OASIS IDtrust Steering Committee

 View Only

Re: [idtrust-sc] IDtrust SC MS Minutes - PKI Workshop

  • 1.  Re: [idtrust-sc] IDtrust SC MS Minutes - PKI Workshop

    Posted 04-22-2007 21:14
    Thanks Patrick.
    
    Jamie/Mary, perhaps you can send me (separately) any material
    that shows which OASIS standards were implemented in ASN.1 and
    how that process worked?  Thanks.
    
    Arshad
    
    Patrick Gannon wrote:
    > Arshad,
    > 
    > While I do not totally understand the details in creating ASN.1 messages vs.
    > XML, I do know that we have had ASN.1 implementations made of other OASIS
    > Standards.  So, it would be better to keep any ASN.1 representation of an
    > OASIS CS or OS kept within the OASIS TC, so that alignment can be maintained
    > and IPR considerations kept consistent.
    > 
    > Please work with Mary & Jamie on the best method to align any ASN.1
    > implementation of SKSML within the OASIS EKMI TC.
    > 
    > Patrick
    > 
    > 
    > -----Original Message-----
    > From: Arshad Noor [mailto:arshad.noor@strongauth.com] 
    > Sent: Sunday, April 22, 2007 4:26 PM
    > To: idtrust-sc@lists.oasis-open.org
    > Subject: Re: [idtrust-sc] IDtrust SC MS Minutes - PKI Workshop
    > 
    > Two comments, Dee:
    > 
    > 1) Related to item #3 ("EKMI TC - Arshad reported significant
    >     interest in the EKMI TC at the OASIS Symposium. He also
    >     stated the need to create an Audit Guidelines SC to encourage
    >     ISACA to join OASIS."), the AGSC already exists; however, we
    >     need to stay actively focus on audit standards to encourage
    >     ISACA members to join OASIS to work with us in the trenches.
    >     Presenting at the ISACA Intl. conference, and sponsoring the
    >     workshop at the regional conference are great ways to begin
    >     this process.
    > 
    > 2) Regarding item #3 in Other Business ("Dee to follow-up with
    >     Russell Housley regarding to concerns related to EKMI overlap
    >     with IETF."), could you elaborate on the discussion and the
    >     overlap that was discussed?
    > 
    >     I am aware of the KEYPROV-WG and the comments raised by Phillip
    >     Hallam-Baker of VeriSign before the EKMI-TC was convened.  I
    >     have also responded to PHB and on the OASIS forum that there is
    >     no overlap.  I am also an observer on the KEYPROV-WG and have
    >     seen nothing that indicates they are focusing on the same issues
    >     that we are.
    > 
    >     I am also aware that Sandi Rood (US DoD), who is a member of
    >     the EKMI-TC and the SKSML-SC has expressed a desire to define
    >     a symmetric key-management protocol in ASN.1.  I have responded
    >     to Sandi (and this is all on the SKSML-SC archives) that OASIS
    >     is an XML-standards based forum, and that the SKSML-SC would
    >     like to know what advantages ASN.1 had over the proposed SKSML
    >     so that we could incorporate that into the design.
    > 
    >     Sandi has responded that one of her colleagues is in the process
    >     of evaluating that difference and she will present the findings
    >     when ready.  In the meantime, they have prepared an ASN.1-based
    >     RFC DRAFT (based on the encourage of Russ Housley) to define a
    >     symmetric key-management protocol.
    > 
    >     It appears to me that this may be descending into a classic ASN
    >     versus XML battle, and this is something neither side will win.
    >     (However, market momentum is for XML - as is OASIS.)
    > 
    >     So, it would be best for EKMI-TC to understand, specifically,
    >     what are the deficiencies that Russ Housely sees in SKSML and
    >     to declare them.  He should be encouraged to join the EKMI-TC
    >     and participate in the discussion on the SKSML-SC.
    > 
    > Arshad Noor
    > StrongAuth, Inc.
    > 
    > 
    > 
    > Dee Schur wrote:
    > 
    >>Respectfully submitted, send changes.
    >>Best,
    >>Dee
    >>
    > 
    >