マルチプル・アイデンティティ

The multiple identities feature allows to use 3 virtual smart cards in place of one, giving bigger flexibility in the every day use, as well as separation between user identities (business, personal etc.) or even allowing usage of it for more than one user (PINs are separate).

All of the smart cards have separate data objects, meaning they all could have different keys, certificates stored, and PINs set. Identities do not interact between each other.

The virtual smart cards are identifiable by the first digit of the serial number, which is replaced by identity number for second (“1”) and third one (“2”). Serial number is not changed for the first identity.

使用方法

IDを変更するには、カスタムCCIDコマンドを送信すれば十分です。これは``pynitrokey``ツールで実現できます。

  1. pynitrokeyのインストール.

  2. Nitrokey Startを接続し、認識されたことを確認してください。

    $ nitropy start list
    *** Nitrokey tool for Nitrokey FIDO2 & Nitrokey Start
    :: 'Nitrokey Start' keys:
       FSIJ-1.2.15-87042524: Nitrokey Nitrokey Start (RTM.10)
    
  3. <ID>``を``0``に置き換えて、アイデンティティを変更します。``1、または``2``となります。

    $ nitropy start set-identity <ID>
    *** Nitrokey tool for Nitrokey FIDO2 & Nitrokey Start
    Trying to set identity to <ID>
    device has reset, and should now have the new identity
    

制限事項

バージョンRTM.10では、1つだけ制限があります。3つ目のIDは1024バイト以下の証明書を保存できます。他の2つのIDでは、1つの証明書につき標準で2048バイトの制限があります。