pkcs11 — archive
[Date Prev]
| [Thread Prev]
| [Thread Next]
| [Date Next]
— [Date Index]
| [Thread Index]
| [Month Index]
| [List Home]
Re: [pkcs11] Sensitivity and extractability of derived keys
Thanks Michael.
I think you are referring to 6.25.5 (Master key derivation).
I still don't see 3).
Say 3) is there, I believe it's still fine to have 3) , and having all options open for the implementor.
I also strongly believe that the implementor will have to reference the Key Management Security Policy (set by Security Administrator), and set these sensitivity attributes accordingly.
-Oscar On 08/14/13 08:38 AM, Michael StJohns wrote: On 8/14/2013 6:08 AM, Oscar So wrote: Michael, Can you point me to the section of the spec which mentions 3) ?
Robert mostly copied the TLS12 stuff from TLS.
That text is in the TLS (2.25.5) section (and is in the SSL 2.24.5 section as well).
I haven't had a chance to look elsewhere.
Mike Also, I believe 3) is an option, an open option.
You do 3) only if you absolutely need it.
Otherwise, by default, one should not do 3).
Thanks!
-Oscar
[Date Prev]
| [Thread Prev]
| [Thread Next]
| [Date Next]
— [Date Index]
| [Thread Index]
| [Month Index]
| [List Home]