Skip to content
Bob Relyea edited this page Mar 5, 2025 · 1 revision

PKCS11 3.1 Work Items

Proposers should plan to review the relevant sections of the updated documents related to their proposed changes, to make sure all updates are made correctly. If proposer is no longer active in TC, the chairs and secretary will ask someone else to cover the review. The reviewer should verify the content, including any amendments made by voice vote, were included correctly in both the specification document and header files (if applicable). Change first cell to GREEN after ALL work is completed (approved by TC, added to specification and header file, changes reviewed). Note: All Proposals(other than editorial items) not completed by October 14, 2020 will be pushed into PKCS#11 v3.2

# Proposer(s) Issue Summary Description Link(s) to Proposal Date(s) Approved Links to Ballots and/or Minutes where approved Added to Which Document by Editor(s) Content reviewed by whom during committee review/Date Header File Reviewed By
1 Tim Hudson Profile and Test case testing with XML Test cases for profiles document in XML with annotation for interop and conformance. draft profile prose F2F presentation 14 Oct 2020 https://wiki.oasis-open.org/pkcs11/Meetingminutes/Minutes14102020 pkcs11-profiles-v3.1-wd03.docx TimH 28Oct20 Hamish C. Reviewed 10-Nov-2021 (Bob R. 20-Jul-2020. Reviewed against original proposal: only minor editorial changes that look intentional. One issue: 1.3.1 label in section 4.6.4 should point to 4.3.1) Hamish C. Reviewed 1-Sept-2021 new Profile CKP present
2 Bob Relyea IKE Proposal Add Daniel's comments - DUE 15-Mar-2020 https://www.oasis-open.org/apps/org/workgroup/pkcs11/download.php/67088/PKCS11_IKE_SPEC.doc 27 May 2020 https://wiki.oasis-open.org/pkcs11/Meetingminutes/Minutes27052020 pkcs11-curr-v3.1-wd01.docx new section 2.64 and pkcs11-spec-v3.1-wd03(markup).docx section 6.64 - DieterB 17Nov20 Bob R, 13-Apr-2020, changes needed See email Changes are complete in WD 05, reviwed by Bob R 20-Jul-2021 Re-Reviewed on Hamish C, 27-Aug-2021
3 Michelle Brochmann HSS Spec Proposal Updated May 12, 2020 https://www.oasis-open.org/apps/org/workgroup/pkcs11/download.php/67172/PKCS11_HSS_SPEC_5-12-2020.docx 27 May 2020 https://wiki.oasis-open.org/pkcs11/Meetingminutes/Minutes27052020 pkcs11-curr-v3.1-wd01.docx new section 2.65 and pkcs11-spec-v3.1-wd03(markup).docx section 6.65 - DieterB 17Nov20 Michelle B, 8-Dec-2020 Hamish C, 16-Aug-2021
4 Bob Relyea (with Daniel's help) C_Decrypt / C_DecryptFinal behavior Fix NSS. And fix the specification. Proposal updated Apr 27, 2020 https://markmail.org/message/abcp2jjqh6vot7i2?q=C_Decrypt+list:org%2Eoasis-open%2Elists%2Epkcs11-comment+order:date-forward&page=1 & proposals: https://www.oasis-open.org/apps/org/workgroup/pkcs11/download.php/67128/New_wording_for_ckr_buffer_too_small.docx & https://www.oasis-open.org/apps/org/workgroup/pkcs11/download.php/67089/New_wording_for_ckr_buffer_too_small.docx 27 May 2020 https://wiki.oasis-open.org/pkcs11/Meetingminutes/Minutes27052020 Amended Spec pkcs11-spec-v3.1-wd03(markup).docx section 5.2 - TonyC Nov20 Jonathan S, 31-Mar-2021 N/A
6 Bob R (+ Tim H) Incoming comment HKDF Amendments Bob to fix spec (remove items) and propose two TLS13 HKDF profiles (work with Tim). Updated Apr 30,2020 https://www.oasis-open.org/apps/org/workgroup/pkcs11/email/archives/201911/msg00010.html - Proposals https://www.oasis-open.org/apps/org/workgroup/pkcs11/download.php/67129/HKDF_Update.docx & https://www.oasis-open.org/apps/org/workgroup/pkcs11/download.php/67130/HKDF_Policy.docx 27 May 2020 https://wiki.oasis-open.org/pkcs11/Meetingminutes/Minutes27052020 pkcs11-curr-v3.1-wd01.docx amendment in section 2.62.4 and pkcs11-spec-v3.1-wd03(markup).docx section 6.62.4 - DieterB 17Nov20 Bob R, 13-Apr-2020 Hamish C, 14-Apr-2021
7 Bob R Add new IV generator to match TLS Previously lumped in under HKDF but warrants separatation https://www.oasis-open.org/apps/org/workgroup/pkcs11/document.php?document_id=67131 24 June 2020 https://wiki.oasis-open.org/pkcs11/Meetingminutes/Minutes24062020 pkcs11-curr-v3.1-wd01.docx amendments in section 2.13 and pkcs11-spec-v3.1-wd03(markup).docx section 6.13 - DieterB 17Nov20 Bob R, 13-Apr-2020 Hamish C, 14-Apr-2021

PKCS11 3.1 Action Items

Other action items. The results will contribute to the completion of PKCS#11 v3.1 Note: All AIs (other than editorial items) not completed by October 14, 2020 will be pushed into KMIP v3.2

# Owner Description Due Status Source Updated (Editor-Date) Reviewed in Updated Document (Meeting Date)
1 Oscar S v2.40 & v2.40E1 comments review May 27, 2020 Closed 2020 F2F Minutes PKCS#11-Spec-v3.1-WD01 Tony C 14-Dec-2021
2 Tony C contact Robert K regarding IV generation in GCM 21-Jul-2020 Closed 2020 F2F Minutes & https://lists.oasis-open.org/archives/pkcs11-comment/201906/msg00008.html N/A N/A
3 Tony C Provide a polite "no thanks" email in response to the "2 new functions" comment 21-Jul-2020 Closed 2020 F2F Minutes & https://markmail.org/message/b6oc3ucirz6c3x32?q=pkcs11-version+3+list:org.oasis-open.lists.pkcs11-comment N/A N/A
4 Dieter B Update specification to remove backwards compatibility issues Editorial Cleanup (Oct 2020) Closed 2020 F2F Minutes pkcs11-curr-v3.1-wd01.docx amendments in section 2.16, 2.3.20 and 2.1.23 / pkcs11-spec-v3.1-wd03(markup).docx sections 6.16, 6.3.20 and 6.1.23 - DieterB 17Nov20 Hamish C, 23-June-2021
5 Bob R Allocate a new identifier for CKM_AES_KEY_WRAP_PAD and CKM_ECDH_AES_KEY_WRAP / CKM_RSA_AES_KEY_WRAP --- Closed 2020 F2F Minutes , superseeded by "Amend Identifiers following Updates AES Key Wrap specification discussions" below N/A N/A
6 Bob R Update Spec & Profiles for HKDF 15Apr2020 Closed 2020 F2F Minutes Spec: pkcs11-curr-v3.1-wd01.docx amendment in section 2.62.4 and pkcs11-spec-v3.1-wd03(markup).docx section 6.62.4 - DieterB 17Nov20. Profile noted in WD03 Bob R 14-Apr-2021
7 Tony C & Dieter B Take first pass at spec & mech merge + cleanup Editorial Cleanup (Oct 2020) Open 2020 F2F Minutes PKCS#11-Spec-v3.1-WD01 Posted for review Noted Daniel M 31-Mar2021
8 Bob R Review common usage for Edwards ECC Curve usage in TLS - check with Jakub June 2020 Closed https://wiki.oasis-open.org/pkcs11/Meetingminutes/Minutes13052020 - resolution https://wiki.oasis-open.org/pkcs11/Meetingminutes/Minutes08072020 no changes needed N/A
9 Tony C & Dieter B Draft note for inclusion in Mechanisms doc regarding Edwards ECC Curves compatibility Editorial Cleanup (Oct 2020) Open https://wiki.oasis-open.org/pkcs11/Meetingminutes/Minutes13052020 pkcs11-curr-v3.1-wd01.docx amendments in section 2.3.5, 2.3.6, 2.3.7, 2.3.8 and pkcs11-spec-v3.1-wd03(markup).docx sections 6.3.5, 6.3.6, 6.3.7, 6.3.8 - DieterB 17Nov20 Prose for DER encoding has been included int the latest release
10 Bob R Look at the TLS spec and the RedHat solutions to determine most common format for CKA_EC_POINT as per Mintes 10 June 2020 Closed https://wiki.oasis-open.org/pkcs11/Meetingminutes/Minutes13052020 - New AI raised per July 22, 2020 Meeting N/A N/A
11 Dieter B Correct bits v bytes error for C_Sign & C_Verify inputs Editorial Cleanup (Oct 2020) Open https://wiki.oasis-open.org/pkcs11/Meetingminutes/Minutes13052020 pkcs11-curr-v3.1-wd01.docx amendment in table 22 and pkcs11-spec-v3.1-wd03(markup).docx table 53 - DieterB 17Nov20 Changes to the table has been made is is correct. Unrelated, while looking for the table, I noticed 3 tables which are not properly linked as tables in section 6.2.19, 6.2.10, and 6.2.21 ** Aug21 Tony C - checked table links - all ok
12 Michelle B Add an error code and explanatory text to be used when a system is taking too long to generate larger keys (eg HSS) 30-Sep-2020 Closed https://wiki.oasis-open.org/pkcs11/Meetingminutes/Minutes27052020 <insert></insert> pkcs11-curr-v3.1-wd01.docx amendment in section 2.65.4 and pkcs11-spec-v3.1-wd03(markup).docx section 6.65.4- DieterB 17Nov20 Michelle B, 17-Mar-2021
13 Dieter B Clarify PKCS#11 spec content relating to CKA_EC Point. Spec needs to be clear. Editorial Cleanup (Oct 2020) Open Minutes - July 22, 2020 pkcs11-curr-v3.1-wd01.docx amendments in section 2.3.5, 2.3.6, 2.3.7, 2.3.8 and pkcs11-spec-v3.1-wd03(markup).docx sections 6.3.5, 6.3.6, 6.3.7, 6.3.8 - DieterB 17Nov20 rrelyea 22-Jan-2022
15 Tony C & Dieter B Add additional detail to the spec regarding padding Editorial Cleanup (Oct 2020) Open Minutes - August 19, 2020 & https://lists.oasis-open.org/archives/pkcs11-comment/202007/msg00000.html pkcs11-v3.1-wd02.docx section 6.7 lines 8850-8854 and and pkcs11-spec-v3.1-wd03(markup).docx lines 8780-8784: updated wording This looks good to me. Vendors that implement AES_KEY_WRAP should review this as well.
16 Bob R Add Error code identifier to match Michelle's HSS Long Key Gen proposal 30-Sep-2020 Closed Minutes - September 16, 2020 TBA Aug21, TonyC - No Action needed - closing
17 Tony C & Dieter B Tidy up inconsistency in CKA_PUBLIC_EXPONENT - move spec definition to mechanisms section Editorial Cleanup (Oct 2020) Open Minutes - July 22, 2020 pkcs11-curr-v3.1-wd01.docx amendment in section 2.1.3 and pkcs11-spec-v3.1-wd03(markup).docx section 6.1.3 - DieterB 17Nov20 Jonathan S-H, 29-Jul-2021
18 Tony C & Dieter B Include note to deprecate CKM_ECDH-AES_KEY_WRAP TBA Open See Minutes https://wiki.oasis-open.org/pkcs11/Meetingminutes/Minutes28042021 - April 24, 2021 Tony C 2-Sep-2021 Deprecation notice added to §6.3.20 Y
19 Tony C & Dieter B Amend next WD to correct errors in IKE (s6.64) per Daniel M TBA Open Email - https://www.oasis-open.org/apps/org/workgroup/pkcs11/email/archives/202106/msg00007.html & Minutes - https://wiki.oasis-open.org/pkcs11/Meetingminutes/Minutes18082021 Tony C 2-Sep-2021 noted WD updates successful Daniel M 2-Sep-2021 note updates reviewed

Dropped Items

Proposer(s) Issue Summary Description Link(s) to Proposal Date(s) Approved Links to Ballots and/or Minutes where approved Added to Which Document by Editor(s) Content reviewed by whom during committee review/Date Header File Reviewed By
Incoming comment Suggestion of 2 new functions - C_Encrypt_By_Handle TBA https://markmail.org/message/b6oc3ucirz6c3x32?q=pkcs11-version+3+list:org%2Eoasis-open%2Elists%2Epkcs11-comment TBA TBA TBA TBA TBA

Clone this wiki locally