Thank you for accommodating the feedback! From: Mike Jones <[email protected]> Date: Wednesday, June 3, 2020 at 12:50 PM To: Eric Rescorla <[email protected]>, Rich Salz <[email protected]> Cc: "[email protected]" <[email protected]>, "[email protected]" <[email protected]>, "[email protected]" <[email protected]> Subject: RE: [COSE] [Last-Call] Last Call: <draft-ietf-cose-webauthn-algorithms-05.txt> (COSE and JOSE Registrations for WebAuthn Algorithms) to Proposed Standard
https://tools.ietf.org/html/draft-ietf-cose-webauthn-algorithms-07<https://urldefense.proofpoint.com/v2/url?u=https-3A__tools.ietf.org_html_draft-2Dietf-2Dcose-2Dwebauthn-2Dalgorithms-2D07&d=DwMGaQ&c=96ZbZZcaMF4w0F4jpN6LZg&r=4LM0GbR0h9Fvx86FtsKI-w&m=DvfsL_9B8lxskQQnz5n1hVZdxOcmcspl9ELLMoJYh9s&s=esjhelKNCOaAstmxHzyCBJlfSkzc5XMRDTxea9HuXMw&e=> now registers secp256k1 and ES256K as “Recommended: No”, per your requests. -- Mike From: Mike Jones Sent: Saturday, May 23, 2020 4:49 PM To: Eric Rescorla <[email protected]>; [email protected] Cc: [email protected]; Jim Schaad <[email protected]>; [email protected] Subject: Re: [COSE] [Last-Call] Last Call: <draft-ietf-cose-webauthn-algorithms-05.txt> (COSE and JOSE Registrations for WebAuthn Algorithms) to Proposed Standard I can certainly change the COSE recommendation status from Yes to No, if that’s the prevailing opinion. Those that have decided to use secp256k1 over the NIST and 25519 curves will likely continue to do so no matter what we decide in this regard. I’ll wait until the last call expires on Wednesday to see what other comments may come in and then publish an updated draft. Thanks all, -- Mike From: COSE <[email protected]<mailto:[email protected]>> On Behalf Of Eric Rescorla Sent: Saturday, May 23, 2020 2:36 PM To: Salz, Rich <[email protected]<mailto:[email protected]>> Cc: [email protected]<mailto:[email protected]>; Jim Schaad <[email protected]<mailto:[email protected]>>; [email protected]<mailto:[email protected]> Subject: Re: [COSE] [Last-Call] Last Call: <draft-ietf-cose-webauthn-algorithms-05.txt> (COSE and JOSE Registrations for WebAuthn Algorithms) to Proposed Standard Good catch. We definitely should not be recommending sep256k1. -Ekr On Sat, May 23, 2020 at 1:30 PM Salz, Rich <[email protected]<mailto:[email protected]>> wrote: > I believe that the IESG needs to debate if this document should be the one which makes the secp256k1 curve a recommended IETF curve to use. A good point, albeit slightly subtle. +1. -- last-call mailing list [email protected]<mailto:[email protected]> https://www.ietf.org/mailman/listinfo/last-call<https://urldefense.proofpoint.com/v2/url?u=https-3A__www.ietf.org_mailman_listinfo_last-2Dcall&d=DwMGaQ&c=96ZbZZcaMF4w0F4jpN6LZg&r=4LM0GbR0h9Fvx86FtsKI-w&m=DvfsL_9B8lxskQQnz5n1hVZdxOcmcspl9ELLMoJYh9s&s=3Ykwsawl45_2B5UEHJYv3Vi7wGccDfprp-3-slYzL4g&e=>
_______________________________________________ COSE mailing list [email protected] https://www.ietf.org/mailman/listinfo/cose
