iTC Meeting Minutes 2023 09 14 - DSC-iTC/cPP GitHub Wiki

Agenda

Attendees

  • Brian Wood

  • Bob Clemens

  • Jerry Myers

  • Yi Mao

Record of Decisions

  • None

Action Items

  • Review of the SFRs since the crypto catalog changes were integrated

Minutes

The call started with a review of the three new pull requests. These were all merged based on agreement on the call.

The call then moved on to the hardware issues (Issue #72 and Issue #73). There was a lot of discussion about how to handle side channel. Issue #72 has the summary of the decision of the group (to reject the comment but to move text out of the SPD). It was generally agreed that the DSC is not like a smart card and so having this specific type of expectation, when the DSC would be an embedded component in a larger product, is not the same as stand alone products.

Brian then provided a review of the other sections of the project. He noted that the cPP and SD categories are left to cleanup issues, and that the crypto issues are waiting on catalog updates (for the SD) to close them. The CC:2022 issue still open is waiting on a response from NIAP, but the current plan is to not change anything.

The introduction category has the most work left outside of a general review of the SFRs now that the crypto requirements have been changed. The cPP needs review to fix the places where the change in requirements has broken dependencies (or created ones that didn’t previously exist), and needs to be checked before starting the public review period.

Brian stated that the crypto updates should be reviewed prior to launching the public review. The introduction could be updated later as it is informative, but the SFRs should be reviewed fully.

Brian proposed that the cPP version be moved to v2.0 for this release instead of v1.1 due to the number of changes and the new support for CC:2022.

Yi stated that Google should be added to the list of contributing organizations, and to possibly remove Samsung. Brian stated that he felt Samsung should remain, though Google could certainly be added.

The call ended at 1:02pm EDT.

⚠️ **GitHub.com Fallback** ⚠️