[jose] Re: Strawperson consensus call for changes to draft-ietf-jose-hpke-encrypt-01

Michael Jones <michael_b_jones@hotmail.com> Fri, 12 July 2024 23:51 UTC

Return-Path: <michael_b_jones@hotmail.com>
X-Original-To: jose@ietfa.amsl.com
Delivered-To: jose@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 89C3BC180B61; Fri, 12 Jul 2024 16:51:33 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.233
X-Spam-Level:
X-Spam-Status: No, score=-1.233 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, FORGED_HOTMAIL_RCVD2=0.874, FREEMAIL_FROM=0.001, HTML_MESSAGE=0.001, RCVD_IN_MSPIKE_H2=-0.001, RCVD_IN_ZEN_BLOCKED_OPENDNS=0.001, SPF_PASS=-0.001, T_SCC_BODY_TEXT_LINE=-0.01, URIBL_DBL_BLOCKED_OPENDNS=0.001, URIBL_ZEN_BLOCKED_OPENDNS=0.001] autolearn=no autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (2048-bit key) header.d=hotmail.com
Received: from mail.ietf.org ([50.223.129.194]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id ISqyFb6Y0geK; Fri, 12 Jul 2024 16:51:29 -0700 (PDT)
Received: from BN1PR04CU002.outbound.protection.outlook.com (mail-eastus2azolkn19010000.outbound.protection.outlook.com [52.103.12.0]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 8E1EAC16940A; Fri, 12 Jul 2024 16:51:29 -0700 (PDT)
ARC-Seal: i=1; a=rsa-sha256; s=arcselector10001; d=microsoft.com; cv=none; b=mciEo6eKlBeXwG4qJNsxzouhoApW5YhxpYCEEs53lRmLaAgGMD0/PyLUWLuLezHbHvUzWttHEcQ7GhaJaoOZpJM4fo4plHBStSRpHNSRixeh41E1w6pkE/5Y2LIiMPwq5lJuG4fdFxOvUPSK49wywFdp14puSB6fk4N0ghmXuZfoBolP9LxUuiRHyD8L57St7gg0UcOdRwtcDxbmf1zY24E6Dw8eEkpqwLN2HybT3z8hoXcfhVGLWrWFGXqKW+0ZJwkwt4CtfcmF5r1evPj/MZNROwoF+pK9aToNSPeU2pHH52JksHLfWyuENxCrzFVIei0n+AjtmUkJu51k3yXctA==
ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=microsoft.com; s=arcselector10001; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-AntiSpam-MessageData-ChunkCount:X-MS-Exchange-AntiSpam-MessageData-0:X-MS-Exchange-AntiSpam-MessageData-1; bh=nbXbe8lwF/RuAv2PdgZquIIIv3GeOSfqRAGCyiabv9A=; b=xGG6hPM9mZ0WQHf7jFSOyDrn+0He+fgnKDcwWDRzhv8zceADw6VruHfXS9pDN1roNjeK84LVUjKrqrxKGsq1BJndzd4gh7FYFofbmW1ba2rMVwq+zqtjUWs4xL6DDJoBp5uo2XuxN/NDbIMjcfFpO8j7qJzVb6L4RRdoixSJGBll4SH1nyQRQ9x2gGsXfP7uNn8HfXJFPqg3AZ7BFAjfykD6fXnpRX0/ghfc0N7dobfLhPYC4WSbabJdKvnpwRzA+7ScG4YGCMbLKYglOPHd9E3YDUakMP5UhAsd5CQE9BRxL7Enkuvpvwelzn/XkpN4lqVeUb54HfMtqX+rNQW3mQ==
ARC-Authentication-Results: i=1; mx.microsoft.com 1; spf=none; dmarc=none; dkim=none; arc=none
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=hotmail.com; s=selector1; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-SenderADCheck; bh=nbXbe8lwF/RuAv2PdgZquIIIv3GeOSfqRAGCyiabv9A=; b=VmqSh92fCHIOG5MfCeH6UJU0FwfiXRzmFOSWkcKsNWZH81FnkzSezuPWDykMh3ngs/fuXxmm99Ty5u8uSPpBYQDUFkezSlPRznDFHNHwdUyuwoi6iUhXF+fOaSoNFsMkjwJSn/+V6hokKHKUbfjWSx5XokCOSbookTsGuttL42N33qtM5uLwBqFW2yf22Lw/KCTLsWqlEGsa9HVDBWAn4H4cu/U4yuamJTsLvzzxgkeWN7AQNEPyFenYVIpeAUF5tbtMga8iw3ChdReYHaw/gAO+XT+lOz6pQI0RIocvGsRTV4WV+yFNl0EPlLL5Hn+vC4+BsiWw2LyZcriW+O58+Q==
Received: from PH0PR02MB7430.namprd02.prod.outlook.com (2603:10b6:510:b::9) by SJ2PR02MB10049.namprd02.prod.outlook.com (2603:10b6:a03:566::19) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.20.7762.23; Fri, 12 Jul 2024 23:51:26 +0000
Received: from PH0PR02MB7430.namprd02.prod.outlook.com ([fe80::67ac:16c1:95b5:fcdc]) by PH0PR02MB7430.namprd02.prod.outlook.com ([fe80::67ac:16c1:95b5:fcdc%6]) with mapi id 15.20.7762.020; Fri, 12 Jul 2024 23:51:26 +0000
From: Michael Jones <michael_b_jones@hotmail.com>
To: Brian Campbell <bcampbell=40pingidentity.com@dmarc.ietf.org>, Orie Steele <orie@transmute.industries>
Thread-Topic: [jose] Re: Strawperson consensus call for changes to draft-ietf-jose-hpke-encrypt-01
Thread-Index: AQHa1Kj1yCRlxgaLYU2z1q0mXV/DtrHzwrzw
Date: Fri, 12 Jul 2024 23:51:26 +0000
Message-ID: <PH0PR02MB74300975D1DEC40DB1CF1366B7A62@PH0PR02MB7430.namprd02.prod.outlook.com>
References: <CAN8C-_KEv4s2SHBYi9ZeCi+Jjxk08r9tg+sqt1wtcgnyswCBgQ@mail.gmail.com> <CA+k3eCRWtTmP9ObFjQOvhrUh3yDXwXA8tRbzT1r_Z1Z2mnjuYw@mail.gmail.com>
In-Reply-To: <CA+k3eCRWtTmP9ObFjQOvhrUh3yDXwXA8tRbzT1r_Z1Z2mnjuYw@mail.gmail.com>
Accept-Language: en-US
Content-Language: en-US
X-MS-Has-Attach:
X-MS-TNEF-Correlator:
x-tmn: [fXck//VtJzOMHztam+ft8t5IQrJtdUf8]
x-ms-publictraffictype: Email
x-ms-traffictypediagnostic: PH0PR02MB7430:EE_|SJ2PR02MB10049:EE_
x-ms-office365-filtering-correlation-id: 6c8dd543-4c4b-4033-8257-08dca2cd8aff
x-microsoft-antispam: BCL:0;ARA:14566002|461199028|8060799006|9400799024|12050799009|19110799003|102099032|4302099013|3412199025|440099028|1602099012;
x-microsoft-antispam-message-info: 7brSprfzQFwiP6ezw9jcBMpWNT4mwfEYlSMYF54MuInAMcRM3XtVZbjNratj7jqTxxq/YUYJy1KNR2XAYIykQKdL3lCaAkZKpCMo0oQDlg3dRqkYoGYOFi+0M6lcH1OGu90TuW1TtBvSHyQuaRxp6GK75hVyWwDGEoFIzoacpX1Y347omzBvkv1C/z5VVwkNUPNetrNUwnK6i1ZXX7iVrgoQVFNNETJNGNE/ejmbNSEeC/9yWd6h31FLYPgb/hLoP0VSeJVRaGP0LZMU9OJYigGwvG3EAKFzpdUHoTngkTepuAq4q8RSk8efbirBgnH2RCOAsdT23OyZswpZ/6XGnbV87ZGlXAkQ5n5fePqe/wqnW7PcTmOT8rB3JjlJTsnVCxP1hpPx5gwU0/8iLsXxsmBgR/6ga7RWsiGbXmonIGeVpWi3SONbOHP0zo84X8exsOVM7fH4JRrTbISQTnWPp4lIxAIjHKJfCyGVtEQCozdC6hY4FVOjSlKA58zMM1qKnfHv4AA0lHnSTqAT734Dg7mlXIXnfPqh9l6eeOlhTfJSz3axV9fsxPVjoXmLXVXs+iNyX4jRNrLGsDDtx+i6ong3OrzmLEm17qm6Zkm1FqkkK809PHqXtdt5f2FdsZpFe5kDLPV2JrWMqiubhGVVM265/88BRv2X+OTuYwhInzJmplX6idIWyTp7quQYCUOvKZpGQTbyYeAKPvLpQ33PwpjtFvvD77u8RQadJ6VAMkgVYaDofVCAubKxOR1q/192bBIXbbwb/NJUK1/f6m2qxuxNFetqY/H2i41zF9jnRrfX2patxaCZshSo0ack2Dpx
x-ms-exchange-antispam-messagedata-chunkcount: 1
x-ms-exchange-antispam-messagedata-0: R+WaBsco+lY39OXcdwjs1eDeyFSywGSZns7k+b+LmV9jarBGJ4qp/GxIIDwQ2teZ29bjUqWGeEcWaAgLjLghLwbNgRAwl2WHpSSGambNhrQOK4mdTu6Hot17HNbprQ9De707unQLSwU7xgikFwcbWTELXgydyoLy7qrtZJMCav9K20j1cT11FZ8J2LoiShl+631mGLEDkAQMYPFdRQFtXblkjz90OZEtKpOflfG1Q5kPORzTspDo/J16FPAgJa//KB/prB8jC/thmaCerreFy4Ga43A+KV2JoXTpaqkFrR8v0Zs6c6KtH9jK3hRhKmp27tV+YH9QxKZThL4xZKXpk5JujJkmSrx9jUBacWkPPoodkRdFTEfMKtXG0pT8aSWLSBi9VEmsvmVlH34Ngsb9cxpwaY+UkHRj5tSqOPXZKFWG/4NP9EJDVKCviboDZda7+CzRNLLFNicQcPgx++tqVJkNtT0cvI/qDvLWiHX5SerHvo2BMV743pU21UJ2r2oL0c0gDh/9T7a8XJ9wBSD0JUvt0KHpQKtvmS6Cwv6l81Xo2F5TmX+uK8lPu7IiZ2AgVyBIzIba3qIBCuerkn3AuX1LiGGqAr67gc99CNE5WMLzZCnSIw75dotD5UfZIkfV8cpiEuGpqzedRx3Ij++jzj0Z8JEagbG1sp1qXod7SsL0whQsanR9tMpQejD7mOfJ+MwQMYSI5irCYdNNjhZUGf+8cTlc8y1x8eSWmqOq/xfcc511Rlt+of/M1qICxiFJI1CRbZxDXFqkjriwSdLNh/B/zw/C/4xaDEUkk7McDGE2uU5ooRZ97dklcN3v2eVONr+5svfWqI+kwVl1q04Y51dINx2tUq3EhLN15eO4KUzaXacZK+s7q3muDb5wKWaMRDHL0oYkOsnVCjTOJhRDSYypzdkhRroamyoqs1cJPxSeyGg1iM6Rvrh0SYfcYliGo3AZ6GIeSoBeWA6NZEvY38mZt71nVyDh4K6+gb9k4ueI4Yf2AiSskyINHHBX2fZcC84e9/scdSEGR7DTB1YdxSPbPmNYNembalRiNvTyCe9Uutu7kmgFun1selBYVPUYO80YqpY+DHr9zKDDVrBouFOSmYYBjXICKj/4Nk/jrFFpiBW1O28igIa6AoVxOnMnJJC4U49Hn7h6E2LwSTynxoRoEwf8Z+UMoF0qjKtMlToNbByn5nbyzToCJTgjSwUZr1Ak0Ob+PzsQo+J9g+mg3NfvrLPtEp4NAawS/eMxzJY=
Content-Type: multipart/alternative; boundary="_000_PH0PR02MB74300975D1DEC40DB1CF1366B7A62PH0PR02MB7430namp_"
MIME-Version: 1.0
X-OriginatorOrg: sct-15-20-4755-11-msonline-outlook-3d941.templateTenant
X-MS-Exchange-CrossTenant-AuthAs: Internal
X-MS-Exchange-CrossTenant-AuthSource: PH0PR02MB7430.namprd02.prod.outlook.com
X-MS-Exchange-CrossTenant-RMS-PersistedConsumerOrg: 00000000-0000-0000-0000-000000000000
X-MS-Exchange-CrossTenant-Network-Message-Id: 6c8dd543-4c4b-4033-8257-08dca2cd8aff
X-MS-Exchange-CrossTenant-originalarrivaltime: 12 Jul 2024 23:51:26.3469 (UTC)
X-MS-Exchange-CrossTenant-fromentityheader: Hosted
X-MS-Exchange-CrossTenant-id: 84df9e7f-e9f6-40af-b435-aaaaaaaaaaaa
X-MS-Exchange-CrossTenant-rms-persistedconsumerorg: 00000000-0000-0000-0000-000000000000
X-MS-Exchange-Transport-CrossTenantHeadersStamped: SJ2PR02MB10049
Message-ID-Hash: IFXMW3FKV2QRESIYGLOHZYSC6QKQS55K
X-Message-ID-Hash: IFXMW3FKV2QRESIYGLOHZYSC6QKQS55K
X-MailFrom: michael_b_jones@hotmail.com
X-Mailman-Rule-Misses: dmarc-mitigation; no-senders; approved; emergency; loop; banned-address; member-moderation; header-match-jose.ietf.org-0; nonmember-moderation; administrivia; implicit-dest; max-recipients; max-size; news-moderation; no-subject; digests; suspicious-header
CC: JOSE WG <jose@ietf.org>, "jose-chairs@ietf.org" <jose-chairs@ietf.org>
X-Mailman-Version: 3.3.9rc4
Precedence: list
Subject: [jose] Re: Strawperson consensus call for changes to draft-ietf-jose-hpke-encrypt-01
List-Id: Javascript Object Signing and Encryption <jose.ietf.org>
Archived-At: <https://mailarchive.ietf.org/arch/msg/jose/OcnkjJsEnjJ9J0TSrhxxAuXT9sI>
List-Archive: <https://mailarchive.ietf.org/arch/browse/jose>
List-Help: <mailto:jose-request@ietf.org?subject=help>
List-Owner: <mailto:jose-owner@ietf.org>
List-Post: <mailto:jose@ietf.org>
List-Subscribe: <mailto:jose-join@ietf.org>
List-Unsubscribe: <mailto:jose-leave@ietf.org>

So Brian, its it then your position that JWE should support HPKE key encryption mode (which would use the AEAD algorithm specified by “enc”) but not HPKE integrated encryption mode, which operates directly on the plaintext without a separate content encryption key (CEK) – a mode for which there is no corresponding representation in RFC 7516 (hence some of the difficulties in this whole discussion)?

                                                                -- Mike

From: Brian Campbell <bcampbell=40pingidentity.com@dmarc.ietf.org>
Sent: Friday, July 12, 2024 3:11 PM
To: Orie Steele <orie@transmute.industries>
Cc: JOSE WG <jose@ietf.org>; jose-chairs@ietf.org
Subject: [jose] Re: Strawperson consensus call for changes to draft-ietf-jose-hpke-encrypt-01



On Wed, Jul 10, 2024 at 9:45 AM Orie Steele <orie@transmute.industries<mailto:orie@transmute.industries>> wrote:

### For HPKE JWE Integrated Encryption Mode:

The "enc" value SHALL be "dir".
The working group SHALL draft text explaining what "enc:dir" means, and how it related to "alg".

This doesn't work with RFC7516/JWE's definition of the "enc" header<https://datatracker.ietf.org/doc/html/rfc7516#section-4.1.2>, which states that the `enc` "(encryption algorithm) Header Parameter identifies the content encryption algorithm used to perform authenticated encryption on the plaintext to produce the ciphertext and the Authentication Tag. This algorithm MUST be an AEAD algorithm with a specified key length."





CONFIDENTIALITY NOTICE: This email may contain confidential and privileged material for the sole use of the intended recipient(s). Any review, use, distribution or disclosure by others is strictly prohibited.  If you have received this communication in error, please notify the sender immediately by e-mail and delete the message and any file attachments from your computer. Thank you.