6.6.5.2 UAFX Offline Security Policies
6.6.5.2.1 UAFX Offline Security Policy – Rsa-Pkcs-Sha256 Facet
Table 51 describes the details of the UAFX Offline Security Policy – Rsa-Pkcs-Sha256 Facet.
This security Facet defines a public-key cryptography security policy for Descriptors with average security needs.
| Group | Conformance Unit / Profile Title | Optional |
|---|---|---|
| UAFX OfflineEngineering | UAFX Offline Rsa-Sha256 Limits | False |
| Security | AsymmetricSignatureAlgorithm_RSA-PKCS15-SHA2-256 | False |
| Security | CertificateKeyAlgorithm_RSA | False |
| UAFX OfflineEngineering | UAFX Offline CertificateSignatureAlgorithm_RSA‑PKCS15‑SHA2‑256 | False |
6.6.5.2.2 UAFX Offline Security Policy – Rsa-Pss-Sha256 Facet
Table 52 describes the details of the UAFX Offline Security Policy – Rsa-Pss-Sha256 Facet.
This security Facet defines a public-key cryptography security policy for Descriptors with average security needs.
| Group | Conformance Unit / Profile Title | Optional |
|---|---|---|
| UAFX OfflineEngineering | UAFX Offline Rsa-Sha256 Limits | False |
| Security | AsymmetricSignatureAlgorithm_RSA-PSS-SHA2-256 | False |
| Security | CertificateKeyAlgorithm_RSA | False |
| UAFX OfflineEngineering | UAFX Offline CertificateSignatureAlgorithm_ RSASAA_PSS-SHA2-256 | False |
6.6.5.2.3 UAFX Offline Security Policy – Rsa-Pkcs-Sha384 Facet
Table 53 describes the details of the UAFX Offline Security Policy – Rsa-Pkcs-Sha384 Facet.
This security Facet defines a public-key cryptography security policy for Descriptors with high security needs.
| Group | Conformance Unit / Profile Title | Optional |
|---|---|---|
| UAFX OfflineEngineering | UAFX Offline Rsa-Sha384 Limits | False |
| UAFX OfflineEngineering | UAFX Offline AsymmetricSignatureAlgorithm_RSA‑PKCS15‑SHA2‑384 | False |
| Security | CertificateKeyAlgorithm_RSA | False |
| UAFX OfflineEngineering | UAFX Offline CertificateSignatureAlgorithm_RSA‑PKCS15‑SHA2‑384 | False |
6.6.5.2.4 UAFX Offline Security Policy – Rsa-Pss-Sha384 Facet
Table 54 describes the details of the UAFX Offline Security Policy – Rsa-Pss-Sha384 Facet.
This security Facet defines a public-key cryptography security policy for Descriptors with high security needs.
| Group | Conformance Unit / Profile Title | Optional |
|---|---|---|
| UAFX OfflineEngineering | UAFX Offline Rsa-Sha384 Limits | False |
| UAFX OfflineEngineering | UAFX AsymmetricSignatureAlgorithm_RSASAA_PSS-SHA2-384 | False |
| Security | CertificateKeyAlgorithm_RSA | False |
| UAFX OfflineEngineering | UAFX Offline CertificateSignatureAlgorithm_RSASAA_PSS-SHA2-384 | False |
6.6.5.2.5 UAFX Offline Security Policy – Rsa-Pkcs-Sha512 Facet
Table 55 describes the details of the UAFX Offline Security Policy – Rsa-Pkcs-Sha512 Facet.
This security Facet defines a public-key cryptography security policy for Descriptors with very high security needs.
| Group | Conformance Unit / Profile Title | Optional |
|---|---|---|
| UAFX OfflineEngineering | UAFX Offline Rsa-Sha512Limits | False |
| UAFX OfflineEngineering | UAFX Offline AsymmetricSignatureAlgorithm_RSA‑PKCS15‑SHA2‑512 | False |
| Security | CertificateKeyAlgorithm_RSA | False |
| UAFX OfflineEngineering | UAFX Offline CertificateSignatureAlgorithm_RSA‑PKCS15‑SHA2‑512 | False |
6.6.5.2.6 UAFX Offline Security Policy – Rsa-Pss-Sha512 Facet
Table 56 describes the details of the UAFX Offline Security Policy – Rsa-Pss-Sha512 Facet.
This security Facet defines a public-key cryptography security policy for Descriptors with very high security needs.
| Group | Conformance Unit / Profile Title | Optional |
|---|---|---|
| UAFX OfflineEngineering | UAFX Offline Rsa-Sha512Limits | False |
| UAFX OfflineEngineering | UAFX Offline AsymmetricSignatureAlgorithm_RSASAA_PSS-SHA2-512 | False |
| Security | CertificateKeyAlgorithm_RSA | False |
| UAFX OfflineEngineering | UAFX Offline CertificateSignatureAlgorithm_RSASAA_PSS-SHA2-512 | False |
6.6.5.2.7 UAFX Offline Security Policy – ECC-nistP256 Facet
Table 57 describes the details of the UAFX Offline Security Policy – ECC-nistP256 Facet.
This security Facet defines an elliptic curve cryptography security policy for Descriptors with average security needs. NIST curves are widely implemented and offer better performance than RSA.
| Group | Conformance Unit / Profile Title | Optional |
|---|---|---|
| UAFX OfflineEngineering | UAFX Offline ECC‑nistP256 Limits | False |
| UAFX OfflineEngineering | UAFX Offline AsymmetricSignatureAlgorithm_ECDSA-SHA2-256 | False |
| UAFX OfflineEngineering | UAFX Offline CertificateKeyAlgorithm_ECC-nistP256 | False |
| UAFX OfflineEngineering | UAFX Offline CertificateSignatureAlgorithm_ECDSA‑SHA2‑256 | False |
6.6.5.2.8 UAFX Offline Security Policy – ECC-nistP384 Facet
Table 58 describes the details of the UAFX Offline Security Policy – ECC-nistP384 Facet.
This security Facet defines an elliptic curve cryptography security policy for Descriptors with high security needs. NIST curves are widely implemented and offer better performance than RSA.
| Group | Conformance Unit / Profile Title | Optional |
|---|---|---|
| UAFX OfflineEngineering | UAFX Offline ECC-nistP384 Limits | False |
| UAFX OfflineEngineering | UAFX Offline AsymmetricSignatureAlgorithm_ECDSA-SHA2-384 | False |
| UAFX OfflineEngineering | UAFX Offline CertificateKeyAlgorithm_ECC-nistP384 | False |
| UAFX OfflineEngineering | UAFX Offline CertificateSignatureAlgorithm_ECDSA-SHA2-384 | False |
6.6.5.2.9 UAFX Offline Security Policy – ECC-nistP521 Facet
Table 59 describes the details of the UAFX Offline Security Policy – ECC-nistP521 Facet.
This security Facet defines an elliptic curve cryptography security policy for Descriptors with very high security needs. NIST curves are widely implemented and offer better performance than RSA.
| Group | Conformance Unit / Profile Title | Optional |
|---|---|---|
| UAFX OfflineEngineering | UAFX Offline ECC-nistP521 Limits | False |
| UAFX OfflineEngineering | UAFX Offline AsymmetricSignatureAlgorithm_ECDSA-SHA2-512 | False |
| UAFX OfflineEngineering | UAFX Offline CertificateKeyAlgorithm_ECC-nistP521 | False |
| UAFX OfflineEngineering | UAFX Offline CertificateSignatureAlgorithm_ECDSA-SHA2-512 | False |