Skip to content

[Security Baseline] Unclear requirements for baseline implementation #771

Description

@Johan-Svensk

TL;DR
There is a risk of confusion and different interpretations regarding what shall be implemented and what may be implemented by adopters.
The spec is using wording like “RSA Baseline” and “EC Baseline” in comment fields to indicate some sort of minimum requirement, but it is also used in some table names AND for the entire spec.

To avoid confusion for adopters I suggest we align the security baseline spec with security addon work; currently the addons are pointing to the baseline as the authoritative source what should be supported when implementing one of the addons and only include an informative section regarding what to implement. This may lead to problems since it is not clear what “baseline” means (there is no definition of it in the spec).

  • Does it mean minimum requirements where the word is encountered?
  • An individual algo marked with “baseline” must be implemented and a table with the word “baseline” also needs to be implemented in it’s entirety?
  • If the word “baseline" is not present, does that mean it does not have to be implemented?
  • The whole spec is named “baseline” – does this mean that the whole content of the spec is a minimum requirement?

A clarification (or maybe a different wording or a separate column for the tables) can be added to the spec?

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions