Kantara Initiative Identity Assurance WG Teleconference
...
- Administration:
- Roll Call
- Agenda Confirmation
- Minutes approval: (meeting minutes from 2015-02-26 are having technical difficulties and not available)
- Action Item Review
- Staff reports and updates
- Assurance Review Board (ARB) and Leadership Council (LC) reports and updates
- Call for Tweet-worthy items to feed (@KantaraNews or #kantara)
- Discussion
- FIPS 140-2 versus Common Criteria equivalents
- NIST SP 800-63 update
- AOB
- Adjourn
Attendees
Link to IAWG Roster
...
- Scott Shorter (S)
- Andrew Hughes (VC)
- Devin Kusek
- Lee Aber
- Cathy Tilton
- Rich Furr
- Richard Wilsher
- Adam Madlin
Non-Voting
- Björn Sjöholm
- Pete Palmer
- Angela Rey
Staff
Regrets
- None
Info | ||
---|---|---|
| ||
|
...
title | Selected Non-Voting members for Cut/Paste |
---|
...
Notes & Minutes
Administration
...
FIPS 140-2 language concerns
FIPS 140-2 vs CC topic. On the ARB call this week, discussioons with assessors in Europe noted that Kantara SAC reflects FIPS 140-2 for cryptographic requirements, and national body approved equivalents, which resulted in a perception of a US centric document. Suggested adding relevant common criteria standards for this. ARB has asked IAWG to consider a rewording of those sections that refer directly to the FIPS to reverse the order - make the core reference the ISO standard, or national equivalents.
Cathy agrees but doesn't think this addresses the problem of crypto on mobile devices, where SP 800-63 requires FIPS 140-2 level 1 certified software modules. Major OS on devices do have FIPS 140-2 certification, but that is specific to the handset, chipset, version of OS, etc.
Bjorn - is this an issue for software validation versus hardware validation.
Richard - as a consequence of this - there is an effect that Kantara or FICAM approval could be technically invalidated by the inability of a service to conform to the particular criteria.
Bjorn agrees with the intent of the change.
...
Andrew will respond to Paul that RFI followed by a workshop is a good idea. Didn't hear vocal support of starting the work in advance of starting the scope, after some discussion suggests gathering thoughts to inform what the issues may be. Andrew suggests we work on it at the next available meeting time.
AOB
None
- Motion to adjourn - Richard Wilsher, seconded Adam Madlin