PIV Authentication Key (Mandatory)
This key shall be generated on the PIV Card. The PIV Card shall not permit exportation of the PIV authentication key. The PIV authentication key must be available only through the contact interface of the PIV Card. Private key operations may be performed using an activated PIV Card without explicit user action (e.g., the PIN need not be supplied for each operation).
The PIV Card shall store a corresponding X.509 certificate to support validation
of the public key. The X.509 certificate shall include the FASC-N in the subject
alternative name extension using the pivFASC-N attribute to support physical
access procedures. The expiration date of the certificate must be no later than
the expiration date of the PIV Card.