OASIS Open Mailing List Archives  ·  All Lists  ·  pkcs11  ·  2013-08

pkcs11 — archive

[Date Prev]  |  [Thread Prev]  |  [Thread Next]  |  [Date Next]   —  [Date Index]  |  [Thread Index]  |  [Month Index]  |  [List Home]

Re: [pkcs11] Sensitivity and extractability of derived keys


Thanks Michael. I think you are referring to 6.25.5 (Master key derivation). I still don't see 3). Say 3) is there, I believe it's still fine to have 3) , and having all options open for the implementor. I also strongly believe that the implementor will have to reference the Key Management Security Policy (set by Security Administrator), and set these sensitivity attributes accordingly. -Oscar On 08/14/13 08:38 AM, Michael StJohns wrote: On 8/14/2013 6:08 AM, Oscar So wrote: Michael, Can you point me to the section of the spec which mentions 3) ? Robert mostly copied the TLS12 stuff from TLS. That text is in the TLS (2.25.5) section (and is in the SSL 2.24.5 section as well). I haven't had a chance to look elsewhere. Mike Also, I believe 3) is an option, an open option. You do 3) only if you absolutely need it. Otherwise, by default, one should not do 3). Thanks! -Oscar

[Date Prev]  |  [Thread Prev]  |  [Thread Next]  |  [Date Next]   —  [Date Index]  |  [Thread Index]  |  [Month Index]  |  [List Home]