12.07.2015 Views

Key Management Interoperability Protocol Specification Version 1.1

Key Management Interoperability Protocol Specification Version 1.1

Key Management Interoperability Protocol Specification Version 1.1

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

SHALL always have a valueInitially set byModifiable by serverModifiable by clientDeletable by clientMultiple instances permittedWhen implicitly setApplies to Object TypesYes, if the server has accessto the Digest Value or the<strong>Key</strong> Material (for keys andsecret data), the CertificateValue (for certificates) or theOpaque Data Value (foropaque objects).ServerNoNoNoYesCreate, Create <strong>Key</strong> Pair,Register, Derive <strong>Key</strong>, Certify,Re-certify, Re-key, Re-key<strong>Key</strong> PairAll Cryptographic Objects,Opaque Objects703704705706707708709710711712Table 71: Digest Attribute Rules3.18 Operation Policy NameAn operation policy controls what entities MAY perform which key management operations on the object.The content of the Operation Policy Name attribute is the name of a policy object known to the keymanagement system and, therefore, is server dependent. The named policy objects are created andmanaged using mechanisms outside the scope of the protocol. The policies determine what entities MAYperform specified operations on the object, and which of the object’s attributes MAY be modified ordeleted. The Operation Policy Name attribute SHOULD be set when operations that result in a newManaged Object on the server are executed. It is set either explicitly or via some default set by the server,which then applies the named policy to all subsequent operations on the object.ObjectOperation Policy NameText StringEncoding713Table 72: Operation Policy Name AttributeSHALL always have a valueInitially set byModifiable by serverModifiable by clientDeletable by clientMultiple instances permittedWhen implicitly setApplies to Object TypesNoServer or ClientYesNoNoNoCreate, Create <strong>Key</strong> Pair,Register, Derive <strong>Key</strong>, Certify,Re-certify, Re-key, Re-key<strong>Key</strong> PairAll Objects714Table 73: Operation Policy Name Attribute Ruleskmip-spec-v<strong>1.1</strong>-cos01 21 September 2012Standards Track Work Product Copyright © OASIS Open 2012. All Rights Reserved. Page 44 of 164

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!