WARNINGS PRESENT
This diagnostic session evaluated the local Digital Trust infrastructure across 4 cryptographic layers using vendor-neutral standards only (X.509, PKCS#11, CryptoAPI, CNG/KSP).
The scan discovered 408 certificate(s) across all Windows certificate stores, 12 legacy CSP provider(s), and 6 CNG Key Storage Provider(s).
Digital Signature Operations: 2 signing operation(s) performed, 1 verification(s) executed. See detailed Signature Test Results section below.
| Property | Value |
|---|---|
| Session ID | DTL-20260811-160116 |
| Operating System | Windows 11 Enterprise (Build 26200.8875) v25H2 |
| Architecture | x64 (AMD64) [App: 32-bit on 64-bit OS] |
| Computer Name | DESKTOP-74NE1NQ |
| Current User | Foroughi |
| Privilege Level | Standard User |
| Cryptographic Service | RUNNING |
| Smart Card Service | STOPPED |
| Certificate Propagation | RUNNING |
| CNG Available | YES |
The following signature operations were performed during this session:
A7B7D28036C7E98ADA980F13740B75E9BFEB494A739D6486BB177106D844C525056E3199E5ACAEF215FD6D9901A1EB9D...2254973783116E672D96FAC165CAC188BE92FE69A7B7D28036C7E98ADA980F13740B75E9BFEB494A739D6486BB177106D844C525056E3199E5ACAEF215FD6D9901A1EB9D...The iPassCSPv1 token cryptographic service provider successfully performed SHA-256 digital signature operations, demonstrating full modern hash algorithm support at the hardware token layer.
Significance: This validates that vendor token middleware can bypass legacy Microsoft CSP limitations (which typically only support SHA-1) and expose modern algorithms natively through CryptoAPI.
The Windows Smart Card Service is currently STOPPED, yet token-backed signing operations succeeded via the vendor CSP's direct communication path.
Interoperability Insight: This demonstrates that certain vendor CSPs (like iPassCSPv1) communicate with hardware tokens through their own middleware channels, independent of the Windows Smart Card subsystem. This is a critical diagnostic finding for cross-vendor interoperability analysis.
7 legacy Microsoft cryptographic provider(s) are installed that do not natively support SHA-256 hash objects. Certificates bound to these providers cannot produce SHA-256 signatures without algorithm injection techniques (HP_HASHVAL) or provider migration.
Recommendation: Migrate keys to Microsoft Enhanced RSA and AES Cryptographic Provider or use CNG/KSP-backed certificates for modern signing operations.
This tool implements diagnostics against the following open standards, ensuring complete vendor neutrality:
| Check | Category | Status | Summary |
|---|---|---|---|
| System Information | System | WARNING | |
| CryptoAPI / CSP Diagnostics | CryptoAPI | PASS | |
| CNG / KSP Diagnostics | CNG | WARNING | |
| Certificate Store Analysis | Certificate | PASS | Total: 408 | Personal: 2 (usable: 2, token: 2) | System/CA: 405 | Expired (relevant): 0 |
| Provider Name | Type | Sign | Encrypt | Hardware | Algorithms |
|---|---|---|---|---|---|
| iPassCSPv1 | PROV_RSA_FULL (1) | YES | - | HW | RSA_SIGN, SHA-1, SHA-256, SHA-384, SHA-512, MD5 |
| Microsoft Base Cryptographic Provider v1.0 | PROV_RSA_FULL (1) | YES | YES | SW | RC2, RC4, DES, SHA-1, MD2, MD4, MD5, SSL3 SHAMD5, MAC, RSA_SIGN, RSA_KEYX, HMAC |
| Microsoft Base DSS and Diffie-Hellman Cryptographic Provider | PROV_DSS_DH (13) | YES | YES | SW | CYLINK MEK, RC2, RC4, DES, SHA-1, MD5, DSA_SIGN, DH_KEYX, DH_KEYX |
| Microsoft Base DSS Cryptographic Provider | PROV_DSS (3) | YES | - | SW | SHA-1, MD5, DSA_SIGN |
| Microsoft Base Smart Card Crypto Provider | PROV_RSA_FULL (1) | YES | YES | HW | RC2, RC4, DES, 3DES TWO KEY, 3DES, SHA-1, SHA-256, SHA-384, SHA-512, MD2, MD4, MD5, SSL3 SHAMD5, MAC, RSA_SIGN, RSA_KEYX, HMAC, AES 128, AES 192, AES 256 |
| Microsoft DH SChannel Cryptographic Provider | Unknown (18) | YES | YES | SW | CYLINK MEK, RC2, RC4, DES, 3DES TWO KEY, 3DES, SHA-1, MD5, DSA_SIGN, DH_KEYX, DH_KEYX, SSL3 MASTER, TLS1 MASTER, SCH MASTER HASH, SCH MAC KEY, SCH ENC KEY |
| Microsoft Enhanced Cryptographic Provider v1.0 | PROV_RSA_FULL (1) | YES | YES | SW | RC2, RC4, DES, 3DES TWO KEY, 3DES, SHA-1, MD2, MD4, MD5, SSL3 SHAMD5, MAC, RSA_SIGN, RSA_KEYX, HMAC |
| Microsoft Enhanced DSS and Diffie-Hellman Cryptographic Provider | PROV_DSS_DH (13) | YES | YES | SW | CYLINK MEK, RC2, RC4, DES, 3DES TWO KEY, 3DES, SHA-1, MD5, DSA_SIGN, DH_KEYX, DH_KEYX |
| Microsoft Enhanced RSA and AES Cryptographic Provider | PROV_RSA_AES (24) | YES | YES | SW | RC2, RC4, DES, 3DES TWO KEY, 3DES, SHA-1, SHA-256, SHA-384, SHA-512, MD2, MD4, MD5, SSL3 SHAMD5, MAC, RSA_SIGN, RSA_KEYX, HMAC, AES 128, AES 192, AES 256 |
| Microsoft RSA SChannel Cryptographic Provider | PROV_RSA_SCHANNEL (12) | YES | YES | SW | AES 128, AES 256, RC2, RC4, DES, 3DES TWO KEY, 3DES, SHA-1, MD5, SSL3 SHAMD5, MAC, RSA_KEYX, HMAC, SSL2 MASTER, SSL3 MASTER, TLS1 MASTER, SCH MASTER HASH, SCH MAC KEY, SCH ENC KEY |
| Microsoft Strong Cryptographic Provider | PROV_RSA_FULL (1) | YES | YES | SW | RC2, RC4, DES, 3DES TWO KEY, 3DES, SHA-1, MD2, MD4, MD5, SSL3 SHAMD5, MAC, RSA_SIGN, RSA_KEYX, HMAC |
| OpenSC CSP | PROV_RSA_FULL (1) | YES | YES | HW | RC2, RC4, DES, 3DES TWO KEY, 3DES, SHA-1, SHA-256, SHA-384, SHA-512, MD2, MD4, MD5, SSL3 SHAMD5, MAC, RSA_SIGN, RSA_KEYX, HMAC, AES 128, AES 192, AES 256 |
| KSP Name | Status | Hardware | Software | Removable | Comment |
|---|---|---|---|---|---|
| iPass Key Storage Provider | AVAILABLE | YES | - | YES | |
| Microsoft Software Key Storage Provider | AVAILABLE | - | YES | - | |
| Microsoft Passport Key Storage Provider | AVAILABLE | YES | YES | - | |
| Microsoft Platform Crypto Provider | AVAILABLE | YES | - | - | |
| Microsoft Pluton Cryptographic Provider | UNAVAILABLE | - | - | - | |
| Microsoft Smart Card Key Storage Provider | AVAILABLE | YES | YES | YES |
| Store | Subject | Issuer | Provider | Key Status | Validity |
|---|---|---|---|---|---|
| CurrentUser\MY | C=IR, O=iPass Token, CN=iPass Test User | C=IR, O=iPass Test, CN=iPass Test CA | iPassCSPv1 | TOKEN | VALID |
| CurrentUser\TrustedPeople | CN=Foroughi | CN=Foroughi | Microsoft Enhanced Cryptographic Provider v1.0 | PRESENT | VALID |
| LocalMachine\MY | C=IR, O=iPass Token, CN=iPass Test User | C=IR, O=iPass Test, CN=iPass Test CA | iPassCSPv1 | TOKEN | VALID |
Note: Report shows only personal and trusted certificates. Total certificates in all stores: 408 (system/CA certificates omitted for brevity).