FIPS 201 PIV Profiles (Third-Party Applets, Face to Face)

Note:
  • For Gemalto PIV profile (that is, the card with Gemalto PIV applet v1.20), it is necessary to obtain a Gemalto PIV card with configuration “USG 010”.

  • For Oberthur PIV profile, ActivID CMS 4.0 SP2 expects Cosmo card with BAP# 81758.

PIV FIPS201 F2F Java Card – OT 2.3.2 – 2048

PIV2 Profile with OT End-Point applets v2.3.2 (SP 800-73-3)

Supported Devices

Supported Pre-Issuance IDs

Oberthur ID-One PIV 2.3.2 on Cosmo v7

PIV FIPS201 F2F Java Card – OT 2.3.5 / 2.4.0 – 2048

PIV2 Profile with OT End-Point applets v2.3.5 / 2.4.0 (SP 800-73-4)

  • Supports SP 800-73-3 objects, including PIV Discovery, Iris, Key History and Key Management Key objects. It can accommodate 2048-bit PKI keys and the full set of PIV objects is loaded by ActivID CMS (PIV mandatory and optional objects).

  • Only for Oberthur PIV cards with PIV applet v2.3.5 or v2.4.0.

    Note:
    • For Oberthur PIV profiles with Oberthur PIV applet 2.3.5, use BAP #087420 / #087424 / #087465.

    • For Oberthur PIV profiles with Oberthur PIV applet 2.4.0, use BAP #087434.

  • In addition to the card pre-issuance keys, the following keys must be present in the HSM for profile issuance. As these keys are post-issuance keys, they should be generated in the HSM:

    • For the pre-issuance Card AES 128: MK_CM_ACE_AES_16_OPSC_1_ENC, _MAC, _KEK, PIV_CARD_ADMINISTRATOR_KEY_9B_AES_16 (16-byte AES keys)

    • For the pre-issuance Card AES 256: MK_CM_ACE_AES_32_OPSC_1_ENC, _MAC, _KEK, PIV_CARD_ADMINISTRATOR_KEY_9B_AES_32 (32-byte AES keys)

Supported Devices

Supported Pre-Issuance IDs

Oberthur ID-One PIV 2.3.5 on Cosmo v8

Oberthur ID-One PIV 2.4.0 on Cosmo v8

PIV FIPS201 F2F Java Card - IDEMIA ID-One PIV 2.4.X - 2048

PIV / CIV Profile with IDEMIA End-Point applets v2.4.1 and v2.4.2 (SP800-73-4)

  • Supports SP 800-73-4 objects, including PIV Discovery, Iris, Key History and Key Management Key objects.

  • Only for IDEMIA PIV cards with PIV applet v2.4.1 or v2.4.2.

    Note:
    • For IDEMIA PIV profiles with IDEMIA PIV applet 2.4.1, use BAP #087484.

    • For IDEMIA PIV profiles with IDEMIA PIV applet 2.4.2, use BAP #087584.

  • VCI application is available.

  • PIN is numeric only.

  • In addition to the card pre-issuance keys, the following keys must be present in the HSM for profile issuance. As these keys are post-issuance keys, they should be generated in the HSM:

    • For the pre-issuance Card AES 128: MK_CM_ACE_AES_16_OPSC_1_ENC, _MAC, _KEK, PIV_CARD_ADMINISTRATOR_KEY_9B_AES_16 (16-byte AES keys)

    • For the pre-issuance Card AES 256: MK_CM_ACE_AES_32_OPSC_1_ENC, _MAC, _KEK, PIV_CARD_ADMINISTRATOR_KEY_9B_AES_32 (32-byte AES keys)

Supported Devices

Supported Pre-Issuance IDs

Oberthur ID-One PIV 2.4.1 on Cosmo v8.1 (BAP 087484)

Oberthur ID-One PIV 2.4.2 on Cosmo v8.2 (BAP 087584)