Search the Site

My Social
Meta
Powered by Squarespace
« Uninstall SafeSign on OSX | Main | OSX and Aladdin eToken »
Wednesday
Dec102008

SafeSign and OSX

After my blog post on OSX and Aladdin eToken I received a phonecall from Haaino @ AET Europe. He offered the SafeSign software for OSX so I could try their OSX software as well.

The SafeSign software is used with smartcards and smartcard readers like the OmniKey smartcard readers. Through my line of work, no lack of smartcards and/or readers. Only the software was missing (up till now).

The package I received contained TokenLounge software and the SafeSign v3.0 drivers for OSX. After installation of the software, you're left with Token Administration, and TokenLounge Software. The software installation took place on an iMac running OSX 10.5.5.

Token Admin Token AdminToken Lounge Token LoungeThe two smartcard readers (a GemPC Twin, and a OmniKey CardMan 3121) were recognized immediately by the software (as shown in the Token Admin screenshot).

After this I had to add the smartcard to FireFox. This process is similar to the eToken process. Just follow the procedure described on the eToken post. For completing this you need to refer to the following file:

/usr/local/lib/libaetpkss.dylib

SafeSign support in FireFox SafeSign support in FireFox

Same goes for using (SafeSign) smartcards with TrueCrypt.

SafeSign support in TrueCrypt SafeSign support in TrueCryptIt seems though that you can only use one Security Device at a time with TrueCrypt (you can always change the Library Path to another device)

The interface of the Token Lounge software suggests that you can map identities (certificates) to user accounts in OSX. Suggests, because about an hour before I tested the software my company smartcard got fried for some weird reason. So this piece of software will be tested when I receive my new company smartcard with matching signing and encryption certificates.

Conclusion so far: easy installable software. No opinion yet on it's usage and/or integration with the rest of OSX.

Guess I've earned being a Certified SafeSign Identity Client Administrator

:D

Reader Comments (15)

can you map identities (certificates) to user accounts in OSX? how?

February 27, 2009 | Unregistered Commenterteo

The SafeSign/AET Token Lounge application enables you to map user certificates to local OSX accounts. I haven't tried this yet though.
I don't know if there are other (free/opensource) applications that can do this.

February 28, 2009 | Unregistered CommenterWillem

Could you please give me clue, where I can download SafeSign 3.0 ?

July 21, 2009 | Unregistered Commenteralex

The SafeSign software isn't freely downloadable. You should contact EAT Europe for a copy. They do have evaluation versions of the software.

July 21, 2009 | Unregistered CommenterWillem

I have strange behavior of my smart cart reader. I have Omnikey 3121. My system is 10.5.6 (tested with 10.5.7 too)
pcscdtest - completed successefully. But my keychain doesn't see my smartcard (its HID Crescendo iClass)
Its doesn't apear in keychain like CACxxxx.
What you can suggest ?

July 22, 2009 | Unregistered Commenteralex

Hi Alex, I guess the keychain integration just isn't there. I struggled with this in the beginning as well. At one point I got the smartcard working under firefox, but I had the problem that I couldn't figure out how to get a new certificate on it or even use it properly. Soon after that I heard that AET had the appropriate middle-ware to combine things together into a working environment.
When I had that working I stopped pursuing other means of getting it to work.

Perhaps http://www.cms.hu-berlin.de/dl/zertifizierung/SC/Einsatz/Install-MacOSX_html" rel="nofollow">this link will help.

July 22, 2009 | Unregistered CommenterWillem

Dear Willem,

Thank you for this link. But looks, like ftp with additional software, that mention on this site is always down.
Anyway, I have found this manual, that told, that my card should work under Mac OS X with Keychain: http://www.hidglobal.com/documents/crescendo_macOSX_Guide_en.pdf
Pgae 4 of it says:
"TokenLounge is the TokenD implementation for the MAC OS X Keychain.
It can be found (like any other TokenD implementations) in: System/Library/Security/Tokend/SafeSign.tokend"

I don't have SafeSign.tokend in my system. What problem may be with ?

July 27, 2009 | Unregistered Commenteralex

@alex
TokenLounge and (anything mentioning) SafeSign is part of the AET Europe software.
Note that they are two different software packages if I recall correctly.
One is the driver/middleware and the other is the TokenLoung software for integrating into several OSX applications (like keychain).

July 27, 2009 | Unregistered CommenterWillem

Thank you, Willem,

Thank you for the clue. Yes, I missed this. Looks like TokenLounge is not free software, so I should buy it.

July 27, 2009 | Unregistered Commenteralex

We are looking at file/folder encryption on os x server . Would
like to give access to these files to various users
on network with hardware token .

What is the best option to achieve this

August 18, 2009 | Unregistered CommenterManoj

@Manoj
That depends entirely on:
1) What you're trying to achieve
2) The budget available

Should the content always be encrypted on the server (to prevent data-leakage when the server is stolen), or it to ensure that someone with physical access can't access the data?
If a user can access the data over the network, the transit over the network (and temporary storage on the user PC) should also be safeguarded.

So this can't be easily answered, and as Johnny Five would say; 'Need more input'.

PGP has some commercial solutions in keeping data safe on PC's, servers and for data in transit, but I don't know if they are all available for OSX.

August 18, 2009 | Unregistered CommenterWillem

Thanks a LOT for your information! I finally managed to use my certificate on a Mac! I successfully used it on Firefox.

I used SafeSign 3.0 on SL (10.6.2).

I wonder if, with SafeSign (no TokenLounge here), I could also use my certificate with Safari.

March 26, 2010 | Unregistered Commenteroculos

For as far as I know you need Tokenlounge to use your certificates within Mail and Safari. Last thing I heard was that the Snow Leopard version of SafeSign Tokenlounge was still in Beta / under construction.

March 27, 2010 | Registered CommenterWillem

how, could I have the link of Safesign 3 for snow leopard (mac) or Tokenlounge.dmg

Thanks and regards

March 29, 2010 | Unregistered Commenterrovira206

You can request a (evaluation) license @ AET Europe. There's no other (legal) way of getting your hands on the software as far as I know.

March 30, 2010 | Registered CommenterWillem

PostPost a New Comment

Enter your information below to add a new comment.

My response is on my own website »
Author Email (optional):
Author URL (optional):
Post:
 
Some HTML allowed: <a href="" title=""> <abbr title=""> <acronym title=""> <b> <blockquote cite=""> <code> <em> <i> <strike> <strong>