Versions Compared
Key
- This line was added.
- This line was removed.
- Formatting was changed.
This article describes the Card Verifiable Certificate (CVC), which is a special certificate type that can be created in Smart ID Certificate Manager (CM).
The CVC is a certificate type used with:
- Smart cards in German health control, also called "elektronische Gesundheitskarten"
- Machine-readable travel documents and eIDAS tokens, used in German ID cards (Personalausweis) and European passports and driving licenses
The purpose of the CVC is to verify the card itself, and to provide a mutual authentication mechanism between terminal and chip.
Some of the characteristics are:
- The CVC contains only a small amount of data
- Part of the key and attributes are contained in the signature and/or certificate. This makes it possible to recover this data during authentication.
CM supports CVCs for root CAs, subordinate/intermediate CAs, link CAs and for issuing card-holder or client CVCs. The format of the CVC is identified by the Certificate Profile Identifier (CPI), which is part of the certificate itself. See the "Card Verifiable Certificate (CVC) Formats" chapter in the Technical Description for a list of supported CPIs in CM.
You use Administrator's workbench (AWB) in Certificate Manager (AWB) for for these tasks.
Prerequisites
Expand | ||
---|---|---|
| ||
See the prerequisites in Create CA key in Certificate Manager and Create CA in Certificate Manager. |
Step-by-step instruction
Expand | ||
---|---|---|
| ||
|
Expand | ||
---|---|---|
| ||
|
Expand | ||
---|---|---|
| ||
There are two options to create a Link CA: Manually
Use Create Link CVCA button
|
Expand | ||
---|---|---|
| ||
All the necessary preparations for CVCs have now been made. Use the CM Software Development Kit (SDK) to issue the certificates. |