Is the Session API within the approved scope of CMVP certificate #5313?
还没有人认领这个 Issue。
评估
- 难度
- 5/5
- 预计耗时
- 一周以上
- 新手友好度
- 25/100
- Issue 类型
- 文档
- 描述清晰度
- 需要澄清
- 活跃度
- 冷清
- 技术栈
- c
- 领域
- cryptography, security
调研方向
从链接的 #5313 Security Policy 开始,重点查看其中的服务表、AES-GCM IV Generation - External 条目以及 IG C.H Scenario 3 声明;然后将这些陈述与 101.2.0 changelog 和列出的 Session API exports 进行比较。当维护者明确 SessionSenderInit 后接 SessionGcmEncrypt 是否属于 approved mode 使用并满足 Scenario 3 时,即视为完成。
由索引模型根据 Issue 内容生成。
描述
libsymcrypt.so exports SymCryptSessionSenderInit, SymCryptSessoinReceiverInit, SymCryptSessionGcmEncrypt, SymCryptSessionGcmDecrypt and SymCryptSessionDestroy (VERSION_101.). The 101.2.0 changelog describes these as enabling "multithreaded IV generation within the SymCrypt FIPS boundary."
The #5313 Security Policy does not name a Session service in its services table, and registers IV Generation - External for AES-GCM. The certificate seperately claims IG C.H Scenario 3.
When a caller uses SymCryptSessionSenderInit followed by SymCryptSessionGcmEncrypt, so that the module constructs and increments the nonce internally, is that an approved-mode use of the module under #5313? Does it satisfy the Scenario 3 claim?
Trying to understand so we can use the module in approved mode correctly. Thanks!
- 主要语言
- C
- 星标
- 893
- 派生
- 90
- PR 合并指标
- 30 天内没有已合并 PR
环境准备
- 没有 Dockerfile 或 Docker Compose 文件
- 有 Pull Request 模板
- 没有贡献指南
从这里开始
- 先读完整个 Issue,再读项目的贡献指南。
- 在 Issue 下留言说明你要接手 —— 这能避免两个人做同样的事。
- Fork 仓库,在一个分支上完成修改。
- 提交 Pull Request,并在描述里引用这个 Issue 编号。
microsoft/SymCrypt 的其他 Issue
-
难度 1/5 1 小时以内 新手友好度 85/100
-
难度 4/5 3-5 天 新手友好度 55/100
-
bug compiler-support
难度 4/5 3-5 天 新手友好度 42/100
-
enhancement
难度 5/5 一周以上 新手友好度 25/100
-
难度 5/5 一周以上 新手友好度 25/100
查看 microsoft/SymCrypt 的全部 Issue
相似的 Issue
-
难度 2/5 1-3 小时 新手友好度 72/100
NASA-AMMOS/BSL#355 ·
维护者通常 1 天内回复
-
#242 leftovers: dated narrative and shas in the social-features test plan可能已有人在做 关联的 PR 仍在进行中或已合并。 未关闭
难度 2/5 1-3 小时 新手友好度 72/100
EchoTools/nevr-runtime#264 ·
维护者通常 1 天内回复
-
area/docdb kind/bug priority/medium status/awaiting-triage
难度 2/5 1-3 小时 新手友好度 82/100
yugabyte/yugabyte-db#34873 ·
维护者通常 1 天内回复
-
难度 1/5 1 小时以内 新手友好度 70/100
维护者通常 1 天内回复
-
category:port-update
难度 2/5 1-3 小时 新手友好度 72/100
维护者通常 2 天内回复