Skip to content

keyexhchangeinit record #20

@jfisherbah

Description

@jfisherbah

It is suggested to consider adding verbiage to permit the strict-kex-[c|s]-v00@openssh.com key exchange to bein the TOE's KeyExchangeInit record (e.g. an Application note on FCS_SSH_EXT.1.6 indicating that this is explicitly permissible as it is not changing the key exchange algorithm itself and just defines specific rules for the message counter and permissible next messages). Note: this would also require additional verbiage for the ‘ext-info’ indicator that would also be present.

Suggested test activities for this would be:
o Add a test that the TOE correctly obeys this value depending on the negotiated state.
o This would also be recommended as a clarity item for the test activity sections of FCS_SSH_EXT.1.6

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions