[jose] Profileability of JWP and JWA

Watson Ladd <watsonbladd@gmail.com> Sun, 03 March 2024 20:05 UTC

Return-Path: <watsonbladd@gmail.com>
X-Original-To: jose@ietfa.amsl.com
Delivered-To: jose@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id E889CC14F600 for <jose@ietfa.amsl.com>; Sun, 3 Mar 2024 12:05:56 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.108
X-Spam-Level:
X-Spam-Status: No, score=-2.108 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, FREEMAIL_FROM=0.001, RCVD_IN_ZEN_BLOCKED_OPENDNS=0.001, SPF_HELO_NONE=0.001, SPF_PASS=-0.001, T_SCC_BODY_TEXT_LINE=-0.01] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (2048-bit key) header.d=gmail.com
Received: from mail.ietf.org ([50.223.129.194]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id PSg3EWrPpCJd for <jose@ietfa.amsl.com>; Sun, 3 Mar 2024 12:05:56 -0800 (PST)
Received: from mail-wr1-x432.google.com (mail-wr1-x432.google.com [IPv6:2a00:1450:4864:20::432]) (using TLSv1.3 with cipher TLS_AES_128_GCM_SHA256 (128/128 bits) key-exchange X25519 server-signature RSA-PSS (2048 bits) server-digest SHA256) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 81ACFC14F5F8 for <jose@ietf.org>; Sun, 3 Mar 2024 12:05:56 -0800 (PST)
Received: by mail-wr1-x432.google.com with SMTP id ffacd0b85a97d-33d754746c3so2183307f8f.1 for <jose@ietf.org>; Sun, 03 Mar 2024 12:05:56 -0800 (PST)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20230601; t=1709496354; x=1710101154; darn=ietf.org; h=to:subject:message-id:date:from:mime-version:from:to:cc:subject :date:message-id:reply-to; bh=7H/RC4x5MJlz41tIrzET+5yxuNpWGcCvJvDQ/0FG49Q=; b=Gky5qqfZy0SkGEGXwzOP5rRyyha6F7alFJDkwFDpHjOxESadpUc6ekHFagJgKtEd3m zf/CEJPtR9VCoISO/iqAO21X6phC1nDjGyM5epwHui2ebY0tVVObZhUDN/qNMd47COoB 85vZ/5NsqMQ/qW7oxNPvPgTYtclASe+P9Y30T7Il8g/Izgz+VEXzZQyO9WlQw2rVv1Vz e9CEpyTJbPf1HXzeT6jhOB5nuFEA5goTR8lfImsOZPFPxBmAq4GagCS2r6R5+nY+9i6t guUMKxPaCqEYaPwVA8MDV0YDxvhP/OtJJP6RVk4eE2aTIFSXnCv+IhYDrr19/ej+gTOc 7Z1Q==
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20230601; t=1709496354; x=1710101154; h=to:subject:message-id:date:from:mime-version:x-gm-message-state :from:to:cc:subject:date:message-id:reply-to; bh=7H/RC4x5MJlz41tIrzET+5yxuNpWGcCvJvDQ/0FG49Q=; b=suDQMlSQt834IMknQZdFbDQRgQr05wINla61Op3ePs+SD/cB/hfdx+KmCQqgsb7G5F GT8pNXzTt25/7wmwccd4hvJ0FVAQ0elPdLvoKfJC5nmcSbQlAyXDZEhg72mGSGBOlbnk yOMuRc+NsjbyVtrcPHv0+L39LK91X+IB//5RPpf8WkiRyS4TOwV9dkRSfm+SSsO9GomI AAKh8+9ynfT9QaHsdTE6pWvVs3PkyzM2j3cfaKwyHgjpVnVF5E4tknP+/TbcGXR5zMFV qbr41XVwlDqgAjyqaHj5HjMSUl8lRWhP58HKx9nQO4ReeuzcnvQrGdVIiDR2oSC67jNN IpGQ==
X-Gm-Message-State: AOJu0YyRDJbV4yZbUwepiL1+11h8eFftFgZpJGuo7ZUpx3TK1Davuyx6 GPK8gmTtrueqfbYMsjLF7kDsfboFN8NVmHLRbUEa+3Hy9slsvIdSbMYlS/oq5HcPmdoUd4Ze5S6 aPRdd+lZahWP4RG+t/N1EMWsxL40gW37Y
X-Google-Smtp-Source: AGHT+IGf7fNZCyK/TElVCUm3LKFB2HaAlSmz8sBXY8hFv9mJErO0E5y6UQAagX/GVJHy81VV/dxgEkUvRwKlvUJ/AKk=
X-Received: by 2002:a5d:4525:0:b0:33d:e2d9:8401 with SMTP id j5-20020a5d4525000000b0033de2d98401mr5200040wra.51.1709496353547; Sun, 03 Mar 2024 12:05:53 -0800 (PST)
MIME-Version: 1.0
From: Watson Ladd <watsonbladd@gmail.com>
Date: Sun, 03 Mar 2024 12:05:42 -0800
Message-ID: <CACsn0cn=1d0LbKyR2Kf1dXBx86hJ_CMuRNoBpraKSRrXtBUU+Q@mail.gmail.com>
To: jose@ietf.org
Content-Type: text/plain; charset="UTF-8"
Archived-At: <https://mailarchive.ietf.org/arch/msg/jose/4gSk0vWWGIUlgF0R9ZH2wkSnECc>
Subject: [jose] Profileability of JWP and JWA
X-BeenThere: jose@ietf.org
X-Mailman-Version: 2.1.39
Precedence: list
List-Id: Javascript Object Signing and Encryption <jose.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/jose>, <mailto:jose-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/jose/>
List-Post: <mailto:jose@ietf.org>
List-Help: <mailto:jose-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/jose>, <mailto:jose-request@ietf.org?subject=subscribe>
X-List-Received-Date: Sun, 03 Mar 2024 20:05:57 -0000

Dear Joseans,

I've read the recently revised complex of drafts, and have some
questions about how we envision profiling working. It seems like the
documents defer a lot of the capabilities to the algorithms document,
while imposing some convention on what the claims representation along
the lines of "the names of the claims are strings suitable for JSON
object keys and have an order, and the claim values can only be
selectively revealed". This matters for both developing more
algorithms and for profilng: it may be that we end up with a profile
having to pick an algorithm, and that new algorithms with new
capabilities end up needing special treatment at the level of say
SPICE.

Secondly I'm curious where things like binding to upper level
protocols or enclaves are supposed to fit in here.

Sincerely,
Watson Ladd

-- 
Astra mortemque praestare gradatim