OASIS Mailing List ArchivesView the OASIS mailing list archive below
or browse/search using MarkMail.

 


Help: OASIS Mailing Lists Help | MarkMail Help

office message

[Date Prev] | [Thread Prev] | [Thread Next] | [Date Next] -- [Date Index] | [Thread Index] | [List Home]


Subject: [OASIS Issue Tracker] Updated: (OFFICE-2738) ODF 1.2 Part 3 section4.8.12 manifest:salt guidance



     [ http://tools.oasis-open.org/issues/browse/OFFICE-2738?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel ]

Dennis Hamilton updated OFFICE-2738:
------------------------------------

    Resolution: 
Replace the text of 4.8.12 manifest:salt with 

"""
The manifest:salt attribute carries the value of a cryptographically-random binary value designed to mitigate certain cryptographic attacks on the password.  There is no maximum length to the salt.  See [RFC2898] for further considerations in the use of salts with key-derivation and other cryptographic functions.  The salt is encoded in the attribute value as base64binary.
"""

Simplified the statement and tied it to [RFC2898] in the resolution.

> ODF 1.2 Part 3 section 4.8.12 manifest:salt guidance
> ----------------------------------------------------
>
>                 Key: OFFICE-2738
>                 URL: http://tools.oasis-open.org/issues/browse/OFFICE-2738
>             Project: OASIS Open Document Format for Office Applications (OpenDocument) TC
>          Issue Type: Bug
>          Components: Packaging, Part 3 (Packages), Security
>    Affects Versions: ODF 1.2 CD 05
>         Environment: This clarification applies to ODF 1.0/1.1/IS 26300 and ODF 1.2 drafts.  The specific text is addressed to ODF 1.2 CD05 Part 3 and the section numbering there.
>            Reporter: Dennis Hamilton
>            Assignee: Dennis Hamilton
>            Priority: Minor
>             Fix For: ODF 1.2 CD 06
>
>
> The 4.8.12 manifest:salt attribute specification provides no guidance on the generation of salt values by package producers.

-- 
This message is automatically generated by JIRA.
-
If you think it was sent incorrectly contact one of the administrators: http://tools.oasis-open.org/issues/secure/Administrators.jspa
-
For more information on JIRA, see: http://www.atlassian.com/software/jira

        


[Date Prev] | [Thread Prev] | [Thread Next] | [Date Next] -- [Date Index] | [Thread Index] | [List Home]