Symmetric Key Foundry FIPS140 test cases proposal

From
Jim Flood <>
Date
2013-01-11T20:46:00+00:00
ID
Thread
Symmetric Key Foundry FIPS140 test cases proposal
Since I don't officially support 1.1 yet, and will not for the RSA conference, my server will fail all of these tests because they all use KMIP 1.1 client.
At the of the doc, it refers to "Key Management Interoperability Protocol Profiles Version 1.0", so I'm not sure if this is intentional (to exclude 1.0 servers) or not.
It's not a problem for me

--
I'm just pointing it out.
I would like to verify, though, that the proper response for any 1.1 request to a 1.0 server is to fail the command. That is, a 1.0 server is not allowed to execute any request from a 1.1 client.
Regards,  Jim
On Fri, Jan 11, 2013 at 12:14 PM, Lockhart, Robert  < 
>  wrote:
I will take care of moving them later tonight when I get back to the Bay Area if no one else minds.
I was hesitant to put them as mandatory but I figured might as well keep algorithms grouped.
Bob L.
Robert A. (Bob)

Lockhart
Chief Solutions Architect - Key Management  THALES e-Security, Inc.

--------------------------------------------

T:     +1 954 888 6245  (Direct)  M:    +1 510 410 0585
F:     +1 408 457 7681
E:      <mailto: 
>  W:     www.thales-esecurity.com < http://www.thales-esecurity.com
>
On Jan 11, 2013, at 9:51, "Bruce Rich" <  <mailto:  >> wrote:
Yes, please move DES3-112 from mandatory to optional (so cases SKFF-M-4, SKFF-M-9, SKFF-M-14...all to SKFF-O-somethingorother).
The only other immediate comment was that it was a little jarring to see most of the testcases run AFTER revoking the key, but I agree that since the server doesn't police the key state but just reports it, the testcases should run just fine.
Bruce A Rich  brich at-sign us dot ibm dot com
From:        "Lockhart, Robert" <  <mailto:  >>
To:        "  <mailto:  >" <  <mailto:  >>
Date:        01/11/2013 02:06 AM
Subject:        [kmip-interop-tech] Symmetric Key Foundry FIPS140 test cases proposal
Sent by:        <  <mailto:  >>
________________________________
There may still be glitches in this but I think it is fairly complete for what is required.  I used XML based on readability although my cut and paste from the parser required reformatting thus the lateness of the delivery today.  I put it back in Word 97 to 2003 format which my current version changed some formatting I had, so more delays.
The test cases cover AES and 3DES as mandatory and Skipjack as optional.  I included 3DES 112 (2 key) but I know that is being or has been deprecated so can be removed if people want.
These are the first set of tests I would like to include in next week’s interoperability tests for RSA again as optional tests for those who want to give it a go.  I am looking for feedback on these test cases as some of the test cases included apply to existing profiles in 1.1 and thus 1.2 as well as some of the newer proposed or discussed profiles.  If I get a chance to ship one additional by tomorrow I will do so as it relates to opaque objects ranging in size from a few bytes to potentially megabytes as discussed on the call today (John Leiseboer, if you have something already I am wide open to it as time is very limited for me over the next week or two).
Bob L.
Robert A. (Bob)

Lockhart  Chief Solutions Architect – Key Management  Thales e-Security, Inc.   [attachment "kmip-test-v1.2-sym-key-foundry-FIPS140-wd01.doc" deleted by Bruce Rich/Austin/IBM]

---------------------------------------------------------------------

To unsubscribe, e-mail:   <mailto: 
>
For additional commands, e-mail:   <mailto:  >