Mike: > I can add a sentence along the lines of the following to make Jim’s points > below clearer to non-expert readers: > > “The specific identifiers used to tie the key derivation to the sender (Party > U) and the receiver (Party V) are application specific and beyond the scope > of this specification.”
I see the attraction of this approach, but I wonder if it would be possible to also include some advice to applications that make use of JOSE. If the parties that are trying to form a pairwise key make different assumptions, then we do not get interoperability. I am just trying to improve the likelihood of interoperability. Russ
_______________________________________________ jose mailing list [email protected] https://www.ietf.org/mailman/listinfo/jose
