• Our new ticketing site is now live! Using either this or the original site (both powered by TrainSplit) helps support the running of the forum with every ticket purchase! Find out more and ask any questions/give us feedback in this thread!

Pkpass barcodes

Status
Not open for further replies.

blimmo

Member
Joined
30 Jul 2025
Messages
635
Location
West Mids
I recently (ish) bought a ticket from railsmartr (I needed fee free advance amendment). I received .pkpass files and added the passes to this app https://github.com/SeineEloquenz/fosswallet

The barcodes displayed wouldn't scan (no problem as the guards that checked them just looked at them and accepted them despite the failed scan...) and I later noticed that the barcode generated was not the same as the one generated by Google wallet.

Was this a mistake by railsmartr in their pkpass (and therefore would be fixed by using trainsplit) or was this a bug in the wallet app? I guess really I'm asking if any of the trainsplit people have tested their pkpasses in other wallets.
 
Sponsor Post - registered members do not see these adverts; click here to register, or click here to log in
R

RailUK Forums

trains999

Member
Joined
11 Sep 2025
Messages
6
Location
england
if the google wallet one is fine then surely it’s a problem with the application? and not the ticketing site?
 

blimmo

Member
Joined
30 Jul 2025
Messages
635
Location
West Mids
if the google wallet one is fine then surely it’s a problem with the application? and not the ticketing site?
Seems entirely possible to me that the pkpass is relying on whatever default Google wallet is using for barcode display when it should be specifying one for example.
 

CyrusWuff

Established Member
Joined
20 May 2013
Messages
5,428
Location
London
As an aside, Google Wallet has supported importing tickets in PKPASS format since April 2024. Sadly this isn't the case for Samsung Wallet, however.
 

pepperpot80

Member
Joined
29 Sep 2009
Messages
78
Location
Hove
Mild suspicion that the fosswallet app doesn't have the necessary public keys available to hand? Or potentially trying to use a public key but not the right public key?

The developer of intertube has some interesting insight from trying to reverse-engineer the barcode payloads:
Technically, the ticket data is actually signed with RSA and PKCS#1 (I think). Ticket issuers generate a payload containing the ticket data, pad it a bit, and then use their RSA private key to create a signed message they put into the barcode. A ticket scanner has a set of the issuers’ public keys on hand to verify the signature and read the original payload.
 

Adam Williams

Established Member
Joined
2 Jan 2018
Messages
3,498
Location
Warks
It doesn't need any keys to be able to render an Aztec, the payload it needs to encode into a 2D barcode is within the pkpass file. There would be no reason to try and decrypt it.
 
Status
Not open for further replies.

Top