You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

SAM PSO(执行安全操作):CDS(计算数字签名)6982错误技术问询

Troubleshooting 6982 Error in RSASSA-PSS SHA256 Signature with PSO:CDS

Hey there, that 6982 error (Security status not satisfied) is usually a sign that your card's security context isn't properly set up for RSASSA-PSS signing, or you're missing a required step in the workflow. Let's walk through the key areas to diagnose and fix this:

1. Verify the MSE:SET Command Parameters

Your MSE command is 002241B606800191840110 — let's unpack this to ensure it correctly configures the RSASSA-PSS context:

  • P1=41: Correctly indicates we're setting up for signature generation
  • P2=B6: This value should map to RSASSA-PSS + SHA-256. Some cards use B8 instead of B6 for SHA-256 (depending on ISO 7816-4 mechanism coding) — check your card's docs for the exact value.
  • The data field 06800191840110: For RSASSA-PSS, many cards require explicit specification of PSS parameters (like salt length, which defaults to the hash length, 32 bytes for SHA256). A valid MSE data block for RSASSA-PSS SHA256 might look like 06092A864886F70D01010B032100 (OID for RSASSA-PSS + SHA256 digest parameter).

Try adjusting the MSE command to use the mechanism parameters your card expects.

2. Confirm Private Key File Permissions & Type

You selected the file with 00A40800043D002F0100 (a 9000 response means selection worked), but double-check:

  • Is this EF a signature-specific private key? Cards often separate keys by usage — using an encryption key for signing will trigger security errors.
  • Does this key require extra authentication beyond SAM PIN? Some cards have separate PINs for signing operations, or require a secure messaging context even after PIN auth. Review your card's access control rules for this private key.

3. Check PSO:CDS Command Format

Your PSO command starts with 002A9E9A20 followed by the hash value. Validate these details:

  • P1=9E, P2=9A: This should correspond to "Compute Digital Signature using RSASSA-PSS". Confirm this matches your card's expected P1/P2 values — some cards use 9E 9B or other combinations.
  • Are you passing the right input type? For RSASSA-PSS, some cards expect the original raw ASN.1 data (they handle SHA256 hashing internally). If you're sending the precomputed hash, you need to configure the MSE context to indicate the input is a pre-hashed digest (look for a flag in the MSE data to specify this).

4. Validate Hash Data Format

You provided the SHA256-hashed ASN.1 data as 860c30a5f2b254ee92cbd3ec5c4282a940853aaef5f36d50ca20050637aaf4b0 — this is correctly a 32-byte SHA256 digest (64 hex characters = 32 bytes). Ensure you're sending it in big-endian byte order (which it appears to be) with no extra padding or missing bytes in the PSO command.

Example Adjusted Workflow

If your card requires explicit PSS parameters in MSE, try this modified sequence:

  1. MSE:SET for RSASSA-PSS SHA256:
    002241B80B06092A864886F70D01010B032100
    
    • P2=B8: Adjust if your card uses a different value for SHA256 + RSASSA-PSS
    • Data field: OID for RSASSA-PSS + SHA256 digest parameter
  2. Select Private Key File:
    00A40800043D002F0100
    
  3. PSO:CDS with Precomputed Hash:
    002A9E9A20860c30a5f2b254ee92cbd3ec5c4282a940853aaef5f36d50ca20050637aaf4b0
    
    (Or send raw ASN.1 data if your card prefers that — replace the 20 length byte and hash with the raw data's length and bytes.)

If none of these fix the issue, refer to your card's official documentation for the exact RSASSA-PSS signing workflow — different cards have subtle variations in command parameters and required security contexts.


内容的提问来源于stack exchange,提问作者BMErEr

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.21 07:01:26