cimer2

Ministry of Interior

eID Client

 

Management Application for Hungarian eID Card

User Guide

 

Date of publication: 20/10/2022

File name and version number of publication:
 
eSzig_eSzemelyiKliens_AP_Felhasznaloi_v19_ENG.docx.docx

Program version supported by user guide: eSzemélyi Kliens v1.7. x.

Document Information: It covers the current and supported version of the 1.7 eID Clients.

1          Purpose of Document

This guide is part of the eID Client software package. It aims to present how to use the personal e-ID Card Management Application.

2          Contents

1     Purpose of Document. 2

2     Contents. 2

3     Introduction.. 4

3.1     Supported card readers (eID Client) 4

3.2     Supported operating systems. 4

4     Functionalities of the eID Client Card Management Application.. 7

4.1     Starting the application. 7

4.2     The application main panel. 7

4.3     Card check. 8

4.3.1       Error messages related to the card reader 9

4.3.2       Error-messages related to the card. 9

4.3.3       Error messages related to the identification functionality (e-Identification) 10

4.3.4       Error messages related to the electronic signature (e-Signature) functionality. 10

4.3.5       eNEK applet for public transport verification. 11

4.3.6       ePassport function verification. 11

4.4     PIN management with card reader without PIN pad. 12

4.4.1       Blocked PIN code. 15

4.5     PIN management with card reader with PIN pad. 18

4.5.1       Blocked PIN code. 22

4.5.2       Where to find the activation PIN related to the personal e-ID card. 23

4.5.3       Where to find the activation PIN related to the electronic signature. 24

4.5.4       Have you forgotten your PUK code?. 24

4.5.5       How to get a new PUK code. 24

4.5.6       Authentication methods. 24

4.6     Information. 26

4.7     Certificate. 28

4.8     ePassport. 29

4.9     Settings. 29

4.9.1       Run on startup. 30

4.9.2       Check for updates at startup. 30

4.9.3       Enable eSign function. 31

4.9.4       Enabling eSign PIN status check. 31

4.9.5       Enable ePass data overview.. 31

4.9.6       Home PC. 32

4.9.7       Storing CAN (Card Access Number) in cache (Cache CAN) 32

4.9.8       Approve reading essential data. 32

4.9.9       Show close reminder 32

4.9.10          Show exit reminder 33

4.9.11          Languages. 33

4.9.12          Update. 33

5     List of Figures. 33

 


3          Introduction

This user guide aims to support the processes of the new personal e-ID card with a storage unit (hereinafter: personal e-ID card or permanent personal ID) by presenting how to use the Card Management Application, i.e. the eID Client and the card reader peripheral devices serving the former.

The Card Management Application is a core part of the eID Client software package, required for using the personal e-ID card in a PC environment. The application performs the following main tasks:

a)       It manages the PIN codes related to the electronic ID card (e-Identification PIN, e-Signature PIN activation; e-Identification PIN, e-Signature PIN change, entering CAN number; e-Identification PIN, e-Signature PIN, unlocking wrong PIN and changing it by entering PUK code)

b)      It enables the activation of the e-Identification and e-Signature functionalities of the personal e-ID card as well as access to these for various applications in a PC environment.

c)       It helps display information about the connected card reader and the status of the personal e-ID card.

3.1        Supported card readers (eID Client)

When choosing an appropriate card reader for the application we recommend examining the following parameters:

The use of the following card readers is supported officially:

3.2        Supported operating systems

The current version of the application supports the following operating systems and functionalities:

-          Windows XP, 7, 8.1, 10 (32/64 bit) – management of PIN codes; management of e-Identification, e-Signature activation and e-Signature functionalities

Downloadable installer for the management of PIN codes and of the e-Identification, e-Signature activation and e-Signature functionalities for a 32 bit operational system: eSzemelyi_Kliens _1_6_x.msi

The installers are standard MSI installers and thus support local as well as remote installation.

-          Linux distributions: CentOS 7, Debian 10, OpenSuse 15.2, Ubuntu 20.04 LTS

Note: The Gnome X11 surface is supported only from the 3.4 version after the installation of the following extension: https://extensions.gnome.org/extension/495/topicons/

Downloadable installer for the management of PIN codes and of the e-Identification, e-Signature activation and e-Activation functionalities for 32 bit operating systems: eSzemelyi_Kliens_x86_1_6_x.deb, eSzemelyi_Kliens _x86_1_7_x.rpm

 

Downloadable installer for the management of PIN codes and of the e-Identification, e-Signature activation and e-Signature functionalities for 64 bit operating systems: eSzemelyi_Kliens_x64_1_6_x.deb, eSzemelyi_Kliens _x64_1_7_x.rpm

 

-          MacOS: Mojave, Catalina, Big Sur

 

Downloadable installer for the management of PIN codes and of the e-Identification, e-Signature activation and e-Signature functionalities: eSzemelyi_Kliens _1_7_x.dmg


 

Glossary

 

eID Client: an application supporting the personal e-ID card processes of the card management service

CAN number: a 6-digit number sequence in the middle of the photo side of the permanent ID card

e-Identification activation PIN: an activating PIN code related to the permanent ID card, which is a 5-digit activation code required for generating a PIN code for the permanent ID card. The e-Identification activation PIN code is specified on the ‘Personal identification card - code card’ enclosed in the envelope received when applying for the ID Card.

e-Identification PIN: the PIN code related to the permanent personal e-ID card, required for using the ID card via electronic administrations; it verifies the eligibility of access of the holder of the ID card and is made up of 6 digits of the holder’s choice.

e-Signature activation PIN: the 5-digit activation PIN code related to the electronic signature, required for generating a PIN code related to the electronic signature. The e-Signature activation PIN code is specified on the “Electronic signature code card” enclosed in the envelope received when applying for the e-signature.

e-Signature PIN: the PIN code related to the electronic signature, required for generating an electronic signature, is a set of data verifying signatory’s eligibility of access and is made up of 7 digits of the signatory’s choice

PUK code: an unlocking code to be used after repeated failures to correctly enter the PIN code related to the permanent personal ID or the electronic signature, made up of randomly generated 10 digits. The same PUK code can be used for changing the PIN code related to the permanent personal ID/ electronic signature.

 

Transport ID and functionality (eNEK applet for public transport verification): The e-ID card provides a number of functions, which is connected to multiple services. Due to the technological development of the e-ID card it is compatible with public transport systems which provide their services within the framework of the National Unified Card System (Nemzeti Egységes Kártyarendszer - NEK). The e-ID cards issued between 1 January 2016 and 14 November 2016 have a storage unit (chip) which has the specificity that it is not capable for using the public transport functionality (eNEK) technically by default, therefore it is necessary to upload the required eNEK applet to the e-ID Card to reach the relevant functionality & systems.

 

The special application which supports the function is automatically placed on the e-ID cards issued after 14 November 2016, so they are appropriate for using the public transport system by default. A unique identifier (traffic identifier) can be read out from the application, for the reading process there is no need to enter either CAN or PIN.

4          Functionalities of the eID Client Card Management Application

4.1        Starting the application

The installed application can be started from the Desk, by clicking on the shortcut icon “eID Client” placed on the Desk, or from the Start Menu. Alternatively – depending on the user settings, in default setting – the application starts automatically when logging in.

Note: On Settings tab it can be set/reset with the checkbox “Run on startup” whether the eID Client should automatically start after the computer has started. /See: Figure 25: eID Client – Settings menu/

4.2        The application main panel

After starting the application the main panel is displayed, comprising four major sections: the menu bar” (File, Help) the select view side bar menu (Card Check, PIN management, Info, Certificate, ePassport, Settings), the active side bar view and the status line (Card reader verification, Card verification, eID function verification, e-Sign function verification, eNEK applet for public transport verification, ePassport function verification).

Note: There are different information about the card in each view of the side bar menu. When you select a view, the relevant page is updated and displayed on the active side bar view.

Figure 1 : eID Client – Application main panel


4.3        Card check

When you select the Cyan Card check icon 25x31 Card Check view, the relevant card verification view is displayed.

This view aims to display the information on the card use status, i.e. the card reader status, the ID card status, the status of e-Identification (eID), e-Signature (eSign), public transport (eNEK) and ePassport functionalities.

Figure 2 : eID Client – Card verification menu

Status checking:

If an item in the list operates properly, there is a green tick next to this item and the writing „OK” under it

If it does not operate properly at the moment, there is a red „X”  next to the list item and some status information about the problem under it.

 

A yellow or red exclamation mark (depending on the severity) and status information describe the warning and indicate the problem related to the operation of the item concerned or the measures to take.

 

 

If some warning or error are active, this is indicated by a change in the icon of the related view. The icon related to the view concerned changes to yellow or red.

 

For example: On the basis of “Figure 2 : eID Client – Card verification menu”, according to the reported error the card has not been activated yet, so activation can be initiated by clicking on either the link “Change Transport PIN” or the button [Change] in the view “PIN Management”.

4.3.1         Error messages related to the card reader

4.3.1.1        Card reader not found

The error message “Card reader not found” appears if the program is unable to detect a card reader connected to the computer. If there is a card reader connected to the computer and this message appears nevertheless, try to disconnect then reconnect the reader and check if the appropriate driver is installed on the computer. If the problem is not solved nevertheless, call the customer service by dialling 1818.

4.3.1.2        Not compatible card reader

The message “The card reader is not compatible with the ID card” under the “Card reader verification” section means that the detected card reader contains a firmware, which is not fully compatible with the Hungarian eID card. As a consequence, the application cannot guarantee the appropriate operation and some functions may not work properly. We recommend you to only use supported card readers.

4.3.2         Error-messages related to the card

4.3.2.1        Please insert your smart card

If you see the error message “Please insert your smart card”, it means that the application is unable to detect the card. If there is a card in the reader, please remove it, then insert it back into the reader. If this does not solve the problem, please ask the customer service for help by dialling 1818.

4.3.2.2        Incorrect CAN

If the message “CAN enter failed!” appears, it means that the previous attempt to enter the CAN number of the card failed. The application can be used nevertheless, but it is unable to read the card, so several of its functionalities will not be accessible. Please reinsert the card and enter the correct CAN number.

4.3.2.3        PUK blocked

If the message “PUK blocked” appears, it means that the wrong PUK code was entered more times than allowed.

4.3.3         Error messages related to the identification functionality (e-Identification)

4.3.3.1        Change Transport PIN

The message “Please change the Transport PIN” appears, with reference to verifying the e-Identification functionality, if you have not yet used the activation PIN code related to the personal ID card. After entering this activation PIN code you can set the permanent PIN code. The card is ready for use but in order to use the identification functionality online, the permanent PIN code must be entered (for further information, please read 4.5.2Where to find the activation PIN related to the card”).

4.3.3.2        PIN code is blocked

The message “PIN code is blocked” appears if the wrong PIN code related to the permanent ID card was entered more times than allowed. In this case, the blocked status of the PIN code can be unlocked using a PUK code and entering a new PIN code simultaneously.

4.3.3.3        Only one try left

The message “Only one try left” is a warning that the wrong PIN has been entered as many times as allowed and there is just one last opportunity to enter the correct code. If the correct code is entered, the counter will reset and the error message will disappear.

4.3.4         Error messages related to the electronic signature (e-Signature) functionality

4.3.4.1        Please change the Transport PIN

The message “Please change the Transport PIN” appears with reference to verifying the e-Signature function if you have not used the transport PIN code related to your e-signature yet. The card is ready to use but using the electronic signature function requires activating the document by the transport PIN code related to electronic signature (for further information see 4.5.3).

4.3.4.2        The certificate expires in <number> days

The certificate expires in less than a month. In order to ensure smooth card use, the certificate must be renewed.

4.3.4.3        PIN code blocked

The message “PIN code blocked” appears if a wrong PIN code related to the electronic signature has been entered more times than allowed. In that case the PIN code can be changed by using the PUK code.

4.3.4.4        The certificate has expired

The validity of the certificate has expired. The certificate cannot be used after its expiration; its further use requires renewal. Please contact support.

4.3.4.5        Only one try left

The message “Only one try left” is a warning indicating that a wrong PIN code related to the electronic signature has been entered at the maximum number of times allowed, and you have just one last opportunity to enter it correctly. If you enter the correct PIN code, the counter will reset and the error message will disappear.

4.3.4.6        The e-Signature functionality is not prepared on the card

The e-Signature functionality is not prepared on the personal e-ID card; until this functionality is prepared, the card cannot be used for digital signature.

4.3.4.7        eSign function is active, but a certificate could not be detected on the card

The e-Signature function is not valid, due to the uncompleted certificate update process. Please repeat the update procedure and don't use the eSign function until the process has successfully been completed.

4.3.5         eNEK applet for public transport verification

Two states can be the result of the verification of the public transport function:

1.       “Correct” ŕ In this case, the e-ID Card is properly prepared for using the public transport function (eNEK applet).

2.       “The card doesn’t have the eNEK applet (for public transport).“ŕ In case of e-ID Cards issued before 14th November 2016, it is necessary to upload ex post the eNEK applet to the e-ID Card storage unit. You can use either of the following methods to upload the appropriate eNek applet ex post or upgrade an eNEK applet that is already uploaded on your e-ID Card:

·         personally in any of the government offices and in certain ticket offices of the public transport service providers (e.g. MÁV, DKV) already connected to the system

·         online, through the dedicated web portal (Webes Ügysegéd) ŕ e-ID Card (click on eSzemélyi - SZIG bubble) ŕNational Unified Card System (click on the NEK - Nemzeti egységes kártyarendszer kérelem) application by using the appropriate smart card reader and the e-ID Client card management application.

 

During the installation of the eNEK applet the citizen must enter the PIN code belonging to the identification function of the e-ID Card. As soon as the eNEK applet has been installed, the public transport function can be used (public transport service providers will be able to read the unique identifier from the applet). The eNEK applet will be instantly installed on the e-ID Card free of charge.

4.3.6         ePassport function verification

The ePassport function verification is disabled by default, therefore a “No information” message is displayed about the result of verification. The verification can be enabled by the Display ePassport details” option in the Settings view. Enabling this setting the “OK” message is displayed after a successful reading.

 

4.4        PIN management with card reader without PIN pad

In the view “PIN Management” you can manage the PIN codes serving to identify the user and perform PIN operations. The select view icon is the following:

Cyan Pin Management icon 25x25.

On the active side bar view you can select if you want to manage the PIN code related to the permanent ID card or the one related to the electronic signature. When first using the permanent ID card you will see the tabs “eID Transport PIN” and “eSign Transport PIN”. Replacing these with the PIN codes of your choice, you will retain the opportunity of changing PIN codes.

 

On the page you can see the number of attempts allowed, which is 3 by default. If you enter a wrong PIN code more than three times, this will generate a blocked status, as a consequence of which the same PIN code cannot be used again. The blocked PIN code may be unlocked and a new PIN may be set by entering the PUK code.

If the permanent personal ID card has not been activated yet, the card must be activated as the first PIN management operation by starting the activation of the card or of the e-Signature service from the tabs eID PIN or eSign PIN, using the [Change] button. /See: “Figure 2 : eID Client – Card verification menu”/

If the permanent personal ID has been activated already, previously entered PIN codes can be changed according to Figure 3 : e-Personal Client - PIN management menu – reader without PIN pad

IMPORTANT: You can try to enter the right PIN code 3 times at the maximum, and have maximally 10 attempts for entering the correct PUK code. If the maximum number of attempts has been reached, the code will enter a blocked status.

 

Figure 3 : e-Personal Client - PIN management menu – reader without PIN pad

By clicking on the “Change” button, the dialogue panel <eID> PIN change or <eSign> PIN change will appear.

The header of the dialogue panel PIN change depends on which tab the [Change] button was reached from, the two alternative dialogue panel headers being “eID PIN change” or “eSign PIN change”.

Figure 4: eID Client - "eID Transport PIN change" panel

In order to change your PIN code, first enter the old code, then the new code, which must be of the expected length. The „eID Transport PIN” and the “eSign Transport PIN” codes must be used before activating the card and are both 5 digits long. After the card activation the PIN code entered by the user is 6 digits long in the case of “eID PIN” and 7 digits long in the case of “eSign PIN”.

In the case of a forgotten PIN code, it is possible to set a new PIN code with the PUK code. This function is available if you click on the "Forgot your PIN code?" link.

 

Figure 5: e-ID Client - Forgot your PIN code link

4.4.1         Blocked PIN code

If the number of remaining attempts reaches zero, the PIN code will be put into a blocked status.

Figure 6: eID – Unlocking blocked PIN code I – without PINPAD

In order to unlock the blocked PIN code, click on [Unblock] to enter the PUK code.

Figure 7: e-Personal Client – Unlocking blocked PIN code II – Entering PUK code

After successfully entering the PUK code, enter the new PIN code in order to unlock the blocked PIN code.

In case you use a reader without a PIN pad, the program counts the number of attempts still available for entering the correct PUK code at the bottom of the panel.

Figure 8: eID Client – Unlocking a blocked PIN code III – Entering a new PIN

The procedure is the same when changing the e-Sign PIN code, only the header is different (instead of “eID PIN change”, the header „eSign PIN change” will appear in the panel heading and field heading).

In case of a forgotten PIN code, it is possible to set a new PIN code with the PUK code. This function is available if you click on the "Forgot your PIN code?" link. When using reader without PIN pad, the correct PUK code is still available attempts are counted at the bottom of the window.

Figure 9: e-ID Client - Change forgotten PIN code

4.5        PIN management with card reader with PIN pad

In the view “PIN Management” you can manage the PIN codes serving to identify the user and perform PIN operations. The select view icon is the following:

Cyan Pin Management icon 25x25.

In the active side bar view you can select if you want to manage the PIN code related to the permanent ID card or the one related to the electronic signature. When first using the permanent ID card you will see the panels „eID Transport PIN” and the “eSign Transport PIN” Replacing these with the PIN codes of your choice, you will retain the opportunity of changing PIN codes.

On the page you can see the number of attempts allowed, which is 3 in the base case. If you enter a wrong PIN code more than three times, this will generate a blocked status, as a consequence of which the same PIN code cannot be used again. The blocked PIN code may be unlocked and a new PIN may be set by entering the PUK code.

If the permanent personal ID card has not been activated yet, the card must be activated as the first PIN management operation by starting the activation of the card or of the e-Signature (eSign) service from the tabs eID PIN or eSign PIN, using the [Change] button. /See: “Figure 10: eID Client - PIN management menu - reader with PIN pad”/

If the permanent personal ID has been activated already, previously entered PIN codes can be changed according to Figure 11: eID Client - PIN management menu – Entering code on PIN pad required.

IMPORTANT: You can try to enter the right PIN code 3 times at the maximum, and have maximally 10 attempts for entering the correct PUK code. If the maximum number of attempts has been reached, the code will enter a blocked status.

 

Figure 10: eID Client - PIN management menu - reader with PIN pad

If you click on the button [Change], the dialogue PIN change will appear on the screen of the PIN pad. In the meantime the computer screen will turn grey and until the code has been entered, no other operations will be allowed.

Note: If the screen turns grey, the eID Client application cannot be used until the required code is entered on the card reader or entering the code is refused on the PIN pad by pressing the button [C]. (If the device has broken down, it does not connect to the computer and is unable to show any communication, you can take back control from the unresponsive card reader by clicking on the light square in the top left bottom of the computer screen.

Figure 11: eID Client - PIN management menu – Entering code on PIN pad required

For changing the PIN code, first enter the old code, then the new code of the expected length on the PIN pad. The message displayed on the PIN pad:

Note: In the case of card readers commercially available, messages may appear in the English, German or Hungarian language.

Figure 12: Entering e-ID PIN code on the PIN pad

(If you can see Hungarian text, then “Please give the eID PIN Code”)

 

In the case of a forgotten PIN code, it is possible to set a new PIN code with the PUK code. This function is available if you click on the "Forgot your PIN code?" link.

 

Figure 13: e-ID Client - Change forgotten PIN code - Entering e-ID PUK code on the PIN pad

 

 

After entering the PUK code, following the instructions on the card reader's display, you can set the new PIN code.

 

4.5.1         Blocked PIN code

If the number of attempts allowed reaches zero, the PIN code will enter a blocked status.

Figure 14: eID Client – Unlocking blocked PIN code I – with PIN pad

In order to unlock the blocked PIN code, you can enter the PUK code on the PIN pad keyboard by pressing the [Unblock] button. If you use a card reader with a PIN pad, the number of attempts still available for entering the correct PUK code is counted by the program in the “Info” section of the Card info view.

 

Figure 15: Entering the PUK code on the PIN pad - Blocked PIN II

(You can see Hungarian text, but “Please give the PUK")

After successfully entering the PUK code, the new PIN code must be entered twice in order to unlock the blocked PIN code.

 

Figure 16: Entering a new PIN code on the PIN pad - Blocked PIN III

(You can see Hungarian text, but “Please give the new eID PIN")

Figure 17: Entering a new PIN code on the PIN pad – Blocked PIN IV

(You can see Hungarian text, but “Please give the new eID PIN again")

When changing the e-Sign PIN code, the same procedure must be followed, only the names are different.

4.5.2         Where to find the activation PIN related to the personal e-ID card

The activation PIN related to the personal e-ID card is a temporary code meant to ensure the security of the personal e-ID card while it is being delivered. For safe use please change it as soon as possible. This activation PIN code and PUK code are specified on the personal ID code card received when applying for the personal ID.

Figure 18: Personal identification card code card

4.5.3         Where to find the activation PIN related to the electronic signature

The Transport PIN related to the electronic signature is a temporary code meant to ensure the security of the electronic signature functionality of the personal e-ID card while it is being delivered. For safe use please change it as soon as possible. This activation Transport PIN code is specified on the Electronic signature code card received when applying for the electronic signature for the personal ID.

Figure 19: Electronic signature code card

4.5.4         Have you forgotten your PUK code?

If you cannot remember your PUK code (e.g. you have lost your Personal ID code card) or it has been put into a blocked status, it is impossible to retrieve the PUK code or unlock its blocked status.

4.5.5         How to get a new PUK code

If a wrong PUK code has been entered more times than allowed, it will enter a blocked status. The blocked status of the PUK code cannot be unlocked. There is no opportunity to change the PUK code. (Note: In the future, a related development will be available to make it possible to perform PIN operations in the case of cards with blocked PUK codes as well.)

IMPORTANT: If your PUK code is blocked, you have the opportunity to come to the document office personally and, by giving your CAN number you will be able to perform PIN operations.

4.5.6         Authentication methods

The Cryptographic Tokens (i.e. digital information for encryption and decryption) contain objects that are suitable for performing cryptographic operations. These tokens can be secret or publicly accessible. Secret objects are protected by some authentication mechanism, which can be authentication by the card holder or authentication by secret key. Authentication by the card holder is also based on some secret known only to the card holder, like a password or PIN code, or can be biometric-based authentication (e.g. by fingerprint) provided this is supported by the device. The current version of the personal e-ID card does not support the biometric authentication of the card holder.

Certain card operations – e.g. electronic signature – require the card holder’s approval. In every case authentication by the card holder is required with one of the PIN codes. Depending on the card reader, the code has to be entered on the device itself, in the case of card readers with a PIN pad. This is safer as the code entered is not outside the reader.

If the status of the PIN code related to the electronic signature is “not initialised”, the electronic signature function cannot be performed. In that case, the initialisation of the PIN related to the electronic signature is possible on a terminal with special access privileges, at the customer service of the document office or government office.

The card management application automatically asks for authentication or approval by the card holder – in the case of CAN – using the appropriate method, as required for the performance of the operation concerned.

Depending on the card functionality required – and on the reader – the appropriate panel appears asking for the card holder’s authentication or approval.

Figure 20: Entering CAN number for e-Signature

 

If the card reader device has a reader with a PIN pad, a window appears asking the user to enter the CAN number on the reader (Note: No screen message in English).

Figure 21: Enter CAN number for e-Sign on the PIN Pad

(You can see Hungarian text, but “Please enter your CAN number")

4.6        Information

The “Info” view contains information that may be required for the service providing technical assistance for the identification and solution of the arising errors.

The icon of the information view is:

Cyan Info icon 29x22

The information view provides an overview of the parameters, arranged into main groups, of the computer running the application, the version number of the application, the registered cards and card readers as well as of parameters to be changed by users.

·         Operating System: Under the menu item operating system you can find some basic information about the operating system running on the computer, its version and the type of processor used

·         Installed components: Under the item installed components you can find files related to the eID Client software package and its versions that were installed on the computer when the software was downloaded.

·         Card info: Under the item card information you can find current status information on the PIN codes related to the permanent personal ID and the electronic signature, the PUK code and the certificate.

·         Registered Smart Card readers: Under the item registered card readers you can see the card reader drivers installed.

·         Registered Smart Cards: Under the item registered cards you can see the card drivers.

·         Settings: Under the last item Settings you can see the parameters of the application, which users can freely change, having the appropriate access privileges, under the view Settings.

Figure 22: eID Client – Information menu

You can see a button below. The “Save details” button saves the contents of the information view in a text file.

4.7        Certificate

Certificates with public keys can be viewed in the view “Certificate”. The icon of the view is:Cyan Certificated icon 22x30

In this view you can see the certificate label, the certificate issuer, the date of validity and details about the certificate. The certificate label always has a default value which cannot be changed. At the top of the view you can always see a certificate icon, which is one of the following:

cert

General purpose certificate (e.g.: certificate without private key, CA certificate)

cert_key

Card holder certificate with private key

certroot

Root CA Certificate

 

 

Figure 23: eID Client – Certificate menu

 

4.8        ePassport

The ePasport’s storage unit has been designed in accordance with the international ePassport standards, in order to be suitable for the application at the automated border control stations, such as the ones at the european airports. The ePassport function may be also suitable for electronic personal data recording, if the card is handed over to an administrator, hotel receptionist, concierge or other person. Due to data security reasons, the personal data can be accessed only after entering the correct the CAN number (6 digit number on the front) or the data lines between the relation symbols on the back. Hence the personal data can be recorded only by a person who got the ID. The accessible data is the same as the visually visible data. However, fingerprints stored within the mentioned data set can be accessed only by authorized people (such as border police).

eID Client 1.7 is able to read and display passport data stored in Personal e-ID Card (excluding fingerprint) upon CAN request. This feature can be helpful for those who want to familiarize themselves with the electronic data content of their own ID.

Due to the large size of the image data, reading takes longer (~ 10 seconds).

This feature is off by default.

Figure 24: eID Client – ePassport

4.9        Settings

In the “Settings” view, the settings of the application can be changed whereby you can tailor-make the use of the program, making it more convenient. The icon of the view is:

Cyan Settings icon 25x25

The page has six options to be set one by one, and the user can also select the language of the application.

Figure 25: eID Client – Settings menu

4.9.1         Run on startup

Enabling the first setting makes it possible for the application to start together with the operating system. If enabled, every time the operating system starts loading, the application will start, too.

4.9.2         Check for updates at startup

If the setting “Update on Start” is enabled, the program will check for updates on the internet at every startup. This can be done by the user, too, by clicking on the button “Check for update”, or from the menu. If the program finds an update, a dialogue box appears and the user can decide whether or not to install the update concerned.

Figure 26: eID Client – Software update – New version available

Note: In the case of MAC OS the functionality is currently not supported, it is to be installed in a later version of the application. By pressing the button “Check for updates”, an error message appears. You can download the latest version from the following site: https://eszemelyi.hu/kartyaolvaso/kartyaolvaso_alkalmazas

4.9.3         Enable eSign function

It enables or disables the use of the electronic signature function on the computer concerned. This function (Enable eSign function) is also available from the menu. If the card does not support electronic signature function, enabling does not have an effect, but disabling it will disable the use of this function even with cards that would support it.

Note: Disabling the e-Signature function does not affect the operation of the card so this setting disables only the component supporting making the electronic signature on the PC concerned, required for reaching the electronic signature function of the card.

4.9.4         Enabling eSign PIN status check

It enables or disables whether the status of the e-Signature PIN code has to be checked when the ID card is attached to the reader. Checking of the e-Signature PIN and usage of the e-Signature function is only possible after entering the CAN (Card Access Number).

When any of the settings described in 4.9.4 and in 4.9.5 is enabled, a pop-up window, requesting for CAN is shown after the card has been attached to the reader. To avoid the pop-up window disable both settings.

This option can be enabled or disabled also from the File menu.

4.9.5         Enable ePass data overview

It enables or disables whether the data stored in ePassport application is read and displayed when the ID card is attached to the reader. Reading of the ePass data can take some time (up to 10-20 seconds) and is only possible after entering the CAN (Card Access Number). By default this option is disabled, as it can be annoying when using the ID card regularly.

When any of the settings described in 4.9.4 and in 4.9.5 is enabled, a pop-up window, requesting for CAN is shown after the card has been attached to the reader. To avoid the pop-up window disable both settings.

4.9.6         Home PC

The third setting may be enabled only on the user’s own computer. Disabling the option automatically disables the option “Storing CAN in cache”. If not enabled, the application will automatically remove the certificate related to the card concerned when the card is removed.

4.9.7         Storing CAN (Card Access Number) in cache (Cache CAN)

Enable this setting only on your own computer! The program will run faster and will be more convenient as it will store the CAN last entered, but considering that this will be stored on the computer, you must not enable this on a computer that others, too, have access to.

If you enable this setting, the application will store the CAN until the user places another card with a different CAN in the reader. In this case – and provided the CAN entered was correct – the CAN will be requested once again and will then be stored. The setting furthermore affects the CAN request on the reader with PIN pad, which does not forward the CAN requested to the application in any case. In order to enable storing, the application requests the CAN, just like with readers without a PIN pad, on the user’s computer also in the case of a reader with a PIN pad.

4.9.8        Approve reading essential data

If the eID Client detects a PIN Pad type reader, the user access window can be disabled.

4.9.9         Show close reminder

If the setting is enabled, every time the user clicks on the Close button in the upper right corner, the program shows a reminder that the application is still running in the background. The functionality can also be closed on the pop up window.

Figure 27: eID Client – Close application reminder (Quit)

4.9.10     Show exit reminder

If this setting is allowed, any time the user clicks on the menu item Exit, the program displays a reminder that the personal e-ID card functions will not be accessible on the computer concerned. The function can be deactivated also on the pop up window. 

Figure 28: e eID Client – Exit reminder (Quit)

4.9.11     Languages

In the section “Languages” you can choose if the eID Client should communicate with the user in English or Hungarian. This setting refers to all the elements of the program package.

4.9.12     Update

In the section Update you can find the date of the last updating and initiate manual updating. This function is also accessible from the menu.

5          List of Figures

1.       Figure 1 : eID Client – Application main panel. 7

2.       Figure 2 : eID Client – Card verification menu. 8

3.       Figure 3 : e-Personal Client - PIN management menu – reader without PIN pad. 13

4.       Figure 4: eID Client - "eID Transport PIN change" panel. 13

5.       Figure 5: e-ID Client - Forgot your PIN code link. 14

6.       Figure 6: eID – Unlocking blocked PIN code I – without PINPAD.. 15

7.       Figure 7: e-Personal Client – Unlocking blocked PIN code II – Entering PUK code. 16

8.       Figure 8: eID Client – Unlocking a blocked PIN code III – Entering a new PIN.. 17

9.       Figure 9: e-ID Client - Change forgotten PIN code. 18

10.   Figure 10: eID Client - PIN management menu - reader with PIN pad. 19

11.   Figure 11: eID Client - PIN management menu – Entering code on PIN pad required. 20

12.   Figure 12: Entering e-ID PIN code on the PIN pad. 20

13.   Figure 13: e-ID Client - Change forgotten PIN code - Entering e-ID PUK code on the PIN pad. 21

14.   Figure 14: eID Client – Unlocking blocked PIN code I – with PIN pad. 22

15.   Figure 15: Entering the PUK code on the PIN pad - Blocked PIN II 22

16.   Figure 16: Entering a new PIN code on the PIN pad - Blocked PIN III 23

17.   Figure 17: Entering a new PIN code on the PIN pad – Blocked PIN IV.. 23

18.   Figure 18: Personal identification card code card. 23

19.   Figure 19: Electronic signature code card. 24

20.   Figure 20: Entering CAN number for e-Signature. 25

21.   Figure 21: Enter CAN number for e-Sign on the PIN Pad. 25

22.   Figure 22: eID Client – Information menu. 27

23.   Figure 23: eID Client – Certificate menu. 28

24.   Figure 24: eID Client – ePassport. 29

25.   Figure 24: eID Client – Settings menu. 30

26.   Figure 25: eID Client – Software update – New version available. 31

27.   Figure 26: eID Client – Close application reminder (Quit). 32

28.   Figure 27: e eID Client – Exit reminder (Quit). 33