Re: [COSE] tstr values for kty, alg, crv, etc.

AJITOMI Daisuke <ajitomi@gmail.com> Sun, 08 August 2021 08:13 UTC

Return-Path: <ajitomi@gmail.com>
X-Original-To: cose@ietfa.amsl.com
Delivered-To: cose@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id C2C423A20C1 for <cose@ietfa.amsl.com>; Sun, 8 Aug 2021 01:13:29 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.097
X-Spam-Level:
X-Spam-Status: No, score=-2.097 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, FREEMAIL_FROM=0.001, HTML_MESSAGE=0.001, SPF_HELO_NONE=0.001, SPF_PASS=-0.001, URIBL_BLOCKED=0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (2048-bit key) header.d=gmail.com
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id 0vLalNLd4ZTm for <cose@ietfa.amsl.com>; Sun, 8 Aug 2021 01:13:25 -0700 (PDT)
Received: from mail-io1-xd34.google.com (mail-io1-xd34.google.com [IPv6:2607:f8b0:4864:20::d34]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id E14C13A20BF for <cose@ietf.org>; Sun, 8 Aug 2021 01:13:24 -0700 (PDT)
Received: by mail-io1-xd34.google.com with SMTP id x10so11006727iop.13 for <cose@ietf.org>; Sun, 08 Aug 2021 01:13:24 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20161025; h=mime-version:references:in-reply-to:from:date:message-id:subject:to :cc; bh=rc8K4uu0QnksYYb06r8mYgpsxoDx+A1//tyD6O7ucI0=; b=cmAcCMRoYworly7l2PWl2mm6DUWAlxz5zfVd+Feo9Av9afFJ+wo1thbtiFCf0YDaAB vKt/dlNrszV00NdEPTh31nNOpBmcEUHFtC6BF73rJXwVlZEdzuRGY2lysqYJEwCjc4So Vrvq9xbE7O2DCsptbAWInIWtzJQEK/uBy1Lex9/wjMOrZtlx9JRS76ORdhWSDmeFpAgf Hm/lFRHjUhiFFKZUCQyPvZqZQccNN+e3uhI7/wKQrIs3J+Pe+rGxOXqa5tkZobrBJ220 ZSDijKvCu/6sSaJXpS3VfHDWmbApKA+zbY3elwGPHUIu0iuLMecCy78T+r55DkKqU14e Nu1A==
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20161025; h=x-gm-message-state:mime-version:references:in-reply-to:from:date :message-id:subject:to:cc; bh=rc8K4uu0QnksYYb06r8mYgpsxoDx+A1//tyD6O7ucI0=; b=e8CBZAOD6ESzJfKW1kfH9j9fDCcE0dCrToA7huSSqW9VXHGQZAgDPXzT8v+ohBV2fq ZfOdjhQJY4oQkq/Uguhi/fjezMUOG6EnYwTS5PEuUOCkLNIwgYnc+EONZafVCJX7N8KM DDTRGJga95SnMpCaMd8M/5B+0hYEtDqq8uzvCBwqUfRh3jV0ekE8KDJO/qj1AsEdJeki Bvqh6/X8mydnFLMYkmS21w2m3WWa/vZc6g4Ab7R2PPuymEofWaqWxkBcyRecbr0n0Isk 0kU8yQn7AeKXC8HZtwsukEYyzeVFZlgTyxgpTx5YM95YPy+czNu4pQb1INcqoyM5ykE6 k3oQ==
X-Gm-Message-State: AOAM530rCU39v5kpSZP0fpGICaS2OIDcfWc6GAR8S3ZU+f2B0mhY1lGY ws7DZVZkJily8KXOe5qemb5IK6UsdXTfL9VfpQ==
X-Google-Smtp-Source: ABdhPJy0ivlHIUA/5AWaasWIvT+yj+mwLYaTI4YPWRJhuzHZBm7HAWv0bDw7UA6029R0b+9a+IDI3Z9ElAl3PXpYXfI=
X-Received: by 2002:a92:d3d1:: with SMTP id c17mr571919ilh.86.1628410402950; Sun, 08 Aug 2021 01:13:22 -0700 (PDT)
MIME-Version: 1.0
References: <CAFWvErVLfud5ffyzKdBJmzm7Wj+=osfZ0u7tKVpniicZDYqjxg@mail.gmail.com> <815DB7E9-555A-4A7D-B3DE-CC807DE3A222@tzi.org> <41E79CBD-04D1-4C0F-BEE3-4F63780D514E@island-resort.com> <CAFWvErWfSkzHGwLaP0t7RsufgkMiryrHkp4zWoVsRGR718Dqow@mail.gmail.com> <313B433A-ACCA-4D2E-AA20-53A6CAA4E92A@island-resort.com> <9734.1628378538@localhost>
In-Reply-To: <9734.1628378538@localhost>
From: AJITOMI Daisuke <ajitomi@gmail.com>
Date: Sun, 08 Aug 2021 17:13:10 +0900
Message-ID: <CAFWvErXkR1vVNQFjn+rVCe8jaJ7DspBUq5kVJdGzonBU98Ctbw@mail.gmail.com>
To: Michael Richardson <mcr+ietf@sandelman.ca>, cose@ietf.org
Cc: Laurence Lundblade <lgl@island-resort.com>, Carsten Bormann <cabo@tzi.org>, jodonogh@qti.qualcomm.com
Content-Type: multipart/alternative; boundary="0000000000009dd50c05c907d75a"
Archived-At: <https://mailarchive.ietf.org/arch/msg/cose/DBEnWzuU142zsCsdJkQSTP7o_LA>
Subject: Re: [COSE] tstr values for kty, alg, crv, etc.
X-BeenThere: cose@ietf.org
X-Mailman-Version: 2.1.29
Precedence: list
List-Id: CBOR Object Signing and Encryption <cose.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/cose>, <mailto:cose-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/cose/>
List-Post: <mailto:cose@ietf.org>
List-Help: <mailto:cose-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/cose>, <mailto:cose-request@ietf.org?subject=subscribe>
X-List-Received-Date: Sun, 08 Aug 2021 08:13:30 -0000

> We can deprecate tstr as key.
> We can say that no signer MUST NEVER emit this again.
> We can say that a verifier MAY accept tstr as a key.

This sounds reasonable to me.

Since any tstr labels are not registered in the IANA registry for now and
there are no implementations that support the tstr labels as far as I know,

I think there is room to make the tstr labels deprecated.

Thanks,
Daisuke

2021年8月8日(日) 8:22 Michael Richardson <mcr+ietf@sandelman.ca>:

>
> Laurence Lundblade <lgl@island-resort.com> wrote:
>     > I don’t think tstr can be removed from the standard. That would break
>     > backwards compatibility. Maybe a strong recommendation could be added
>     > with the comment that many implementations don’t support tstr.
>
> Any system built upon COSE that does not support tstr as a key is already
> broken if many implementations don't support it.
>
> We can deprecate tstr as key.
> We can say that no signer MUST NEVER emit this again.
> We can say that a verifier MAY accept tstr as a key.
>
>     > There is a revision of 8152 in process right now called 8152bis. That
>     > seems like the place to do it.
>
> It is pretty late to do this.  8152bis is in AUTH48, we need the
> proxy-author
> and WG chairs to agree to this immediately.
>
> I agree that having two ways things is not a good thing.
>
> --
> Michael Richardson <mcr+IETF@sandelman.ca>   . o O ( IPv6 IøT consulting )
>            Sandelman Software Works Inc, Ottawa and Worldwide
>