diff --git a/sp800-63-3.md b/sp800-63-3.md index 4ee4b44b..bdf449d5 100644 --- a/sp800-63-3.md +++ b/sp800-63-3.md @@ -6,6 +6,7 @@ description: "NIST Special Publication 800-63-3" {{ site.time | date_to_rfc822 }} {% include_relative sp800-63-3/cover.md %} +{% include_relative sp800-63-3/errata.md %} {% include_relative sp800-63-3/sec1_2_introduction.md %} {% include_relative sp800-63-3/sec3_definitions.md %} {% include_relative sp800-63-3/sec4_model.md %} diff --git a/sp800-63-3/errata.md b/sp800-63-3/errata.md new file mode 100644 index 00000000..4a161f8a --- /dev/null +++ b/sp800-63-3/errata.md @@ -0,0 +1,17 @@ +
+ + +
+## Errata +
+ +This table contains changes that have been incorporated into Special Publication 800-63-3. Errata updates can include corrections, clarifications, or other minor changes in the publication that are either editorial or substantive in nature. + +|Date|Type|Change|Location +|----|----|----|----| +|2017-12-01|Editorial|Removed the term ‘cryptographic’ from the AAL3 description.|Executive Summary| +||Editorial|Updated reference to Risk Management Framework|§5| +||Editorial|Fixed verbiage in xAL flowcharts|Figures6-1, 6-2, and 6-3| +||Editorial|Added NISTIR 8062 as a reference|§8.1| +||Editorial|Added definitions for disassociability, manageability, processing, and predictability|Appendix A| +|2019-XX-XX|Added definition for authorization component|Appendix A| diff --git a/sp800-63a.md b/sp800-63a.md index a0ca329b..0c7d6f45 100644 --- a/sp800-63a.md +++ b/sp800-63a.md @@ -6,6 +6,7 @@ description: "NIST Special Publication 800-63A" {{ site.time | date_to_rfc822 }} {% include_relative sp800-63a/cover.md %} +{% include_relative sp800-63a/errata.md %} {% include_relative sp800-63a/sec1_2_introduction.md %} {% include_relative sp800-63a/sec3_definitions.md %} {% include_relative sp800-63a/sec4_ial.md %} diff --git a/sp800-63a/errata.md b/sp800-63a/errata.md new file mode 100644 index 00000000..8b88fb46 --- /dev/null +++ b/sp800-63a/errata.md @@ -0,0 +1,23 @@ +
+ + +
+## Errata +
+ +This table contains changes that have been incorporated into Special Publication 800-63C. Errata updates can include corrections, clarifications, or other minor changes in the publication that are either editorial or substantive in nature. + +|Date|Type|Change|Location +|----|----|----|----| +|2017-12-01|Editorial|Made minor grammatical edits throughout the document.|N/A| +||Editorial|Changed ‘Normative’ to ‘Informative’|Table 2-1| +||Substantive|Changed ‘Normative’ to ‘Informative’|§4.1| +||Editorial|Confirmed‘Normative’|§4.2| +||Substantive|Clarifiedthe requirements about processing of attributes|§4.2 Bullet 4 +||Substantive|Reduced rigor in requirement|§4.3| +||Substantive|Clarified and removed ambiguity in requirement|§4.4| +||Substantive|Clarified requirement|§4.4.1.3| +||Substantive|Clarified and removed ambiguity in requirement|§4.4.1.6| +||Substantive|Updated the section to be ‘Informative’|§6| +||Substantive|Changed the title to processing limitation; clarified the language, incorporated privacy objectives language, and specified that consent is explicit|§8.3| +||EditorialAdded NISTIR 8062 as a reference|§10.1| diff --git a/sp800-63b.md b/sp800-63b.md index ed07418b..f38039b9 100644 --- a/sp800-63b.md +++ b/sp800-63b.md @@ -6,6 +6,7 @@ description: "NIST Special Publication 800-63B" {{ site.time | date_to_rfc822 }} {% include_relative sp800-63b/cover.md %} +{% include_relative sp800-63b/errata.md %} {% include_relative sp800-63b/sec1_2_introduction.md %} {% include_relative sp800-63b/sec3_definitions.md %} {% include_relative sp800-63b/sec4_aal.md %} diff --git a/sp800-63b/errata.md b/sp800-63b/errata.md new file mode 100644 index 00000000..cd782356 --- /dev/null +++ b/sp800-63b/errata.md @@ -0,0 +1,24 @@ +
+ + +
+## Errata +
+ +This table contains changes that have been incorporated into Special Publication 800-63C. Errata updates can include corrections, clarifications, or other minor changes in the publication that are either editorial or substantive in nature. + +|Date|Type|Change|Location +|----|----|----|----| +|2017-12-01|Editorial|Updated AAL descriptions for consistency with other text in document|Introduction| +||Editorial|Deleted “cryptographic” to consistently reflect authenticator options at AAL3|§4.3| +||Substantive|Refined the requirements about processing of attributes|§4.4| +||Editorial|Make language regarding activation factors for multifactor authenticators consistent|§5.1.5.1, 5.1.8.1, and 5.1.9.1| +||Substantive|Recognizeuse of hardware TPM as hardware crypto authenticator|§5.1.7.1, 5.1.9.1| +||Editorial|Improve normative language on authenticated protected channels for biometrics|§5.2.3| +||Editorial|Changed “transaction” to “binding transaction” to emphasize that requirement doesn’t apply to authentication transactions|§6.1.1| +||Editorial|Replaced out-of-context note at end of section 7.2|§7.2| +||Editorial|Changed IdP to CSP to match terminology used elsewhere in this document|Table 8-1| +||Editorial|Corrected capitalization of Side Channel Attack|Table 8-2| +||Substantive|Changed the title to processing limitation; clarified the language, incorporated privacy objectives language, and specified that consent is explicit|§9.3| +||Editorial|Added NISTIR 8062 as a reference|§11.1| +||Editorial|Corrected title of SP 800-63C|§11.3| diff --git a/sp800-63c.md b/sp800-63c.md index 11e7e90f..d2dadc1d 100644 --- a/sp800-63c.md +++ b/sp800-63c.md @@ -6,6 +6,7 @@ description: "NIST Special Publication 800-63C" {{ site.time | date_to_rfc822 }} {% include_relative sp800-63c/cover.md %} +{% include_relative sp800-63c/errata.md %} {% include_relative sp800-63c/sec1_2_introduction.md %} {% include_relative sp800-63c/sec3_definitions.md %} {% include_relative sp800-63c/sec4_fal.md %} @@ -17,5 +18,4 @@ description: "NIST Special Publication 800-63C" {% include_relative sp800-63c/sec10_usability.md %} {% include_relative sp800-63c/sec11_examples.md %} {% include_relative sp800-63c/references.md %} -{% include_relative sp800-63c/errata.md %} diff --git a/sp800-63c/cover.md b/sp800-63c/cover.md index 00b6530c..6fdd24ca 100644 --- a/sp800-63c/cover.md +++ b/sp800-63c/cover.md @@ -195,5 +195,3 @@ The terms "CAN" and "CANNOT" indicate a possibility and capability, whether mate [11. Assertion Examples](#examples) [12. References](#references) - -[Errata](#errata)