TL;DR
There is a risk of confusion and different interpretations regarding what shall be implemented and what may be implemented by adopters.
The spec is using wording like “RSA Baseline” and “EC Baseline” in comment fields to indicate some sort of minimum requirement, but it is also used in some table names AND for the entire spec.
To avoid confusion for adopters I suggest we align the security baseline spec with security addon work; currently the addons are pointing to the baseline as the authoritative source what should be supported when implementing one of the addons and only include an informative section regarding what to implement. This may lead to problems since it is not clear what “baseline” means (there is no definition of it in the spec).
- Does it mean minimum requirements where the word is encountered?
- An individual algo marked with “baseline” must be implemented and a table with the word “baseline” also needs to be implemented in it’s entirety?
- If the word “baseline" is not present, does that mean it does not have to be implemented?
- The whole spec is named “baseline” – does this mean that the whole content of the spec is a minimum requirement?
A clarification (or maybe a different wording or a separate column for the tables) can be added to the spec?
TL;DR
There is a risk of confusion and different interpretations regarding what shall be implemented and what may be implemented by adopters.
The spec is using wording like “RSA Baseline” and “EC Baseline” in comment fields to indicate some sort of minimum requirement, but it is also used in some table names AND for the entire spec.
To avoid confusion for adopters I suggest we align the security baseline spec with security addon work; currently the addons are pointing to the baseline as the authoritative source what should be supported when implementing one of the addons and only include an informative section regarding what to implement. This may lead to problems since it is not clear what “baseline” means (there is no definition of it in the spec).
A clarification (or maybe a different wording or a separate column for the tables) can be added to the spec?