commoncriteria / mobile-device

Protection Profile for Mobile Device Fundamentals
The Unlicense
14 stars 3 forks source link

FIA_X509_EXT.2.1 possibly blank selection #62

Open woodbe opened 2 years ago

woodbe commented 2 years ago

The SFR in v3.2 currently lists this selection as the first available in the requirement:

[selection: IPsec in accordance with the PP-Module for VPN Client, mutually authenticated DTLS as defined in the Package for Transport Layer Security]

The problem is that neither of these two selections is mandatory, and so could end up with the case where neither is selected. There is no option for "no other methods" here. There is a "no additional uses" selection in the second selection in the SFR, but it is clear that the first selection is specifically for transport methods while the second is for signing and other uses.

There should be an option in the first selection to allow for a "no additional methods".