OASIS Mailing List ArchivesView the OASIS mailing list archive below
or browse/search using MarkMail.

 


Help: OASIS Mailing Lists Help | MarkMail Help

imi message

[Date Prev] | [Thread Prev] | [Thread Next] | [Date Next] -- [Date Index] | [Thread Index] | [List Home]


Subject: Re: [imi] Hopefully last change to the IMI spec before producing aCommittee Draft


John Bradley <jbradley@mac.com> wrote on 02/18/2009 08:51:08 PM:

> The important points are that it is card specific entropy stored by
> the IdP and never disclosed to RPs in any way.


Actually, this entropy needs to be treated as a secret and it should be [pseudo]random. The danger is not from RPs but from other cardholders from the same IdP.

Regards,
Mike



[Date Prev] | [Thread Prev] | [Thread Next] | [Date Next] -- [Date Index] | [Thread Index] | [List Home]