Next in thread →
Next in month →
Re: [pkcs11] Sensitivity and extractability of derived keys
Thanks Michael. I think you are referring to 6.25.5 (Master key derivation). I still don't see 3). Say 3) is there, I believe it's still fine to have 3) , and having all options open for the implementor. I also strongly believe that the implementor will have to reference the Key Management Security Policy (set by Security Administrator), and set these sensitivity attributes accordingly. -Oscar On 08/14/13 08:38 AM, Michael StJohns wrote: On 8/14/2013 6:08 AM, Oscar So wrote: Michael, Can you point me to the section of the spec which mentions 3) ? Robert mostly copied the TLS12 stuff from TLS. That text is in the TLS (2.25.5) section (and is in the SSL 2.24.5 section as well). I haven't had a chance to look elsewhere. Mike Also, I believe 3) is an option, an open option. You do 3) only if you absolutely need it. Otherwise, by default, one should not do 3). Thanks! -Oscar
Next in thread →
Next in month →