Re: [COSE] Consensus Call: Adoption of the COSE Token

Ludwig Seitz <ludwig@sics.se> Fri, 13 November 2015 07:39 UTC

Return-Path: <ludwig@sics.se>
X-Original-To: cose@ietfa.amsl.com
Delivered-To: cose@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id AE4171B41AC for <cose@ietfa.amsl.com>; Thu, 12 Nov 2015 23:39:46 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.9
X-Spam-Level:
X-Spam-Status: No, score=-1.9 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1] autolearn=ham
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id GOo92X-52d_y for <cose@ietfa.amsl.com>; Thu, 12 Nov 2015 23:39:45 -0800 (PST)
Received: from mail-lf0-x22d.google.com (mail-lf0-x22d.google.com [IPv6:2a00:1450:4010:c07::22d]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 64CC71B41A9 for <cose@ietf.org>; Thu, 12 Nov 2015 23:39:44 -0800 (PST)
Received: by lffz63 with SMTP id z63so47842929lff.0 for <cose@ietf.org>; Thu, 12 Nov 2015 23:39:42 -0800 (PST)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=sics_se.20150623.gappssmtp.com; s=20150623; h=subject:to:references:from:message-id:date:user-agent:mime-version :in-reply-to:content-type; bh=zVL0HN/UXEdFdlEw7UEQgWGsogAxOjhqV9ATo/qEGCE=; b=sahUvKoCaaiBK+S8abI9sQGzgJGyowmDnAUqzzKkPs0g1Xz2sXExeLMYWUwOgqhLON O5XRl6dVlAl4r42RBWlxrl2TA30KtiDZlGBk9ws6/gjj7TMEwa2ctnRTeG62Olze4Llm XYPTDcT9eTa6xtKIt8Rz3ONFTDFJwY0/KFgQXTAvxqaCyHEvqJ9mfnN69pZNF44oe8Pw ATBNJp8n8cMKc7ZOwg0JthGLHYLljJeKpzNOmHqduANFBI8lKFEZgG/+f84Mw7+I44Gk xIf3OP9IoAH11McUrTb/jmo6lInydZC3p5KnMMcPt4rTC98/tHPUDJ/H40hmjkenbun7 F08Q==
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20130820; h=x-gm-message-state:subject:to:references:from:message-id:date :user-agent:mime-version:in-reply-to:content-type; bh=zVL0HN/UXEdFdlEw7UEQgWGsogAxOjhqV9ATo/qEGCE=; b=CjNlUoJnEcLYbKVRIEedXN+qeuJV5LmFPppyp4N9QtrBy8+T4fvAm5+0J94M8GJH6B 8iIzGgicsJzcBS4I1daBciLccDOwnCDVr815BGAr/5Dx5LAQ0F/ysUIKnR6aZxiPDJjZ HAsf3pkIVDOK67jsTwCLj5skKXq//YeMD9z83n89AQ+BDdvIge/0buvoEVmVIEru+MJV Z2TJwBCc3gU08jj4Ac3u/UvcoVM3RrBw8pe0aN2I8S2jutEQ+FDjYCVQMDTKD6QW0pIe zjwKk5lPxs7bf3YGttX+dTwjskjCMPjVLKySqzaam5bkJvffw6MZs6TeLhWUupv1givv aFuQ==
X-Gm-Message-State: ALoCoQnE/tDGrd2tm0y5Ge/l2iAJykoAT3oy0s1GRY6XQHPBvhAeDMV2dimGL+wz69sTMPDtN33p
X-Received: by 10.25.79.17 with SMTP id d17mr9200856lfb.40.1447400382488; Thu, 12 Nov 2015 23:39:42 -0800 (PST)
Received: from [192.168.0.108] ([85.235.10.186]) by smtp.gmail.com with ESMTPSA id l5sm2855533lbc.36.2015.11.12.23.39.41 for <cose@ietf.org> (version=TLSv1.2 cipher=ECDHE-RSA-AES128-GCM-SHA256 bits=128/128); Thu, 12 Nov 2015 23:39:41 -0800 (PST)
To: cose@ietf.org
References: <B163C432-E13C-4D35-B86B-066C1365232A@mit.edu>
From: Ludwig Seitz <ludwig@sics.se>
Message-ID: <564593B5.6060403@sics.se>
Date: Fri, 13 Nov 2015 08:39:33 +0100
User-Agent: Mozilla/5.0 (X11; Linux x86_64; rv:38.0) Gecko/20100101 Thunderbird/38.3.0
MIME-Version: 1.0
In-Reply-To: <B163C432-E13C-4D35-B86B-066C1365232A@mit.edu>
Content-Type: multipart/signed; protocol="application/pkcs7-signature"; micalg="sha-256"; boundary="------------ms050308090901030008080407"
Archived-At: <http://mailarchive.ietf.org/arch/msg/cose/29ttdnmFFaW1SK2FlOqV5rCkO7w>
Subject: Re: [COSE] Consensus Call: Adoption of the COSE Token
X-BeenThere: cose@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: CBOR Object Signing and Encryption <cose.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/cose>, <mailto:cose-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/cose/>
List-Post: <mailto:cose@ietf.org>
List-Help: <mailto:cose-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/cose>, <mailto:cose-request@ietf.org?subject=subscribe>
X-List-Received-Date: Fri, 13 Nov 2015 07:39:46 -0000

On 2015-11-07 09:01, Justin Richer wrote:
> At the Yokohama meeting, the chairs agreed to do a consensus call
> regarding the adoption and placement of new work to define a COSE
> Token, analogous to the JWT from JOSE. In the room, there was a
> general sentiment of support for the work being done, with the wide
> adoption of JWT and its driving of JOSE being a common theme of
> precedent. What wasn’t clear is where the work should be done and to
> what end it should drive. The six positions we are asking the working
> group to consider and voice their support for are:

> A) Define the COSE Token within the COSE working group along side the COSE Messages (and potentially COSE Auxiliary Algorithms) draft.
> B) Define the COSE Token inside the OAuth working group.
> C) Define the COSE Token inside the ACE working group.
> D) Don’t define the COSE Token anywhere.
> E) You need more information to decide.
> F) You don’t give a flying rat about the COSE Token.*
>


C)

Both A) and B) would require rechartering, I believe we can get away 
with the CWT in C) without rechartering.

I think we need to have both ACE and OAuth expertise on this. 
Furthermore we need to integrate this with the other ACE work, which is 
why I think C) is the right choice.

/Ludwig

-- 
Ludwig Seitz, PhD
SICS Swedish ICT AB
Ideon Science Park
Building Beta 2
Scheelevägen 17
SE-223 70 Lund

Phone +46(0)70-349 92 51
http://www.sics.se