FIPS 186-4

Peter Williams pwilliams at rapattoni.com
Wed Jul 24 11:23:55 EDT 2013


note the semantics:

The National Institute of Standards and Technology (NIST) has released a revision to the digital standard used ....

**to ensure** the integrity of electronic documents, as well as the identity of the signer.

folks have adopted the legal interpretation of "ensuring".

Now folks have got a-used to having interpretations (perhaps secret) of public law as a means of setting administrative law, one can expect lots of the practice. Its rather "convenient".

Ensuring is contentious since it invokes a particular OECD-legal theory. This probably tells you a lot about what is going on in the "international review circuit" that is setting joint-policy on identity and encryption. There are those who wanted "ensuring" all along, since it invokes a particular set of jurisprudence cases pertinent to bilateral trusts.

Note the original formulation (based on UN and EU "digital signature" covenants): "This publication prescribes the Digital Signature Algorithm (DSA) for ...digital signature generation and verification."

The change is akin to describing an orange originally as a citrus fruit to, now, an initiative to better address colds and flus through a program of vitamin-C delivery to the worlds needy.
________________________________________
From: dev-bounces at shibboleth.net [dev-bounces at shibboleth.net] on behalf of Ian Young [ian at iay.org.uk]
Sent: Wednesday, July 24, 2013 1:26 AM
To: Shib Dev
Subject: FIPS 186-4

NIST have just published a new edition of FIPS 186, the Digital Signature Standard.  According to the press release:

        http://www.nist.gov/itl/csd/fips-072313.cfm

… the substantive changes are guidance about random number and prime number generation, which probably means it's more relevant to the libraries we use than to our code.

        -- Ian


More information about the dev mailing list