• Open Menu Close Menu
  • Apple
  • Shopping Bag
  • Apple
  • Mac
  • iPad
  • iPhone
  • Watch
  • TV
  • Music
  • Support
  • Search apple.com
  • Shopping Bag

Lists

Open Menu Close Menu
  • Terms and Conditions
  • Lists hosted on this site
  • Email the Postmaster
  • Tips for posting to public mailing lists
Re: [Fed-Talk] Re: FIPS 140-2 discussion...
[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Re: [Fed-Talk] Re: FIPS 140-2 discussion...


  • Subject: Re: [Fed-Talk] Re: FIPS 140-2 discussion...
  • From: "Timothy J. Miller" <email@hidden>
  • Date: Fri, 15 May 2009 10:00:41 -0500

Amanda Walker wrote:

Indeed.  Defeating a security product via cryptanalysis is extremely
rare--because it's usually unnecessary.  Key distribution and handling
is very, very hard to get right.  This is why software-only products
can only get to level 2 compliance, for example

Software alone only gets level 1. Software only gets level 2 when it's restricted to running on specific hardware:


"""
Security Level 2 allows the software and firmware components of a cryptographic module to be executed on a general purpose computing system using an operating system that


• meets the functional requirements specified in the Common Criteria (CC) Protection Profiles (PPs) listed in Annex B and

• is evaluated at the CC evaluation assurance level EAL2 (or higher).

An equivalent evaluated trusted operating system may be used. A trusted operating system provides a level of trust so that cryptographic modules executing on general purpose computing platforms are comparable to cryptographic modules implemented using dedicated hardware systems.
"""


-- Tim


Attachment: smime.p7s
Description: S/MIME Cryptographic Signature

 _______________________________________________
Do not post admin requests to the list. They will be ignored.
Fed-talk mailing list      (email@hidden)
Help/Unsubscribe/Update your Subscription:

This email sent to email@hidden

  • Follow-Ups:
    • Re: [Fed-Talk] Re: FIPS 140-2 discussion...
      • From: Amanda Walker <email@hidden>
References: 
 >[Fed-Talk] Drive Encryption - Cross Platform compatible (From: Michael Pike <email@hidden>)
 >RE: [Fed-Talk] Drive Encryption - Cross Platform compatible (From: "Hopfner, Philip (Phil) (CIV)" <email@hidden>)
 >RE: [Fed-Talk] Drive Encryption - Cross Platform compatible (From: "Allan B. Marcus" <email@hidden>)
 >Re: [Fed-Talk] Drive Encryption - Cross Platform compatible (From: "Pike, Michael (IHS/NPA)" <email@hidden>)
 >Re: [Fed-Talk] Drive Encryption - Cross Platform compatible (From: Amanda Walker <email@hidden>)
 >Re: [Fed-Talk] Drive Encryption - Cross Platform compatible (From: Basil Decina <email@hidden>)
 >Re: [Fed-Talk] Drive Encryption - Cross Platform compatible (From: Amanda Walker <email@hidden>)
 >Re: [Fed-Talk] Drive Encryption - Cross Platform compatible (From: Basil Decina <email@hidden>)
 >Re: [Fed-Talk] Drive Encryption - Cross Platform compatible (From: Amanda Walker <email@hidden>)
 >[Fed-Talk] Re: FIPS 140-2 discussion... (From: "Shawn A. Geddis" <email@hidden>)
 >Re: [Fed-Talk] Re: FIPS 140-2 discussion... (From: Amanda Walker <email@hidden>)

  • Prev by Date: Re: [Fed-Talk] Re: FIPS 140-2 discussion... Apple's CSP certification
  • Next by Date: Re: [Fed-Talk] Re: FIPS 140-2 discussion... Apple's CSP certification
  • Previous by thread: Re: [Fed-Talk] Re: FIPS 140-2 discussion... Apple's CSP certification
  • Next by thread: Re: [Fed-Talk] Re: FIPS 140-2 discussion...
  • Index(es):
    • Date
    • Thread