IMPORANT: Comments on draft-eastlake-additional-xmlsec-uris-08

<Frederick.Hirsch@nokia.com> Thu, 07 February 2013 21:24 UTC

Return-Path: <Frederick.Hirsch@nokia.com>
X-Original-To: ietf@ietfa.amsl.com
Delivered-To: ietf@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 4CFEC21F88C8 for <ietf@ietfa.amsl.com>; Thu, 7 Feb 2013 13:24:54 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -6.599
X-Spam-Level:
X-Spam-Status: No, score=-6.599 tagged_above=-999 required=5 tests=[BAYES_00=-2.599, RCVD_IN_DNSWL_MED=-4]
Received: from mail.ietf.org ([64.170.98.30]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id 6MCWTgh8hdGB for <ietf@ietfa.amsl.com>; Thu, 7 Feb 2013 13:24:53 -0800 (PST)
Received: from mgw-sa01.nokia.com (smtp.nokia.com [147.243.1.47]) by ietfa.amsl.com (Postfix) with ESMTP id 541CD21F86AA for <ietf@ietf.org>; Thu, 7 Feb 2013 13:24:53 -0800 (PST)
Received: from vaebh106.NOE.Nokia.com (vaebh106.europe.nokia.com [10.160.244.32]) by mgw-sa01.nokia.com (Sentrion-MTA-4.2.2/Sentrion-MTA-4.2.2) with ESMTP id r17LOnU9021237; Thu, 7 Feb 2013 23:24:49 +0200
Received: from smtp.mgd.nokia.com ([65.54.30.56]) by vaebh106.NOE.Nokia.com over TLS secured channel with Microsoft SMTPSVC(6.0.3790.4675); Thu, 7 Feb 2013 23:24:49 +0200
Received: from 008-AM1MPN1-033.mgdnok.nokia.com ([169.254.3.155]) by 008-AM1MMR1-001.mgdnok.nokia.com ([65.54.30.56]) with mapi id 14.02.0318.003; Thu, 7 Feb 2013 21:24:47 +0000
From: Frederick.Hirsch@nokia.com
To: d3e3e3@gmail.com
Subject: IMPORANT: Comments on draft-eastlake-additional-xmlsec-uris-08
Thread-Topic: IMPORANT: Comments on draft-eastlake-additional-xmlsec-uris-08
Thread-Index: AQHOBXmOQN1lvM8iSkKXEQ8LZYxYOg==
Date: Thu, 07 Feb 2013 21:24:47 +0000
Message-ID: <1CB2E0B458B211478C85E11A404A2B270190A4C6@008-AM1MPN1-033.mgdnok.nokia.com>
References: <3679302F-114B-4319-B351-14DC3F813859@nokia.com>
In-Reply-To: <3679302F-114B-4319-B351-14DC3F813859@nokia.com>
Accept-Language: en-US
Content-Language: en-US
X-MS-Has-Attach:
X-MS-TNEF-Correlator:
x-originating-ip: [10.163.58.212]
Content-Type: text/plain; charset="us-ascii"
Content-ID: <FAEF769553E125468BB20555765929F2@mgd.nokia.com>
Content-Transfer-Encoding: quoted-printable
MIME-Version: 1.0
X-OriginalArrivalTime: 07 Feb 2013 21:24:49.0132 (UTC) FILETIME=[8F28CAC0:01CE0579]
X-Nokia-AV: Clean
X-Mailman-Approved-At: Fri, 08 Feb 2013 10:12:54 -0800
Cc: draft-eastlake-additional-xmlsec-uris@tools.ietf.org, Frederick.Hirsch@nokia.com, ietf@ietf.org
X-BeenThere: ietf@ietf.org
X-Mailman-Version: 2.1.12
Precedence: list
List-Id: IETF-Discussion <ietf.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/ietf>, <mailto:ietf-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/ietf>
List-Post: <mailto:ietf@ietf.org>
List-Help: <mailto:ietf-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/ietf>, <mailto:ietf-request@ietf.org?subject=subscribe>
X-List-Received-Date: Thu, 07 Feb 2013 21:24:54 -0000

Don

I've received feedback from XML Security working group members that propose you change the URIs in the draft RFC for AES Key Wrap with Padding to match what is in XML Encryption 1.1, both because we are going to Recommendation and because there is code that currently uses those values.

Can you please make the change, using the xmlenc11 URIs I listed below in item 1?

Thanks

regards, Frederick

Frederick Hirsch
Nokia



On Feb 7, 2013, at 11:04 AM,  wrote:

> Donald 
> 
> Some additional comments on draft http://tools.ietf.org/pdf/draft-eastlake-additional-xmlsec-uris-08.pdf
> 
> sorry about the delay getting these comments to you.
> 
> (1) We have defined different *informative* URIs for AES Key Wrap with Padding in XML Encryption 1.1 [http://www.w3.org/TR/xmlenc-core1/#sec-kw-aes-with-pad] which are different from those in the RFC, namely
> 
> http://www.w3.org/2009/xmlenc11#kw-aes-128-pad
> 
> http://www.w3.org/2009/xmlenc11#kw-aes-192-pad
> 
> http://www.w3.org/2009/xmlenc11#kw-aes-256-pad
> 
> I suggest we change this informative appendix of XML Encryption 1.1 (and the Security Algorithms Cross-Reference) to match what is in the RFC draft. Thomas, is there any problem with that at this PR stage?
> 
> Those in the RFC draft are:
> 
> http://www.w3.org/2007/05/xmldsig-more#kw-aes128-pad 
> 
> http://www.w3.org/2007/05/xmldsig-more#kw-aes192-pad 
> 
> http://www.w3.org/2007/05/xmldsig-more#kw-aes256-pad
> 
> (2) ConcatKDF fragment needs fixing in 4.1 and change log Appendix A due to a typo
> 
> "2009/xmlenc11#ConctKDF [XMLENC]" should be "2009/xmlenc11#ConcatKDF [XMLENC]"
> 
> "#ConctKDF," should be "#ConcatKDF,"
> 
> (3) To some degree the fragment index and URI index replicate the published W3C Note, XML Security Algorithm Cross-Reference and could be incorporated there.
> 
> (4) I suggest an update to the Introduction to mention XML Security 1.1 as follows
> 
> after "All of these standards and recommendations use URIs [RFC3986] to identify algorithms and keying information types."
> 
> add
> 
> "The W3C has subsequently produced updated  XML Signature 1.1  [XMLDSIG11] and XML Encryption 1.1 [XMLENC11} versions as well as a new XML Signature Properties specification [XMLDSIG-PROPERTIES].
> 
> (5) Typo in introduction
> 
> "Canoncialization" should be "Canonicalization"
> 
> (6) References
> 
> Add references to XML Signature 1.1, XML Encryption 1.1, XML Signature Properties, XML Security Algorithm Cross-Reference (all to be updated upon Recommendation publication)
> 
> Signature properties has added a namespace: xmlns dsp="http://www.w3.org/2009/xmldsig-properties"
> 
> [XMLDSIG-CORE1]
> D. Eastlake, J. Reagle, D. Solo, F. Hirsch, T. Roessler, K. Yiu. XML Signature Syntax and Processing Version 1.1. 24 January 2013. W3C Proposed Recommendation. (Work in progress) URL:http://www.w3.org/TR/2013/PR-xmldsig-core1-20130124/
> 
> [XMLENC-CORE1]
> J. Reagle; D. Eastlake; F. Hirsch; T. Roessler. XML Encryption Syntax and Processing Version 1.1. 24 January 2013. W3C Proposed Recommendation. (Work in progress) URL:http://www.w3.org/TR/2013/PR-xmlenc-core1-20130124/
> 
> [XMLDSIG-PROPERTIES]
> Frederick Hirsch. XML Signature Properties. 24 January 2013. W3C Proposed Recommendation. (Work in progress.) URL: http://www.w3.org/TR/2013/PR-xmldsig-properties-20130124/
> 
> [XMLSEC-ALGS] F Hirsch, T Roessler, K Yiu XML Security Algorithm Cross-Reference, 24 January 2013 W3C Working Group Note http://www.w3.org/TR/2013/NOTE-xmlsec-algorithms-20130124/
> 
> 
> regards, Frederick
> 
> Frederick Hirsch, Nokia
> Chair XML Security WG
> 
> 
>