Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

FIA_CMCC_EXT.1, FIA_CMCS_EXT.1.3, and FIA_CMPC_EXT.1 Mutual Authentication #17

Open
kenji-lightship opened this issue May 17, 2024 · 1 comment

Comments

@kenji-lightship
Copy link

kenji-lightship commented May 17, 2024

The SFRs require renewal requests using mutual authentication; however, it cannot be guaranteed the certificate that is being renewed is a TLS client certificate, so the TLS/HTTPS server would be expected to reject the mutual authentication due to an invalid EKU (lack of TLS client EKU).

@kenji-lightship kenji-lightship changed the title FIA_CMCC_EXT.1 and FIA_CMPC_EXT.1 Mutual Authentication FIA_CMCC_EXT.1, FIA_CMCS_EXT.1.3, and FIA_CMPC_EXT.1 Mutual Authentication May 17, 2024
@jfisherbah
Copy link
Contributor

  • FIA_CMCC_EXT.1 app note - added clarification as to when clientAuth EKU is needed
  • FIA_CMCS_EXT.1.3 app note - added clarification on what must be included based on the supported transport of CMC request
  • FIA_CMPC_EXT.1.2 SFR updated to make the controller of CMP import/export capability selectable between admin and supported function capabilities
  • FIA_CMPC_EXT.1.2 app note updated to clarify when one vs the other controller would be selected in CMPC_EXT.1.2
    Believe can be closed.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

2 participants