usnistgov / 800-63-3

Home to public development of NIST Special Publication 800-63-3: Digital Authentication Guidelines
https://pages.nist.gov/800-63-3/
Other
702 stars 102 forks source link

Errata Issues #1915

Closed paul-grassi closed 4 years ago

paul-grassi commented 6 years ago

I haven't validated, just getting this out of my inbox.

i) the table of errata states that there is a ‘substantive’ change to the rigor in §4.3, but all I can see is the removal of the redundant second instance of ‘CSP’. Is the table wrong or is there a substantive change missing, or is my eyesight failing me? ii) there appears to be no change in §6 – wasn’t the problem only in Table 2.1? iii) you and I discussed Table 5-1 and I thought we had agreed wording to allow phrasing such as “demonstrate or show other reasonable expectation that the Issuing Source of the evidence” to allow that reasonable expectation to allow ready use of such sources as DMV-issued docs … but no erratum was provided. Oversight or change of mind?

And with regard to 63B: iv) changes to §5.2.3 are too subtle for me to determine (which may not be saying much).

jimfenton commented 5 years ago

Need to study item iii more -- could have been too large a change for an erratum.

jimfenton commented 5 years ago

i) Yes, the change is just the redundant word, and the nature of the change is mischaracterized in the errata table.

ii) The change from normative to informative for Section 6 was just in Table 2-1, not the section itself.

iii) Not sure of the context (where in Table 5-1) of this proposed change, but it sounds like a normative change that's not appropriate for errata.

iv) The subtle change in -63B Section 5.2.3 was the addition of another "SHALL be" for one of the phrases in the sentence. But I'm a little confused by the "and the sensor or endpoint SHALL be established" phrase; not sure what this is requiring.