FIPS 201 PIV Profiles (Service Bureau)

Note: These profiles are deprecated and can no longer be used to create new device policies. They are included for legacy purposes.
Note:  
  • For Gemalto PIV profile (that is, card with Gemalto PIV applet v1.20), it is necessary to obtain a Gemalto PIV card with configuration “USG 010”.

  • For Oberthur PIV profile, ActivID CMS 4.0 SP2 expects Cosmo card with BAP# 81758.

  • For Oberthur PIV profiles with Oberthur PIV applet 2.3.2, use BAP #087282.

  • For Oberthur PIV profiles with Oberthur PIV applet 2.3.5, use BAP #087420 / #087424 / #087465.

  • For Oberthur PIV profiles with Oberthur PIV applet 2.4.0, use BAP #087434.

  • For IDEMIA PIV profiles with IDEMIA PIV applet 2.4.1, use BAP #087484

  • For PIV FIPS201 SB Activation Java Card - IDEMIA ID-One PIV 2.4.1 - 2048 profile, PIN is numeric only.

These profiles activate the PIV cards personalized by the card manufacturer service bureau. The card activation Card activation refers to the unlocking of an application or GlobalPlatform locked card. This operation is usually associated with batch issuance and help desk operations. In the context of PIV, card activation implies PIN authentication to the PIV card to “activate” privileged operations. In the context of BMS, card activation refers to the tasks required to complete the issuance of a card after its receipt from the service bureau that produced it process consists of:

  • Injecting and generating the PKI credentials (PKI 1024 or 2048),

  • Swapping the Card Manager keys,

  • Swapping the PIV Card Administrator key (9B), and

  • Setting up the PIV Local PIN for the user and setting up the PUK.

PIV FIPS201 SB Activation Java Card – OCS

PIV2 Activation Profile with OCS End-Point applets v1.08. Card with Oberthur PIV applet v1.08.

Note: This profile is deprecated and can no longer be used to create new device policies. It is included for legacy purposes.

Supported Devices

Supported Pre-Issuance IDs

Oberthur ID-One Cosmo v5.2D 64K Fast ATR with PIV application SDK

PIV FIPS201 SB Activation Java Card – OCS 1024/2048

PIV2 Activation Profile with OCS End-Point applets v1.08. Card with Oberthur PIV applet v1.08.

Note: This profile is deprecated and can no longer be used to create new device policies. It is included for legacy purposes.

Supported Devices

Supported Pre-Issuance IDs

Oberthur ID-One Cosmo v5.2D 64K Fast ATR with PIV application SDK

PIV FIPS201 SB Activation Java Card – OCS 2048

PIV2 Activation Profile with OCS End-Point applets v1.08. Card with Oberthur PIV applet v1.08.

Note: This profile is deprecated and can no longer be used to create new device policies. It is included for legacy purposes.

Supported Devices

Supported Pre-Issuance IDs

Oberthur ID-One Cosmo v5.2D 64K Fast ATR with PIV application SDK

PIV FIPS201 SB Activation Java Card – Gemalto

PIV2 Activation Profile for Gemalto SafesITe applets v1.20. Card With Gemalto PIV applet SafeSite v1.20.

Note: This profile is deprecated and can no longer be used to create new device policies. It is included for legacy purposes.

Supported Devices

Supported Pre-Issuance IDs

Gemalto TOP DM GX4 FIPS with PIV application

PIV FIPS201 SB Java Card – Gemalto 1.55 – 2048

PIV2 Activation Profile for Gemalto applets V1.55 (SP 800-73-3). Card with Gemalto PIV applet v1.55.

Note: This profile is deprecated and can no longer be used to create new device policies. It is included for legacy purposes.

Supported Devices

Supported Pre-Issuance IDs

Gemalto TOP DL GX4 FIPS with PIV application