I meant, I had not seen this announce yet, at all. And yes I am aware we are told all things smartcard are supposed to be on another list, but I had not seen it announced anywhere and to be honest, I feel it is very relevant on this list since we have Federal mandates like M-11-11. It is the main reason I’m on this list.
One thing I’ve noticed is that the PKCS#11 shim is gone in Mountain Lion. Even after this new installer.
Also, if anyone in the Federal Government is working with a PKINIT implementation based on native support, please contact me. At NASA we had been told Apple and OS X Forge stopped this effort and have heard nothing since; so the new installers mentioning the PKINIT implementation is a surprise to us. We’d like to check out anything new in this area.
-Ridley
From: fed-talk-bounces+ridley.disiena=email@hidden [mailto:fed-talk-bounces+ridley.disiena=email@hidden] On Behalf Of Disiena, Ridley J. (GRC-VO00)[DB Consulting Group, Inc.]
Sent: Friday, September 28, 2012 8:36 AM
To: email@hidden
Subject: [Fed-Talk] Updated smartcard installer?
I didn’t see this announced yet on this list:
http://smartcardservices.macosforge.org/trac/wiki/installers
(1) **NEW** Smart Card Services Update v2.0.b2-MtLion (Sep 18, 2012)
OS Requirement: OS X Mountain Lion v10.8
SHA-1 Hash: 4b012dd7a8f39f68311a6f48aa734c9231ac1e3f
This installs the Tokend modules which no longer ship from Apple as part of Mac OS X beginning with OS X Lion (v10.7). Note that this installer will ONLY install onto OS X Mountain Lion v10.8. The Tokend modules installed are: BELPIC, CAC, CACNG, JPKI and PIV.
New to this release:
• JPKI.Tokend - Build 38522 added to the update to support LASCOM in Japan.
• cacloginconfig.plist - Default configuration file as optional install for those using Attribute Matching or PKINIT configurations.
• SystemCACertificates.keychain - Automatically added to the Keychain Search List if not already present.
Interesting that they are still suggesting attribute matchine, is that not worse than using a password?
Ridley DiSiena - CISSP
ETADS - ICAM Device Integration (IDI) / NASA ICAM Engineering
email@hidden