Derived secrets SHOULD

Make 8.3 SHOULD not must

Raised by:
Ian Fette
Opened on:
8.3 says "Any derived secret that convey a similar level of authority as the original secret it MUST also be protected at the same level as the original secret"

I propose that we change the MUST to a SHOULD, as it's just not practical for many sites.
Related Actions Items:
No related actions
Related emails:
  1. Meeting record: 2008-05-14 (from on 2008-06-06)
  2. ISSUE-211 (Derived secrets SHOULD): Make 8.3 SHOULD not must [wsc-xit] (from on 2008-05-14)

Related notes:

Section 8 is moving to its own item; it's a beyond June issue

Mary Ellen Zurko, 22 May 2008, 20:17:57

has been removed from wsc-ui

Mary Ellen Zurko, 16 Jan 2009, 20:43:32

Display change log ATOM feed

Mary Ellen Zurko <>, Chair, Thomas Roessler <>, Staff Contact
Tracker (configuration for this group), originally developed by Dean Jackson, is developed and maintained by the Systems Team <>.
$Id: 211.html,v 1.1 2010/10/11 09:35:13 dom Exp $