Keyfob Station — Code Audit Open Items

# Keyfob Station — Code Audit Open Items

Last updated: 2026-08-31 (TODO-Tracking nach Forgejo migriert: keyfob-station#1–8; I5-Milestone bis 11.09.)

## CLOSED — private key format (M5/M10), fully resolved 2026-08-17

KLMS delivers field[8] (DGI A003) card-ready as AES-128-CBC, IV=0, ISO 9797-1 M2; the
station verifies structure only and forwards untouched (065ee6b). HW-verified on two
fobs with GA ECDSA signatures passing.

## CLOSED — container signature verification, 2026-08-21 (e818a68)

`verify_signature` (textbook RSA over SHA-256 of header‖encrypted payload, key
`data/clypeum_signing_pubkey.pem`, configurable via `signing_pubkey_path`) is **wired
and ENFORCED** in the KLMS flow. Empirically confirmed against the dev KLMS
(`container signature VERIFIED`, full green cycle). Production signing-key
confirmation → extern, siehe keyfob-station#7 (+ #1).

## KLMS Team — remaining OPEN items (external)

→ **Nach Forgejo migriert: keyfob-station#7** (Root-CA / CID-Header / Checksum-Spec / Signing-Key-Continuity) + **keyfob-station#1** (WI-14-Call: report_usage + Signing-Key). Ursprüngliche Tabelle:

| # | Issue | What's needed |
|---|-------|---------------|
| C1 | `accept_invalid_certs` | Valid root CA or fixed cert chain — station config-ready (default secure) |
| — | Empty `cryptoDataContainerId` header | Populate (`validate_cid` ready to enforce) |
| — | Signing-key continuity | Confirm the pubkey also matches the production KLMS |
| — | Container checksum algorithm unspecified | Spec for header values 0x00–0x03 |
| — | `report_usage` alignment | Status values/payload semantics (method ready, unwired by decision) |
| — | getVersions / getContainerTypes return empty | Response shape or permissions? (minor) |

## Session log

**2026-08-27 (audit round 7):** remote-machine feedback fixed — reader fallback
(256a060: ACR1281 enumerated without "PICC" in the name; monitor-driven panels OK,
name-filtered Provision/Re-install failed; now PICC → non-SAM → first, reader list
logged) + FESN/SPID displayed in Validate / Production (Files) / Production (KLMS) /
single-fob Provision. Round-7 review resolved the SPID representation question with
remote-log evidence (**40-byte ASCII hex string** — display code correct; stale 20-byte
doc + double-encoded audit JSON fixed); KLMS validation-reconnect now fails the run
(was success-without-signature-check); failed attempts retain read-back FESN/SPID in
the terminal ProdResult; packaging discovery rewritten (recursive FESN.txt scan,
newest batch wins, @() guard against PS scalar-unwrap char-indexing — a real bug the
dry-run caught). Mechanical suite: clippy 0 ×3 variants, 105 tests, fmt/doc clean.
**2026-08-21:** Transport diagrams; signature check wired → VERIFIED → ENFORCED (e818a68).
**2026-08-20:** user guides (Word) shipped in deployment; certs hints corrected.
**2026-08-19:** keys-only dev_profiles.toml + deny_unknown_fields.
**2026-08-18:** diagrams committed (ECIES); deployment packaging; size-optimized profile.
**2026-08-17:** KLMS on CBC; ECB bridge removed; two-fob HW verification.
**2026-08-14:** 500 root-cause; bridge; hardening; audit round 5; notes consolidation.

## Deployment history

- 2026-08-26 → three self-contained variant zips (dev/test with content, prod without;
  prod ships only the production user guide)
- 2026-08-27 → shipped to remote test machine; reader issue found & fixed same day

## Documented as Intentional (won't fix)

IAM empty user/pass (mTLS public client) · textbook RSA verify (Clypeum format) · wrapper KDF
zero LABEL/CONTEXT · KF_APPLET_SELECT_AID copy · STATIC_KEY_TABLE test duplication · ISD
SELECT variants via `builders::select` · prod-station dev-keys copy · result-struct mirrors.

## Refactoring — COMPLETE

H7 SCP03 handshake ×5, M20 god functions, H2 audit doc (HW-verified) · Audit rounds 5–7:
error unification, typed StepStatus, C-MAC helper, builders::select, kf-klms tests,
fail-closed validation paths (incl. KLMS reconnect), tag-keyed KLMS fields, panic-safe
workers, dep cleanup, enforced container signature, reader-discovery fallback.

## Remaining open (ours)

Nichts Offenes mehr in Joplin — **Optional backlog (AES-Blocksize-Konstante, fesn_text/spid_text-Dedupe) → keyfob-station#6.** Rest: Forgejo-Issues #1–5 (I5).

## Workspace & Notes

- `D:\Development\Workspaces\rust-workspace\keyfob-station` (origin ssh://192.168.1.2,
  pushed through 8bac041)
- Key Fob Station notebook: audit note (live state), Project Status (snapshot + ops),
  specs, history. PlantUML: docs/diagrams/{KDF,Transport,HSM_Backup}.

## Current state (commit 8bac041)

- All 3 build variants ZERO warnings; clippy/rustfmt/rustdoc clean; 105 tests green
- KLMS flow enforces: mTLS → token → wrapper-key decrypt → signature verify →
  session-key gate → SCP03 → personalization → GA validation (reconnect failures
  included) — all HW-verified
- FESN/SPID read-back displayed in all four result panels; SPID confirmed 40-B ASCII
- Deployment: three variant zips rebuilt at 8bac041, ready to re-ship

id: bb3506f46ead40df8a7f965a73339928
parent_id: beb251c3b3f9490285e6cb68942a5145
created_time: 2026-08-13T20:19:34.178Z
updated_time: 2026-08-31T18:44:48.419Z
is_conflict: 0
latitude: 0.00000000
longitude: 0.00000000
altitude: 0.0000
author: 
source_url: 
is_todo: 0
todo_due: 0
todo_completed: 0
source: joplin-desktop
source_application: net.cozic.joplin-desktop
application_data: 
order: 1786652374178
user_created_time: 2026-08-13T20:19:34.178Z
user_updated_time: 2026-08-31T18:44:48.419Z
encryption_cipher_text: 
encryption_applied: 0
markup_language: 1
is_shared: 0
share_id: 
conflict_original_id: 
master_key_id: 
user_data: 
deleted_time: 0
is_locked: 0
extracted_resource_ids: 
type_: 1