OASIS Mailing List ArchivesView the OASIS mailing list archive below
or browse/search using MarkMail.

 


Help: OASIS Mailing Lists Help | MarkMail Help

office message

[Date Prev] | [Thread Prev] | [Thread Next] | [Date Next] -- [Date Index] | [Thread Index] | [List Home]


Subject: [OASIS Issue Tracker] Updated: (OFFICE-3297) Part 3 [Blowfish]Reference Out-of-Date, Misleading



     [ http://tools.oasis-open.org/issues/browse/OFFICE-3297?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel ]

Michael Brauer updated OFFICE-3297:
-----------------------------------

    Resolution: 
Rename the Normative References to [Blowfish] to [Schneier] and in sections 3.4.2 and 4.8.1.

Add the following note to section 4.8.1

Note: An errata for [Schneier] is available at [Schneier-Errata]

where [Schneier-Errata] is

"[Schneier-Errata] Bruce Schneir, Applied Cryptography 2nd. Ed. - Errata, http://www.schneier.com/book-applied-errata.html";

I have no objections to renaming the entry from [Blowfish] to [Schneier], and mentioning the errata that exists also seems to be a good idea. But I think we should treat the reference to the book and the one to the errata as separate bibliographic entries, because they are separate resources.

There is further the issue that the link to the reference is not versioned and that we have no hints how long it will be valid. This makes it difficult to use it in a normative reference. I therefore suggest to add it as a non normative reference. See "Resolution"



> Part 3 [Blowfish] Reference Out-of-Date, Misleading
> ---------------------------------------------------
>
>                 Key: OFFICE-3297
>                 URL: http://tools.oasis-open.org/issues/browse/OFFICE-3297
>             Project: OASIS Open Document Format for Office Applications (OpenDocument) TC
>          Issue Type: Bug
>          Components: External References, Packaging, Part 3 (Packages), Security
>    Affects Versions: ODF 1.0, ODF 1.0 (second edition), ODF 1.1, ODF 1.2 CD 05
>         Environment: This applies to all versions of ODF but the description and proposal is specific to ODF 1.2 CD05, with correction proposed for ODF 1.2 CD06.  This is part of a series of issues that apply to encryption in Part 3 and should probably be reviewed and discussed as a block.
>            Reporter: Dennis Hamilton
>            Assignee: Dennis Hamilton
>             Fix For: ODF 1.2 CD 06
>
>
> The current reference when there is mention of the default Blowfish CFB encryption algorithm is
> [Blowfish] Bruce Schneier, Applied Cryptography (Second Edition), John Wiley & Sons, ISBN: 0-471-11709-9, 1996.
> While Blowfish is discussed in the referenced technical publication, that is not all that is there.  In addition, the description of CFB (and alternatives) is not specific to Blowfish and is discussed in a different part of the text.  
> Finally, there is an errata for Applied Cryptography (Second Edition) that is relevant to the consideration of various methods (including CFB) in employing an encryption algorithm.

-- 
This message is automatically generated by JIRA.
-
If you think it was sent incorrectly contact one of the administrators: http://tools.oasis-open.org/issues/secure/Administrators.jspa
-
For more information on JIRA, see: http://www.atlassian.com/software/jira

        


[Date Prev] | [Thread Prev] | [Thread Next] | [Date Next] -- [Date Index] | [Thread Index] | [List Home]