Skip to content

FCS_TLSC_EXT.1.2 conflict in use of other ciphersuites #45

Description

@woodbe

At the end of the TLS 1.2 selection, it states "and shall not offer other TLS 1.2 ciphersuites"

then in the App note it states " However, this requirement does not restrict the TOE's ability to propose additional non-deprecated ciphersuites beyond the ones listed in this requirement in its client hello message as indicated in the ST."

The straight interpretation of the SFR is that you can't add anything beyond that list, and then the app note says it's OK. App notes should be informative, not normative, and shouldn't be used to modify the SFR in this way. If other ciphersuites are allowed but not to be claimed, this should be noted in the SFR or more like the TLS 1.3, have no further comment.

The phrase "and shall not offer other TLS 1.2 ciphersuites" should be removed as this will keep the app note as informative and also bring the 1.2 requirements in line with the 1.3 requirements.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions