I believe some further work in due:

This PR <https://github.com/NeilMadden/jose-deprecate-none-rsa1_5/pull/10>
addresses the following minor finds:

   - `The 'none' algorithm`, `The 'RSA1_5' algorithm`, and `Guidance on
   deprecation` promoted from H2 subsections of the Introduction to top-level
   (H1) sections
   - anchored the `none` section (`{#none}`) and replaced `Sec. 1.1` in
   Security Considerations with `{{none}}` (auto-tracked section number)
   - `{{RFC8017}} (section 7.2)` → `{{Section 7.2 of RFC8017}}`; `Section
   7.1 of {{RFC7518}}` → `{{Section 7.1 of RFC7518}}`
   - `[OpenID.Core]` → `{{OpenID.Core}}` (single brackets don't render)
   - `applictions` → `applications`
   - "currently lists 12" → "At the time of writing it lists 17"

Remaining finds:

   - Inconsistent algorithm-name formatting: `"none"`/`"RSA1_5"` vs. ``
   `none` ``/`` `RSA1_5` ``. Pick one.
   - `{{I-D.irtf-cfrg-rsa-guidance}}` is IRTF/CFRG (Informational, -08, in
   IRSG poll) and targets "any deployments or protocols", "for IETF protocols"
   is slightly off; "for new protocols and deployments" would be more accurate.
   - Lowercase "should" with `bcp14-tagged` enabled is ambiguous;
   capitalize or rephrase per instance
   - "MUST disable support for these algorithms by default" vs. "can
   continue to do so": make the opt-in allowance explicit; tie to RFC 7518
   §3.6 "MUST NOT accept Unsecured JWSs by default"
   - IANA DE Instructions: IND-CCA2 scope too narrow; The `alg` category
   spans key encryption, key wrapping, ECDH-ES, key-agreement+wrap, and `dir`.
   IND-CCA2 fits PKE/KEMs, not all of the others. Scope the criterion to
   key-encryption/KEM `alg`s (and align with the PQ & PQ/T work
   <https://datatracker.ietf.org/doc/draft-ietf-jose-hpke-pq-pqt/>).
   - IANA DE Instructions: There's subtlety in the EUF-CMA one. A MAC is
   not a digital signature, and JOSE is deliberate about that distinction. A
   Designated Expert reading the instruction literally could conclude the
   EUF-CMA bar doesn't apply when someone registers a new MAC.

Furthermore, there are WICG documents being incubated that will do register
a number of "JSON Web Signature and Encryption Algorithms" IANA Registry
"alg" values for JWK Usage only (i.e. they don't define a JWS or JWE
algorithm but allow key representation for Web Cryptography APIs needs) -
those would not be possible with the proposed DE instructions. I recommend
further scoping the updates by Usage Location and stating that JWK-only
registrations stay governed by the general RFC 7518 §7.1 rule.

I offer to submit a PR for these too.

S pozdravem,
*Filip Skokan*


On Wed, 6 May 2026 at 16:30, Karen O'Donoghue via Datatracker <
[email protected]> wrote:

> This message starts a WG Last Call for:
> draft-ietf-jose-deprecate-none-rsa15-04
>
> This Working Group Last Call ends on 2026-05-20
>
> Abstract:
>    This document updates [RFC7518] to deprecate the JWS algorithm "none"
>    and the JWE algorithm "RSA1_5".  These algorithms have known security
>    weaknesses.  It also updates the Review Instructions for Designated
>    Experts to establish baseline security requirements that future
>    algorithm registrations should meet.
>
> Please review and indicate your support or objection to proceed with the
> publication of this document by replying to this email keeping
> [email protected]
> in copy. Objections should be explained and suggestions to resolve them are
> highly appreciated.
>
> Authors, and WG participants in general, are reminded of the Intellectual
> Property Rights (IPR) disclosure obligations described in BCP 79 [1].
> Appropriate IPR disclosures required for full conformance with the
> provisions
> of BCP 78 [1] and BCP 79 [2] must be filed, if you are aware of any.
> Sanctions available for application to violators of IETF IPR Policy can be
> found at [3].
>
> Thank you.
>
> [1] https://datatracker.ietf.org/doc/bcp78/
> [2] https://datatracker.ietf.org/doc/bcp79/
> [3] https://datatracker.ietf.org/doc/rfc6701/
>
> The IETF datatracker status page for this Internet-Draft is:
> https://datatracker.ietf.org/doc/draft-ietf-jose-deprecate-none-rsa15/
>
> There is also an HTML version available at:
>
> https://www.ietf.org/archive/id/draft-ietf-jose-deprecate-none-rsa15-04.html
>
> A diff from the previous version is available at:
>
> https://author-tools.ietf.org/iddiff?url2=draft-ietf-jose-deprecate-none-rsa15-04
>
> _______________________________________________
> jose mailing list -- [email protected]
> To unsubscribe send an email to [email protected]
>
_______________________________________________
jose mailing list -- [email protected]
To unsubscribe send an email to [email protected]

Reply via email to