Supported Attributes
All the attributes conform to the PKCS#11 Cryptographic Token Interface Standard v2.40.
The following tables list the attributes implemented in the Crescendo PKCS#11 API:
General Object Attributes
| Attribute | Supported |
| CKA_CLASS | Yes |
| CKA_TOKEN | Yes |
| CKA_PRIVATE | Yes |
| CKA_LABEL | Yes 2 |
| CKA_APPLICATION | Yes 3 |
| CKA_VALUE | Yes |
| CKA_OBJECT_ID | No |
| CKA_MODIFIABLE | Yes 1 |
| CKA_COPYABLE | Yes 1 |
| CKA_DESTROYABLE | Yes 1 |
Notes
1. Always set to FALSE (0) in this release 2. The CKA_LABEL is read only in this release 3. The value is always PIV in this release
Certificate Object Attributes
| Attribute | Supported |
| CKA_CERTIFICATE_TYPE | Yes 1 |
| CKA_TRUSTED | Yes 2 |
| CKA_CERTIFICATE_CATEGORY | Yes |
| CKA_CHECK_VALUE | Yes |
| CKA_START_DATE | Yes |
| CKA_END_DATE | Yes |
| CKA_PUBLIC_KEY_INFO | Yes |
| CKA_SUBJECT | Yes |
| CKA_ID | Yes |
| CKA_ISSUER | Yes |
| CKA_SERIAL_NUMBER | Yes |
| CKA_URL | Yes 3 |
| CKA_HASH_OF_SUBJECT_PUBLIC_KEY | Yes |
| CKA_HASH_OF_ISSUER_PUBLIC_KEY | Yes 3 |
| CKA_JAVA_MIDP_SECURITY_DOMAIN | Yes 4 |
Notes
1. In this release, the library will always report the value CKC_X_509 for this attribute 2. In this release, the library will always report the value TRUE (1) for this attribute 3. In this release, the library will always report an empty value for this attribute 4. In this release, the library will always report the value CK_SECURITY_DOMAIN_UNSPECIFIED for this attribute
Key Object Attributes
| Attribute | Supported |
| CKA_KEY_TYPE | Yes |
| CKA_SUBJECT | Yes 1 |
| CKA_ID | Yes 6 |
| CKA_SENSITIVE | Yes |
| CKA_ENCRYPT | Yes 4 |
| CKA_DECRYPT | Yes 4 |
| CKA_WRAP | Yes 4 |
| CKA_UNWRAP | Yes 4 |
| CKA_SIGN | Yes 4 |
| CKA_SIGN_RECOVER | Yes 4 |
| CKA_VERIFY | Yes 4 |
| CKA_VERIFY_RECOVER | Yes 4 |
| CKA_DERIVE | Yes 4 |
| CKA_START_DATE | Yes 1 |
| CKA_END_DATE | Yes 1 |
| CKA_MODULUS | Yes |
| CKA_MODULUS_BITS | Yes |
| CKA_PUBLIC_EXPONENT | Yes |
| CKA_PRIVATE_EXPONENT | Yes 3 |
| CKA_PRIME_1 | Yes 3 |
| CKA_PRIME_2 | Yes 3 |
| CKA_EXPONENT_1 | Yes 3 |
| CKA_EXPONENT_2 | Yes 3 |
| CKA_COEFFICIENT | Yes 3 |
| CKA_PUBLIC_KEY_INFO | Yes |
| CKA_PRIME | No |
| CKA_SUBPRIME | No |
| CKA_BASE | No |
| CKA_PRIME_BITS | No |
| CKA_SUB_PRIME_BITS | No |
| CKA_VALUE_BITS | Yes |
| CKA_VALUE_LEN | Yes |
| CKA_EXTRACTABLE | Yes |
| CKA_LOCAL | Yes 2 |
| CKA_NEVER_EXTRACTABLE | Yes |
| CKA_ALWAYS_SENSITIVE | Yes |
| CKA_KEY_GEN_MECHANISM | Yes 3 |
| CKA_ECDSA_PARAMS | No |
| CKA_EC_PARAMS | Yes |
| CKA_EC_POINT | Yes |
| CKA_SECONDARY_AUTH | No |
| CKA_AUTH_PIN_FLAGS | No |
| CKA_ALWAYS_AUTHENTICATE | Yes 2 |
| CKA_WRAP_WITH_TRUSTED | Yes 5 |
| CKA_GOSTR3410_PARAMS | No |
| CKA_GOSTR3411_PARAMS | No |
| CKA_GOST28147_PARAMS | No |
Notes
1. Only available if the key has a corresponding certificate on the card. 2. In this release, this will always be set to TRUE (1) 3. In this release, this will always return CK_UNAVAILABLE_INFORMATION 4. These attributes are determined on the usage attribute of the associated certificate, if available. In the future, the algorithm to determine this may change so applications should not rely on these values. These attributes should be considered as unsupported in the current release. 5. In this release, this will always be set to FALSE (0) 6. The CKA_ID, a sequence of raw bytes, is a "key identifier", which is used to tie together the associated certificate, public key and private key. If the associated certificate contains the SKI extension, it's value should match the CKA_ID. The CKA_ID value may or may not also be stored on the token.
Hardware Feature Object Attributes
| Attribute | Supported |
| CKA_HW_FEATURE_TYPE | No |
| CKA_RESET_ON_INIT | No |
| CKA_HAS_RESET | No |
Domain Parameters Object Attributes
| Attribute | Supported |
| CKA_PRIME | No |
| CKA_SUBPRIME | No |
| CKA_BASE | No |
| CKA_PRIME_BITS | No |
| CKA_SUB_PRIME_BITS | No |
| CKA_VALUE_BITS | No |
| CKA_VALUE_LEN | No |
OTP Object Attributes
| Attribute | Supported |
| CKA_OTP_FORMAT | No |
| CKA_OTP_LENGTH | No |
| CKA_OTP_TIME_INTERVAL | No |
| CKA_OTP_USER_FRIENDLY_MODE | No |
| CKA_OTP_CHALLENGE_REQUIREMENT | No |
| CKA_OTP_TIME_REQUIREMENT | No |
| CKA_OTP_COUNTER_REQUIREMENT | No |
| CKA_OTP_PIN_REQUIREMENT | No |
| CKA_OTP_USER_IDENTIFIER | No |
| CKA_OTP_SERVICE_IDENTIFIER | No |
| CKA_OTP_SERVICE_LOGO | No |
| CKA_OTP_SERVICE_LOGO_TYPE | No |
| CKA_OTP_COUNTER | No |
| CKA_OTP_TIME | No |
Supported Mechanisms
All the mechanisms conform to the PKCS#11 Cryptographic Token Interface Standard v2.40 and to the PKCS #11 Cryptographic Token Interface Current Mechanisms Specification Version 2.40.
The following table lists the mechanisms implemented in the Crescendo PKCS#11 API:
| Mechanism | Description | Supported |
| CKM_RSA_X_509 | X.509 (raw) RSA mechanism | Yes |
| CKM_RSA_PKCS_OAEP | PKCS #1 RSA OAEP mechanism | Yes |
| CKM_RSA_PKCS_KEY_PAIR_GEN | PKCS #1 RSA key pair generation mechanism | No |
| CKM_RSA_PKCS | PKCS #1 v1.5 RSA mechanism | Yes |
| CKM_RSA_PKCS_PSS | PKCS #1 RSA PSS mechanism | Yes |
| CKM_SHA1_RSA_PKCS_PSS | PKCS #1 RSA PSS signature with SHA-1 mechanism | Yes |
| CKM_SHA256_RSA_PKCS_PSS | PKCS #1 RSA PSS signature with SHA-256 mechanism | Yes |
| CKM_SHA512_RSA_PKCS_PSS | PKCS #1 RSA PSS signature with SHA-512 mechanism | Yes |
| CKM_SHA1_RSA_PKCS | PKCS #1 v1.5 RSA signature with SHA-1 mechanism | Yes |
| CKM_SHA256_RSA_PKCS | PKCS #1 v1.5 RSA signature with SHA-256 mechanism | Yes |
| CKM_SHA512_RSA_PKCS | PKCS #1 v1.5 RSA signature with SHA-512 mechanism | Yes |
Supported Functions
All the functions conform to the PKCS#11 Cryptographic Token Interface Standard v2.40.
The following tables list the functions implemented in the Crescendo PKCS#11 API:
General Purpose Functions
| Function | Description | Supported |
| C_Initialize | Initializes Cryptoki | Yes1 |
| C_Finalize | Cleans up miscellaneous Cryptoki-associated resources | Yes |
| C_GetInfo | Obtains general information about Cryptoki | Yes |
| C_GetFunctionList | Obtains entry points of Cryptoki library functions | Yes |
Notes
1. The current implementation only fully supports single-threaded use with the CKF_LIBRARY_CANT_CREATE_OS_THREADS flag set. Although the C_Initialize function will always successfully return, the library is not guaranteed to respect the C_Initialize parameters. In particular, the library may create threads even when CKF_LIBRARY_CANT_CREATE_OS_THREADS is set, the library may use system threads even when provided pointers to custom mutex functions and the library may malfunction when accessed in parallel from multiple threads. In future versions, the C_Initialize call will likely fail in unsupported scenarios.
Slot and Token Management Functions
Session Management Functions
Object Management Functions
Notes
1. The function supports deleting public/private keys and certificates only. On C4000 tokens, when a public (or private key) is deleted, the associated private (or public) key will be deleted as well. 2. Only the CKA_ID attribute for public/private keys and certificates is supported. When it is set on one object in a public/private key and certificate triple, it is automatically updated for the other objects in the triple.
Encryption Functions
| Function | Description | Supported |
| C_EncryptInit | Initializes an encryption operation | Yes |
| C_Encrypt | Encrypts single-part data | Yes |
| C_EncryptUpdate | Continues a multiple-part encryption operation | Yes |
| C_EncryptFinal | Finishes a multiple-part encryption operation | Yes |
Decryption Functions
| Function | Description | Supported |
| C_DecryptInit | Initializes a decryption operation | Yes |
| C_Decrypt | Decrypts single-part encrypted data | Yes |
| C_DecryptUpdate | Continues a multiple-part decryption operation | Yes |
| C_DecryptFinal | Finishes a multiple-part decryption operation | Yes |
Message Digest Functions
| Function | Description | Supported |
| C_DigestInit | Initializes a message-digesting operation | No |
| C_Digest | Digests single-part data | No |
| C_DigestUpdate | Continues a multiple-part message-digesting operation | No |
| C_DigestKey | Digests the value of a secret key as part of a message-digesting operation | No |
| C_DigestFinal | Finishes a multiple-part message-digesting operation | No |
Signing and MACing Functions
| Function | Description | Supported |
| C_SignInit | Initializes a signature (private key encryption) operation | Yes |
| C_Sign | Signs single-part data | Yes |
| C_SignUpdate | Continues a multiple-part signature operation | Yes |
| C_SignFinal | Finishes a multiple-part signature operation | Yes |
| C_SignRecoverInit | Initializes a signature operation, where the data can be recovered from the signature | No |
| C_SignRecover | Signs data, where the data can be recovered from the signature | No |
Verifying Signatures and MACs Functions
| Function | Description | Supported |
| C_VerifyInit | Initializes a verification operation, where the signature is an appendix to the data | Yes |
| C_Verify | Verifies a signature, where the signature is an appendix to the data | Yes |
| C_VerifyUpdate | Continues a multiple-part verification operation | Yes |
| C_VerifyFinal | Finishes a multiple-part verification operation | Yes |
| C_VerifyRecoverInit | Initializes a verification operation, where the data is recovered from the signature | No |
| C_VerifyRecover | Verifies a signature, where the data is recovered from the signature | No |
Dual-Purpose Cryptographic Functions
Key Management Functions
| Function | Description | Supported |
| C_GenerateKey | Generates a secret key, creating a new key object | No |
| C_GenerateKeyPair | Generates a public/private key pair, creating new key objects | Yes |
| C_WrapKey | Wraps (encrypts) a key, creating a wrapped key object | No |
| C_UnwrapKey | Unwraps (decrypts) a wrapped key, creating a new key object | No |
| C_DeriveKey | Derives a key from a base key, creating a new key object | No |
Random Number Generation Functions
| Function | Description | Supported |
| C_SeedRandom | Mixes additional seed material into the token’s random number generator | No |
| C_GenerateRandom | Generates random data | No |
Legacy Parallel Function Management Functions
HID Proprietary Extensions
PIN Unblock Functions
The module additionally supports the following proprietary functions & mechanism allowing to unblock a PIN using a PUK code:
When the module is loaded as a dynamical library using the dlopen method, the functions can be accessed using dlsym, e.g. in C++,
extern CK_RV
C_VerifyUnblockPINInit(CK_SESSION_HANDLE hSession, CK_MECHANISM_PTR pMechanism, CK_OBJECT_HANDLE hPuk);
extern CK_RV
C_VerifyUnblockPIN(CK_SESSION_HANDLE hSession, CK_UTF8CHAR_PTR pNewPin, CK_ULONG ulNewLen, CK_UTF8CHAR_PTR pPuk, CK_ULONG ulPukLen);
...
auto lib = dlopen("libactivclient-pkcs11.so", RTLD_LAZY | RTLD_DEEPBIND);
dlsym(lib, "C_VerifyUnblickPINInit")
);
dlsym(lib, "C_VerifyUnblickPIN")
);
auto unblock_f = dlsym(lib, "C_VerifyUnblickPIN");
...
auto rv = unblock_init_f(session, &mech, hPuk);
...
AC_EXPORT CK_RV C_VerifyUnblockPINInit(CK_SESSION_HANDLE hSession, CK_MECHANISM_PTR pMechanism, CK_OBJECT_HANDLE hPuk)
Initializes a PIN unblock operation.
AC_EXPORT CK_RV C_VerifyUnblockPIN(CK_SESSION_HANDLE hSession, CK_UTF8CHAR_PTR pNewPin, CK_ULONG ulNewLen, CK_UTF8CHAR_PTR pPuk, CK_ULONG ulPukLen)
Performs a PIN unblock operation, which was previously initialized by C_VerifyUnblockPINInit.