Skip to content

Potential need for STIP-specific FCS_CKM.1 #14

Description

@jfisherbah

The published STIP module referenced FCS_CKM.1 in the NDcPP as the basis for how public keys are generated. However, the latest version of the NDcPP now restricts key generation strictly to CNSA compliant algorithms. Since the STIP module deliberately requires non-CNSA TLS ciphers to be supported, would this imply that key generation algorithms not conformant to CNSA would be needed (e.g. 2048-bit RSA)?

If so, a STIP specific iteration of FCS_CKM.1 would need to be defined in the module, similar to how a STIP-specific iteration of FCS_COP was defined for obsolete symmetric key algorithms.

Regardless of how this is handled, FDP_CER_EXT.1.4/Server will need to be updated to specifically tie the mechanism used to generate the subject public key to a specific SFR.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions