Re: [COSE] Éric Vyncke's No Objection on draft-ietf-cose-cwt-claims-in-headers-09: (with COMMENT)

Michael Jones <michael_b_jones@hotmail.com> Tue, 28 November 2023 21:36 UTC

Return-Path: <michael_b_jones@hotmail.com>
X-Original-To: cose@ietfa.amsl.com
Delivered-To: cose@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 4465EC151527; Tue, 28 Nov 2023 13:36:20 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.233
X-Spam-Level:
X-Spam-Status: No, score=-1.233 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, FORGED_HOTMAIL_RCVD2=0.874, FREEMAIL_FROM=0.001, RCVD_IN_MSPIKE_H2=-0.001, RCVD_IN_ZEN_BLOCKED_OPENDNS=0.001, SPF_PASS=-0.001, T_SCC_BODY_TEXT_LINE=-0.01, URIBL_BLOCKED=0.001, URIBL_DBL_BLOCKED_OPENDNS=0.001, URIBL_ZEN_BLOCKED_OPENDNS=0.001] autolearn=no autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (2048-bit key) header.d=hotmail.com
Received: from mail.ietf.org ([50.223.129.194]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id H3LlIxUcJW1C; Tue, 28 Nov 2023 13:36:16 -0800 (PST)
Received: from NAM10-DM6-obe.outbound.protection.outlook.com (mail-dm6nam10olkn2012.outbound.protection.outlook.com [40.92.41.12]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 1732DC151081; Tue, 28 Nov 2023 13:36:13 -0800 (PST)
ARC-Seal: i=1; a=rsa-sha256; s=arcselector9901; d=microsoft.com; cv=none; b=MGvlK3C5RWFkZItC4kzsVYiw/xHYCRUQ4bEwcAB8jsNg6CGodGSwveyWqp5w77rsOObb4dYrKMfM9R+w/uq09uOBmhQN2d9XSTl3AtcK3+6kNbrrYbRz2CJF1bF+H7LWfTiP5RMhn6R3jkSr4otdqHNHRy9SwMPn5Op27kE2pCowiphiKuVRACnKJF7tCxk+I4tkZKQjKzzlcFwGFROBJkBR2f8Unzqmf1BXWNFuzeJIdXN313ogSjmPdzEqEjvhHfH/+sYMtP52d2g8J+RPcTNO4sNPhB6uspEoEEJzl4LruIHG+TqNo0QxDx6lCIHqtQq/6zMTN7dsUf7pQXBdIQ==
ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=microsoft.com; s=arcselector9901; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-AntiSpam-MessageData-ChunkCount:X-MS-Exchange-AntiSpam-MessageData-0:X-MS-Exchange-AntiSpam-MessageData-1; bh=HyxZrap1jSUpWY1I5Q6Atq55BuA7OKUV89h4rLne4nk=; b=Ny+rVFIsWmmqq0Dl9AwcdRDwcINe0ys3ea3TTo6oKEOH0r1JPOOi27b1CG0RfcYIdinxKFtSnhYcNej0dUC6HcoAiQ68phOQlPpx5NuF+tc2mvudhmk+QLwevUcLfgym994w+s/vvlelaBN9o4GWfgaKVroDauq6axMwGM7qg0rGGY8Q9SFXVCat0MNw8P8vTVWbQZCZAuNxAxa5/UOvfJkLmLOESmjI5bvwiN5I5biPA2FqGzuj1R+EmACD3Z2NRaZdLDDcLBs/UqhmDicfRCZTi/YAM88tdkda2qD6RItoQPIwUTbYXhj0PxB2n4NVy32ITQZwUUR9FECdHGBCgw==
ARC-Authentication-Results: i=1; mx.microsoft.com 1; spf=none; dmarc=none; dkim=none; arc=none
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=hotmail.com; s=selector1; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-SenderADCheck; bh=HyxZrap1jSUpWY1I5Q6Atq55BuA7OKUV89h4rLne4nk=; b=oeIZq+v2UKTOJlW7bqlqJccejfV4uzfla0/O40RDcHCI5X9sWuU7+Y4T6c6JSgiL51iPTdZXJXRSnme0uV7Y/zVYfdMtoIx0QIj18kCB64Jjt8xOrRmgCs1zekl6BNGPyRIUpixj2LRtiK2m8FVHmQgZ1NHL8f1S+9P5LEXup6WXjy6lKvYEMjrLksetmA9crpGB9bwip2Qrfsy7agwXw3DwPZ9pA+1O1hAJDSgHsoOCiuxSM4QtPHoRWCD/vwnI/eg0NbKiRJIb5P8jEuKjy7yf7CpIvHWiw9tEFvDtbYDCqvFBJJUqJrcHNRcEGrQea3/uBJOdAiVl8UXdtLZa8g==
Received: from SJ0PR02MB7439.namprd02.prod.outlook.com (2603:10b6:a03:295::14) by CY8PR02MB9544.namprd02.prod.outlook.com (2603:10b6:930:76::6) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.20.7025.29; Tue, 28 Nov 2023 21:36:11 +0000
Received: from SJ0PR02MB7439.namprd02.prod.outlook.com ([fe80::38a6:2b20:d72f:21cb]) by SJ0PR02MB7439.namprd02.prod.outlook.com ([fe80::38a6:2b20:d72f:21cb%7]) with mapi id 15.20.7025.021; Tue, 28 Nov 2023 21:36:11 +0000
From: Michael Jones <michael_b_jones@hotmail.com>
To: Éric Vyncke <evyncke@cisco.com>, The IESG <iesg@ietf.org>
CC: "draft-ietf-cose-cwt-claims-in-headers@ietf.org" <draft-ietf-cose-cwt-claims-in-headers@ietf.org>, "cose-chairs@ietf.org" <cose-chairs@ietf.org>, "cose@ietf.org" <cose@ietf.org>, "mprorock@mesur.io" <mprorock@mesur.io>, "orie@transmute.industries" <orie@transmute.industries>, "Hannes.Tschofenig@gmx.net" <Hannes.Tschofenig@gmx.net>
Thread-Topic: Éric Vyncke's No Objection on draft-ietf-cose-cwt-claims-in-headers-09: (with COMMENT)
Thread-Index: AQHaIRm689eqBVitsUSR/urNVRbx+rCQPREw
Date: Tue, 28 Nov 2023 21:36:11 +0000
Message-ID: <SJ0PR02MB7439576F3E3CA2042225DA5DB7BCA@SJ0PR02MB7439.namprd02.prod.outlook.com>
References: <170107973192.33027.13442282570620667585@ietfa.amsl.com>
In-Reply-To: <170107973192.33027.13442282570620667585@ietfa.amsl.com>
Accept-Language: en-US
Content-Language: en-US
X-MS-Has-Attach:
X-MS-TNEF-Correlator:
x-tmn: [LOOUnlQ6eZlW0DZEvtTVCR2TRCfSIh6XjphoWcydoC/1NdyPzEcVMigwQEeJVAGj]
x-ms-publictraffictype: Email
x-ms-traffictypediagnostic: SJ0PR02MB7439:EE_|CY8PR02MB9544:EE_
x-ms-office365-filtering-correlation-id: 9fd2a7a7-57d4-41d3-78d9-08dbf05a0a48
x-microsoft-antispam: BCL:0;
x-microsoft-antispam-message-info: zsV/nEiVD5qKiFxkbMn+tmWNxtP4BWfYdCxcJiRRwtkJO5UMIxusYiYWiDdQIvDJXX/tauk/Pmfe+a9vsR9Yf3jn8Cx/+KK15oFD9lU0gipFEIEuN6pGTjfMW2pTil0FYa0KALnpFfGHnidd01NGtsB44MI1db9Rra/dcl5SFmyAKgK+OK3OoMQw121wawm0TWhN+XTOBGa3PGp22lmWcZFGgFGpdhler3TJhPsnKnAz+wwqffiWFxQR+CYxfWuyvEIWjTtsQtcP8RFdC8FpdCiMQ68ymssgtiVfTv6nHekkrjXIpk4BXSgIxQv+zI3jgKlMm76oNREnnR/CyU09V8FW1iD4LmbIRgb8G2Km50SGdeBU0ICLYv8+pWTvO5eeTfe0BJreAHahYgN/6IlSVVaKFzRrRDzuRBxkbnwrzuaKvELWS9Th1h2qq2hkaIFc/T1Pxy5MJu9l2+AVkVm7JDEjrrrho1G4Hos4lXTweYxterti9vYXFCiiBfTE4CtZ+SeR4bne04+Ok0AJoC/DsYaN4cBTQVV1WeIcEN/mTucg/RMivIOfjDdKTy81SIK8tCWzHKpexruCTu/NXeEpi5PBgt8LMH54ZUVwX9hHKgXM57L+82FBT1hzXPzzlAMtAjwA3fE6nZEjvo+JiF+2tA==
x-ms-exchange-antispam-messagedata-chunkcount: 1
x-ms-exchange-antispam-messagedata-0: ijUCNPapL2XTqufH3fQkNPzaZtAOCtYqJTBjluUM39yHovoIqF3R+sKTWBA5bXhc1Uk6agRmTNoXCcuUzCBWr1w2ag+Pbh0ujeQakCsxESJedgbrVDnquNeWvUQNbPwnM2tXAAjzFTlMYJyrH/nY98hCYVomuvcpPpU2FD/lPzkrGyjcwCwkJze35aBG9Q7vwRtBvuGhBHWMpMWdgPWMz+my4ELyOhlwzM2wnPbOHAI9U+gJhlW4SEponB9tZ2ijN01aPVDIG0NKozfGl4TNA5a5FxdRhGKPaU2HL06j8dhgPIe9Dyf8eJ4Pt2wFU/O/H8MHjcmIITb2OLAmjNKXc3xYA8++w4W9x7DC90IaXmEAxTrF4ycEC4J2XDe5yH6e1/C/xwQU1hUuUHAFjEFqA3PpBRPYD6BuepHIPwmFXSVDhT6TV53zP7zFvd+E3rgETs+uSUMzOtaJNzYZXaSCW9U32/NHYm7DHBKImlyT58bLKuCUUOQxZVhRNuPnQSk1KflVcIRXNAdi65Vaof+tfQVqaQgcJDKjIJh3LKhPkpF9/GYUVwWXDh0Anxn+aMahJVt47RWCQ0BZOKmzQ8D/Y+jtStS1YXJBB1/gnhBuLut8SFyhO5141BQSohxz5tTLkksbUeNM/Cv8PP4MVNNtSoDFRk8eiJHQyP1WHDTOYzpWi2fQhmjMxsSkJB+2vEpqATPeArOr/G/lz9/I6vl3PukJiXYMRNSJLHPdgkGoz90HXQdGqXJ5MJ9HC6taZySjf1XQ3bFis9xZWOleSuqjKsdZdIJIrrCMNasgCGpTBvzcg4jxIPEdKbkSfofNkJzvCPazcLL+CzT0Sbg5cM+D7QJ6qDlIsOL1BnAi8bcNoGOv2Cos9RVdrmaR5PL2RZR02FkXRHBz/nElP2GEy0OapvvAIO72cp4sum79H6cT8S1gbYvVnTySNRtqYgzwUk+qF3Qqb/rpsnr+r5Rjg9aJhT+qy2SaT+XiXKZxiwwLi0vXNSWjL7e5wrMMigEkLczhPS8ODWp5USfY08kk5m240qyXBsqETFIkolEKtsw6G3zUvWArrB5qWuL3S4wvnPjJ31yNSqW+TmSa804GBCN+xUknmvSLNbACnXkJVu3JgqNoxllhqGa9tZPcGNk5isIeqTPn5mtAstWxIk73zZndMj2VAzhUYyFb7qcN5TLhoSqHhrxne8a9Qwvh9vEl4VERyr63ejtSXex8Hzfhpo/qrApQCI+aap9EPty2eP2nhL6AwcBL77o5VTFgj88evTBfuvBHfenIKv6Jschb4oRkOQ==
Content-Type: text/plain; charset="iso-8859-1"
Content-Transfer-Encoding: quoted-printable
MIME-Version: 1.0
X-OriginatorOrg: sct-15-20-4755-11-msonline-outlook-3d941.templateTenant
X-MS-Exchange-CrossTenant-AuthAs: Internal
X-MS-Exchange-CrossTenant-AuthSource: SJ0PR02MB7439.namprd02.prod.outlook.com
X-MS-Exchange-CrossTenant-RMS-PersistedConsumerOrg: 00000000-0000-0000-0000-000000000000
X-MS-Exchange-CrossTenant-Network-Message-Id: 9fd2a7a7-57d4-41d3-78d9-08dbf05a0a48
X-MS-Exchange-CrossTenant-rms-persistedconsumerorg: 00000000-0000-0000-0000-000000000000
X-MS-Exchange-CrossTenant-originalarrivaltime: 28 Nov 2023 21:36:11.3009 (UTC)
X-MS-Exchange-CrossTenant-fromentityheader: Hosted
X-MS-Exchange-CrossTenant-id: 84df9e7f-e9f6-40af-b435-aaaaaaaaaaaa
X-MS-Exchange-Transport-CrossTenantHeadersStamped: CY8PR02MB9544
Archived-At: <https://mailarchive.ietf.org/arch/msg/cose/e7tI8WN4fSCDv9QIduBqUwc6sWc>
Subject: Re: [COSE] Éric Vyncke's No Objection on draft-ietf-cose-cwt-claims-in-headers-09: (with COMMENT)
X-BeenThere: cose@ietf.org
X-Mailman-Version: 2.1.39
Precedence: list
List-Id: CBOR Object Signing and Encryption <cose.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/cose>, <mailto:cose-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/cose/>
List-Post: <mailto:cose@ietf.org>
List-Help: <mailto:cose-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/cose>, <mailto:cose-request@ietf.org?subject=subscribe>
X-List-Received-Date: Tue, 28 Nov 2023 21:36:20 -0000

Thanks Éric.

The "should" you're referring to is in the Privacy Considerations section.  I've generally followed the convention that RFC 2119 language is only used to impose normative requirements in the main body of the specification and not in the Privacy Considerations or Security Considerations, which are just that: things to consider - not normative requirements.

That said, I'd consider arguments for changing the text if you find my reasoning to be flawed.

                                Best wishes,
                                -- Mike

-----Original Message-----
From: Éric Vyncke via Datatracker <noreply@ietf.org>
Sent: Monday, November 27, 2023 2:09 AM
To: The IESG <iesg@ietf.org>
Cc: draft-ietf-cose-cwt-claims-in-headers@ietf.org; cose-chairs@ietf.org; cose@ietf.org; mprorock@mesur.io; orie@transmute.industries; orie@transmute.industries; Hannes.Tschofenig@gmx.net
Subject: Éric Vyncke's No Objection on draft-ietf-cose-cwt-claims-in-headers-09: (with COMMENT)

Éric Vyncke has entered the following ballot position for
draft-ietf-cose-cwt-claims-in-headers-09: No Objection

When responding, please keep the subject line intact and reply to all email addresses included in the To and CC lines. (Feel free to cut this introductory paragraph, however.)


Please refer to https://www.ietf.org/about/groups/iesg/statements/handling-ballot-positions/
for more information about how to handle DISCUSS and COMMENT positions.


The document, along with other ballot positions, can be found here:
https://datatracker.ietf.org/doc/draft-ietf-cose-cwt-claims-in-headers/



----------------------------------------------------------------------
COMMENT:
----------------------------------------------------------------------

# Éric Vyncke, INT AD, comments for draft-ietf-cose-cwt-claims-in-headers-09

Thank you for the work put into this document.

Please find below one non-blocking COMMENT points.

Special thanks to Orie Steele for the shepherd's detailed write-up including
the WG consensus *but it lacks* the justification of the intended status.

Other thanks to Hannes Tschofenig, the IoT directorate reviewer (at my
request), please consider this int-dir review:
https://datatracker.ietf.org/doc/review-ietf-cose-cwt-claims-in-headers-07-iotdir-telechat-tschofenig-2023-10-31/
(and I have read the email discussions with the authors, thanks to all)

I hope that this review helps to improve the document,

Regards,

-éric

# COMMENTS (non-blocking)

## Section 3

Is there a reason for using a non-normative "should" in `applications and
protocols using them *should* ensure that these COSE objects are only made
visible` ?