Re: SCVP chapter 3.3
Tim Polk <tim.polk <at> nist.gov>
2006-03-01 18:05:01 GMT
Peter,
IMHO, the most straightforward implementation of requestorRef would be
achieved if the server maintained ordering and simply appended their name
to the current value. There is currently one sentence in Section 7 that
implies this technique.
However, there is no security rationale for requiring ordering in the
requestorRef list of names. All that is required is that previous values
be included in subsequent requests.
Since this is not a security requirement, and there is no reason to limit
developers, I will make the appropriate changes to sections 3.3 and 7 to
indicate the requestorRef is not ordered. (I will post the text later
today...)
SCVP servers that don't implement relay MUST satisfy the requirements in
sections 3.3 and 4.7. That is, they MUST copy the value into the
requestorRef field in the response. Such servers need not satisfy any
additional requirements from Section 7. That is, such servers need not
review the names in requestorRef for their own name, since loopback is not
an issue.
Thanks,
Tim Polk
At 03:26 PM 3/1/2006 +0100, you wrote:
>I think that the text in 3.3 is not good and there is double text with
(Continue reading)