Smartcard authentication in 10 steps

Configuration is done using the sdtsmartcardadmin GUI from /usr/dt/bin.

This example uses an internal card reader with PayFlex cards.

  1. Select 'Add Reader' and chose the only internal model available.

  2. Activate smartcard services by restarting the OCF server (automatic after finishing first step).

  3. In the 'Card Services' menu, select PayFlex and activate services for this type of card.

  4. Click the 'Smart cards' item from the menu and load the ATR (answer to reset) for this card. Note: this is not one of the ATRs in the list that you sometimes get to see, you have to click 'Add' and select the new card's ATR.

  5. In the 'Load Applet' menu, select the authentication applet (the only one currently available) and load it onto the card. If the card already contains the applet, because it has been used before, you get an error. Applets can not be removed from this type of card!

  6. Select 'Config Applet', set the PIN (defaults to $$$$java) and select the username of the person that will be using the card. In my experience, user passwords should be max. 8 characters long for authentication via smartcard to work.

  7. Configure removal options (in the tabs).

  8. Log out.

  9. Insert card.

  10. Test PIN and login.

