I'd file a bug against Numbus... Or maybe Vladimir, could you do that?
-- Mike
From: jose [mailto:[email protected]] On Behalf Of Brian Campbell
Sent: Wednesday, February 12, 2014 3:58 PM
To: [email protected]
Subject: [jose] question about the size of coordinate parameters in EC JWKs
Could anyone in this fine WG explain (probably again, I missed it the first
time) the rational behind the text 'The length of this octet string MUST be the
full size of a coordinate for the curve specified in the "crv" parameter.',
which is in the definitions of the X and Y Coordinate parameters for EC keys in
JWA [1]?
This message last month on the list
http://www.ietf.org/mail-archive/web/jose/current/msg03901.html and an off list
message indicate that both the jose4j and Nimbus JOSE+JWT implementations
aren't following spec on the length of the octet string being the full size of
a coordinate for the curve. Which suggests that there maybe potential
interoperability problems with certain EC JWKs.
I'm just trying to wrap my head around the issue so any help in that would be
appreciated.
[1]
http://tools.ietf.org/html/draft-ietf-jose-json-web-algorithms-20#section-6.2
_______________________________________________
jose mailing list
[email protected]
https://www.ietf.org/mailman/listinfo/jose