.\" Automatically generated by Pandoc 3.10.1 .\" .TH "GPSHELL" "1" "" "3.0.0" "GPShell Documentation" .SH NAME \f[B]gpshell\f[R] \- command line tool for the management of GlobalPlatform compliant smart cards .SH SYNOPSIS .PP \f[B]gpshell\f[R] \f[I]scriptfile\f[R] .SH DESCRIPTION gpshell can manage applications on smart cards supporting the GlobalPlatform. This comprises the installation and deletion of applications, getting the applications status and card data. These applications are practical always Java Card applets. Additional key management commands are provided. .PP The most common way to use gpshell is a script file. But it is also possible to read the commands from stdin if no script file is provided. .PP Within a script environment variables can be accessed with the syntax \f[CR]${ENV_VAR_NAME}\f[R]. .PP Reading the commands from stdin allows one to feed in the commands dynamically and use conditionals when using the \c .UR https://en.wikipedia.org/wiki/Expect Expect .UE \c \ pattern. Tools are available for a variety of script languages, shells and programming languages. Example are to support environment variables and handle results and output conditionally. .PP There are several \f[CR]txt\f[R] example scripts provided in \f[CR]gpshell/examples/gpshell\f[R], installed under \f[CR]/usr/share/doc/gpshell/examples/\f[R], and available \c .UR https://github.com/kaoh/globalplatform/tree/master/gpshell/examples/gpshell online .UE \c \&. .SH COMMANDS .TP \f[B]#\f[R] Start a line with a comment. .TP \f[B]//\f[R] Starts a line with a comment. .TP \f[B]mode_201\f[R] Set protocol mode to OpenPlatform 2.0.1. This is the default. .TP \f[B]mode_211\f[R] Set protocol mode to GlobalPlatform 2.1.1 and later .TP \f[B]visa_key_derivation\f[R] For cards which use the VISA key derivation scheme for the key calculation, like GemXpresso Pro, Palmera Protect or some JCOP cards this must be set. .TP \f[B]emv_cps11_key_derivation\f[R] For cards which uses the EMV CPS 1.1 key derivation scheme for the key calculation, like a Sm\(atrtCafe Expert 3.0 this must be set. .TP \f[B]enable_trace\f[R] Enable APDU trace .PP You will see the sent APDUs in clear text. The last two bytes of the response are the response code. A response code of 9000 means success, otherwise the response code indicates an error. This may be OK when deleting a non existing applet or package. .TP \f[B]enable_timer\f[R] Enable the logging of the execution times of commands. .TP \f[B]establish_context\f[R] Establish context. This must always be executed before connecting to a card. .TP \f[B]list_readers\f[R] List the card readers. .TP \f[B]card_connect\f[R] \-reader \f[I]readerName\f[R] \-protocol \f[I]protocol\f[R] Connect to card in the reader with \f[I]readerName\f[R]. By default protocol is 0 = T0. .TP \f[B]card_connect\f[R] \-readerNumber \f[I]x\f[R] \-protocol \f[I]protocol\f[R] Connect to card in the \f[I]x\f[R] th reader in the system. By default protocol is 0 = T0. .TP \f[B]open_sc\f[R] \-keyind \f[I]x\f[R] \-keyver \f[I]x\f[R] \-key \f[I]key\f[R] \-mac_key \f[I]mac\-key\f[R] \-enc_key \f[I]enc\-key\f[R] \-kek_key \f[I]kek\-key\f[R] \-security \f[I]securityLevel\f[R] \-scp \f[I]protocol\f[R] \-scpimpl \f[I]impl\f[R] \-keyDerivation \f[I]derivation\f[R] Open a secure channel .PP For OpenPlatform 2.0.1\(cq cards only \-keyind \-keyver \-mac_key and \-enc_key are necessary. .PP For GlobalPlatform 2.1.1 and later cards \-scp and \-scpimpl should not be necessary to supply. You must also specify \-kek_key. .PP If the card supports a Secure Channel Protocol Implementation with only one base key, specify this key with \-key and omit the others. .PP If the card uses a key derivation mechanism you must enable the derivation mode with the \-keyDerivation option and you must specify with \-key the master (mother) key. \-kek_key, \-mac_key and \-enc_key are not relevant is this case. See the section Options and Key Derivation. \f[B]NOTE:\f[R] If the secure channel is going to be opened when no security domain is selected then the command get_secure_channel_protocol_details must be executed before to be able to get the Secure Channel Protocol Implementation. .TP \f[B]select\f[R] \-AID \f[I]AID\f[R] Select AID instance .TP \f[B]install\f[R] \-file \f[I]appletFile\f[R] \-priv \f[I]privilege\f[R] \-sdAID \f[I]sdAID\f[R] \-AID \f[I]AIDInPkg\f[R] \-pkgAID \f[I]packageAID\f[R] \-instAID \f[I]instanceAID\f[R] \-nvCodeLimit \f[I]x\f[R] \-nvDataLimit \f[I]y\f[R] \-instParam \f[I]installationParams\f[R] \-sdParam \f[I]sdParams\f[R] \-uiccSystemSpecParam \f[I]uiccSystemSpecParams\f[R] \-simSpecParam \f[I]simSpecParams\f[R] Load and installs an applet in one step .PP The parameters \-AID \-instAID \-pkgAID \-nvCodeLimit can be detected automatically and the \-AID and \-instAID is set to the first applet in \f[I]appletfile\f[R]. .PP For the \f[I]sdAID\f[R] the AID selected with the select command is chosen if not given. Otherwise the default Card Manager / Security Issuer Domain AID is chosen. Usually you do not have to pass it. .PP \-instParam specifies applet installation parameters for the install() method \-sdParam specifies Security Domain install parameters added to tag `C9' (e.g., tag `C1' with tags `81',`82',`83',`84',`86',`87') \-uiccSystemSpecParam specifies parameters according to ETSI TS 102 226, sect. 8.2.1.3.2.2 to use the Card Application Toolkit (CAT) functionality or to access the UICC file system. The parameters have to be already encoded without the outer tag `EA'. \-simSpecParam specifies parameters according to ETSI TS 102 226, sect. 8.2.1.3.2.1 to use the SIM Application Toolkit (STK) functionality or to access the SIM file system. The parameters have to be already encoded without the outer tag `CA'. .TP \f[B]install_for_load\f[R] \-pkgAID \f[I]packageAID\f[R] \-sdAID \f[I]sdAID\f[R] \-nvCodeLimit \f[I]y\f[R] Applet load preparation .PP For the \f[I]sdAID\f[R] the AID selected with the select command is chosen if not given. Otherwise the default Card Manager / Security Issuer Domain AID is chosen. Usually you do not have to pass it. .PP This command may be needed if the combined install command does not work. .TP \f[B]load\f[R] \-file \f[I]appletFile\f[R] Load applet .PP This command may be needed if the combined install command does not work. .TP \f[B]install_for_install\f[R] \-priv \f[I]privilege\f[R] \-AID \f[I]AIDInPkg\f[R] \-pkgAID \f[I]pkgAID\f[R] \-instAID \f[I]instanceAID\f[R] \-nvDataLimit \f[I]x\f[R] \-instParam \f[I]installationParams\f[R] \-sdParam \f[I]sdParams\f[R] \-uiccSystemSpecParam \f[I]uiccSystemSpecParams\f[R] \-simSpecParam \f[I]simSpecParams\f[R] .IP .EX Instantiate applet .EE .PP This command may be needed if the combined install command does not work. Or you want to install a pre\-installed Security Domain. .TP \f[B]install_for_make_selectable\f[R] \-priv \f[I]privilege\f[R] \-instAID \f[I]instanceAID\f[R] .IP .EX Makes an installed applet instance selectable .EE .PP This command may be needed if the combined install command does not work. Typically this is used after an \f[I]install_for_install\f[R] followed by personalization. .TP \f[B]card_disconnect\f[R] Disconnect card .TP \f[B]get_status\f[R] \-element \f[I]e0\f[R] .IP .EX List applets and packages and security domains .EE .TP \f[B]get_status\f[R] \-element \f[I]20\f[R] List packages .TP \f[B]get_status\f[R] \-element \f[I]40\f[R] .IP .EX List applets or security domains .EE .TP \f[B]get_status\f[R] \-element \f[I]80\f[R] List Card Manager / Security Issuer Domain .TP \f[B]release_context\f[R] Release context .TP \f[B]put_sc_key\f[R] \-keyver \f[I]keyver\f[R] \-newkeyver \f[I]newkeyver\f[R] \-mac_key \f[I]new_MAC_key\f[R] \-enc_key \f[I]new_ENC_key\f[R] \-kek_key \f[I]new_KEK_key\f[R] Add or replace a key set version .PP If a new key set version is to be added \f[I]keyver\f[R] must be set to 0. If \f[I]keyver\f[R] equals \f[I]newkeyver\f[R] an existing key version is replaced. An existing key set version cannot be replaced with a key set version using a different key size. .TP \f[B]put_sc_key\f[R] \-keyver \f[I]keyver\f[R] \-newkeyver \f[I]newkeyver\f[R] \-key \f[I]key\f[R] \-keyDerivation \(lqderivation\(rq Replace key set version \f[I]keyver\f[R] using key derivation \f[I]derivation\f[R] using the master (mother) key \f[I]y\f[R] .TP \f[B]put_dm_token_keys\f[R] \-keyver \f[I]keyver\f[R] [\-newkeyver \f[I]newkeyver\f[R]] \-file \f[I]public_key_file\f[R] [\-pass \f[I]password\f[R]] .IP .EX Add an asymmetric (RSA/ECC) delegated management token verification key. If *newkeyver* is not provided, it defaults to 0x70. .EE .TP \f[B]put_dm_receipt_keys\f[R] \-keyver \f[I]keyver\f[R] [\-newkeyver \f[I]newkeyver\f[R]] \-key \f[I]new_receipt_generation_key\f[R] .IP .EX Add a symmetric delegated management receipt generation key. If *newkeyver* is not provided, it defaults to 0x701. .EE .TP \f[B]send_apdu\f[R] \-sc 0 \-APDU \f[I]apdu\f[R] Send APDU \f[I]apdu\f[R] without secure channel .PP The APDU is given as hex without spaces and without leading 0x. .TP \f[B]send_apdu_nostop\f[R] \-sc 0 \-APDU \f[I]apdu\f[R] Same as \f[B]send_apdu\f[R] but not stopping in case of connection or GlobalPlatform errors. .PP The APDU is given as hex without spaces and without leading 0x. .TP \f[B]get_data\f[R] \-identifier \f[I]identifier\f[R] A GET DATA command returning the data for the given identifier. See the identifier options for details. .TP \f[B]get_key_information_templates\f[R] \-keyTemplate \f[I]index\f[R] A GET DATA command returning the key information templates in the selected security domain. \f[B]NOTE:\f[R] The security domain must be selected and this only works outside of a secure channel. .TP \f[B]get_extended_card_resources_information\f[R] .IP .EX A GET DATA command returning the extended card resources information in the issuer security domain. __NOTE:__ The security domain must be selected and this only works outside of a secure channel. .EE .TP \f[B]get_secure_channel_protocol_details\f[R] .IP .EX A GET DATA command returning the secure channel protocol details and remembering them for a later open_sc. __NOTE:__ The security domain must be selected and this only works outside of a secure channel. .EE .TP \f[B]print\f[R] .IP .EX Prints a line of text. Prints an empty line if no text is given. .EE .TP \f[B]install_for_personalization\f[R] \-aid \f[I]AID\f[R] .IP .EX Prepare a security domain for the personalization of an applet with following store_data commands. __NOTE:__ The security domain must be selected and this only works outside of a secure channel. .EE .TP \f[B]store_data\f[R] \-dataFormat \f[I]format\f[R] \-dataEncryption \f[I]encryption\f[R] \-data \f[I]data\f[R] .IP .EX Executes a STORE DATA command passing the *data* to the selected applet. .EE .TP \f[B]get_card_recognition_data\f[R] .IP .EX A GET DATA command returning the card recognition data. __NOTE:__ The security domain must be selected. .EE .TP \f[B]delete\f[R] \-AID \f[I]aid\f[R] .IP .EX Deletes an applet or package with the specified AID. .EE .TP \f[B]delete_key\f[R] \-keyver \f[I]keyver\f[R] \-keyind \f[I]keyind\f[R] .IP .EX Deletes a key set version with a DELETE command. .EE .RS .PP If only the keyver is passed the complete key set version is deleted. By default keyind is 0xFF to delete the complelist_readerste key set version. If keyver is 0 all key set with the passed keyind are deleted. .RE .TP \f[B]gemXpressoPro\f[R] .IP .EX Enables support for GemXPresso card which enables the visa2 key derivation mode. .EE .TP \f[B]exit\f[R] .IP .EX Exit the shell. Useful in interactive mode. .EE .SH OPTIONS .TP \f[B]\-keyind\f[R] \f[I]x\f[R] Key index \f[I]x\f[R] .TP \f[B]\-keyver\f[R] \f[I]x\f[R] Key set version x .TP \f[B]\-newkeyver\f[R] \f[I]x\f[R] New key set version x .TP \f[B]\-key\f[R] \f[I]key\f[R] Key value in hex .TP \f[B]\-mac_key\f[R] \f[I]key\f[R] MAC key value in hex .TP \f[B]\-enc_key\f[R] \f[I]key\f[R] ENC key value in hex .TP \f[B]\-kek_key\f[R] \f[I]key\f[R] KEK key value in hex .TP \f[B]\-security\f[R] \f[I]x\f[R] 0: clear, 1: MAC, 3: MAC+ENC, 51: MAC+ENC+R\-MAC+E\-ENC (SCP03 only), 19: MAC+ENC\-R\-MAC (SCP02+SCP03 only), 17: MAC+R\-MAC (SCP02+SCP03 only) .TP \f[B]\-reader\f[R] \f[I]readerName\f[R] Smart card reader name .TP \f[B]\-readerNumber\f[R] \f[I]x\f[R] Number of the reader in the system to connect to. If \-reader is given this is ignored. .TP \f[B]\-protocol\f[R] \f[I]x\f[R] Protocol, 0:T=0, 1:T=1 Should not be necessary to be stated explicitly. .TP \f[B]\-AID\f[R] \f[I]aid\f[R] Applet ID .TP \f[B]\-sdAID\f[R] \f[I]aid\f[R] Security Domain AID .TP \f[B]\-pkgAID\f[R] \f[I]aid\f[R] Package AID .TP \f[B]\-instAID\f[R] \f[I]aid\f[R] Instance AID .TP \f[B]\-nvCodeLimit\f[R] \f[I]x\f[R] Non\-volatile code size limit .TP \f[B]\-nvDataLimit\f[R] \f[I]x\f[R] Non\-volatile data size limit .TP \f[B]\-vDataLimit\f[R] \f[I]x\f[R] Volatile data size limit .TP \f[B]\-file\f[R] \f[I]name\f[R] File name .TP \f[B]\-instParam\f[R] \f[I]param\f[R] Installation parameter .TP \f[B]\-sdParam\f[R] \f[I]param\f[R] Security Domain install parameters added to tag `C9' (e.g., tag `C1' with tags `81',`82',`83',`84',`86',`87'). .TP \f[B]\-uiccSystemSpecParam\f[R] \f[I]param\f[R] UICC System Specific Parameters according to ETSI TS 102 226, sect. 8.2.1.3.2.2. .TP \f[B]\-simSpecParam\f[R] \f[I]param\f[R] SIM File Access and Toolkit Application Specific Parameters according to ETSI TS 102 226, sect. 8.2.1.3.2.1. .TP \f[B]\-element\f[R] \f[I]x\f[R] Element type to be listed in hex .IP \(bu 2 80 \- Card Manager / Card Issuer Security Domain only. .IP \(bu 2 40 \- Applications (and Security Domains only in GP211 and later). .IP \(bu 2 20 \- Executable Load Files only. .IP \(bu 2 10 \- Executable Load Files and their Executable Modules only (Only GP211 and later) .TP \f[B]\-format\f[R] \f[I]x\f[R] Sets the format of the response of the get_status command. This is only used for GlobalPlatform cards and required and only needed if the default is not supported by the smart card. .TP \f[B]\-dataFormat\f[R] \f[I]x\f[R] Sets the data format flag for store_data command. Default 0. .IP \(bu 2 0 \- No general encryption information or non \- encrypted data .IP \(bu 2 0x20 \- Application dependent encryption of the data .IP \(bu 2 0x40 \- RFU(encryption indicator) .IP \(bu 2 0x60 \- Encrypted data. Must be encrypted with data encryption key. .TP \f[B]\-dataEncryption\f[R] \f[I]x\f[R] Sets the encryption format flag for store_data command. Note that this is just a flag and the data must be passed already in the correct encryption. Default 0. .IP \(bu 2 0 \- No general data structure information .IP \(bu 2 0x08 \- DGI format of the command data field .IP \(bu 2 0x10 \- BER\-TLV format of the command data field .IP \(bu 2 0x18 \- RFU (data structure information) .TP \f[B]\-responseDataExpected\f[R] \f[I]x\f[R] Sets if response data is expected for store_data command. 1 for expecting response data. Default 0. .TP \f[B]\-keyTemplate\f[R] \f[I]x\f[R] Sets the key template index to return for the get_key_templates command. Default 0. .IP \(bu 2 0 \- Deprecated format .IP \(bu 2 2 \- New format (default) .TP \f[B]\-sc\f[R] \f[I]x\f[R] Secure Channel mode (0 off, 1 on) .TP \f[B]\-APDU\f[R] \f[I]apdu\f[R] APDU to be sent. Must be in hex format, e.g.\ 80CA00CF00. .TP \f[B]\-priv\f[R] \f[I]x\f[R] Privilege. E.g. 0x04 Default Selected .TP \f[B]\-scp\f[R] \f[I]x\f[R] Secure Channel Protocol (1 SCP01, 2 SCP02, 3 SCP03, default no set). Should not be necessary to be stated explicitly. .TP \f[B]\-scpimpl\f[R] \f[I]x\f[R] Secure Channel Implementation (default not set) Should not be necessary to be stated explicitly. See the get_secure_channel_protocol_details command to detect the Secure Channel Protocol Implementation. \f[B]NOTE:\f[R] The value can be passed as decimal value or hexadecimal prefixed by \(lq0x\(rq. The hexadecimal version is the common one. .TP \f[B]\-pass\f[R] \f[I]password\f[R] Password for key decryption .TP \f[B]\-identifier\f[R] \f[I]identifier\f[R] Identifier for the tag for the get_data command. Must be in hex format, e.g., 9F7F. .PP There are several identifiers available, but in general not all cards are supporting them. The GlobalPlatform specification v2.3.1 lists a few in section 11.3.3.1. It is useful to use some ASN.1 parser to interpret these data, like \c .UR https://lapo.it/asn1js asn1js .UE \c .PP Some useful identifiers are: .IP \(bu 2 9F7F \- CPLC (Card Production Life Cycle) Data .IP \(bu 2 00E0 \- Key Information Templates. Instead of the first byte 00 also 01, \&... can be used to get more key information templates if available. There is a dedicated command for getting this: get_key_information_templates .IP \(bu 2 2F00 \- List of applications .IP \(bu 2 FF21 \- Extended card resources. There is a dedicated command for getting this: get_extended_card_resources_information .IP \(bu 2 0066 \- Card Recognition Data. There is a dedicated command for getting this: get_card_recognition_data .TP \f[B]\-data\f[R] \f[I]data\f[R] Data in hex format for the store_data command. .TP \f[B]\-noStop\f[R] Does not stop in case of an error .TP \f[B]\-keyType\f[R] \f[I]keyType\f[R] Type of the key for the put_sc_key command. Must be in hex format, e.g.\ 88. .SS Format of CPLC data You see the command trace of a GET DATA command and the interpreted result. .IP .EX => 80 CA 9F 7F 00 ..... (12102 usec) <= 9F 7F 2A 47 90 50 40 47 91 81 02 31 00 83 58 00 ..*G.P\(atG...1..X. 11 68 91 45 81 48 12 83 65 00 00 00 00 01 2F 31 .h.E.H..e...../1 30 31 31 36 38 00 00 00 00 00 00 00 00 90 00 01168.......... Status: No Error IC Fabricator : 4790 IC Type : 5040 Operating System ID : 4791 Operating System release date : 8102 (11.4.2008) Operating System release level : 3100 IC Fabrication Date : 8358 (23.12.2008) IC Serial Number : 00116891 IC Batch Identifier : 4581 IC Module Fabricator : 4812 IC Module Packaging Date : 8365 (30.12.2008) ICC Manufacturer : 0000 IC Embedding Date : 0000 IC Pre\-Personalizer : 012F IC Pre\-Perso. Equipment Date : 3130 (10.5.2003) IC Pre\-Perso. Equipment ID : 31313638 IC Personalizer : 0000 IC Personalization Date : 0000 IC Perso. Equipment ID : 00000000 .EE .PP Dates are stored as 2 bytes, the first specifying the year in the decade and the last 3 bytes the day within the year. .TP \f[B]\-keyDerivation\f[R] \f[I]derivation method\f[R] Possible values are \f[I]none\f[R], \f[I]visa1\f[R], \f[I]visa2\f[R] or \f[I]emvcps11\f[R] .PP Choose \f[I]visa2\f[R] if you have a card which uses the VISA key derivation scheme for the key calculation, like GemXpresso Pro or some JCOP cards you must set this. .PP Choose \f[I]emvcps11\f[R] If you have a card which uses the EMV CPS 1.1 key derivation scheme for the key calculation, like a Sm\(atrtCafe Expert 3.0 and later you must set this. Also for put_sc_key this is necessary for Sm\(atrtcafe 5.0 (and earlier(?)) cards .PP \f[I]visa1\f[R] is an old VISA key derivation scheme and is only needed for older cards. .SH ENVIRONMENT .TP \f[B]GLOBALPLATFORM_DEBUG\f[R] Enables debugging output from the underlying GlobalPlatform library. .TP \f[B]GLOBALPLATFORM_LOGFILE\f[R] Sets the log file name for the debugging output. If the environment variable \f[CR]GLOBALPLATFORM_LOGFILE\f[R] is set to \(lqstderr\(rq \f[CR]stderr\f[R] shall be used. .SH Key Derivation .TP \f[B]visa2\f[R] .IP .EX For the VISA2 key derivation scheme, like used in a GemXpresso Pro or some JCOP cards. .EE .TP \f[B]emvcps11\f[R] For the key derivation according to EMV CPS 1.1 (CDK (CPG 2.04)), like Sm\(atrtCafe Expert 3.0 and later. .PP Known unsupported key derivation schemes are: .IP \(bu 2 CDK (CPG 2.02) .IP \(bu 2 ISK(D) .SH Supported Cards .IP \(bu 2 Gemalto IDCore 3010 .IP \(bu 2 Oberthur CosmopoliC 32K (OP201) .IP \(bu 2 CosmopoliC 64K V5.2 (GP211, SCP01, Impl05) .IP \(bu 2 Axalto Cyberflex e\-gate 32k (OP201) .IP \(bu 2 GemXpresso R3.2 E64 .IP \(bu 2 IBM JCOP v2.2 41 (GP211) .IP \(bu 2 IBM JCOP 31 (36k) .IP \(bu 2 Palmera Protect V5 .IP \(bu 2 JTopV15 .IP \(bu 2 Nokia 6131 NFC Phone (GP211) .IP \(bu 2 Axalto Cyberflex Access 64k .IP \(bu 2 Gemalto Generations Flexible .IP \(bu 2 Sm\(atrtCafe Expert 3.0 .IP \(bu 2 Tongfang420 .IP \(bu 2 Infineon SECORA™ ID S .IP \(bu 2 JCOP4 P71 .IP \(bu 2 JCPO3 P60 EMV .IP \(bu 2 JCOP3 P60 SecID CS .IP \(bu 2 JCOP3 P40 EMV .IP \(bu 2 JCOP3 P40 SecID .IP \(bu 2 JCOP2.4.x .IP \(bu 2 JCOP 4.5 .IP \(bu 2 JCOP J3R180 .SH Misc .SS About install_for_load and install For CosmopoliC 64K (tested on V5.2), you need to specify the Security Domain AID. For example, .IP .EX install \-file helloworld.cap \-sdAID A000000003000000 \-nvCodeLimit 4000 .EE .PP For GemXpresso R3.2 E64, you need to specify the Security Domain AID (Card Manager AID). For example, .IP .EX install \-file helloworld.cap \-sdAID A000000018434D00 \-nvCodeLimit 4000 .EE .SS JCOP cards If you cannot authenticate to your card it might be not fused. In this case you need the transport key from the vendor. Execute the JCOP IDENTIFY command. .PP select \-aid A000000167413000FF Offset 14 (decimal) of the response has the pre\-personalized state. 00h means not fused (not personalized), 01h means fused. .SS CyberFlex cards For the Cyberflex you also need the CAP transformer (I believe this is a kind of obfuscator) which you must apply to the CAP file. Download it from http://www.trusted\-logic.fr/down.php and use it. .SH BUGS .TP JCOP 10 install_for_load fails for unknown reason, so nothing can be installed. .PP Some cards are not supporting the GET DATA command. This command is used by GPShell for retrieving the secure channel parameters. So you have to pass \-scp 2 \-scpimpl 0x15 to open_sc command. .SH AUTHOR Karsten Ohme \f[I]k_o_\(atusers.sourceforge.net\f[R] Snit Mo \f[I]snitmo\(atgmail.com\f[R] .PP See the file \f[CR]AUTHORS\f[R] for a complete list.