Re: [jose] Canonical JSON form

David Waite <david@alkaline-solutions.com> Sun, 18 November 2018 19:37 UTC

Return-Path: <david@alkaline-solutions.com>
X-Original-To: jose@ietfa.amsl.com
Delivered-To: jose@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 71BBE12D4E7 for <jose@ietfa.amsl.com>; Sun, 18 Nov 2018 11:37:21 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.901
X-Spam-Level:
X-Spam-Status: No, score=-1.901 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, SPF_PASS=-0.001] autolearn=ham autolearn_force=no
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id jIXO9OxZqNkl for <jose@ietfa.amsl.com>; Sun, 18 Nov 2018 11:37:20 -0800 (PST)
Received: from alkaline-solutions.com (lithium5.alkaline-solutions.com [173.255.196.46]) by ietfa.amsl.com (Postfix) with ESMTP id 09A2D126DBF for <jose@ietf.org>; Sun, 18 Nov 2018 11:37:19 -0800 (PST)
Received: from [IPv6:2601:282:202:b210:5841:bb9:234b:641d] (unknown [IPv6:2601:282:202:b210:5841:bb9:234b:641d]) by alkaline-solutions.com (Postfix) with ESMTPSA id 75EF93169E; Sun, 18 Nov 2018 19:37:19 +0000 (UTC)
Content-Type: text/plain; charset=utf-8
Mime-Version: 1.0 (1.0)
From: David Waite <david@alkaline-solutions.com>
X-Mailer: iPhone Mail (16C5050a)
In-Reply-To: <7b1d293c-1d97-44e4-0cd8-55ec1db6c3b5@gmail.com>
Date: Sun, 18 Nov 2018 12:37:15 -0700
Cc: Jim Schaad <ietf@augustcellars.com>, Carsten Bormann <cabo@tzi.org>, jose@ietf.org
Content-Transfer-Encoding: quoted-printable
Message-Id: <AD2DB2EB-3F06-4C55-94E4-CED60F6FF4CF@alkaline-solutions.com>
References: <12DD2F97-80C3-4606-9C6B-03F7A4BF19DE@gmail.com> <CAOASepNX4aYVmPWXyODn0E2Om_rimACPECqJBvZSOXVVd_p8LA@mail.gmail.com> <D21F3A95-0085-4DB7-A882-3496CC091B34@gmail.com> <CAOASepM=hB_k7Syqw4+b7L2vd6E_J0DSAAW0mHYdLExBZ6VBuw@mail.gmail.com> <00ad01d460f4$69ae8a00$3d0b9e00$@augustcellars.com> <8436AEE7-B25A-4538-B8F6-16D558D9A504@gmail.com> <MEAPR01MB35428606C09BF315DE04CC79E5E10@MEAPR01MB3542.ausprd01.prod.outlook.com> <CAHbuEH6DCD7Zc+PK3TnCBkKv1esnROwyCcDb8ZR+TKwgQQ+yXQ@mail.gmail.com> <0E6BD488-74D5-4640-BC31-5E45B0531AFC@gmail.com> <CAHbuEH5oH-Km6uAjrSr0pEHswFBLuDpfVweQ+gpj472yk+8iTQ@mail.gmail.com> <073CB50F-8D91-4EF6-90BE-FC897D557AA6@oracle.com> <A37D69B1-6B77-4E11-8BB9-A0209C77752C@tzi.org> <434fbdb6-0202-5a02-4cec-9332fbbe548c@gmail.com> <FBBFA6FA-4B0C-4239-9145-0B713120EC98@tzi.org> <01fd01d47f5f$4c4889f0$e4d99dd0$@augustcellars.com> <7b1d293c-1d97-44e4-0cd8-55ec1db6c3b5@gmail.com>
To: Anders Rundgren <anders.rundgren.net@gmail.com>
Archived-At: <https://mailarchive.ietf.org/arch/msg/jose/-mAPGiBVk84OLRu0x5ihdKmWlj0>
Subject: Re: [jose] Canonical JSON form
X-BeenThere: jose@ietf.org
X-Mailman-Version: 2.1.29
Precedence: list
List-Id: Javascript Object Signing and Encryption <jose.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/jose>, <mailto:jose-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/jose/>
List-Post: <mailto:jose@ietf.org>
List-Help: <mailto:jose-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/jose>, <mailto:jose-request@ietf.org?subject=subscribe>
X-List-Received-Date: Sun, 18 Nov 2018 19:37:21 -0000

Not to be a jerk (I promise!), but is there documentation of the TEEP issues with using JWS/JWE structure?

The existing specs seem to use JOSE as-is, I didn’t immediately see anything on the ML or in GitHub issues. 

It is difficult to fairly argue a specific desired solution to a non-disclosed problem set. Especially when so many people have battle scars from implementing that solution in the past. 

-DW

> On Nov 18, 2018, at 11:06 AM, Anders Rundgren <anders.rundgren.net@gmail.com> wrote:
> 
> There's no mystery going on here.  The TEEP folks needed Signed Data rather than Signature objects with embedded Data.