Symmetric Key Foundry FIPS140 test cases proposal

From
Bruce Rich <>
Date
2013-01-11T17:51:00+00:00
ID
Thread
Symmetric Key Foundry FIPS140 test cases proposal
Yes, please move DES3-112 from mandatory
 to optional (so cases SKFF-M-4, SKFF-M-9, SKFF-M-14...all to SKFF-O-somethingorother).

The only other immediate comment was
 that it was a little jarring to see most of the testcases run AFTER revoking
 the key, but I agree that since the server doesn't police the key state
 but just reports it, the testcases should run just fine.

 Bruce A Rich
 brich at-sign us dot ibm dot com
From:
    "Lockhart, Robert"
 <>
To:
    ""
 <>
Date:
    01/11/2013 02:06 AM
Subject:
      [kmip-interop-tech]
 Symmetric Key Foundry FIPS140 test cases proposal

Sent by:
      <>

There may still be glitches in this but
 I think it is fairly complete for what is required.  I used XML based
 on readability although my cut and paste from the parser required reformatting
 thus the lateness of the delivery today.  I put it back in Word 97
 to 2003 format which my current version changed some formatting I had,
 so more delays.



The test cases cover AES and 3DES as mandatory
 and Skipjack as optional.  I included 3DES 112 (2 key) but I know
 that is being or has been deprecated so can be removed if people want.



These are the first set of tests I would
 like to include in next week’s interoperability tests for RSA again as
 optional tests for those who want to give it a go.  I am looking for
 feedback on these test cases as some of the test cases included apply to
 existing profiles in 1.1 and thus 1.2 as well as some of the newer proposed
 or discussed profiles.  If I get a chance to ship one additional by
 tomorrow I will do so as it relates to opaque objects ranging in size from
 a few bytes to potentially megabytes as discussed on the call today (John
 Leiseboer, if you have something already I am wide open to it as time is
 very limited for me over the next week or two).



Bob L.



Robert A. (Bob)

Lockhart

Chief Solutions Architect
 – Key Management

Thales e-Security, Inc.

 [attachment "kmip-test-v1.2-sym-key-foundry-FIPS140-wd01.doc"
 deleted by Bruce Rich/Austin/IBM]

---------------------------------------------------------------------

To unsubscribe, e-mail: 
For additional commands, e-mail: