On 19/03/2019 02.17, Rob Stradling via dev-security-policy wrote:
> On 18/03/2019 17:05, Kurt Roeckx wrote:
>> On Mon, Mar 18, 2019 at 03:30:37PM +0000, Rob Stradling via 
>> dev-security-policy wrote:
>>>
>>> When a value in column E is 100%, this is pretty solid evidence of
>>> noncompliance with BR 7.1.
>>> When the values in column E and G are both approximately 50%, this
>>> suggests (but does not prove) that the CA is handling the output from
>>> their CSPRNG correctly.
>>
>> Sould F/G say >= 64, instead of > 64?
> 
> Yes.  Fixed.  Thanks!

Perhaps it would make sense to separate out <64, ==64, >64?

100% "64-bit" serial numbers would indicate an algorithm using 63 bits
of entropy and the top bit coerced to 1.


-- 
Hector Martin "marcan" (mar...@marcan.st)
Public Key: https://mrcn.st/pub
_______________________________________________
dev-security-policy mailing list
dev-security-policy@lists.mozilla.org
https://lists.mozilla.org/listinfo/dev-security-policy
            • RE: P... Jeremy Rowley via dev-security-policy
            • Re: P... Rob Stradling via dev-security-policy
            • Re: P... Peter Bowen via dev-security-policy
            • Re: P... identrust--- via dev-security-policy
            • Re: P... Rob Stradling via dev-security-policy
            • Surve... Rob Stradling via dev-security-policy
            • Re: S... Rob Stradling via dev-security-policy
            • Re: S... Rob Stradling via dev-security-policy
            • Re: S... Kurt Roeckx via dev-security-policy
            • Re: S... Rob Stradling via dev-security-policy
            • Re: S... Hector Martin 'marcan' via dev-security-policy
            • Re: S... Rob Stradling via dev-security-policy
            • RE: S... Doug Beattie via dev-security-policy
            • Re: S... Wayne Thayer via dev-security-policy
            • Re: S... Andrew Ayer via dev-security-policy
            • Re: P... Jaime Hablutzel via dev-security-policy
            • Re: P... Daymion Reynolds via dev-security-policy
            • Re: P... Jaime Hablutzel via dev-security-policy
            • Re: P... Hector Martin 'marcan' via dev-security-policy
            • Re: P... Jaime Hablutzel via dev-security-policy
  • Re: Pre-Incident Report - G... Daymion Reynolds via dev-security-policy

Reply via email to