OASIS Key Management Interoperability Protocol (KMIP) TC

 View Only
  • 1.  Groups - Proposal for modification to Conformance Section (Conformance_Clause_Proposal_V3.doc) uploaded

    Posted 07-10-2009 20:14
    This is revision 3 of the Proposal for Modification of the Conformance
    section of the Specification and the Usage Guide. 
    
     -- Mr. Walt Hubis
    
    The document revision named Proposal for modification to Conformance
    Section (Conformance_Clause_Proposal_V3.doc) has been submitted by Mr. Walt
    Hubis to the OASIS Key Management Interoperability Protocol (KMIP) TC
    document repository.  This document is revision #2 of
    Conformance_Clause_Proposal.doc.
    
    Document Description:
    Includes several proposals on modifications and movement of the conformance
    section and a "simple" to use table of requirements for claiming
    conformance.
    
    View Document Details:
    http://www.oasis-open.org/committees/document.php?document_id=33327
    
    Download Document:  
    http://www.oasis-open.org/committees/download.php/33327/Conformance_Clause_Proposal_V3.doc
    
    Revision:
    This document is revision #2 of Conformance_Clause_Proposal.doc.  The
    document details page referenced above will show the complete revision
    history.
    
    
    PLEASE NOTE:  If the above links do not work for you, your email application
    may be breaking the link into two pieces.  You may be able to copy and paste
    the entire link address into the address field of your web browser.
    
    -OASIS Open Administration
    


  • 2.  Re: [kmip] Groups - Proposal for modification to Conformance Section (Conformance_Clause_Proposal_V3.doc) uploaded

    Posted 07-16-2009 15:17

    Overall, I like the proposal.

    However, I think one key provision that will be problematic with this proposal is Section 13.3.
    In general, there are no standing committees at OASIS.  Once a standard is completed, the TCs cease their work.  So I'm not sure how one would get a profile approved when the TC has dissolved.  And since this seems to be the engine that drives this mechanism, I'm not sure where that leaves us.
     
    Bruce A Rich
    brich at-sign us dot ibm dot com



    From: walt.hubis@lsi.com
    To: kmip@lists.oasis-open.org
    Date: 07/10/2009 03:13 PM
    Subject: [kmip] Groups - Proposal for modification to Conformance Section   (Conformance_Clause_Proposal_V3.doc) uploaded





    This is revision 3 of the Proposal for Modification of the Conformance
    section of the Specification and the Usage Guide.

    -- Mr. Walt Hubis

    The document revision named Proposal for modification to Conformance
    Section (Conformance_Clause_Proposal_V3.doc) has been submitted by Mr. Walt
    Hubis to the OASIS Key Management Interoperability Protocol (KMIP) TC
    document repository.  This document is revision #2 of
    Conformance_Clause_Proposal.doc.

    Document Description:
    Includes several proposals on modifications and movement of the conformance
    section and a "simple" to use table of requirements for claiming
    conformance.

    View Document Details:
    http://www.oasis-open.org/committees/document.php?document_id=33327

    Download Document:  
    http://www.oasis-open.org/committees/download.php/33327/Conformance_Clause_Proposal_V3.doc

    Revision:
    This document is revision #2 of Conformance_Clause_Proposal.doc.  The
    document details page referenced above will show the complete revision
    history.


    PLEASE NOTE:  If the above links do not work for you, your email application
    may be breaking the link into two pieces.  You may be able to copy and paste
    the entire link address into the address field of your web browser.

    -OASIS Open Administration




  • 3.  RE: Conformance Section / today's discussion

    Posted 07-16-2009 15:48
    
    
    
    
    
    To comment on the discussion from today's call around conformance claims:
     
    Supports should mean : will process and provide a valid and meaningful response, not just "I don't do that".
     
    I would think any conformant system must reply "I can't" to anything it doesn't support.  A system that can't (one that fails or ignores when presented something it doesn't support) shouldn't be able to claim conformance.  A sender must be able to expect a response from a conformant system.
     
     
     
    ALSO
    algorithm discussion --
    I might only support AES 128
    A client might REQUIRE AES 256
    If I don't handle it I should respond and the client would need to seek a different partner.
    A different client might be fine downgrading to AES 128 and would lower its request and continue with the same partner.
    Thus the system should be responding to requests but need not support everything to claim conformance.
    You can extend this to other algorithms (rather than just key sizes) but the concept is what needs to be contained in the conformance section.
     

    Peter M Zelechoski, CISSP, MBA-TM     Vice President International Product Development
    Election Systems & Software            pzelechoski@essvote.com      402-970-1242



  • 4.  Re: [kmip] Groups - Proposal for modification to Conformance Section (Conformance_Clause_Proposal_V3.doc) uploaded

    Posted 07-16-2009 16:26
    Hi Bruce,

      That's not quite true. A TC doesn't cease its work until it has either agreed to dissolve or until it finishes the work items described in the Charter. Most TCs continue to update that list of work items as time processes and further refinements/enhancements/additions/modifications/etc are deemed appropriate. The only thing a TC cannot do is expand its scope of work. Most TCs produce multiple iterations of a spec (v1.0, v1.1, v.1.2, v2.0), profiles, and other ancillary works in support of the specs themselves.

    Regards,

    Mary

    Mary P McRae
    Director, Standards Development
    Technical Committee Administrator
    OASIS: Advancing open standards for the information society
    twitter: fiberartisan  #oasisopen
    phone: 1.603.232.9090

    Standards are like parachutes: they work best when they're open.








    On Jul 16, 2009, at 11:16 AM, Bruce Rich wrote:


    Overall, I like the proposal.

    However, I think one key provision that will be problematic with this proposal is Section 13.3.
    In general, there are no standing committees at OASIS.  Once a standard is completed, the TCs cease their work.  So I'm not sure how one would get a profile approved when the TC has dissolved.  And since this seems to be the engine that drives this mechanism, I'm not sure where that leaves us.
     
    Bruce A Rich
    brich at-sign us dot ibm dot com



    From: walt.hubis@lsi.com
    To: kmip@lists.oasis-open.org
    Date: 07/10/2009 03:13 PM
    Subject: [kmip] Groups - Proposal for modification to Conformance Section   (Conformance_Clause_Proposal_V3.doc) uploaded





    This is revision 3 of the Proposal for Modification of the Conformance
    section of the Specification and the Usage Guide.

    -- Mr. Walt Hubis

    The document revision named Proposal for modification to Conformance
    Section (Conformance_Clause_Proposal_V3.doc) has been submitted by Mr. Walt
    Hubis to the OASIS Key Management Interoperability Protocol (KMIP) TC
    document repository.  This document is revision #2 of
    Conformance_Clause_Proposal.doc.

    Document Description:
    Includes several proposals on modifications and movement of the conformance
    section and a "simple" to use table of requirements for claiming
    conformance.

    View Document Details:
    http://www.oasis-open.org/committees/document.php?document_id=33327

    Download Document:  
    http://www.oasis-open.org/committees/download.php/33327/Conformance_Clause_Proposal_V3.doc

    Revision:
    This document is revision #2 of Conformance_Clause_Proposal.doc.  The
    document details page referenced above will show the complete revision
    history.


    PLEASE NOTE:  If the above links do not work for you, your email application
    may be breaking the link into two pieces.  You may be able to copy and paste
    the entire link address into the address field of your web browser.

    -OASIS Open Administration





  • 5.  Re: [kmip] Groups - Proposal for modification to Conformance Section (Conformance_Clause_Proposal_V3.doc) uploaded

    Posted 07-16-2009 19:21

    Mary,

    Thanks for the clarification.  In doing a quick re-read of our charter, it seems that it is quiet on the topic of profiles, so it's unclear whether this is expanding the scope of work or not.  Minimally. profile governance work may extend the anticipated time commitments of some of the TC members.

    Bruce A Rich
    brich at-sign us dot ibm dot com



    From: Mary McRae <mary.mcrae@oasis-open.org>
    To: Bruce Rich/Austin/IBM@IBMUS
    Cc: walt.hubis@lsi.com, kmip@lists.oasis-open.org
    Date: 07/16/2009 11:25 AM
    Subject: Re: [kmip] Groups - Proposal for modification to Conformance Section   (Conformance_Clause_Proposal_V3.doc) uploaded





    Hi Bruce,

      That's not quite true. A TC doesn't cease its work until it has either agreed to dissolve or until it finishes the work items described in the Charter. Most TCs continue to update that list of work items as time processes and further refinements/enhancements/additions/modifications/etc are deemed appropriate. The only thing a TC cannot do is expand its scope of work. Most TCs produce multiple iterations of a spec (v1.0, v1.1, v.1.2, v2.0), profiles, and other ancillary works in support of the specs themselves.

    Regards,

    Mary

    Mary P McRae
    Director, Standards Development
    Technical Committee Administrator
    OASIS: Advancing open standards for the information society
    email: mary.mcrae@oasis-open.org
    web: www.oasis-open.org
    twitter: fiberartisan  #oasisopen
    phone: 1.603.232.9090

    Standards are like parachutes: they work best when they're open.








    On Jul 16, 2009, at 11:16 AM, Bruce Rich wrote:


    Overall, I like the proposal.


    However, I think one key provision that will be problematic with this proposal is Section 13.3.

    In general, there are no standing committees at OASIS.  Once a standard is completed, the TCs cease their work.  So I'm not sure how one would get a profile approved when the TC has dissolved.  And since this seems to be the engine that drives this mechanism, I'm not sure where that leaves us.

     
    Bruce A Rich
    brich at-sign us dot ibm dot com



    From: walt.hubis@lsi.com
    To: kmip@lists.oasis-open.org
    Date: 07/10/2009 03:13 PM
    Subject: [kmip] Groups - Proposal for modification to Conformance Section   (Conformance_Clause_Proposal_V3.doc) uploaded






    This is revision 3 of the Proposal for Modification of the Conformance
    section of the Specification and the Usage Guide.

    -- Mr. Walt Hubis

    The document revision named Proposal for modification to Conformance
    Section (Conformance_Clause_Proposal_V3.doc) has been submitted by Mr. Walt
    Hubis to the OASIS Key Management Interoperability Protocol (KMIP) TC
    document repository.  This document is revision #2 of
    Conformance_Clause_Proposal.doc.

    Document Description:
    Includes several proposals on modifications and movement of the conformance
    section and a &quot;simple&quot; to use table of requirements for claiming
    conformance.

    View Document Details:

    http://www.oasis-open.org/committees/document.php?document_id=33327

    Download Document:  

    http://www.oasis-open.org/committees/download.php/33327/Conformance_Clause_Proposal_V3.doc

    Revision:
    This document is revision #2 of Conformance_Clause_Proposal.doc.  The
    document details page referenced above will show the complete revision
    history.


    PLEASE NOTE:  If the above links do not work for you, your email application
    may be breaking the link into two pieces.  You may be able to copy and paste
    the entire link address into the address field of your web browser.

    -OASIS Open Administration







  • 6.  Re: [kmip] Groups - Proposal for modification to Conformance Section (Conformance_Clause_Proposal_V3.doc) uploaded

    Posted 07-16-2009 20:08
    Hi Bruce,

      Yes, that's for the TC to decide. I'm not aware of an existing TC that has ever taken that position (that creation of a profile is out of scope) but it's up to the participants. As far as time commitments go, again, there is no 'required' membership; members are free to join/leave as appropriate. Of course those employers that are paying employees to sit on committees might have a different opinion ;)

    Regards,

    Mary







    On Jul 16, 2009, at 3:20 PM, Bruce Rich wrote:


    Mary,

    Thanks for the clarification.  In doing a quick re-read of our charter, it seems that it is quiet on the topic of profiles, so it's unclear whether this is expanding the scope of work or not.  Minimally. profile governance work may extend the anticipated time commitments of some of the TC members.

    Bruce A Rich
    brich at-sign us dot ibm dot com



    From: Mary McRae <mary.mcrae@oasis-open.org>
    To: Bruce Rich/Austin/IBM@IBMUS
    Cc: walt.hubis@lsi.com, kmip@lists.oasis-open.org
    Date: 07/16/2009 11:25 AM
    Subject: Re: [kmip] Groups - Proposal for modification to Conformance Section   (Conformance_Clause_Proposal_V3.doc) uploaded





    Hi Bruce,

      That's not quite true. A TC doesn't cease its work until it has either agreed to dissolve or until it finishes the work items described in the Charter. Most TCs continue to update that list of work items as time processes and further refinements/enhancements/additions/modifications/etc are deemed appropriate. The only thing a TC cannot do is expand its scope of work. Most TCs produce multiple iterations of a spec (v1.0, v1.1, v.1.2, v2.0), profiles, and other ancillary works in support of the specs themselves.

    Regards,

    Mary

    Mary P McRae
    Director, Standards Development
    Technical Committee Administrator
    OASIS: Advancing open standards for the information society
    email: mary.mcrae@oasis-open.org
    web: www.oasis-open.org
    twitter: fiberartisan  #oasisopen
    phone: 1.603.232.9090

    Standards are like parachutes: they work best when they're open.








    On Jul 16, 2009, at 11:16 AM, Bruce Rich wrote:


    Overall, I like the proposal.


    However, I think one key provision that will be problematic with this proposal is Section 13.3.

    In general, there are no standing committees at OASIS.  Once a standard is completed, the TCs cease their work.  So I'm not sure how one would get a profile approved when the TC has dissolved.  And since this seems to be the engine that drives this mechanism, I'm not sure where that leaves us.

     
    Bruce A Rich
    brich at-sign us dot ibm dot com



    From: walt.hubis@lsi.com
    To: kmip@lists.oasis-open.org
    Date: 07/10/2009 03:13 PM
    Subject: [kmip] Groups - Proposal for modification to Conformance Section   (Conformance_Clause_Proposal_V3.doc) uploaded






    This is revision 3 of the Proposal for Modification of the Conformance
    section of the Specification and the Usage Guide.

    -- Mr. Walt Hubis

    The document revision named Proposal for modification to Conformance
    Section (Conformance_Clause_Proposal_V3.doc) has been submitted by Mr. Walt
    Hubis to the OASIS Key Management Interoperability Protocol (KMIP) TC
    document repository.  This document is revision #2 of
    Conformance_Clause_Proposal.doc.

    Document Description:
    Includes several proposals on modifications and movement of the conformance
    section and a &quot;simple&quot; to use table of requirements for claiming
    conformance.

    View Document Details:

    http://www.oasis-open.org/committees/document.php?document_id=33327

    Download Document:  

    http://www.oasis-open.org/committees/download.php/33327/Conformance_Clause_Proposal_V3.doc

    Revision:
    This document is revision #2 of Conformance_Clause_Proposal.doc.  The
    document details page referenced above will show the complete revision
    history.


    PLEASE NOTE:  If the above links do not work for you, your email application
    may be breaking the link into two pieces.  You may be able to copy and paste
    the entire link address into the address field of your web browser.

    -OASIS Open Administration








  • 7.  RE: [kmip] Groups - Proposal for modification to Conformance Section (Conformance_Clause_Proposal_V3.doc) uploaded

    Posted 07-16-2009 20:23
    
    
    
    
    
    
    
    
    
    
    
    

    We could certainly consider updating the charter to be explicit about a) profiles, and b) ongoing spec maintenance by following the procedures described in the OASIS TC Process (http://www.oasis-open.org/committees/process.php) re: rechartering.

    I refer you to the current SSTC charter as an example (http://www.oasis-open.org/committees/security/charter.php).  That TC has gone through a couple of charter revisions in its long history (it started in Nov 2000) as it moved from SAML 1.0 to 1.1 to 2.0.

    That current charter uses wording in the purpose, scope and deliverables to account for creation of new profiles of use and spec maintenance.  The last update was back in Nov 2003 and that revision has served the ongoing work since then.

    While I’m not suggesting that the KMIP TC has to continue in existence for the next 10 years or more, there is nothing that precludes that if evolution of the spec and creation of new profiles truly serves the interests of the industry.

    Rob Philpott

    RSA, the Security Division of EMC
    Senior Technologist | e-Mail: robert.philpott@rsa.com | Office: (781) 515-7115 | Mobile: (617) 510-0893

    From: Mary McRae [mailto:mary.mcrae@oasis-open.org]
    Sent: Thursday, July 16, 2009 4:07 PM
    To: Bruce Rich
    Cc: kmip@lists.oasis-open.org
    Subject: Re: [kmip] Groups - Proposal for modification to Conformance Section (Conformance_Clause_Proposal_V3.doc) uploaded

    Hi Bruce,

      Yes, that's for the TC to decide. I'm not aware of an existing TC that has ever taken that position (that creation of a profile is out of scope) but it's up to the participants. As far as time commitments go, again, there is no 'required' membership; members are free to join/leave as appropriate. Of course those employers that are paying employees to sit on committees might have a different opinion ;)

    Regards,

    Mary

    On Jul 16, 2009, at 3:20 PM, Bruce Rich wrote:




    Mary,

    Thanks for the clarification.  In doing a quick re-read of our charter, it seems that it is quiet on the topic of profiles, so it's unclear whether this is expanding the scope of work or not.  Minimally. profile governance work may extend the anticipated time commitments of some of the TC members.

    Bruce A Rich
    brich at-sign us dot ibm dot com


    From:

    Mary McRae <mary.mcrae@oasis-open.org>

    To:

    Bruce Rich/Austin/IBM@IBMUS

    Cc:

    walt.hubis@lsi.com, kmip@lists.oasis-open.org

    Date:

    07/16/2009 11:25 AM

    Subject:

    Re: [kmip] Groups - Proposal for modification to Conformance Section   (Conformance_Clause_Proposal_V3.doc) uploaded





    Hi Bruce,

      That's not quite true. A TC doesn't cease its work until it has either agreed to dissolve or until it finishes the work items described in the Charter. Most TCs continue to update that list of work items as time processes and further refinements/enhancements/additions/modifications/etc are deemed appropriate. The only thing a TC cannot do is expand its scope of work. Most TCs produce multiple iterations of a spec (v1.0, v1.1, v.1.2, v2.0), profiles, and other ancillary works in support of the specs themselves.

    Regards,

    Mary

    Mary P McRae
    Director, Standards Development
    Technical Committee Administrator
    OASIS: Advancing open standards for the information society
    email: mary.mcrae@oasis-open.org
    web: www.oasis-open.org
    twitter: fiberartisan  #oasisopen
    phone: 1.603.232.9090

    Standards are like parachutes: they work best when they're open.








    On Jul 16, 2009, at 11:16 AM, Bruce Rich wrote:


    Overall, I like the proposal.


    However, I think one key provision that will be problematic with this proposal is Section 13.3.

    In general, there are no standing committees at OASIS.  Once a standard is completed, the TCs cease their work.  So I'm not sure how one would get a profile approved when the TC has dissolved.  And since this seems to be the engine that drives this mechanism, I'm not sure where that leaves us.

     
    Bruce A Rich
    brich at-sign us dot ibm dot com


    From:

    walt.hubis@lsi.com

    To:

    kmip@lists.oasis-open.org

    Date:

    07/10/2009 03:13 PM

    Subject:

    [kmip] Groups - Proposal for modification to Conformance Section   (Conformance_Clause_Proposal_V3.doc) uploaded





    This is revision 3 of the Proposal for Modification of the Conformance
    section of the Specification and the Usage Guide.

    -- Mr. Walt Hubis

    The document revision named Proposal for modification to Conformance
    Section (Conformance_Clause_Proposal_V3.doc) has been submitted by Mr. Walt
    Hubis to the OASIS Key Management Interoperability Protocol (KMIP) TC
    document repository.  This document is revision #2 of
    Conformance_Clause_Proposal.doc.

    Document Description:
    Includes several proposals on modifications and movement of the conformance
    section and a &quot;simple&quot; to use table of requirements for claiming
    conformance.

    View Document Details:

    http://www.oasis-open.org/committees/document.php?document_id=33327

    Download Document:  

    http://www.oasis-open.org/committees/download.php/33327/Conformance_Clause_Proposal_V3.doc

    Revision:
    This document is revision #2 of Conformance_Clause_Proposal.doc.  The
    document details page referenced above will show the complete revision
    history.


    PLEASE NOTE:  If the above links do not work for you, your email application
    may be breaking the link into two pieces.  You may be able to copy and paste
    the entire link address into the address field of your web browser.

    -OASIS Open Administration