OASIS Mailing List ArchivesView the OASIS mailing list archive below
or browse/search using MarkMail.

 


Help: OASIS Mailing Lists Help | MarkMail Help

dss-x message

[Date Prev] | [Thread Prev] | [Thread Next] | [Date Next] -- [Date Index] | [Thread Index] | [List Home]


Subject: Re: [dss-x] nonce support for RFC 3161 timestamp missing?


Hi Juan Carlos,

that's why I filed issue DSSX-11 to be sure ne detail will be lost.

Greetings,

Andreas

> Hi Andreas,
>
> It is OK for me...as long as the text in the new spec makes an
> explicit mention to this in normative text.
>
> Regards
> Juan Carlos.
> El 21/3/17 a las 18:07, Andreas Kuehne escribió:
>> Hi Juan Carlos,
>>
>> frankly I don't see any reason why the ServicePolicy should not serve as
>> a holder for RFC3161's 'reqPolicy'.
>> And this timestamping topic is another reason to support a set of
>> policies.
>>
>> Greetings,
>>
>> Andreas
>>> Hi,
>>>
>>> I agree that it seems that the request does not incorporate the
>>> nonce...but in the RFC3161 there is also another field: reqPolicy,
>>> which I am not sure can be asimilated to the ServicePolicy...if we are
>>> going to "mimic" the request from the RFC 3161, shouldn't mimic also
>>> this field?. I am not saying that we should exactly mimic, just that
>>> if we add the nonce, maybe we should also add the reqPolicy, unless we
>>> clearly feel that the servicePolicy element could play the same role
>>>
>>> Regards
>>> Juan Carlos.
>>>
>>>
>>> El 21/3/17 a las 13:22, Mr. Stefan Hagen escribió:
>>>> Hi Andreas,
>>>> On 21/03/17 13:15, Andreas Kuehne wrote:
>>>>> Hi experts,
>>>>>
>>>>>
>>>>> I just came across the nonce element in the RFC 3161 :
>>>>>
>>>>> "The nonce [...] allows the client to verify the timeliness of the
>>>>> response when no local clock is available. [...] the same nonce value
>>>>> MUST be included in the response "
>>>>>
>>>>> We do mention the nonce in the core document but only in terms of
>>>>> verification processing. I can't find a way to include a nonce
>>>>> value in
>>>>> a request. Did we just forget to mention the optional input
>>>>> 'Nonce'? If
>>>>> yes, it would be a good moment to add it into the refurbished core
>>>>> ;-)
>>>> the latter and yes the suggested remediation also :-)
>>>>
>>>> Thank you!
>>>>
>>>> Best,
>>>> Stefan
>>>
>>>
>>> ---------------------------------------------------------------------
>>> To unsubscribe from this mail list, you must leave the OASIS TC that
>>> generates this mail.  Follow this link to all your TCs in OASIS at:
>>> https://www.oasis-open.org/apps/org/workgroup/portal/my_workgroups.php
>>>
>>
>
>
> ---------------------------------------------------------------------
> To unsubscribe from this mail list, you must leave the OASIS TC that
> generates this mail.  Follow this link to all your TCs in OASIS at:
> https://www.oasis-open.org/apps/org/workgroup/portal/my_workgroups.php
>


-- 
Andreas Kühne 
phone: +49 177 293 24 97 
mailto: kuehne@trustable.de

Trustable Ltd. Niederlassung Deutschland Gartenheimstr. 39C - 30659 Hannover Amtsgericht Hannover HRB 212612

Director Andreas Kühne

Company UK Company No: 5218868 Registered in England and Wales 



[Date Prev] | [Thread Prev] | [Thread Next] | [Date Next] -- [Date Index] | [Thread Index] | [List Home]