Groups - pkcs11-cka_uuid-wrapWithUUID-cka-derive-template.docx uploaded

From
Michael StJohns
Date
2013-08-01T13:55:00+00:00
ID
Thread
Groups - pkcs11-cka_uuid-wrapWithUUID-cka-derive-template.docx uploaded
Submitter's message This is the formal submission for CKA_UUID and CKA_WRAP_WITH_UUID.
It is also the formal submission for CKA_DERIVE_TEMPLATE (not previously described) and a slight update in the wording for CKA_UNWRAP_TEMPLATE with respect to how that template can be changed.

--
Michael StJohns Document Name : pkcs11-cka_uuid-wrapWithUUID-cka-derive-template.docx Description Three items here, but did this as a single document since the edits were all in this section:

1) Fixing the text on CKA_UNWRAP_TEMPLATE to indicate it can be set once and then is read-only.

2) Adding CKA_UUID and CKA_WRAP_WITH_UUID.
The first attribute marks each key with a pseudo-random UUID that changes anytime the key changes.
The second points to the first for the purpose of uniquely identifying a key that can be used to wrap this key.

3) Added CKA_DERIVE_TEMPLATE.
This exactly mirrors CKA_UNWRAP_TEMPLATE in that it is applied to a key derived from the key this attribute is on.
This is necessary to set things like the sensitivity or extractability of derived keys.
Download Latest Revision Public Download Link Submitter : Michael StJohns Group : OASIS PKCS 11 TC Folder : Working Drafts Date submitted : 2013-08-01 06:54:29