[COSE] Consensus Call: RSA 1.5

Justin Richer <jricher@MIT.EDU> Sat, 07 November 2015 08:02 UTC

Return-Path: <jricher@mit.edu>
X-Original-To: cose@ietfa.amsl.com
Delivered-To: cose@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 165BF1A8A12 for <cose@ietfa.amsl.com>; Sat, 7 Nov 2015 00:02:29 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -4.211
X-Spam-Level:
X-Spam-Status: No, score=-4.211 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, RCVD_IN_DNSWL_MED=-2.3, SPF_PASS=-0.001, T_RP_MATCHES_RCVD=-0.01] autolearn=ham
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id JLtEJDyZERHx for <cose@ietfa.amsl.com>; Sat, 7 Nov 2015 00:02:28 -0800 (PST)
Received: from dmz-mailsec-scanner-7.mit.edu (dmz-mailsec-scanner-7.mit.edu [18.7.68.36]) (using TLSv1 with cipher DHE-RSA-AES256-SHA (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id E09B51A8953 for <cose@ietf.org>; Sat, 7 Nov 2015 00:02:27 -0800 (PST)
X-AuditID: 12074424-f79216d00000156e-83-563db01246ec
Received: from mailhub-auth-3.mit.edu ( [18.9.21.43]) (using TLS with cipher DHE-RSA-AES256-SHA (256/256 bits)) (Client did not present a certificate) by dmz-mailsec-scanner-7.mit.edu (Symantec Messaging Gateway) with SMTP id 97.F4.05486.210BD365; Sat, 7 Nov 2015 03:02:26 -0500 (EST)
Received: from outgoing.mit.edu (outgoing-auth-1.mit.edu [18.9.28.11]) by mailhub-auth-3.mit.edu (8.13.8/8.9.2) with ESMTP id tA782Q3V021880 for <cose@ietf.org>; Sat, 7 Nov 2015 03:02:26 -0500
Received: from [10.21.87.89] ([210.164.9.12]) (authenticated bits=0) (User authenticated as jricher@ATHENA.MIT.EDU) by outgoing.mit.edu (8.13.8/8.12.4) with ESMTP id tA781tmw002081 (version=TLSv1/SSLv3 cipher=DHE-RSA-AES256-SHA bits=256 verify=NOT) for <cose@ietf.org>; Sat, 7 Nov 2015 03:02:25 -0500
From: Justin Richer <jricher@MIT.EDU>
Content-Type: text/plain; charset="utf-8"
Content-Transfer-Encoding: quoted-printable
Message-Id: <D4508FC8-FD8C-4389-BE70-6775E7A1B635@mit.edu>
Date: Sat, 07 Nov 2015 17:01:58 +0900
To: cose@ietf.org
Mime-Version: 1.0 (Mac OS X Mail 8.2 \(2104\))
X-Mailer: Apple Mail (2.2104)
X-Brightmail-Tracker: H4sIAAAAAAAAA+NgFjrBIsWRmVeSWpSXmKPExsUixCmqrSu0wTbM4NtkE4tpW6eyOjB6LFny kymAMYrLJiU1J7MstUjfLoEr48Orq0wF3zgrDlz2b2D8wN7FyMkhIWAisaptBjOELSZx4d56 ti5GLg4hgcVMErtfPYRyjjBK/F9/kgWkSkhgL5PEy4f+IDabgKrE/JW3mEBsZgF1iT/zLjFD 2NoSyxa+BrOFBRQknsw/D7aNV8BKYteqJWwgNouAisTaDyD1HBwiAoISdzvNIUr0JF7duswK cZCsxO7fj5gmMPLNQrJhFpINs5C0LGBkXsUom5JbpZubmJlTnJqsW5ycmJeXWqRrrpebWaKX mlK6iREUYOwuKjsYmw8pHWIU4GBU4uHd8MMmTIg1say4MvcQoyQHk5Iob0mMbZgQX1J+SmVG YnFGfFFpTmrxIUYJDmYlEV6J1UA53pTEyqrUonyYlDQHi5I476YffCFCAumJJanZqakFqUUw WRkODiUJ3lPrgBoFi1LTUyvSMnNKENJMHJwgw3mAhgetBxleXJCYW5yZDpE/xagoJc67CKRZ ACSRUZoH1wtKAJeWcPK8YhQHekWYlwmknQeYPOC6XwENZgIa7BBlAzK4JBEhJdXAaPKkRL3Q hcFD3y5tl/q3Ro3jq+90mcsejd32buuyB2IT8s8nvZ5y4vXj2N5tz5/ME52d5LwxVEcj7KHz 58O6aczz5iXUWJyfdeDdo/MrNwS8NJNLiuM+6X3vmmgLv0jF/O6YI7If/zSt3KDe8FV52/eZ cvYZV66vn8EkMK37krFo8vIw+0lJxUosxRmJhlrMRcWJAFeEN3XbAgAA
Archived-At: <http://mailarchive.ietf.org/arch/msg/cose/WhVZKJSNqhZfkZgHzofDsmXG8fc>
Subject: [COSE] Consensus Call: RSA 1.5
X-BeenThere: cose@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: CBOR Object Signing and Encryption <cose.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/cose>, <mailto:cose-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/cose/>
List-Post: <mailto:cose@ietf.org>
List-Help: <mailto:cose-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/cose>, <mailto:cose-request@ietf.org?subject=subscribe>
X-List-Received-Date: Sat, 07 Nov 2015 08:02:29 -0000

At the Yokohama meeting, the chairs agreed to do a consensus call regarding the definition of RSA 1.5 algorithms within the messages draft or an auxiliary draft. This functionality is analogous to the RS* series of signature methods in JWS and the RSA1_5 encryption method in JWE. The five positions we are asking the working group to consider and voice their support for are:

A) Drop all support for RSA 1.5 signatures and encryption.
B) Define RSA 1.5 support in an auxiliary draft.
C) Define RSA 1.5 support in the main draft (note that this option was previously discussed on the list and did not find favor at the time, so if you want it back you’ll need to make a strong case).
D) You need more information to decide.
E) You don’t give a flying rat about RSA 1.5.*

Note that this is distinct from RSA PSS support which is being discussed in a separate thread.

The consensus call will remain open for two weeks from today, closing on November 21, 2015; at which time, hopefully we will have a clear answer and direction for our editor.

Thank you,
 — Justin & Kepeng, your COSE chairs

* I promised those in the room at Yokohama to offer a flying rat option, for which I am deeply sorry.