OASIS Open Mailing List Archives  ·  All Lists  ·  kmip-interop-tech  ·  2012-11

kmip-interop-tech — archive

[Date Prev]  |  [Thread Prev]  |  [Thread Next]  |  [Date Next]   —  [Date Index]  |  [Thread Index]  |  [Month Index]  |  [List Home]

Cryptomathic questions on KMIP implementation


Hi all, Cryptomathic is looking at implementing the KMIP protocol soon (server side). Before starting, we have a few questions from our engineers concerning some vendor implementations and KMIP compliance: 1-            KMIP uses TLS as a secure tunnel between the KMIP Client and the KMIP server. Is there a requirement for having the TLS session terminated into an HSM (Hardware Security Module) or do we allow the termination on the server? 2-            Related to question 1, KMIP allows the transfer of keys in clear (unwrapped keys) through the secure TLS tunnel. In case, the TLS is not terminated into an HSM, the key will exist in clear in the KMIP server memory. We see this as a security issue. How have the different vendors implemented such a case? 3-            Is the handle of asynchronous KMIP messages on the KMIP server mandatory for a KMIP server compliance? Thanks for your feedback and best regards, Boris Schumperli Cryptomathic Inc. Cell: +1-514-299-2938

[Date Prev]  |  [Thread Prev]  |  [Thread Next]  |  [Date Next]   —  [Date Index]  |  [Thread Index]  |  [Month Index]  |  [List Home]