usnistgov / 800-63-3

Home to public development of NIST Special Publication 800-63-3: Digital Authentication Guidelines
https://pages.nist.gov/800-63-3/
Other
702 stars 102 forks source link

VoT guidance #1884

Closed kboeckl closed 6 years ago

kboeckl commented 6 years ago

Please note, this proposed guidance is for discussion purposes. For example, this version suggests that users should not include values that describe requirements under the asserted xAL, but perhaps we should adjust. I've also bolded other notes throughout for consideration.

jricher commented 6 years ago

Overall the content is good, I think it would benefit from some reorganization. Specifically, fitting it in to the overall structure more.

paul-grassi commented 6 years ago

Please address Justin's comments and we can re-review. Nice job.

jricher commented 6 years ago

An additional comment: The management section (the M vector component) needs to be more clearly stated to be talking about an ongoing policy with the account and not signaling an event on the account.

kboeckl commented 6 years ago

@jricher & @paul-grassi: I made a bunch of changes; please review when you have time. Thanks!