usnistgov / ACVP

Industry Working Group on Automated Cryptographic Algorithm Validation
https://csrc.nist.gov/projects/cryptographic-algorithm-validation-program
152 stars 63 forks source link

Clarification Request Regarding Testing Scope for KAS-FFC-SSC #1509

Closed msonje closed 1 month ago

msonje commented 2 months ago

We are seeking clarification regarding the testing scope for KAS-FFC-SSC in accordance with SP800-56Ar3 guidelines. Specifically, we need to ascertain whether DSA KeyGen and SafePrimes testing should be conducted separately or if they are inherently covered within the KAS FFC SSC framework. According to SP800-56Ar3 section 5.6.1.1.1 in the ACVP HTML specifications document, it is stated that the testing of safe-primes (both KeyGen and KeyVer) is applicable to KAS-FFC. However, we have noted a contrasting provision in SP800-56r3 section 5.6, where Key-pair Generation is explicitly mentioned to be outside the scope of KAS testing. To ensure compliance and thoroughness in our testing procedures, we kindly request clarification on whether DSA KeyGen and SafePrimes testing should be treated as separate entities or if they are encompassed within the testing framework of KAS-FFC-SSC.

https://pages.nist.gov/ACVP/draft-hammett-acvp-safe-primes.html image

https://pages.nist.gov/ACVP/draft-hammett-acvp-kas-ssc-ffc.html#section-6.2.2-1.1 image

livebe01 commented 2 months ago

Hi @msonje, DSA KeyGen and SafePrimes should be tested separately from KAS-FFC-SSC. I hope this helps.

jbrock24 commented 2 months ago

@msonje Is this issue resolved? Can we close it out?