Re: [COSE] [jose] Call for Adoption: draft-jones-jose-fully-specified-algorithms

Orie Steele <orie@transmute.industries> Mon, 08 January 2024 14:52 UTC

Return-Path: <orie@transmute.industries>
X-Original-To: cose@ietfa.amsl.com
Delivered-To: cose@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 8816BC151080 for <cose@ietfa.amsl.com>; Mon, 8 Jan 2024 06:52:06 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.085
X-Spam-Level:
X-Spam-Status: No, score=-2.085 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, HTML_MESSAGE=0.001, RCVD_IN_DNSWL_NONE=-0.0001, RCVD_IN_ZEN_BLOCKED_OPENDNS=0.001, SPF_HELO_NONE=0.001, SPF_PASS=-0.001, T_KAM_HTML_FONT_INVALID=0.01, T_REMOTE_IMAGE=0.01, T_SCC_BODY_TEXT_LINE=-0.01, URIBL_BLOCKED=0.001, URIBL_DBL_BLOCKED_OPENDNS=0.001, URIBL_ZEN_BLOCKED_OPENDNS=0.001] autolearn=unavailable autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (2048-bit key) header.d=transmute.industries
Received: from mail.ietf.org ([50.223.129.194]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id qj1fWmGKik4X for <cose@ietfa.amsl.com>; Mon, 8 Jan 2024 06:52:02 -0800 (PST)
Received: from mail-pj1-x1033.google.com (mail-pj1-x1033.google.com [IPv6:2607:f8b0:4864:20::1033]) (using TLSv1.3 with cipher TLS_AES_128_GCM_SHA256 (128/128 bits) key-exchange X25519 server-signature RSA-PSS (2048 bits) server-digest SHA256) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 0976AC15107E for <cose@ietf.org>; Mon, 8 Jan 2024 06:52:02 -0800 (PST)
Received: by mail-pj1-x1033.google.com with SMTP id 98e67ed59e1d1-28be8ebcdc1so1051760a91.0 for <cose@ietf.org>; Mon, 08 Jan 2024 06:52:02 -0800 (PST)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=transmute.industries; s=google; t=1704725521; x=1705330321; darn=ietf.org; h=cc:to:subject:message-id:date:from:in-reply-to:references :mime-version:from:to:cc:subject:date:message-id:reply-to; bh=tIGOiKQNNywW4iCRwHmvS9DLEWFrHhCjUhP2sDXU9A4=; b=gjf96Hhq+swXyFRn7FOWTlR3VgPuLUINXnXUFVl+xyRHZR+PVpety4cb9z1H/DGyDP CEHeZxkrWQaAuPAxz/OSHlpnCb+PONp+bEbT3h9wbbKjBQWJ9HDqqiGUPVVtJgs14HGf MTx1mDGXGvQK1pNW7mxRu5dVo5Z1W6eeGovVQa/NdOFryfvAtAkJXANEdxEzAND+sx6p MJ9GICRJaxqB7KPEA5GSrRQPYWt0mpakrBFJnLFxOTi64kJRDJdtRHFmIeTYNW8IYYoL UQwqUkud7SJUlxEDOsf6Z4kdx/TabVzq81SWFfVQ0esQmVmVSHbsCS+z5cEQFoBK0qGE On6g==
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20230601; t=1704725521; x=1705330321; h=cc:to:subject:message-id:date:from:in-reply-to:references :mime-version:x-gm-message-state:from:to:cc:subject:date:message-id :reply-to; bh=tIGOiKQNNywW4iCRwHmvS9DLEWFrHhCjUhP2sDXU9A4=; b=G+NnYj+RmOzegHEeimaIul2349drnIfdAK6/DdnakD95dEbGQlSKU8dDScQ6OfPCDM nqtoYSMx0/UR1fqzu0LeDjlMhDGTcp7mH/RNWfOPJP+W6EJvz69GXqyp+x/ojzkTQT8g HIsdNztvpSPMbrpGI55hPFWTWWKBeuw6gV6h81tozDJjw8AH7bvEayK4R2bcEot8NgaN 6Y6RqIBquKdREju8Tp/42zdOTqv9fnLApZAeKQcJvpuRYSs5y+TJ6JApopru7DcRAtDc dmnqFoXLoNpKpj3AjrI3f+npyPJMev/OQ36sBdlROoJRMZ8nCXD26fzhjpj8jH4yoSCn 7eZA==
X-Gm-Message-State: AOJu0YwFFqMy5kL5vrVrhWPQ/nXlip7MU6+mlHHxRHM4NEc8ZBT4fVoN Ghw3KmNHNdJcp7Ovd1aa0+Zr6DOnNAzk6O/VWwTjM9uX0mvDpg==
X-Google-Smtp-Source: AGHT+IHrwxkf/VKx+S18hMeBW5fMw0hbaSoicFOq9VxbRq78zRxY7i4qxVGB1rZMkydwneUdutxZuTg7vtZx0DYcaQ0=
X-Received: by 2002:a17:90b:885:b0:28b:39d0:e97c with SMTP id bj5-20020a17090b088500b0028b39d0e97cmr1112525pjb.60.1704725521384; Mon, 08 Jan 2024 06:52:01 -0800 (PST)
MIME-Version: 1.0
References: <CAN8C-_+jskd04A+owwf=P7xKwDDdmB2qOf37o+teDfx8TVzZHQ@mail.gmail.com> <EF57B98F-FE41-488B-B85E-7F9585790B93@gmail.com> <CAMBN2CRJ5o6AMgPY+pxtOD3a=SG2dG3-AJZ7oz7xo1i-otd3wg@mail.gmail.com>
In-Reply-To: <CAMBN2CRJ5o6AMgPY+pxtOD3a=SG2dG3-AJZ7oz7xo1i-otd3wg@mail.gmail.com>
From: Orie Steele <orie@transmute.industries>
Date: Mon, 08 Jan 2024 08:51:50 -0600
Message-ID: <CAN8C-_LqoCjpiy=RC78QKTGhdAR3BnVfypcqdYPoU_T7UVatVw@mail.gmail.com>
To: Manu Sporny <msporny@digitalbazaar.com>
Cc: Neil Madden <neil.e.madden@gmail.com>, Karen ODonoghue <kodonog@pobox.com>, jose@ietf.org, cose <cose@ietf.org>
Content-Type: multipart/alternative; boundary="000000000000245e6f060e705790"
Archived-At: <https://mailarchive.ietf.org/arch/msg/cose/wXlRFJQTX5q7oLNa3djwUlgKIs8>
Subject: Re: [COSE] [jose] Call for Adoption: draft-jones-jose-fully-specified-algorithms
X-BeenThere: cose@ietf.org
X-Mailman-Version: 2.1.39
Precedence: list
List-Id: CBOR Object Signing and Encryption <cose.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/cose>, <mailto:cose-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/cose/>
List-Post: <mailto:cose@ietf.org>
List-Help: <mailto:cose-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/cose>, <mailto:cose-request@ietf.org?subject=subscribe>
X-List-Received-Date: Mon, 08 Jan 2024 14:52:06 -0000

We got some good responses from the TLS list on the interpretation of their
suites, please review them:

https://mailarchive.ietf.org/arch/msg/tls/LXBUvjMdhEpgIEC1CEzTuDKZNwY/

OS

On Mon, Jan 8, 2024 at 8:33 AM Manu Sporny <msporny@digitalbazaar.com>
wrote:

> On Mon, Jan 8, 2024 at 4:19 AM Neil Madden <neil.e.madden@gmail.com>
> wrote:
> > It’s pretty clear that we’re just talking past each other now. I’ve made
> the points I wanted to make. I don’t think you have addressed any of them,
> so I still don’t support adoption of this draft.
>
> I found Neil's concerns compelling.
>
> For better or worse, JOSE uses "polymorphic" algorithm identifiers and
> that's the way things have worked for a long time. The Working Group
> was warned that this was not a good idea at the time, but rough
> consensus landed in the "polymorphic" camp and that's what the
> ecosystem does today.
>
> Adding more options to support both "polymorphic" and "fully
> specified" approaches creates additional complexity that will lead to
> interoperability failures. Don't complicate the ecosystem more than it
> already is.
>
> I do not support the adoption of this draft for the reasons Neil
> mentioned as well as the reasons stated above.
>
> -- manu
>
> --
> Manu Sporny - https://www.linkedin.com/in/manusporny/
> Founder/CEO - Digital Bazaar, Inc.
> https://www.digitalbazaar.com/
>


-- 


ORIE STEELE
Chief Technology Officer
www.transmute.industries

<https://transmute.industries>