Re: [jose] #12: x5c incorrect in JWE

"jose issue tracker" <trac+jose@trac.tools.ietf.org> Wed, 13 March 2013 12:03 UTC

Return-Path: <trac+jose@trac.tools.ietf.org>
X-Original-To: jose@ietfa.amsl.com
Delivered-To: jose@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id C6B5921F8D57 for <jose@ietfa.amsl.com>; Wed, 13 Mar 2013 05:03:10 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -102.599
X-Spam-Level:
X-Spam-Status: No, score=-102.599 tagged_above=-999 required=5 tests=[BAYES_00=-2.599, USER_IN_WHITELIST=-100]
Received: from mail.ietf.org ([12.22.58.30]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id LE3xJO0ylm0q for <jose@ietfa.amsl.com>; Wed, 13 Mar 2013 05:03:10 -0700 (PDT)
Received: from grenache.tools.ietf.org (grenache.tools.ietf.org [IPv6:2a01:3f0:1:2::30]) by ietfa.amsl.com (Postfix) with ESMTP id 1A27921F8D43 for <jose@ietf.org>; Wed, 13 Mar 2013 05:03:09 -0700 (PDT)
Received: from localhost ([127.0.0.1]:59974 helo=grenache.tools.ietf.org ident=www-data) by grenache.tools.ietf.org with esmtp (Exim 4.80) (envelope-from <trac+jose@trac.tools.ietf.org>) id 1UFkOY-0000AJ-DN; Wed, 13 Mar 2013 13:02:58 +0100
MIME-Version: 1.0
Content-Type: text/plain; charset="utf-8"
Content-Transfer-Encoding: 7bit
From: jose issue tracker <trac+jose@trac.tools.ietf.org>
X-Trac-Version: 0.12.3
Precedence: bulk
Auto-Submitted: auto-generated
X-Mailer: Trac 0.12.3, by Edgewall Software
To: draft-ietf-jose-json-web-encryption@tools.ietf.org, michael.jones@microsoft.com, bcampbell@pingidentity.com
X-Trac-Project: jose
Date: Wed, 13 Mar 2013 12:02:58 -0000
X-URL: http://tools.ietf.org/jose/
X-Trac-Ticket-URL: http://trac.tools.ietf.org/wg/jose/trac/ticket/12#comment:2
Message-ID: <080.a744f604a8e1acddefaa722dc1ac2347@trac.tools.ietf.org>
References: <065.7762ca21750ef2a07382e66a81acadef@trac.tools.ietf.org>
X-Trac-Ticket-ID: 12
In-Reply-To: <065.7762ca21750ef2a07382e66a81acadef@trac.tools.ietf.org>
X-SA-Exim-Connect-IP: 127.0.0.1
X-SA-Exim-Rcpt-To: draft-ietf-jose-json-web-encryption@tools.ietf.org, michael.jones@microsoft.com, bcampbell@pingidentity.com, jose@ietf.org
X-SA-Exim-Mail-From: trac+jose@trac.tools.ietf.org
X-SA-Exim-Scanned: No (on grenache.tools.ietf.org); SAEximRunCond expanded to false
Resent-To: ekr@rtfm.com, jhildebr@cisco.com, mbj@microsoft.com
Resent-Message-Id: <20130313120310.1A27921F8D43@ietfa.amsl.com>
Resent-Date: Wed, 13 Mar 2013 05:03:09 -0700
Resent-From: trac+jose@trac.tools.ietf.org
Cc: jose@ietf.org
Subject: Re: [jose] #12: x5c incorrect in JWE
X-BeenThere: jose@ietf.org
X-Mailman-Version: 2.1.12
List-Id: Javascript Object Signing and Encryption <jose.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/jose>, <mailto:jose-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/jose>
List-Post: <mailto:jose@ietf.org>
List-Help: <mailto:jose-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/jose>, <mailto:jose-request@ietf.org?subject=subscribe>
X-List-Received-Date: Wed, 13 Mar 2013 12:03:10 -0000

#12: x5c incorrect in JWE


Comment (by bcampbell@pingidentity.com):

 True, the issues alone don't constitue a case to remove the functionality.

 But what is the case to *have* the functionality?

 As written it doesn't work with the currently defined algorithms (which
 suggests that it's not being used). If those issues are fixed, it provides
 dubious value for the current algorithms but would preclude it's use for
 possible future applications where it'd be more meaningful - like for for
 the sender to provide its own cert chain for use with a ECDH-SS alg.

 Maybe I'm bike-shedding on this one a bit but it seems silly to have it as
 a reserved header that doesn't do anything useful as defined but might
 preclude something useful down the road.

-- 
-------------------------------------+-------------------------------------
 Reporter:                           |       Owner:  draft-ietf-jose-json-
  bcampbell@pingidentity.com         |  web-encryption@tools.ietf.org
     Type:  defect                   |      Status:  new
 Priority:  minor                    |   Milestone:
Component:  json-web-encryption      |     Version:
 Severity:  Submitted WG Document    |  Resolution:
 Keywords:                           |
-------------------------------------+-------------------------------------

Ticket URL: <http://trac.tools.ietf.org/wg/jose/trac/ticket/12#comment:2>
jose <http://tools.ietf.org/jose/>