← Prev in month ← Prev in thread
Next in thread → Next in month →

[OASIS Issue Tracker] Updated: (OFFICE-2725) ODF 1.2 Part 3 section4.8.9 manifest:key-derivation-name incorrect extensibility

From
OASIS Issues Tracker <>
Date
2010-08-04T02:22:02+00:00
ID
704395999.55221280888513065.JavaMail.tomcat55@mw00
Thread
[OASIS Issue Tracker] Updated: (OFFICE-2725) ODF 1.2 Part 3 section4.8.9 manifest:key-derivation-name incorrect extensibility
[ http://tools.oasis-open.org/issues/browse/OFFICE-2725?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel ]

Dennis Hamilton updated OFFICE-2725:
------------------------------------

          Component/s: Part 3 (Packages)
        Fix Version/s: ODF 1.2 CD 06
                           (was: ODF 1.2 CD 05)
    Affects Version/s: ODF 1.2 CD 05
                           (was: ODF 1.2 Part 3 CD 2)

> ODF 1.2 Part 3 section 4.8.9 manifest:key-derivation-name incorrect extensibility
> ---------------------------------------------------------------------------------
>
>                 Key: OFFICE-2725
>                 URL: http://tools.oasis-open.org/issues/browse/OFFICE-2725
>             Project: OASIS Open Document Format for Office Applications (OpenDocument) TC
>          Issue Type: Bug
>          Components: Packaging, Part 3 (Packages), Security
>    Affects Versions: ODF 1.2 CD 05
>         Environment: This issue applies in previous drafts of ODF 1.2 Part 3.  The present issue refers to the precise text of ODF 1.2 CD05 Part 3.
>            Reporter: Dennis Hamilton
>             Fix For: ODF 1.2 CD 06
>
>
> In 4.8.9 manifest:key-derivation-name, the 4-point list after the second paragraph makes reference to section 5.7 of [xmlenc-core] and section 5.1 of [xmlenc-core] as sources of alternative key-derivation algorithms.
> However, there are no key-derivation algorithms specified in section 5.7.  Section 5.7 of [xmlenc-core] is a list of digest algorithms, none of which provide iterative password-based key derivation functions.
> Furthermore, section 5.1 of [xmlenc-core] does not list key-derivation functions as anything that is addressed in [xmlenc-core] and it provides no extensibility on that subject.
> In addition, [xmlenc-core] does not identify nor discuss HMAC functions of any kind.  The only message authentication method referenced in [xmlenc-core] is xml digital signature.

-- 
This message is automatically generated by JIRA.
-
If you think it was sent incorrectly contact one of the administrators: http://tools.oasis-open.org/issues/secure/Administrators.jspa
-
For more information on JIRA, see: http://www.atlassian.com/software/jira
← Prev in month ← Prev in thread
Next in thread → Next in month →