OASIS Mailing List ArchivesView the OASIS mailing list archive below
or browse/search using MarkMail.

 


Help: OASIS Mailing Lists Help | MarkMail Help

office message

[Date Prev] | [Thread Prev] | [Thread Next] | [Date Next] -- [Date Index] | [Thread Index] | [List Home]


Subject: [OASIS Issue Tracker] Updated: (OFFICE-2725) ODF 1.2 Part 3 section4.8.9 manifest:key-derivation-name incorrect extensibility



     [ http://tools.oasis-open.org/issues/browse/OFFICE-2725?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel ]

Dennis Hamilton updated OFFICE-2725:
------------------------------------

          Component/s: Part 3 (Packages)
        Fix Version/s: ODF 1.2 CD 06
                           (was: ODF 1.2 CD 05)
    Affects Version/s: ODF 1.2 CD 05
                           (was: ODF 1.2 Part 3 CD 2)

> ODF 1.2 Part 3 section 4.8.9 manifest:key-derivation-name incorrect extensibility
> ---------------------------------------------------------------------------------
>
>                 Key: OFFICE-2725
>                 URL: http://tools.oasis-open.org/issues/browse/OFFICE-2725
>             Project: OASIS Open Document Format for Office Applications (OpenDocument) TC
>          Issue Type: Bug
>          Components: Packaging, Part 3 (Packages), Security
>    Affects Versions: ODF 1.2 CD 05
>         Environment: This issue applies in previous drafts of ODF 1.2 Part 3.  The present issue refers to the precise text of ODF 1.2 CD05 Part 3.
>            Reporter: Dennis Hamilton
>             Fix For: ODF 1.2 CD 06
>
>
> In 4.8.9 manifest:key-derivation-name, the 4-point list after the second paragraph makes reference to section 5.7 of [xmlenc-core] and section 5.1 of [xmlenc-core] as sources of alternative key-derivation algorithms.
> However, there are no key-derivation algorithms specified in section 5.7.  Section 5.7 of [xmlenc-core] is a list of digest algorithms, none of which provide iterative password-based key derivation functions.
> Furthermore, section 5.1 of [xmlenc-core] does not list key-derivation functions as anything that is addressed in [xmlenc-core] and it provides no extensibility on that subject.
> In addition, [xmlenc-core] does not identify nor discuss HMAC functions of any kind.  The only message authentication method referenced in [xmlenc-core] is xml digital signature.

-- 
This message is automatically generated by JIRA.
-
If you think it was sent incorrectly contact one of the administrators: http://tools.oasis-open.org/issues/secure/Administrators.jspa
-
For more information on JIRA, see: http://www.atlassian.com/software/jira

        


[Date Prev] | [Thread Prev] | [Thread Next] | [Date Next] -- [Date Index] | [Thread Index] | [List Home]