12.07.2015 Views

Key Management Interoperability Protocol Specification Version 1.1

Key Management Interoperability Protocol Specification Version 1.1

Key Management Interoperability Protocol Specification Version 1.1

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

ObjectEncodingObject Type Enumeration, see 9.1.3.2.12545Table 41: Object Type AttributeSHALL always have a valueInitially set byModifiable by serverModifiable by clientDeletable by clientMultiple instances permittedWhen implicitly setApplies to Object TypesYesServerNoNoNoNoCreate, Create <strong>Key</strong> Pair,Register, Derive <strong>Key</strong>, Certify,Re-certify, Re-key, Re-key<strong>Key</strong> PairAll Objects546547548549550551552Table 42: Object Type Attribute Rules3.4 Cryptographic AlgorithmThe Cryptographic Algorithm of an object (e.g., RSA, DSA, DES, 3DES, AES, etc). The CryptographicAlgorithm of a Certificate object identifies the algorithm for the public key contained within the Certificate.The digital signature algorithm used to sign the Certificate is identified in the Digital Signature Algorithmattribute defined in Section 3.16. This attribute SHALL be set by the server when the object is created orregistered and then SHALL NOT be changed or deleted before the object is destroyed.ObjectEncodingCryptographic Algorithm Enumeration, see 9.1.3.2.13553Table 43: Cryptographic Algorithm AttributeSHALL always have a valueInitially set byModifiable by serverModifiable by clientDeletable by clientMultiple instances permittedWhen implicitly setApplies to Object TypesYesServerNoNoNoNoCertify, Create, Create <strong>Key</strong>Pair, Re-certify, Register,Derive <strong>Key</strong>, Re-key, Re-key<strong>Key</strong> Pair<strong>Key</strong>s, Certificates, Templates554555556557Table 44: Cryptographic Algorithm Attribute Rules3.5 Cryptographic LengthFor keys, Cryptographic Length is the length in bits of the clear-text cryptographic key material of theManaged Cryptographic Object. For certificates, Cryptographic Length is the length in bits of the publickmip-spec-v<strong>1.1</strong>-cos01 21 September 2012Standards Track Work Product Copyright © OASIS Open 2012. All Rights Reserved. Page 34 of 164

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!