | powered, T1 present | powered | specific, T1
Gemalto (card removed after connection established) shared, T0|T1 SCARD_W_REMOVED_CARD
Gemalto (card removed after connection established and then reinserted) shared, T0|T1 SCARD_W_REMOVED_CARD SCARD_W_RESET_CARD
Gemalto (reader removed after connection established) shared, T0|T1 SCARD_E_SERVICE_STOPPED SCARD_E_READER_UNAVAILABLE
YubiKey direct, undefined absent | powered, undefined Error: invalid value
Gemalto (with card) direct, undefined present, undefined Error: invalid value
Gemalto (without card) direct, undefined absent, undefined Error: invalid value
Gemalto (card inserted after connection established) direct, undefined absent | present, undefined N.A.
Gemalto (card inserted after connection established) direct, raw N.A. 0x7fb7, raw

then SCARD_W_RESET_CARD

YubiKey direct, raw SCARD_E_NOT_READY present | powered | specific, raw

On Windows, when a reader device is removed after a connection is established not only the connection handle is invalidated but also the context handle (resource manager context) as well. Meaning that one has to establish a new resource manager context to continue operation, whereas in PCSClite the context remains unaffected by the reader removal.