← Prev in month ← Prev in thread
Next in thread → Next in month →

OpenC2 Signature suggestion

From
Martinez, Danny (HII-TSD) <>
Date
2020-08-05T02:07:58+00:00
ID
Thread
OpenC2 Signature suggestion
OpenC2 TC,

This is my first time using this method, I hope it works as intended. Since my organization is temporarily no longer a member of Oasis I am using this method to make suggestions.

Enclosed I have attached my "rough" suggestion for a signature scheme in OpenC2 in relation to LSC issue #363. The general suggestion involves detaching and attaching a signature field to a pre-made OpenC2 payload encompassing headers and content as suggested
 by Dave Kemp in issue #353. 

Since the particular way in which a signature is applied is serialization dependent I suggest that we use best practices for each serialization and define what those are for OpenC2.  In
 this case I utilized JSON serialization as an example. The RFCs (JWS and JCS) referenced as best practice will be specific to JSON serialization only.

PS: I know it needs a little something, but perhaps this will start that conversation.

V/R

Danny Martinez

Principal Cyber Security Engineer

HII Mission Driven Innovative Solutions (HII-MDIS)

Technical Solutions Division

302 Sentinel Drive, Suite 300 | Annapolis Junction, MD 20701

Mobile (407)
 257-0031

Confidentiality Statement: HUNTINGTON INGALLS INDUSTRIES PROPRIETARY - This e-mail contains information proprietary or private to Huntington Ingalls Industries, Inc., and is not to be disclosed to, copied by, or used in any manner by others without the prior
 express, written permission. If you are not the intended recipient, please delete without copying and kindly advise the sender by e-mail of the mistake in delivery.

Attachment:
OpenC2 Message Signature.docx

Description: OpenC2 Message Signature.docx
← Prev in month ← Prev in thread
Next in thread → Next in month →