SafeSign and OSX
After my blog post on OSX and Aladdin eToken I received a phonecall from Haaino @ AET Europe. He offered the SafeSign software for OSX so I could try their OSX software as well.
The SafeSign software is used with smartcards and smartcard readers like the OmniKey smartcard readers. Through my line of work, no lack of smartcards and/or readers. Only the software was missing (up till now).
The package I received contained TokenLounge software and the SafeSign v3.0 drivers for OSX. After installation of the software, you're left with Token Administration, and TokenLounge Software. The software installation took place on an iMac running OSX 10.5.5.
The two smartcard readers (a GemPC Twin, and a OmniKey CardMan 3121) were recognized immediately by the software (as shown in the Token Admin screenshot).
After this I had to add the smartcard to FireFox. This process is similar to the eToken process. Just follow the procedure described on the eToken post. For completing this you need to refer to the following file:
/usr/local/lib/libaetpkss.dylib
Same goes for using (SafeSign) smartcards with TrueCrypt.
It seems though that you can only use one Security Device at a time with TrueCrypt (you can always change the Library Path to another device)
The interface of the Token Lounge software suggests that you can map identities (certificates) to user accounts in OSX. Suggests, because about an hour before I tested the software my company smartcard got fried for some weird reason. So this piece of software will be tested when I receive my new company smartcard with matching signing and encryption certificates.
Conclusion so far: easy installable software. No opinion yet on it's usage and/or integration with the rest of OSX.
Guess I've earned being a Certified SafeSign Identity Client Administrator
:D
I contacted AET Europe in regards to the availablitiy of the SafeSign / Tokenlounge software. Please do not contact me for the software. I can't help (would be a breach of the license agreement). Contact your (local) distributor. An overview of the SafeSign distributors can be found here.
Reader Comments (15)
can you map identities (certificates) to user accounts in OSX? how?
The SafeSign/AET Token Lounge application enables you to map user certificates to local OSX accounts. I haven't tried this yet though.
I don't know if there are other (free/opensource) applications that can do this.
Could you please give me clue, where I can download SafeSign 3.0 ?
The SafeSign software isn't freely downloadable. You should contact EAT Europe for a copy. They do have evaluation versions of the software.
I have strange behavior of my smart cart reader. I have Omnikey 3121. My system is 10.5.6 (tested with 10.5.7 too)
pcscdtest - completed successefully. But my keychain doesn't see my smartcard (its HID Crescendo iClass)
Its doesn't apear in keychain like CACxxxx.
What you can suggest ?
Hi Alex, I guess the keychain integration just isn't there. I struggled with this in the beginning as well. At one point I got the smartcard working under firefox, but I had the problem that I couldn't figure out how to get a new certificate on it or even use it properly. Soon after that I heard that AET had the appropriate middle-ware to combine things together into a working environment.
When I had that working I stopped pursuing other means of getting it to work.
Perhaps http://www.cms.hu-berlin.de/dl/zertifizierung/SC/Einsatz/Install-MacOSX_html" rel="nofollow">this link will help.
Dear Willem,
Thank you for this link. But looks, like ftp with additional software, that mention on this site is always down.
Anyway, I have found this manual, that told, that my card should work under Mac OS X with Keychain: http://www.hidglobal.com/documents/crescendo_macOSX_Guide_en.pdf
Pgae 4 of it says:
"TokenLounge is the TokenD implementation for the MAC OS X Keychain.
It can be found (like any other TokenD implementations) in: System/Library/Security/Tokend/SafeSign.tokend"
I don't have SafeSign.tokend in my system. What problem may be with ?
@alex
TokenLounge and (anything mentioning) SafeSign is part of the AET Europe software.
Note that they are two different software packages if I recall correctly.
One is the driver/middleware and the other is the TokenLoung software for integrating into several OSX applications (like keychain).
Thank you, Willem,
Thank you for the clue. Yes, I missed this. Looks like TokenLounge is not free software, so I should buy it.
We are looking at file/folder encryption on os x server . Would
like to give access to these files to various users
on network with hardware token .
What is the best option to achieve this
@Manoj
That depends entirely on:
1) What you're trying to achieve
2) The budget available
Should the content always be encrypted on the server (to prevent data-leakage when the server is stolen), or it to ensure that someone with physical access can't access the data?
If a user can access the data over the network, the transit over the network (and temporary storage on the user PC) should also be safeguarded.
So this can't be easily answered, and as Johnny Five would say; 'Need more input'.
PGP has some commercial solutions in keeping data safe on PC's, servers and for data in transit, but I don't know if they are all available for OSX.
Thanks a LOT for your information! I finally managed to use my certificate on a Mac! I successfully used it on Firefox.
I used SafeSign 3.0 on SL (10.6.2).
I wonder if, with SafeSign (no TokenLounge here), I could also use my certificate with Safari.
For as far as I know you need Tokenlounge to use your certificates within Mail and Safari. Last thing I heard was that the Snow Leopard version of SafeSign Tokenlounge was still in Beta / under construction.
how, could I have the link of Safesign 3 for snow leopard (mac) or Tokenlounge.dmg
Thanks and regards
You can request a (evaluation) license @ AET Europe. There's no other (legal) way of getting your hands on the software as far as I know.