Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Inconsistency regarding permitted AAL3 authenticator type combinations #1983

Open
jimfenton opened this issue Oct 16, 2020 · 0 comments
Open
Assignees

Comments

@jimfenton
Copy link
Member

the list of Permitted Authenticator Types for AAL3 (4.3.1.) does not match the AAL Summary of Requirements for AAL3 (Table 4-1).

List from 4.3.1 (just the relevant entries):
· Multi-Factor OTP device (software or hardware) (Section 5.1.5) used in conjunction with a Single-Factor Cryptographic Device (Section 5.1.7)
· Multi-Factor OTP Device (hardware only) (Section 5.1.5) used in conjunction with a Single-Factor Cryptographic Software (Section 5.1.6)
· Single-Factor OTP Device (hardware only) (Section 5.1.4) used in conjunction with a Multi-Factor Cryptographic Software Authenticator (Section 5.1.8)

While the correspondent relevant entries of Table 4-1 say this
· SF OTP Device plus MF Crypto Device or Software;

Section 4.3.1 is correct. In the meanwhile, note that Table 4-1 is informative (in anticipation that an inconsistency of this sort might arise).

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
None yet
Development

No branches or pull requests

3 participants
@jimfenton and others