PKI Object Overview

HID Crescendo Cards and Keys manage a set of PKI objects, which may contain private keys, certificates, and associated data structures. These objects are accessed using their standard identifiers, as specified in NIST SP 800-73.

You can retrieve the list of populated PKI objects and their configuration using the GET PROPERTIES command.

Note: The information provided below is applicable only to devices belonging to the Crescendo 4000 family.

Standard PIV Objects

Container Description BER-TLV Tag Key Reference Default Buffer Read / Write Access Rules

Certificate for Authentication

5FC105

9A

Always / PIN

Certificate for Digital Signature

5FC10A

9C

Always / PIN

Certificate for Key Management

5FC10B

9D

Always / PIN

Certificate for Card Authentication

5FC101

9E

Always / PIN

Certificate for Key Management 1

5FC10D

82

Always / PIN

Certificate for Key Management 2

5FC10E

83

Always / PIN

Certificate for Key Management 3

5FC10F

84

Always / PIN

Certificate for Key Management 4

5FC110

85

Always / PIN

Certificate for Key Management 5

5FC111

86

Always / PIN

Certificate for Key Management 6

5FC112

87

Always / PIN

Certificate for Key Management 7

5FC113

88

Always / PIN

Certificate for Key Management 8

5FC114

89

Always / PIN

Certificate for Key Management 9

5FC115

8A

Always / PIN

Certificate for Key Management 10

5FC116

8B

Always / PIN

Certificate for Key Management 11

5FC117

8C

Always / PIN

Certificate for Key Management 12

5FC118

8D

Always / PIN

Certificate for Key Management 13

5FC119

8E

Always / PIN

Certificate for Key Management 14

5FC11A

8F

Always / PIN

Certificate for Key Management 15

5FC11B

90

Always / PIN

Certificate for Key Management 16

5FC11C

91

Always / PIN

Certificate for Key Management 17

5FC11D

92

Always / PIN

Certificate for Key Management 18

5FC11E

93

Always / PIN

Certificate for Key Management 19

5FC11F

94

Always / PIN

Certificate for Key Management 20

5FC120

95

Always / PIN

Card Capability Container (CCC)

5FC107

-

Always / PIN

Cardholder Unique Identifier

5FC102

-

Always / PIN

Printed Information

5FC109

-

PIN / PIN

Cardholder Facial Image

5FC108

-

PIN / PIN

Cardholder Fingerprints

5FC103

-

Always / PIN

Other C4000 Custom Objects (Non-PIV)

Container Description BER-TLV Tag Key Reference Default Buffer Read / Write Access Rules

General-Purpose Certificate 1

5FC160

B0

PIN / PIN **

General-Purpose Certificate 2

5FC161

B1

PIN / PIN **

General-Purpose Certificate 3

5FC162

B2

PIN / PIN **

General-Purpose Certificate 4

5FC163

B3

PIN / PIN **

General-Purpose Certificate 5

5FC164

B4

PIN / PIN **

General-Purpose Certificate 6

5FC165

B5

PIN / PIN **

General-Purpose Certificate 7

5FC166

B6

PIN / PIN **

General-Purpose Certificate 8

5FC167

B7

PIN / PIN **

General-Purpose Certificate 9

5FC168

B8

PIN / PIN **

General-Purpose Certificate 10

5FC169

B9

PIN / PIN **

General-Purpose Certificate 11

5FC16A

BA

PIN / PIN **

General-Purpose Certificate 12

5FC16B

BB

PIN / PIN **

General-Purpose Certificate 13

5FC16C

BC

PIN / PIN **

General-Purpose Certificate 14

5FC16D

BD

PIN / PIN **

General-Purpose Certificate 15

5FC16E

BE

PIN / PIN **

General-Purpose Certificate 16

5FC16F

BF

PIN / PIN **

Cache Freshness Object*

5FC151

-

Always / PIN

Important:

* To prevent issues caused by stale cache data, the Cache Freshness Object should be updated whenever other data on the device is modified. Other HID software (e.g., Crescendo Minidriver, Crescendo Manager, ActivClient) reads this object, compares it to its cached value, and triggers a re-read of the device content if the value has changed. For more details, see Expected Value of the Cache Freshness Object Container.

** Under the default access control rules, General-Purpose PKI object are ignored by the Minidriver and other software because reading of the certificate buffer is protected by a PIN. The access control rules can be updated. See Update PIV Object Access Control Rules.

Expected Value of the Cache Freshness Object Container

The expected value of the Cache Freshness Object container is:

Length Value Description

01h

53h

Container tag

01h

0Ah

Container length

01h

44h

Cache freshness tag

01h

08h

Cache freshness length

08h

Random bytes

Cache freshness value

Topics in this section: