Re: PD 0108: FTP_ITC.1.3 Specifies The Functions For Which A Trusted Channel Is Provided



On Tue, 20 Jul 2004 08:22:36 -0400 (EDT), Tom Benkart <teb@coact.com> said:

> 1. In the STATEMENT section, it is not clear in what way "it is acceptable 
> to replace" the text of the CC SFR.  How about "It is acceptable to use an 
> explicitly stated SFR that replaces"?

Sounds good. 'twill be examined at the ODRB meeting in August.

> 2. Under SUPPORT, #3, some text from the original OR is still included 
> (namely:...).

Hmmm. As written, it's not a problem because there's no identification of the
source, but it would probably better to have made that a "for example" instead
of "namely". 

> 3. In might be helpful to include in the PD a statement that the TSF is not 
> required to enforce usage of the trusted channel by the remote trusted IT 
> product.

Perhaps, but the TOE can never enforce what a remote product does.

Thanks for the close review.

Daniel





Date Index | Thread Index | Problems or questions? Contact list-master@nist.gov