usnistgov/800-63-3

Unclear reference regarding distribution of look-up secrets

Opened this issue · 0 comments

-63B Section 5.1.2.1 says that "look-up secrets SHALL be distributed over a secure channel in accordance with the post-enrollment binding requirements in Section 6.1.2"

However, Section 6.1.2 (and subsidiary section 6.1.2.1) does not directly address this. 5.1.2.1 should probably directly require the use of an authenticated protected channel.