OASIS Mailing List ArchivesView the OASIS mailing list archive below
or browse/search using MarkMail.

 


Help: OASIS Mailing Lists Help | MarkMail Help

kmip message

[Date Prev] | [Thread Prev] | [Thread Next] | [Date Next] -- [Date Index] | [Thread Index] | [List Home]


Subject: Re: [kmip] Groups - Cryptographic Length of Certificates Proposal (KMIPCertificateLengthProposal.doc) uploaded


"For keys, Cryptographic Length is the length in bits of the clear-text cryptographic key material of the Managed Cryptographic Object. For certificates, Cryptographic Length is the length in bits of the encoded Certificate Managed Cryptographic Object."

There are three issues with this:
- one the definition for keys is actually interpreted differently by different implementations for DES keys - does this include or not include the parity bits?
  (I know this isn't part of Judy's change - but it is something to get sorted out if we are changing this section)
- what is the purpose of making this length be specified in bits?
- what purpose does it serve to have this just specified as the length of the encoded certificate - that is not "cryptographic" - and the certificate value has a length in its encoding.

I can see a use in this matching "Cryptographic Length" of the public key contained with in the certificate.

Tim.







[Date Prev] | [Thread Prev] | [Thread Next] | [Date Next] -- [Date Index] | [Thread Index] | [List Home]