Skip to content

Note on TD0972 impact #12

Description

@jfisherbah

NIAP TD0972 restricts the NDcPP selections for cryptography to those permitted by CNSA. Because FCS_TTTC_EXT.1 and FCS_TTTS_EXT.1 currently require various "insecure" ciphersuites to be supported (so as to allow a potentially malicious session to be opened and inspected), that TD would need to be overruled specifically in the STIP case so that various disallowed selections such as 128-bit AES and SHA-1 can be made in support of this.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions