Re: [jose] AEAD algorithms
Eric Rescorla <ekr@rtfm.com> Wed, 18 January 2012 22:45 UTC
Return-Path: <ekr@rtfm.com>
X-Original-To: jose@ietfa.amsl.com
Delivered-To: jose@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 282E011E80B0 for <jose@ietfa.amsl.com>; Wed, 18 Jan 2012 14:45:05 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -102.846
X-Spam-Level:
X-Spam-Status: No, score=-102.846 tagged_above=-999 required=5 tests=[AWL=0.131, BAYES_00=-2.599, FM_FORGED_GMAIL=0.622, RCVD_IN_DNSWL_LOW=-1, USER_IN_WHITELIST=-100]
Received: from mail.ietf.org ([12.22.58.30]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id CV2rVpLH3aSQ for <jose@ietfa.amsl.com>; Wed, 18 Jan 2012 14:45:04 -0800 (PST)
Received: from mail-vx0-f172.google.com (mail-vx0-f172.google.com [209.85.220.172]) by ietfa.amsl.com (Postfix) with ESMTP id 5A9D911E80A2 for <jose@ietf.org>; Wed, 18 Jan 2012 14:45:04 -0800 (PST)
Received: by vcbfk26 with SMTP id fk26so3020971vcb.31 for <jose@ietf.org>; Wed, 18 Jan 2012 14:45:02 -0800 (PST)
Received: by 10.220.116.10 with SMTP id k10mr5081714vcq.25.1326926701212; Wed, 18 Jan 2012 14:45:01 -0800 (PST)
MIME-Version: 1.0
Received: by 10.52.93.163 with HTTP; Wed, 18 Jan 2012 14:44:20 -0800 (PST)
X-Originating-IP: [74.95.2.173]
In-Reply-To: <B23032F8-BFCF-4200-A78E-5C68FE8174B5@gmx.net>
References: <014d01ccd57e$328f27e0$97ad77a0$@augustcellars.com> <BA6DCD05-48A5-4679-A162-09D27C6A3246@gmx.net> <016f01ccd5bd$5563a270$002ae750$@augustcellars.com> <B23032F8-BFCF-4200-A78E-5C68FE8174B5@gmx.net>
From: Eric Rescorla <ekr@rtfm.com>
Date: Wed, 18 Jan 2012 14:44:20 -0800
Message-ID: <CABcZeBPQaSQJddz6rp91ELr5Y5y7ub2hZ+K_-eOcRN-Nmv+pkg@mail.gmail.com>
To: Hannes Tschofenig <hannes.tschofenig@gmx.net>
Content-Type: text/plain; charset="ISO-8859-1"
Content-Transfer-Encoding: quoted-printable
Cc: Jim Schaad <ietf@augustcellars.com>, jose@ietf.org
Subject: Re: [jose] AEAD algorithms
X-BeenThere: jose@ietf.org
X-Mailman-Version: 2.1.12
Precedence: list
List-Id: Javascript Object Signing and Encryption <jose.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/jose>, <mailto:jose-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/jose>
List-Post: <mailto:jose@ietf.org>
List-Help: <mailto:jose-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/jose>, <mailto:jose-request@ietf.org?subject=subscribe>
X-List-Received-Date: Wed, 18 Jan 2012 22:45:05 -0000
On Wed, Jan 18, 2012 at 1:10 AM, Hannes Tschofenig <hannes.tschofenig@gmx.net> wrote: > While I disagree with you even in case of TLS I definitely think that JOSE should list mandatory-to-implement or mandatory-to-use algorithms in the main documents. You can always write an additional document that lists what algorithms are recommended for usage in specific environments and update that document every few years. I don't understand what you disagree with in the case of TLS. TLS does define an MTI. See: http://tools.ietf.org/html/rfc5246#section-9 Perhaps your argument is that TLS shouldn't do this. However, that's quite different from the statement that we are not doing so, with which, like Jim, I don't agree. -Ekr > On Jan 18, 2012, at 10:44 AM, Jim Schaad wrote: > >> <non chair> >> >> It is not quite true that we do not put mandatory to implement algorithms in >> our specs any more. The requirement to have mandated algorithms varies >> depending on the specification and the purpose to which it is to be used. >> It is true that PKIX and CMS do not have mandated algorithms, but S/MIME, >> TLS and DANE do. The difference is generally a question of are we just >> defining a frame work or a protocol. >> >> In this case we are separating the algorithms from the structure, but I >> think that the group as a whole may decide that it will still need to >> specify a set of mandatory algorithms in order to promote interoperability >> as a library. Documents which build on top, such as the JSON token document >> might or might not specify the same, different or any algorithms (inheriting >> what we do). >> >> I have not yet formulated a final personal opinion, but the language I have >> heard in the past on the list is towards specifying mandatory algorithms. >> >> Jim >> >> >>> -----Original Message----- >>> From: Hannes Tschofenig [mailto:hannes.tschofenig@gmx.net] >>> Sent: Tuesday, January 17, 2012 11:59 PM >>> To: Jim Schaad >>> Cc: Hannes Tschofenig; jose@ietf.org >>> Subject: Re: [jose] AEAD algorithms >>> >>> Hi Jim, >>> >>> when you say "mandatory" what do you mean? >>> >>> Already for a while now we are not putting mandatory to implement nor >>> mandatory to use algorithms in our specifications anymore. >>> >>> See also my mail to the OAuth list on that topic: >>> http://www.ietf.org/mail-archive/web/oauth/current/msg08019.html >>> >>> Ciao >>> Hanns >>> >>> On Jan 18, 2012, at 3:12 AM, Jim Schaad wrote: >>> >>>> I would like to see a mandatory AEAD algorithm. While I would prefer >>>> the use of AES-GCM, one algorithm that could be considered is the >>>> composite one purposed by Peter Gutmann in RFC 6476 which does the >>> following: >>>> >>>> States separate encryption and MAC algorithms to be used Defines a >>>> method of deriving separate keys for the encryption and MAC algorithms >>>> from a single common key transported to the end user. >>>> >>>> This makes it appear as a standard AEAD algorithm but it is made up >>>> from common primitives rather than using a special mode that is not >>>> widely distributed. >>>> >>>> Jim >>>> >>>> >>>> _______________________________________________ >>>> jose mailing list >>>> jose@ietf.org >>>> https://www.ietf.org/mailman/listinfo/jose >> >> _______________________________________________ >> jose mailing list >> jose@ietf.org >> https://www.ietf.org/mailman/listinfo/jose > > _______________________________________________ > jose mailing list > jose@ietf.org > https://www.ietf.org/mailman/listinfo/jose
- [jose] AEAD algorithms Jim Schaad
- Re: [jose] AEAD algorithms John Bradley
- Re: [jose] AEAD algorithms Hannes Tschofenig
- Re: [jose] AEAD algorithms Jim Schaad
- Re: [jose] AEAD algorithms Mike Jones
- Re: [jose] AEAD algorithms Hannes Tschofenig
- Re: [jose] AEAD algorithms Carsten Bormann
- Re: [jose] AEAD algorithms Hannes Tschofenig
- Re: [jose] AEAD algorithms Eric Rescorla