There is one serious open issue with COSE-HPKE: https://github.com/cose-wg/draft-ietf-cose-hpke/issues/112. It’s the Recipient_structure, not the headers that MUST be encoded deterministically.
I also think there’s a lot of wording improvement needed in the section on "HPKE Key Encryption Mode”. I’m working on a PR. LL > On Feb 7, 2026, at 8:25 AM, Orie <[email protected]> wrote: > > I believe the JOSE/COSE HPKE documents are ready for wider IETF review. > > Consider this my positive support for both WGLCs, (as an author / implementer) > > OS > > On Tue, Jan 27, 2026 at 12:57 PM Hannes Tschofenig <[email protected] > <mailto:[email protected]>> wrote: >> I have tested my COSE HPKE implementation against Orie's implementation and >> successfully tested HPKE-7 and HPKE-7-KE in all variants (i.e. with and >> without externally provided aad and info). I will test other ciphersuites as >> soon as those algorithm implementations become available. >> >> As an insight from those tests I will update the examples in the draft by >> adding externally provided aad and info. I will do this asap. >> >> Regarding the JOSE HPKE I have tested my implementation against Filip >> Sokan's implementation for HPKE-0, HPKE-1, HPKE-2, HPKE-3 and HPKE-7 worked >> (and the corresponding key encryption modes). I also verified the examples >> in the draft. >> >> In a nutshell: I believe the documents are in good shape. >> >> Ciao >> Hannes >> >> Am 27.01.2026 um 19:13 schrieb Michael Jones: >>> I believe this specification is ready for publication. It incorporates >>> substantive working group feedback and I believe embodies solid consensus >>> decisions. There are multiple independent interoperable implementations. >>> >>> >>> >>> It is well aligned with the JOSE HPKE specification >>> https://datatracker.ietf.org/doc/draft-ietf-jose-hpke-encrypt/. >>> >>> >>> >>> There are other specifications waiting for this one to finish. >>> >>> >>> >>> Let's get it done! >>> >>> >>> >>> -- Mike >>> >>> >>> >>> From: Ivaylo Petrov <[email protected]> >>> <mailto:[email protected]> >>> Sent: Wednesday, January 21, 2026 12:14 PM >>> To: cose <[email protected]> <mailto:[email protected]>; Cose Chairs Wg >>> <[email protected]> <mailto:[email protected]>; >>> [email protected] <mailto:[email protected]> >>> Cc: [email protected] <mailto:[email protected]> >>> Subject: WGLC: draft-ietf-cose-hpke-20 (Ends 2026-02-11) >>> >>> >>> >>> Dear COSE WG members, >>> >>> This message starts a WG Last Call (WGLC) for: >>> https://datatracker.ietf.org/doc/draft-ietf-cose-hpke/ >>> >>> Please review and indicate your support or objection to proceeding with the >>> publication of this document by replying to this email keeping >>> [email protected] <mailto:[email protected]> >>> in copy. Please provide rationale for support and explanations or >>> suggestions >>> for objections. >>> >>> Please note there is a parallel call going on in JOSE working group for the >>> document: >>> https://datatracker.ietf.org/doc/draft-ietf-jose-hpke-encrypt/ >>> >>> Please consider reviewing both documents. >>> >>> This Working Group Last Call ends on 2026-02-11 >>> >>> >>> Thank you, >>> >>> -- Mike and >>> Ivo >>> >>> COSE >>> co-chairs >>> >>> >>> Please note: >>> Authors, and WG participants in general, are reminded of the Intellectual >>> Property Rights (IPR) disclosure obligations described in BCP 79 [1]. >>> Appropriate IPR disclosures required for full conformance with the >>> provisions >>> of BCP 78 [1] and BCP 79 [2] must be filed, if you are aware of any. >>> Sanctions available for application to violators of IETF IPR Policy can be >>> found at [3]. >>> >>> [1] https://datatracker.ietf.org/doc/bcp78/ >>> [2] https://datatracker.ietf.org/doc/bcp79/ >>> [3] https://datatracker.ietf.org/doc/rfc6701/ >>> >>> >>> >>> _______________________________________________ >>> COSE mailing list -- [email protected] <mailto:[email protected]> >>> To unsubscribe send an email to [email protected] >>> <mailto:[email protected]>
_______________________________________________ jose mailing list -- [email protected] To unsubscribe send an email to [email protected]
