I would like to know the X509Certificate2s that are on a smart card, where there could be multiple smart card readers with multiple cards and the cards have multiple certificates on them.
Using SmartCardReader Class I use FindAllCardsAsync to get all smart cards.
- Is it possible then to get the certificates on that smart card?
- Is there any property I can get from Windows.Devices.SmartCards which I can then use with the x509Store?
I have also tried to query the x509Store for certificates to find out if they come from a hardware device. With the help of this X509Certificate2: determine if certificate private key belongs to an hardware device, and if it needs a PIN I am able to get all certificates and to know if they are connected to a card reader.
The problem is that when a card is inserted into the card reader the certificates are added to the store, however, they remain there when you remove the card. The are only removed if you removed the card reader. The question casts the Private Key to a RSACryptoServiceProvider with the following code, however, this automatically shows a dialog to insert a card.
Dim rsaKey As RSACryptoServiceProvider = CType(x509.PrivateKey, RSACryptoServiceProvider)
If rsaKey.CspKeyContainerInfo.HardwareDevice Then
Debug.Print("Certifacte on Card")
End If
Using the x509 store and a X509Certificate2Collection is there another way to work out whether a certificate comes from a smart card and that card is still in the card reader?
By the way the question also has a suggested answer titled My preferred solution which does confirm whether the certificates in the store are software or hardware based, but this does not confirm whether the card is still inserted or not.
Is there any way to use a X509Certificate2 handle to find out the card it comes from, if any and then relate this to a similar property of Windows.Devices.SmartCard?