id: 92330cc77e3748ab971f745bb68e3355
parent_id: 1e88d3d246c24973ad692b1a1d0e8fdc
item_type: 1
item_id: a6768b6c7d2d4dbb855399468b9db6fa
item_updated_time: 1786726778703
title_diff: "[{\"diffs\":[[0,\"2026-08-\"],[-1,\"0\"],[1,\"1\"],[0,\"4)\"]],\"start1\":37,\"start2\":37,\"length1\":11,\"length2\":11}]"
body_diff: "[{\"diffs\":[[0,\"-08-\"],[-1,\"0\"],[1,\"1\"],[0,\"4)\\\n\\\n\"],[-1,\"## C\"],[1,\"> Replaces the 2026-08-04 snapshot (c\"],[0,\"ommit\"],[-1,\":\"],[0,\" `5e\"]],\"start1\":43,\"start2\":43,\"length1\":23,\"length2\":55},{\"diffs\":[[0,\"d05`\"],[-1,\" - Add real PC/SC NFC reader support with SCP03 authentication\\\n\\\n## What Works\\\n\\\n### NFC Reader (Info tab)\\\n- Detects ACR1281U-C1 PICC reader, auto-polls at 100ms\\\n- Reads chip UID, ATR on card placement\\\n- SELECT ISD (`A000000151000000`) -> GET DATA -> OEF ID (B252)\\\n- INITIALIZE UPDATE -> SCP03 C-MAC handshake (verified on real hardware)\\\n- Card cryptogram verification as safety gate before EXTERNAL AUTHENTICATE\\\n- Shows: OEF ID, key version, SCP ID, I-parameter, sequence counter, SCP03 status (green \\\"Authenticated\\\")\\\n\\\n### Provisioning (Provision tab)\\\n- Mock transport mode (safe, no hardware risk)\\\n- Reads container folder -> personalization items (DGI A001-A006)\\\n- SCP03 C-MAC auth with B252 static keys\\\n- STORE DATA personalization (no FACTORY transition)\\\n- Device c\"],[1,\", 91 tests). Live open-items\\\n> tracking lives in **Keyfob Station — Code Audit Open Items**; this note is the\\\n> periodic status snapshot.\\\n\\\n## Commit: `2de34cf` (+ private-key bridge pending commit) on `master`, pushed to origin\\\n\\\n## What Works (all HW-verified unless noted)\\\n\\\n### KLMS REST integration (end-to-end 2026-08-14, one pending item below)\\\n- mTLS + token auth against dev Clypeum CCS, seed lifecycle, container generation (201)\\\n- Container decrypt (wrapper key), tag-keyed field extraction, session-key v\"],[0,\"er\"],[-1,\"t\"],[0,\"if\"],[-1,\"icate (A002) provisioned last\\\n- B252 keys in `dev_keys()` (shared static, not per-card d\"],[1,\"y\\\n- SCP03 via KLMS-delivered keys, auto-provision on tap, retry with re-install (card-stage)\\\n  or plain retry (s\"],[0,\"er\"],[-1,\"i\"],[0,\"ve\"],[-1,\"d)\\\n\\\n### Infrastructure\\\n- `scripts/configure-windows.ps1` - Windows registry fix for 23s delay\\\n- `kf-transport/src/pcsc.rs` - PcscTransport (raw pcsc_sys FFI)\\\n- `kf-dev-station/src/key_profiles.rs` - OEF ID -> keys lookup\\\n- `kf-dev-station/src/scp03_session.rs` - Standalone SCP03 session module (for future GUI buttons)\\\n- `kf-provision/src/lib.rs` - `skip_lifecycle_transition` config flag\\\n- JCShell reference scripts in `reference/jcshell/`\\\n\\\n## What's Next\\\n\\\n1. **Cert read-back verification**: After provisioning A002, read it back to verify\\\n2. **Test container fixtures**: Generate dummy container data for flow testing\\\n3. **Hardware provisioning**: Switch from mock to PcscTransport when ready\\\n4. **FACTORY transition**: Separate explicit operation (not during personalization)\\\n5. **NFC Pairing** (Script 03): Separate, implement if needed\"],[1,\"r-stage) depending on failure classification\\\n- Card-ready private key (48-byte, S-DEK): CBC(IV=0)+M2 forwarded as-is; ECB+M2 bridged\\\n  locally with WARN — **KLMS should switch to CBC** (open, next week)\\\n\\\n### Files production flow\\\n- Re-install + provision + FACTORY + validation, retry-on-failure — HW-verified\\\n\\\n### Infrastructure\\\n- 3 build variants (full / test / minimal), zero clippy warnings across all\\\n- 105 tests, rustfmt + rustdoc clean\\\n- Config-driven typeID / keyBundleType / accept_invalid_certs (klms-config.toml)\\\n- Debug logging of full request forms + response headers (RUST_LOG=debug)\"],[0,\"\\\n\\\n##\"]],\"start1\":100,\"start2\":100,\"length1\":1716,\"length2\":1238},{\"diffs\":[[0,\"ted \"],[-1,\"- \\\"auth exceed\\\"\"],[1,\"— see incident note\"],[0,\") |\\\n\"]],\"start1\":1458,\"start2\":1458,\"length1\":23,\"length2\":27},{\"diffs\":[[0,\"` | \"],[-1,\"Fresh, SCP03 verified, counter reset\"],[1,\"Active test fob (KLMS flow)\"],[0,\" |\\\n|\"]],\"start1\":1507,\"start2\":1507,\"length1\":44,\"length2\":35},{\"diffs\":[[0,\"resh\"],[-1,\", SCP03 verified\"],[0,\" |\\\n\\\n\"]],\"start1\":1568,\"start2\":1568,\"length1\":24,\"length2\":8},{\"diffs\":[[0,\"bers\\\n\\\n- \"],[-1,\"9\"],[0,\"1\"],[1,\"05\"],[0,\" tests p\"]],\"start1\":1586,\"start2\":1586,\"length1\":18,\"length2\":19},{\"diffs\":[[0,\"pass\"],[-1,\" (0 fail)\\\n- SCP03 handshake: ~80us card cryptogram verification, ~50ms INITIALIZE UPDATE\\\n- Monitor poll interval: 100ms (\"],[1,\", 10 crates, workspace at `D:\\\\Development\\\\Workspaces\\\\\rust-workspace\\\\keyfob-station`\\\n- Deploy: `kfs-prod.bat` (release build verified); dev: `kfs-dev.bat`\\\n\\\n## Next Week\\\n\\\n1. KLMS switches field[8] to AES-128-CBC(IV=0)+M2 → drop the ECB bridge\\\n2. Full HW smoke: \"],[0,\"card\"],[-1,\" removal detection)\\\n- GP auth counter: ~15 (resets on successful auth)\\\n\"],[1,\"-ready path through provisioning + GA validation\\\n3. Open external items (see audit note): C1 CA cert, CID header, signature key,\\\n   checksum spec, report_usage semantics\"]],\"start1\":1604,\"start2\":1604,\"length1\":200,\"length2\":436}]"
metadata_diff: {"new":{},"deleted":[]}
encryption_cipher_text: 
encryption_applied: 0
updated_time: 2026-08-14T17:00:01.011Z
created_time: 2026-08-14T17:00:01.011Z
is_locked: 0
type_: 13