Re: [Curdle] Regarding X25519 in JOSE ...

Anders Rundgren <anders.rundgren.net@gmail.com> Mon, 24 July 2017 14:38 UTC

Return-Path: <anders.rundgren.net@gmail.com>
X-Original-To: curdle@ietfa.amsl.com
Delivered-To: curdle@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 1F5F1131D6F for <curdle@ietfa.amsl.com>; Mon, 24 Jul 2017 07:38:59 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2
X-Spam-Level:
X-Spam-Status: No, score=-2 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, FREEMAIL_FROM=0.001, RCVD_IN_DNSWL_NONE=-0.0001, SPF_PASS=-0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (2048-bit key) header.d=gmail.com
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id wDtPkCGk_Y3T for <curdle@ietfa.amsl.com>; Mon, 24 Jul 2017 07:38:57 -0700 (PDT)
Received: from mail-wr0-x244.google.com (mail-wr0-x244.google.com [IPv6:2a00:1450:400c:c0c::244]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 3E620131D33 for <curdle@ietf.org>; Mon, 24 Jul 2017 07:38:57 -0700 (PDT)
Received: by mail-wr0-x244.google.com with SMTP id c24so14086232wra.2 for <curdle@ietf.org>; Mon, 24 Jul 2017 07:38:56 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20161025; h=subject:to:references:from:message-id:date:user-agent:mime-version :in-reply-to:content-language:content-transfer-encoding; bh=3O6aEwVL7Ui0RFPq0i3zzjfrIA1VNLM9aK2HPTMvwPA=; b=jtMyJk+EYwhk9tWOTRL++/m0WyAwbM8IGwO8kvWvEzt47CnQ73UzGbMdDl6karSYt1 1XtxZ9Cs22OzkIDBIxwEI4iPFBFDSghHLDFewDM19fUmsYZG5LMNr2ltPYxu5rkRDXdF NhzFOo5gK2fwq3a2DXK/QBaKeAAfNo8g51ibpBe9Bi8+XKOMa16hV8THxljy9fpY50zx Ib7pCROKq6L8lAlE4LmC/sJbPd7heKhN8ExqyT2EGtLDXRIU/JK3T3Qj/sK5LH7PwyrJ r3l0rwRVxeEYzGfx4NApj6Cya/9edhF5eJzWcxGUyPBygbzh/bjXgZsMBdTzOkNfBiiq aa5Q==
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20161025; h=x-gm-message-state:subject:to:references:from:message-id:date :user-agent:mime-version:in-reply-to:content-language :content-transfer-encoding; bh=3O6aEwVL7Ui0RFPq0i3zzjfrIA1VNLM9aK2HPTMvwPA=; b=UuO4/BTRVGQitumkbvXZb7kdNPeXb78ppBtI+EJLJhQWFaSLwjgh5RQb2J+K/t32Ae u7kpkIlQlatSHt8/5nqxKJYaGDVovo7/+/kFR2viDAfbGc/Cb/m20NE/h9wmTINZCFk5 gA2BWi2vxcIHe5fNWv5zu0Wdabu1bZRUc2drC1sjPMa4rOa4TtR1SCevyKTiQAhepWxE XE9AIgWT4HPH0yUoWY1AvbKISYzG41R3zluJXYxKxoTzrw21ZonGIkUlTh2QEsdbrCr7 gkFoX9Hn65Y+znN5WpEMm17zB91kXL94WkGFOSXisiYBuBke9Q8oVf26b2n3pgYnq884 wemA==
X-Gm-Message-State: AIVw112ri2yRpZlj3amUIRRB7fYXUGaDQkOwaO6wmrGjR0y5FHzsQP0a RPzTpJem4Y6eZGJU
X-Received: by 10.223.139.3 with SMTP id n3mr12512480wra.249.1500907135249; Mon, 24 Jul 2017 07:38:55 -0700 (PDT)
Received: from [192.168.1.79] (25.131.146.77.rev.sfr.net. [77.146.131.25]) by smtp.googlemail.com with ESMTPSA id w19sm4001874wrb.49.2017.07.24.07.38.53 (version=TLS1_2 cipher=ECDHE-RSA-AES128-GCM-SHA256 bits=128/128); Mon, 24 Jul 2017 07:38:54 -0700 (PDT)
To: "Matthew A. Miller" <linuxwolf+ietf@outer-planes.net>, curdle@ietf.org
References: <e6cc679b-02a6-7710-4651-c2b59a56c892@outer-planes.net>
From: Anders Rundgren <anders.rundgren.net@gmail.com>
Message-ID: <1365eab6-f45a-c5e9-99bc-194b5019814e@gmail.com>
Date: Mon, 24 Jul 2017 16:38:51 +0200
User-Agent: Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Thunderbird/52.2.1
MIME-Version: 1.0
In-Reply-To: <e6cc679b-02a6-7710-4651-c2b59a56c892@outer-planes.net>
Content-Type: text/plain; charset="utf-8"; format="flowed"
Content-Language: en-US
Content-Transfer-Encoding: 7bit
Archived-At: <https://mailarchive.ietf.org/arch/msg/curdle/xNCEO9TgRZJs4FlJ8sQxFSnXobQ>
Subject: Re: [Curdle] Regarding X25519 in JOSE ...
X-BeenThere: curdle@ietf.org
X-Mailman-Version: 2.1.22
Precedence: list
List-Id: "List for discussion of potential new security area wg." <curdle.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/curdle>, <mailto:curdle-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/curdle/>
List-Post: <mailto:curdle@ietf.org>
List-Help: <mailto:curdle-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/curdle>, <mailto:curdle-request@ietf.org?subject=subscribe>
X-List-Received-Date: Mon, 24 Jul 2017 14:38:59 -0000

On 2017-07-24 16:26, Matthew A. Miller wrote:
> Hello all,
> 
> It was asked if any work more work is needed to add X25519 (and X448) to
> JOSE.  I believe [RFC8037] covers that, so I don't think any more work
> is necessary right now.

Would it be possible (and not too controversial) describing why
RFC8037 didn't overload the JWK "EC" specification?  The reason
for asking is because the Java camp intends reusing the EC classes
making "OKP" a JOSE-only concept.  Personally, I believe OKP is just
fine (=clean) and should be adopted not only by Java, but by PKCS #11
and .NET as well.

Anders

> 
> 
> Thanks,
> 
> 
> 
> _______________________________________________
> Curdle mailing list
> Curdle@ietf.org
> https://www.ietf.org/mailman/listinfo/curdle
>