Mehrere Identitäten¶
The multiple identities feature allows to use 3 virtual smart cards in place of one, giving bigger flexibility in the every day use, as well as separation between user identities (business, personal etc.) or even allowing usage of it for more than one user (PINs are separate).
All of the smart cards have separate data objects, meaning they all could have different keys, certificates stored, and PINs set. Identities do not interact between each other.
The virtual smart cards are identifiable by the first digit of the serial number, which is replaced by identity number for second (“1”) and third one (“2”). Serial number is not changed for the first identity.
Verwendung¶
Um die Identität zu ändern, reicht es aus, einen eigenen CCID-Befehl zu senden. Dies kann mit dem Tool pynitrokey erreicht werden:
Schließen Sie Ihren Nitrokey Start an und prüfen Sie, ob er erkannt wurde.
$ nitropy start list *** Nitrokey tool for Nitrokey FIDO2 & Nitrokey Start :: 'Nitrokey Start' keys: FSIJ-1.2.15-87042524: Nitrokey Nitrokey Start (RTM.10)
Ändern Sie die Identität, indem Sie
<ID>durch0,1, oder2ersetzen.$ nitropy start set-identity <ID> *** Nitrokey tool for Nitrokey FIDO2 & Nitrokey Start Trying to set identity to <ID> device has reset, and should now have the new identity
Begrenzungen¶
Ab der Version RTM.10 gibt es nur eine Einschränkung - die dritte Identität kann ein Zertifikat speichern, das nicht länger als 1024 Bytes ist. Die anderen beiden Identitäten haben standardmäßig ein Limit von 2048 Bytes pro Zertifikat.