[Nitrokey HSM] What are C.DevAut and C.DICA?

C.DevAut is the Device Authentication certificate used for P2P authentication and key attestation.

C.DICA is the Device Issuer Certification Authority’s certificate that was used to produce the HSM.

There is also a C.SRCA for the Scheme Root Certification Authority that certifies production facilities. The C.SRCA is placed as trust-anchor in applications (e.g. in OpenSC.

All certificates are Card Verifiable Certificates as defined in BSI TR-03110.

In the Smart Card Shell the certificates are displayed in the shell window:

SmartCard-HSM Version 3.4 on JCOP 3          Free memory 50604 byte
Issuer : CVC id-SC-HSM DICA CAR=DESRCACC100001 CHR=DEDICC0400001     CED=22. Oktober 2015 CXD=21. Oktober 2023 
Device : CVC id-SC-HSM Device CAR=DEDICC0400001 CHR=DECC040100200000 CED=19. August 2020 CXD=21. Oktober 2023
1 Like