Malta Identity Card Reader Device -Macintosh Installation and User Guide
Total Page:16
File Type:pdf, Size:1020Kb
Malta Identity Card Reader Device - Macintosh Installation and User Guide Malta Identity Card Reader Device - Macintosh Installation and User Guide Contents 1. Document Purpose ............................................................................................................... 3 2. Smartcard Utility Interface Installation Pre-requisites ........................................................ 4 3. Installation Steps................................................................................................................... 5 4. Changing the Transport Authentication and Signature PINs ........................................... 12 5. Changing the Authentication and Signature PINs ............................................................ 14 6. Firefox configuration steps ................................................................................................ 17 7. Adobe Acrobat configuration steps ................................................................................... 22 8. Frequently Asked Questions .............................................................................................. 28 9. Troubleshooting Guide ....................................................................................................... 36 2 1. Document Purpose To show Malta Identity (ID) card holders how to: • Install the Smartcard Utility software on a Macintosh; • Change the ID card Transport Authentication and Signature PINs; • Configure the Authentication and Signature certificates for usage within the Firefox browser; • Create and embed a Digital Signature within an Adobe document. The document also contains “Frequently Asked Questions” and “Troubleshooting Guide” sections. 3 2. Smartcard Utility Interface Installation Pre-requisites Pre-requisite Further information 1. Operating • macOS 10.11 (El Capitan) Systems • macOS 10.12 (Sierra) • macOS 10.13 (High Sierra) • macOS 10.14 (Mojave) 2. ID card • A valid Citizen or Expatriate Maltese ID card that was issued by the Identity Malta Agency Registration Authority • Your Authentication and Digital Signature PINs that were issued with your ID Card 3. ID card • A compatible ID card reader device as referenced in the Frequently reader and Asked Questions section of this document. drivers • The latest ID card reader drivers installed for your Macintosh operating system version. 4. Browsers • Safari • Firefox (note – requires some additional configuration steps which are contained within this document). 5. Software • Adobe Acrobat for Digital Signature signing (note – requires some additional configuration steps which are contained within this document). 6. System • Sufficient user privileges to install the Smartcard Utility software on Installation your Macintosh. Privileges 4 3. Installation Steps 1. If applicable, uninstall the Gemalto Classic Client software. 2. Go to https://identitymalta.com/eidreader/ and select the link to Download the software required to interact with the e-ID card (MAC OS) Once downloaded: 3. Open the eID_Reader_Software_MACOS_7_2_27.zip file 5 4. Open the macos folder 5. Open the scInterface-7.2.27.678-MacOSX-10_14.dmg file 6. Open the scInterface-7.2.27.678-MacOSX-10_14.pkg file 6 7. Select Continue 8. Select Continue 7 9. Select Continue 10. Select Agree 8 11. Select Install 12. Enter your Username Password and select Install Software 9 13. Select Close 14. Select OK 10 11 4. Changing the Transport Authentication and Signature PINs New ID cards come with a 4 digit Transport Authentication and 4 digit Transport Signature PIN which must be changed to something that you can remember. The minimum and maximum PIN digit requirement for Authentication and Signature is 6 to 8 digits. The first time you use your new ID card with the Smartcard Utility, you will be prompted to change your Transport Authentication and Signature PINs. 1. Connect your ID card reader device to your Macintosh and pair your ID card. Depending on the type of card and reader device, the ID card could be placed inside the card reader device or on top of the contactless symbol. 2. In Applications, Open SmartcardUtility Note – if the SmartCard Utility opens with message “No valid smartcards found”, this may be resolved by installing the latest ID card reader drivers for your Macintosh operating system version. 12 3. To change the Transport Authentication PIN: ➢ Enter the 4 digit Transport Authentication PIN in the Transport PIN field. ➢ Enter a new 6 to 8 digit PIN in the New Authentication PIN field. ➢ Enter the new 6 to 8 digit PIN once more in the Confirm Authentication PIN field. ➢ Select OK Once you have changed your Transport Authentication PIN, you will be prompted to change your Transport Signature PIN. 4. To change the Transport Signature PIN: ➢ Enter the 4 digit Transport Signature PIN in the Transport PIN field. ➢ Enter a new 6 to 8 digit PIN in the New Signature PIN field. ➢ Enter the new 6 to 8 digit PIN once more in the Confirm Signature PIN field. ➢ Select OK 13 5. Changing the Authentication and Signature PINs Once you have changed the Transport Authentication and Signature PINs, any subsequent PIN amendments can be done by following the process below. 1. Connect your ID card reader device to your Macintosh and pair your ID card. Depending on the type of card and reader device, the ID card could be placed inside the card reader device or on top of the contactless symbol. 2. In Applications, Open Smartcard Utility 14 3. To change the Authentication PIN: ➢ Enter the old 6 to 8 digit Authentication PIN in the Old PIN field. ➢ Enter a new 6 to 8 digit PIN in the New PIN field. ➢ Enter the new 6 to 8 digit PIN once more in the Confirm new PIN field. ➢ Select Change PIN 4. Select OK 15 5. To change the Signature PIN: ➢ From the PIN to change drop down menu, ensure Signature PIN is selected. ➢ Enter the old 6 to 8 digit Signature PIN in the Old PIN field. ➢ Enter a new 6 to 8 digit PIN in the New PIN field. ➢ Enter the new 6 to 8 digit PIN once more in the Confirm new PIN field. ➢ Select Change PIN. 6. Select OK 16 6. Firefox configuration steps If you are using Firefox as your primary browser, you will need to initially configure your ID card certificate settings so that Firefox can successfully communicate with your ID card reader device. 1. Connect your ID card reader device to your Macintosh and pair your ID card. Depending on the type of card and reader device, the ID card could be placed inside the card reader device or placed on top of the contactless symbol. 2. Open Firefox and select Preferences from the menu 3. Select Privacy & Security 17 4. Scroll to the bottom of the page and select Security Devices from the Certificates options 5. Select Load 6. In Module Name, replace wording New PKCS#11 Module with wording Malta ID Card and select Browse 18 7. Go to the Library\cv cryptovision directory; locate and select file lipcvp11.dylib and select Open 8. Select OK 19 9. You should now see Malta ID Card on the left-hand side. Expand the list by clicking on Malta ID Card and find the module in the list which has the label Authentication slot. Select Log In. 10. Enter your 6 to 8 digit Authentication PIN and select OK. 20 11. You should see the status of the module as Logged In 12. Repeat the Log In process for the module which has the Qualified Signature Slot label and select OK once complete. The Firefox browser is now configured for reading the Authentication and Signature PINs. 21 7. Adobe Acrobat configuration steps For Adobe Acrobat to communicate with your ID card and card reader device for Digital Signature purposes, you need to manually configure your Adobe certificate settings as a one-off exercise. 1. Connect your ID card reader device to your Macintosh and pair your ID card. Depending on the type of card and reader device, the ID card could be placed inside the card reader device or placed on top of the contactless symbol. 2. Open Adobe Acrobat and select Preferences 3. Within Categories: ➢ Select Security (Enhanced) and ensure the check box for Enable Protected Mode at start-up is deselected (i.e. no tick inside the box). If there is no tick, close the window and go to step 3. ➢ On the popup that appears asking you to confirm you are turning off Protected Mode, select Yes ➢ Close Adobe fully and reopen 22 4. Open the Preferences menu again Within Categories: ➢ Select Signatures ➢ Within Identities & Trusted Certificates, select More 5. Select PKC#S11 Modules Token and then Attach Module 23 6. Add the path /Library/cv Cryptovision/libcvP11.dylib and select OK 7. Enter your 6 to 8 Signature PIN and select OK 8. In Signatures, Creation & Appearance, select More 24 9. Select New 25 10. In Title, add a signature title of your choice and select OK. The preview window shows how your Digital Signature will look if it was applied to an Adobe document. 26 11. Select OK. This completes the Adobe Digital Signature configuration steps. 27 8. Frequently Asked Questions Why have ID card reader devices been introduced? In line with the European Commission’s intention to improve the security of transactions made online, the Government of Malta (GOM) has introduced digital certificates on electronic ID cards which can be read with an ID card reader device. What are the various interface types for the ID card reader devices and what are the usage scenarios? The interface types for the ID card reader devices are described in the table below: Card Connection Type Description Suitable for reading Reader Interface Type Contact There is a physical wire connecting the ID cards that have a visble chip. idenity card reader to your Macintosh. The idenity card needs to be placed into the ID card reader. Contactless There is no requirement for the ID card ID cards that do not have a visible chip to be placed into the ID card reader (the chip is embedded inside the card). device. The ID card reader device can wirelessley detect the ID card providing its within close proximity. Dual This ID card reader can operate in both • ID cards that have a visble chip. Interface a “contact” and “contactless” capacity. • ID cards that do not have a visible chip (the chip is embedded inside the card).