OASIS Open Mailing List Archives  ·  All Lists  ·  idtrust-sc  ·  2007-04

idtrust-sc — archive

[Date Prev]  |  [Thread Prev]  |  [Thread Next]  |  [Date Next]   —  [Date Index]  |  [Thread Index]  |  [Month Index]  |  [List Home]

IDtrust SC MS Minutes - PKI Workshop


Two comments, Dee: 1) Related to item #3 ("EKMI TC - Arshad reported significant interest in the EKMI TC at the OASIS Symposium. He also stated the need to create an Audit Guidelines SC to encourage ISACA to join OASIS."), the AGSC already exists; however, we need to stay actively focus on audit standards to encourage ISACA members to join OASIS to work with us in the trenches. Presenting at the ISACA Intl. conference, and sponsoring the workshop at the regional conference are great ways to begin this process. 2) Regarding item #3 in Other Business ("Dee to follow-up with Russell Housley regarding to concerns related to EKMI overlap with IETF."), could you elaborate on the discussion and the overlap that was discussed? I am aware of the KEYPROV-WG and the comments raised by Phillip Hallam-Baker of VeriSign before the EKMI-TC was convened. I have also responded to PHB and on the OASIS forum that there is no overlap. I am also an observer on the KEYPROV-WG and have seen nothing that indicates they are focusing on the same issues that we are. I am also aware that Sandi Rood (US DoD), who is a member of the EKMI-TC and the SKSML-SC has expressed a desire to define a symmetric key-management protocol in ASN.1. I have responded to Sandi (and this is all on the SKSML-SC archives) that OASIS is an XML-standards based forum, and that the SKSML-SC would like to know what advantages ASN.1 had over the proposed SKSML so that we could incorporate that into the design. Sandi has responded that one of her colleagues is in the process of evaluating that difference and she will present the findings when ready. In the meantime, they have prepared an ASN.1-based RFC DRAFT (based on the encourage of Russ Housley) to define a symmetric key-management protocol. It appears to me that this may be descending into a classic ASN versus XML battle, and this is something neither side will win. (However, market momentum is for XML - as is OASIS.) So, it would be best for EKMI-TC to understand, specifically, what are the deficiencies that Russ Housely sees in SKSML and to declare them. He should be encouraged to join the EKMI-TC and participate in the discussion on the SKSML-SC. Arshad Noor StrongAuth, Inc. Dee Schur wrote: > Respectfully submitted, send changes. > Best, > Dee >

[Date Prev]  |  [Thread Prev]  |  [Thread Next]  |  [Date Next]   —  [Date Index]  |  [Thread Index]  |  [Month Index]  |  [List Home]