Re: [jose] Gen-ART LC review of draft-ietf-jose-json-web-algorithms-31

Mike Jones <> Tue, 23 September 2014 23:18 UTC

Return-Path: <>
Received: from localhost ( []) by (Postfix) with ESMTP id 7293E1A1BCF; Tue, 23 Sep 2014 16:18:17 -0700 (PDT)
X-Virus-Scanned: amavisd-new at
X-Spam-Flag: NO
X-Spam-Score: -1.901
X-Spam-Status: No, score=-1.901 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, HTML_MESSAGE=0.001, RCVD_IN_DNSWL_NONE=-0.0001, SPF_HELO_PASS=-0.001, SPF_PASS=-0.001] autolearn=ham
Received: from ([]) by localhost ( []) (amavisd-new, port 10024) with ESMTP id jMMFuQIgbNzF; Tue, 23 Sep 2014 16:18:13 -0700 (PDT)
Received: from ( []) (using TLSv1 with cipher ECDHE-RSA-AES256-SHA (256/256 bits)) (No client certificate requested) by (Postfix) with ESMTPS id 5AFF01A024C; Tue, 23 Sep 2014 16:18:13 -0700 (PDT)
Received: from ( by ( with Microsoft SMTP Server (TLS) id 15.0.1034.13; Tue, 23 Sep 2014 23:18:13 +0000
Received: from (2a01:111:f400:7c0c::193) by (2a01:111:e400:4000::16) with Microsoft SMTP Server (TLS) id 15.0.1034.13 via Frontend Transport; Tue, 23 Sep 2014 23:18:11 +0000
Received: from ( by ( with Microsoft SMTP Server (TLS) id 15.0.1029.15 via Frontend Transport; Tue, 23 Sep 2014 23:18:10 +0000
Received: from ([]) by ([]) with mapi id 14.03.0195.002; Tue, 23 Sep 2014 23:17:31 +0000
From: Mike Jones <>
To: Roni Even <>, "" <>, "" <>
Thread-Topic: Gen-ART LC review of draft-ietf-jose-json-web-algorithms-31
Thread-Index: Ac/F2mpuDG6JcxI/SbuImTKmZa3+rwCmp0KQAAT2yQADvuHBoA==
Date: Tue, 23 Sep 2014 23:17:30 +0000
Message-ID: <>
References: <013201cfc5da$6c34dd60$449e9820$> <> <02c901cfc888$e53e8160$afbb8420$>
In-Reply-To: <02c901cfc888$e53e8160$afbb8420$>
Accept-Language: en-US
Content-Language: en-US
x-originating-ip: []
Content-Type: multipart/alternative; boundary="_000_4E1F6AAD24975D4BA5B16804296739439BA6F0A0TK5EX14MBXC286r_"
MIME-Version: 1.0
X-EOPAttributedMessage: 0
X-Forefront-Antispam-Report: CIP:; CTRY:US; IPV:NLI; IPV:NLI; EFV:NLI; SFV:NSPM; SFS:(10019020)(438002)(377424004)(377454003)(51914003)(199003)(189002)(95666004)(64706001)(77096002)(2656002)(87936001)(2201001)(92726001)(76176999)(46102003)(90102001)(76482002)(19300405004)(21056001)(85806002)(84326002)(106466001)(107046002)(86362001)(33656002)(83072002)(74662003)(230783001)(79102003)(81342003)(99396002)(85852003)(55846006)(92566001)(77982003)(80022003)(81156004)(81542003)(15202345003)(83322001)(15975445006)(66066001)(31966008)(71186001)(85306004)(16236675004)(4396001)(74502003)(512954002)(20776003)(104016003)(120916001)(19580395003)(68736004)(54356999)(50986999)(6806004)(19625215002)(19617315012)(84676001)(44976005)(19580405001)(69596002)(10300001)(97736003)(86612001); DIR:OUT; SFP:1102; SCL:1; SRVR:DM2PR0301MB1216;; FPR:; MLV:sfv; PTR:InfoDomainNonexistent; A:1; MX:1; LANG:en;
X-Microsoft-Antispam: UriScan:;
X-Microsoft-Antispam: BCL:0;PCL:0;RULEID:;SRVR:DM2PR0301MB1216;
X-O365ENT-EOP-Header: Message processed by - O365_ENT: Allow from ranges (Engineering ONLY)
X-Forefront-PRVS: 0343AC1D30
Received-SPF: Pass ( domain of designates as permitted sender); client-ip=;;
Authentication-Results: spf=pass (sender IP is;
Cc: "" <>, "" <>
Subject: Re: [jose] Gen-ART LC review of draft-ietf-jose-json-web-algorithms-31
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: Javascript Object Signing and Encryption <>
List-Unsubscribe: <>, <>
List-Archive: <>
List-Post: <>
List-Help: <>
List-Subscribe: <>, <>
X-List-Received-Date: Tue, 23 Sep 2014 23:18:17 -0000

Thanks again for your review, Roni.  The resolutions discussed below have been applied in the -32 draft.

                                                                -- Mike

From: Roni Even []
Sent: Thursday, September 04, 2014 2:41 PM
To: Mike Jones;;
Subject: RE: Gen-ART LC review of draft-ietf-jose-json-web-algorithms-31

Hi Mike,

From: Mike Jones []
Sent: 04 September, 2014 10:31 PM
To: Roni Even;<>;<>
Subject: RE: Gen-ART LC review of draft-ietf-jose-json-web-algorithms-31

Thanks for the review, Roni.  I'm also cc'ing the working group so they're aware of your review.  Replies are inline below...

From: Roni Even []
Sent: Monday, September 01, 2014 4:47 AM
Subject: Gen-ART LC review of draft-ietf-jose-json-web-algorithms-31

I am the assigned Gen-ART reviewer for this draft. For background on Gen-ART, please see the FAQ at <>.
Please resolve these comments along with any other Last Call comments you may receive.

Document:  draft-ietf-jose-json-web-algorithms-31

Reviewer: Roni Even

Review Date:2014-9-1

IETF LC End Date: 2014-9-3

IESG Telechat date:

Summary: This draft is ready for publication as a standard track RFC.

Major issues:

Minor issues:

Nits/editorial comments:

  1.  Section 4.8 "This section defines the specifies" should be "specifics"


  1.  Section 5.2.2 "Section 5.2.3 and Section 5.2.5" should be "through" since 5.2.4 also defines instances.


  1.  Section in bullet 1 "the values of these parameters are specified by the AEAD algorithms (in Section 5.2.3 and Section 5.2.5)". Did you mean AEAD in which case is should be expanded and a reference is probably needed or do you need to change it to Authenticated Encryption? Also the "and" should be "through" same as previous comment.

Yes, the "AEAD" should become "Authenticated Encryption" to be consistent with the rest of the spec.  And agreed about "through".

  1.  In section bullet 4 for "number of bits in A" I had to go to bullet 5 to see what A is. Maybe add also here "additional authenticated data"

"A" is defined in the first sentence of as "additional authenticated data".  But there would be no harm the addition you propose.  Knowing that it's defined in the first sentence, do you still want to see the addition?
[Roni Even] I think it will be good to have the definition  so  it is consistent with bullet 5

                                                                Thanks again,
                                                                -- Mike