[Jose-reg-review] Request to register header parameter: svt

Stefan Santesson <stefan@aaa-sec.com> Fri, 03 September 2021 15:32 UTC

Return-Path: <stefan@aaa-sec.com>
X-Original-To: jose-reg-review@ietfa.amsl.com
Delivered-To: jose-reg-review@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 89AB33A2272 for <jose-reg-review@ietfa.amsl.com>; Fri, 3 Sep 2021 08:32:40 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.898
X-Spam-Level:
X-Spam-Status: No, score=-1.898 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, RCVD_IN_MSPIKE_H2=-0.001, SPF_HELO_NONE=0.001, SPF_NONE=0.001, URIBL_BLOCKED=0.001] autolearn=ham autolearn_force=no
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id fFm7K2mi1bMD for <jose-reg-review@ietfa.amsl.com>; Fri, 3 Sep 2021 08:32:36 -0700 (PDT)
Received: from smtp.outgoing.loopia.se (smtp.outgoing.loopia.se [93.188.3.37]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id E73743A226F for <jose-reg-review@ietf.org>; Fri, 3 Sep 2021 08:32:34 -0700 (PDT)
Received: from s807.loopia.se (localhost [127.0.0.1]) by s807.loopia.se (Postfix) with ESMTP id E4A322E97214 for <jose-reg-review@ietf.org>; Fri, 3 Sep 2021 17:32:31 +0200 (CEST)
Received: from s499.loopia.se (unknown [172.22.191.6]) by s807.loopia.se (Postfix) with ESMTP id D5D852E28C04; Fri, 3 Sep 2021 17:32:31 +0200 (CEST)
Received: from s473.loopia.se (unknown [172.22.191.6]) by s499.loopia.se (Postfix) with ESMTP id D11761CE63C9; Fri, 3 Sep 2021 17:32:31 +0200 (CEST)
X-Virus-Scanned: amavisd-new at amavis.loopia.se
Received: from s630.loopia.se ([172.22.191.6]) by s473.loopia.se (s473.loopia.se [172.22.190.13]) (amavisd-new, port 10024) with LMTP id Z1fVR3sD92DA; Fri, 3 Sep 2021 17:32:31 +0200 (CEST)
X-Loopia-Auth: user
X-Loopia-User: mailstore2@aaa-sec.com
X-Loopia-Originating-IP: 85.235.7.89
Received: from [192.168.1.218] (gw.aaa-sec.ideon.se [85.235.7.89]) (Authenticated sender: mailstore2@aaa-sec.com) by s630.loopia.se (Postfix) with ESMTPSA id 5C9E813B94B3; Fri, 3 Sep 2021 17:32:31 +0200 (CEST)
Message-ID: <7f32646a-ac05-dc5a-5fb3-41e61aead96f@aaa-sec.com>
Date: Fri, 03 Sep 2021 17:32:30 +0200
MIME-Version: 1.0
User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10.15; rv:92.0) Gecko/20100101 Thunderbird/92.0
Content-Language: sv-SE
From: Stefan Santesson <stefan@aaa-sec.com>
Organization: 3xA Security AB
To: jose-reg-review@ietf.org
Cc: Russ Housley <housley@vigilsec.com>
Content-Type: text/plain; charset="UTF-8"
Content-Transfer-Encoding: 8bit
Archived-At: <https://mailarchive.ietf.org/arch/msg/jose-reg-review/tgtJNnT3YHElVy90xIBCxlYeTHk>
Subject: [Jose-reg-review] Request to register header parameter: svt
X-BeenThere: jose-reg-review@ietf.org
X-Mailman-Version: 2.1.29
Precedence: list
List-Id: "The JSON Web Algorithm standard \(RFC 7518\) establishes this email list for designated experts to discuss proposed changes, additions, and removals to the set of algorithms in the JSON Object Signing and Encryption \(JOSE\) registry, http://www.iana.org/assignments/jose." <jose-reg-review.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/jose-reg-review>, <mailto:jose-reg-review-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/jose-reg-review/>
List-Post: <mailto:jose-reg-review@ietf.org>
List-Help: <mailto:jose-reg-review-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/jose-reg-review>, <mailto:jose-reg-review-request@ietf.org?subject=subscribe>
X-List-Received-Date: Fri, 03 Sep 2021 15:32:41 -0000


Hi,

The draft https://datatracker.ietf.org/doc/draft-santesson-svt-jws/ is
being requested for publication as individual submission

This draft includes the request to register the JWS Header Parameter 
"svt" as follows:

6.1.  Header Parameter Names Registration

   This section registers the "svt" Header Parameter in the IANA "JSON
   Web Signature and Encryption Header Parameters" registry established
   by [RFC7515].

6.1.1.  Registry Contents

   *  Header Parameter Name: "svt"
   *  Header Parameter Description: Signature Validation Token
   *  Header Parameter Usage Location(s): JWS
   *  Change Controller: IESG
   *  Specification Document(s): Section 3.1 of {this document}


The draft specifies a a profile for including SVT tokens in a JWS using
this defined header parameter ("svt").

The rationale for this claim is described in the referenced document and
the main specification found here:
https://datatracker.ietf.org/doc/draft-santesson-svt/ .

The solution is deployed is real services and it is considered for
national government usage which is the main reason to publish the
specification as an informational RFC.


/Stefan Santesson