Executive Summary

WARNINGS PRESENT

This diagnostic session evaluated the local Digital Trust infrastructure across 4 cryptographic layers using vendor-neutral standards only (X.509, PKCS#11, CryptoAPI, CNG/KSP).

The scan discovered 408 certificate(s) across all Windows certificate stores, 12 legacy CSP provider(s), and 6 CNG Key Storage Provider(s).

Digital Signature Operations: 2 signing operation(s) performed, 1 verification(s) executed. See detailed Signature Test Results section below.

Passed Checks
2
Warnings
2
Failed
0
Certificates
408
CSP Providers
12
CNG KSPs
6

Test Environment

PropertyValue
Session IDDTL-20260811-160116
Operating SystemWindows 11 Enterprise (Build 26200.8875) v25H2
Architecturex64 (AMD64) [App: 32-bit on 64-bit OS]
Computer NameDESKTOP-74NE1NQ
Current UserForoughi
Privilege LevelStandard User
Cryptographic ServiceRUNNING
Smart Card ServiceSTOPPED
Certificate PropagationRUNNING
CNG AvailableYES

Digital Signature Test Results

The following signature operations were performed during this session:

Signature Operation #1

Certificate Subject
PKCS#11 Key on iPass_Token
Certificate Thumbprint (SHA-1)
Provider
PKCS#11 Direct (PKCS#11 v2.20)
Hash Algorithm
SHA-256
Signature Size / Duration
256 bytes in 8625 ms
Result
SUCCESS
Verification
SIGNATURE VALID  |  Certificate: VALID  |  Chain: VALID
Signature (hex preview)
A7B7D28036C7E98ADA980F13740B75E9BFEB494A739D6486BB177106D844C525056E3199E5ACAEF215FD6D9901A1EB9D...

Signature Operation #2

Certificate Subject
C=IR, O=iPass Token, CN=iPass Test User
Certificate Thumbprint (SHA-1)
2254973783116E672D96FAC165CAC188BE92FE69
Provider
iPassCSPv1 (Legacy CSP)
Hash Algorithm
SHA-256
Signature Size / Duration
256 bytes in 9406 ms
Result
SUCCESS
Signature (hex preview)
A7B7D28036C7E98ADA980F13740B75E9BFEB494A739D6486BB177106D844C525056E3199E5ACAEF215FD6D9901A1EB9D...

Interoperability Findings

Token CSP SHA-256 Capability Confirmed

The iPassCSPv1 token cryptographic service provider successfully performed SHA-256 digital signature operations, demonstrating full modern hash algorithm support at the hardware token layer.

Significance: This validates that vendor token middleware can bypass legacy Microsoft CSP limitations (which typically only support SHA-1) and expose modern algorithms natively through CryptoAPI.

Token Operation Independent of Smart Card Service

The Windows Smart Card Service is currently STOPPED, yet token-backed signing operations succeeded via the vendor CSP's direct communication path.

Interoperability Insight: This demonstrates that certain vendor CSPs (like iPassCSPv1) communicate with hardware tokens through their own middleware channels, independent of the Windows Smart Card subsystem. This is a critical diagnostic finding for cross-vendor interoperability analysis.

Legacy CSP Limitations Detected

7 legacy Microsoft cryptographic provider(s) are installed that do not natively support SHA-256 hash objects. Certificates bound to these providers cannot produce SHA-256 signatures without algorithm injection techniques (HP_HASHVAL) or provider migration.

Recommendation: Migrate keys to Microsoft Enhanced RSA and AES Cryptographic Provider or use CNG/KSP-backed certificates for modern signing operations.

Standards Compliance

This tool implements diagnostics against the following open standards, ensuring complete vendor neutrality:

X.509 (RFC 5280)
Certificate format, chain building, validity, extensions
PKCS#11 v2.20+
Cryptographic Token Interface Standard
PKCS#7 / CMS
Cryptographic Message Syntax
Microsoft CryptoAPI (CAPI)
Legacy Windows cryptographic interface
CNG / KSP
Cryptography Next Generation / Key Storage Provider (Vista+)
OCSP (RFC 6960)
Online Certificate Status Protocol
CRL (RFC 5280)
Certificate Revocation Lists
FIPS 180-4
SHA-1, SHA-256, SHA-384, SHA-512
PKCS#1 v2.1
RSA Cryptography Standard

Diagnostic Check Results

CheckCategoryStatusSummary
System InformationSystemWARNING
CryptoAPI / CSP DiagnosticsCryptoAPIPASS
CNG / KSP DiagnosticsCNGWARNING
Certificate Store AnalysisCertificatePASSTotal: 408 | Personal: 2 (usable: 2, token: 2) | System/CA: 405 | Expired (relevant): 0

Legacy Cryptographic Service Providers (CSP)

Provider NameTypeSignEncryptHardwareAlgorithms
iPassCSPv1PROV_RSA_FULL (1)YES-HWRSA_SIGN, SHA-1, SHA-256, SHA-384, SHA-512, MD5
Microsoft Base Cryptographic Provider v1.0PROV_RSA_FULL (1)YESYESSWRC2, RC4, DES, SHA-1, MD2, MD4, MD5, SSL3 SHAMD5, MAC, RSA_SIGN, RSA_KEYX, HMAC
Microsoft Base DSS and Diffie-Hellman Cryptographic ProviderPROV_DSS_DH (13)YESYESSWCYLINK MEK, RC2, RC4, DES, SHA-1, MD5, DSA_SIGN, DH_KEYX, DH_KEYX
Microsoft Base DSS Cryptographic ProviderPROV_DSS (3)YES-SWSHA-1, MD5, DSA_SIGN
Microsoft Base Smart Card Crypto ProviderPROV_RSA_FULL (1)YESYESHWRC2, RC4, DES, 3DES TWO KEY, 3DES, SHA-1, SHA-256, SHA-384, SHA-512, MD2, MD4, MD5, SSL3 SHAMD5, MAC, RSA_SIGN, RSA_KEYX, HMAC, AES 128, AES 192, AES 256
Microsoft DH SChannel Cryptographic ProviderUnknown (18)YESYESSWCYLINK MEK, RC2, RC4, DES, 3DES TWO KEY, 3DES, SHA-1, MD5, DSA_SIGN, DH_KEYX, DH_KEYX, SSL3 MASTER, TLS1 MASTER, SCH MASTER HASH, SCH MAC KEY, SCH ENC KEY
Microsoft Enhanced Cryptographic Provider v1.0PROV_RSA_FULL (1)YESYESSWRC2, RC4, DES, 3DES TWO KEY, 3DES, SHA-1, MD2, MD4, MD5, SSL3 SHAMD5, MAC, RSA_SIGN, RSA_KEYX, HMAC
Microsoft Enhanced DSS and Diffie-Hellman Cryptographic ProviderPROV_DSS_DH (13)YESYESSWCYLINK MEK, RC2, RC4, DES, 3DES TWO KEY, 3DES, SHA-1, MD5, DSA_SIGN, DH_KEYX, DH_KEYX
Microsoft Enhanced RSA and AES Cryptographic ProviderPROV_RSA_AES (24)YESYESSWRC2, RC4, DES, 3DES TWO KEY, 3DES, SHA-1, SHA-256, SHA-384, SHA-512, MD2, MD4, MD5, SSL3 SHAMD5, MAC, RSA_SIGN, RSA_KEYX, HMAC, AES 128, AES 192, AES 256
Microsoft RSA SChannel Cryptographic ProviderPROV_RSA_SCHANNEL (12)YESYESSWAES 128, AES 256, RC2, RC4, DES, 3DES TWO KEY, 3DES, SHA-1, MD5, SSL3 SHAMD5, MAC, RSA_KEYX, HMAC, SSL2 MASTER, SSL3 MASTER, TLS1 MASTER, SCH MASTER HASH, SCH MAC KEY, SCH ENC KEY
Microsoft Strong Cryptographic ProviderPROV_RSA_FULL (1)YESYESSWRC2, RC4, DES, 3DES TWO KEY, 3DES, SHA-1, MD2, MD4, MD5, SSL3 SHAMD5, MAC, RSA_SIGN, RSA_KEYX, HMAC
OpenSC CSPPROV_RSA_FULL (1)YESYESHWRC2, RC4, DES, 3DES TWO KEY, 3DES, SHA-1, SHA-256, SHA-384, SHA-512, MD2, MD4, MD5, SSL3 SHAMD5, MAC, RSA_SIGN, RSA_KEYX, HMAC, AES 128, AES 192, AES 256

CNG Key Storage Providers (KSP)

KSP NameStatusHardwareSoftwareRemovableComment
iPass Key Storage ProviderAVAILABLEYES-YES
Microsoft Software Key Storage ProviderAVAILABLE-YES-
Microsoft Passport Key Storage ProviderAVAILABLEYESYES-
Microsoft Platform Crypto ProviderAVAILABLEYES--
Microsoft Pluton Cryptographic ProviderUNAVAILABLE---
Microsoft Smart Card Key Storage ProviderAVAILABLEYESYESYES

Certificate Inventory (Personal & Signing-Capable)

StoreSubjectIssuerProviderKey StatusValidity
CurrentUser\MYC=IR, O=iPass Token, CN=iPass Test UserC=IR, O=iPass Test, CN=iPass Test CAiPassCSPv1TOKENVALID
CurrentUser\TrustedPeopleCN=ForoughiCN=ForoughiMicrosoft Enhanced Cryptographic Provider v1.0PRESENTVALID
LocalMachine\MYC=IR, O=iPass Token, CN=iPass Test UserC=IR, O=iPass Test, CN=iPass Test CAiPassCSPv1TOKENVALID

Note: Report shows only personal and trusted certificates. Total certificates in all stores: 408 (system/CA certificates omitted for brevity).