From: jose <[email protected]> On Behalf Of Neil Madden
Sent: Friday, September 20, 2019 2:35 AM
To: ivaylo petrov <[email protected]>
Cc: [email protected]; [email protected]
Subject: Re: [jose] 🔔 WGLC of draft-ietf-cose-webauthn-algorithms

 

Thanks, I wasn't aware of this draft. It looks ok, just a few comments from me:

 

secp256k1 is mentioned in the context of signatures and the new ES256K JWS 
algorithm, but when it is registered in the JOSE Elliptic Curve registry it 
will also be usable for ECDH-ES encryption. The current draft mentions JOSE but 
only links to RFC 7515 (JWS). Is the intention that the curve be only used for 
signatures, or is it also intended for encryption?

 

[JLS] That is an interesting question.  Right now I would say that it is only 
for signatures, but it could be expanded to key agreement quite easily.  Is 
there any need for it or are you just speculating?  The big use I know of is 
bit coin which is only signatures and WebAuthn which is only signatures.

 

I'm glad RS1 is not being registered for JOSE, although I'm still a bit 
surprised that it is being registered (even as deprecated) for a standard as 
new as COSE. I can't find any justification in the linked WebAuthn or CTAP 
specs for why this algorithm needs to exist at all. Section 5.3 says that it 
needs to be registered because some WebAuthn TPM attestations use it, but the 
very same section says that the algorithm MUST NOT be used by COSE 
implementations (is a WebAuthn implementation not a COSE implementation?). If 
the normative language in the spec is obeyed then the algorithm will never be 
used and so the registered identifier isn't needed.

 

[JLS] For better or for worse, RS1 is already registered for JOSE, so that is 
the reason it is not registered here.  

 

-- Neil





On 19 Sep 2019, at 16:40, ivaylo petrov <[email protected] <mailto:[email protected]> 
> wrote:

 

Dear JOSE WG,

 

As was suggested (thank you Jim), I am forwarding you this message about the 
COSE WGLC on draft-ietf-cose-webauthn-algorithms [1] as it has actions on "JSON 
Web Signature and Encryption Algorithms" and "JSON Web Key Elliptic Curve" 
registries.

 

The working group last call will end on October 1, 2019.

Please review and send any comments or feedback to the COSE working group. Even 
if your feedback is "this is ready", please let us know.

Thank you,

- Matthew and Ivaylo

COSE Chairs

[1]: https://datatracker.ietf.org/doc/draft-ietf-cose-webauthn-algorithms/

 

 

On Tue, Sep 17, 2019 at 4:31 PM ivaylo petrov <[email protected] 
<mailto:[email protected]> > wrote:

Dear all,

This message starts the Working Group Last Call on the 
draft-ietf-cose-webauthn-algorithms [1].

The working group last call will run for **two weeks**, ending on
October 1, 2019.

Please review and send any comments or feedback to the working group. Even if 
your feedback is "this is ready", please let us know.

Thank you,

- Matthew and Ivaylo

COSE Chairs

[1]: https://datatracker.ietf.org/doc/draft-ietf-cose-webauthn-algorithms/

_______________________________________________
jose mailing list
[email protected] <mailto:[email protected]> 
https://www.ietf.org/mailman/listinfo/jose

 

_______________________________________________
jose mailing list
[email protected]
https://www.ietf.org/mailman/listinfo/jose

Reply via email to