NIAP TD0972 restricts the NDcPP selections for cryptography to those permitted by CNSA. Because FCS_TTTC_EXT.1 and FCS_TTTS_EXT.1 currently require various "insecure" ciphersuites to be supported (so as to allow a potentially malicious session to be opened and inspected), that TD would need to be overruled specifically in the STIP case so that various disallowed selections such as 128-bit AES and SHA-1 can be made in support of this.
NIAP TD0972 restricts the NDcPP selections for cryptography to those permitted by CNSA. Because FCS_TTTC_EXT.1 and FCS_TTTS_EXT.1 currently require various "insecure" ciphersuites to be supported (so as to allow a potentially malicious session to be opened and inspected), that TD would need to be overruled specifically in the STIP case so that various disallowed selections such as 128-bit AES and SHA-1 can be made in support of this.