Return-Path: <ietf@augustcellars.com>
X-Original-To: jose@ietfa.amsl.com
Delivered-To: jose@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix)
 with ESMTP id 5C58A11E8146 for <jose@ietfa.amsl.com>;
 Tue,  3 Sep 2013 15:15:46 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -3.456
X-Spam-Level: 
X-Spam-Status: No, score=-3.456 tagged_above=-999 required=5 tests=[AWL=0.142,
 BAYES_00=-2.599, HTML_MESSAGE=0.001, RCVD_IN_DNSWL_LOW=-1]
Received: from mail.ietf.org ([12.22.58.30]) by localhost (ietfa.amsl.com
 [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id awohMdgpzT5e for
 <jose@ietfa.amsl.com>; Tue,  3 Sep 2013 15:15:41 -0700 (PDT)
Received: from smtp3.pacifier.net (smtp3.pacifier.net [64.255.237.177]) by
 ietfa.amsl.com (Postfix) with ESMTP id A0D7E11E8143 for <jose@ietf.org>;
 Tue,  3 Sep 2013 15:15:41 -0700 (PDT)
Received: from Philemon (mail.augustcellars.com [50.34.17.238]) (using TLSv1
 with cipher AES128-SHA (128/128 bits)) (No client certificate requested)
 (Authenticated sender: jimsch@nwlink.com) by smtp3.pacifier.net (Postfix)
 with ESMTPSA id 4A04B38F2A; Tue,  3 Sep 2013 15:15:41 -0700 (PDT)
From: "Jim Schaad" <ietf@augustcellars.com>
To: "'Richard Barnes'" <rlb@ipv.sx>,
 "'Mike Jones'" <Michael.Jones@microsoft.com>
Date: Tue, 3 Sep 2013 15:14:31 -0700
Message-ID: <02d001cea8f2$f6e81540$e4b83fc0$@augustcellars.com>
MIME-Version: 1.0
Content-Type: multipart/alternative;
 boundary="----=_NextPart_000_02D1_01CEA8B8.4A8BD550"
X-Mailer: Microsoft Outlook 14.0
Thread-Index: Ac6o8sHOdbr6gaNmQfGCd1XXCSCpew==
Content-Language: en-us
Cc: jose@ietf.org
Subject: [jose] Mxed Signature Algorithm TYpes
X-BeenThere: jose@ietf.org
X-Mailman-Version: 2.1.12
Precedence: list
List-Id: Javascript Object Signing and Encryption <jose.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/jose>,
 <mailto:jose-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/jose>
List-Post: <mailto:jose@ietf.org>
List-Help: <mailto:jose-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/jose>,
 <mailto:jose-request@ietf.org?subject=subscribe>
X-List-Received-Date: Tue, 03 Sep 2013 22:15:46 -0000

This is a multipart message in MIME format.

------=_NextPart_000_02D1_01CEA8B8.4A8BD550
Content-Type: text/plain;
	charset="us-ascii"
Content-Transfer-Encoding: 7bit

A side question from this discussion that I would like to see addressed is
should we state any recommendations about mixing different types of
signatures algorithms in the same message.

 

I would think that it makes sense to say that type types "none", "mac" and
"asymmetric-Signature" should never be mixed in the same message because
these different types of algorithms have significantly different security
properties.

 

 

From: jose-bounces@ietf.org [mailto:jose-bounces@ietf.org] On Behalf Of
Richard Barnes
Sent: Tuesday, September 03, 2013 1:33 PM
To: Mike Jones
Cc: jose@ietf.org
Subject: Re: [jose] Text about applications and "alg":"none"

 

This text is still far too weak, and does not reflect what I remember EKR
saying (in particular, there is no MUST).  It does not address the attack
where an application may, in general, be willing to accept both signed and
unsigned content, but each in specific contexts.  Proposed text:

 

"""

JWS implementations MUST provide an interface for applications to specify a
list of "alg" values that are acceptable for the validation of a given JWS
object.  JWS implementations MUST NOT indicate that a JWS object is valid if
the "alg" value for the object is "none", unless the application has
specifically indicated that the value "none" is acceptable for the
particular JWS object being validated.  Applications using "none" MUST
indicate support on a per-object basis, in order to avoid downgrade attacks
that arise if more broadly-applicable preferences are specified.

"""

 

I continue to believe that this is far too subtle, and that applications are
very likely to get it wrong.  It is far simpler and safer to require that a
JWS implementation MUST reject an object with "alg":"none", and have another
content type for unsigned content.

 

Also, if "none" is going to remain, then it needs to be OPTIONAL.  Given all
the above limitations, I don't see how you could justify it being mandatory.

 

--Richard

 

 

On Tue, Sep 3, 2013 at 2:02 PM, Mike Jones <Michael.Jones@microsoft.com>
wrote:

I took an action item during the last call to write text along the lines
suggested by ekr about applications and "alg":"none".  I propose that the
following text be included:

 

It is RECOMMENDED that libraries provide applications a means of specifying
the list of acceptable algorithms used in a JWS object in a way that causes
inputs using algorithms outside the specified set to be rejected.  In
particular, it is intended for applications to use this mechanism to exclude
accepting inputs using "alg":"none" in security contexts where non-integrity
protected inputs are not acceptable.

 

Feedback/proposed wording refinements welcomed.

 

                                                                -- Mike

 


_______________________________________________
jose mailing list
jose@ietf.org
https://www.ietf.org/mailman/listinfo/jose

 


------=_NextPart_000_02D1_01CEA8B8.4A8BD550
Content-Type: text/html;
	charset="us-ascii"
Content-Transfer-Encoding: quoted-printable

<html xmlns:v=3D"urn:schemas-microsoft-com:vml" =
xmlns:o=3D"urn:schemas-microsoft-com:office:office" =
xmlns:w=3D"urn:schemas-microsoft-com:office:word" =
xmlns:m=3D"http://schemas.microsoft.com/office/2004/12/omml" =
xmlns=3D"http://www.w3.org/TR/REC-html40"><head><META =
HTTP-EQUIV=3D"Content-Type" CONTENT=3D"text/html; =
charset=3Dus-ascii"><meta name=3DGenerator content=3D"Microsoft Word 14 =
(filtered medium)"><style><!--
/* Font Definitions */
@font-face
	{font-family:Calibri;
	panose-1:2 15 5 2 2 2 4 3 2 4;}
@font-face
	{font-family:Tahoma;
	panose-1:2 11 6 4 3 5 4 4 2 4;}
/* Style Definitions */
p.MsoNormal, li.MsoNormal, div.MsoNormal
	{margin:0in;
	margin-bottom:.0001pt;
	font-size:12.0pt;
	font-family:"Times New Roman","serif";}
a:link, span.MsoHyperlink
	{mso-style-priority:99;
	color:blue;
	text-decoration:underline;}
a:visited, span.MsoHyperlinkFollowed
	{mso-style-priority:99;
	color:purple;
	text-decoration:underline;}
span.hoenzb
	{mso-style-name:hoenzb;}
span.EmailStyle18
	{mso-style-type:personal-reply;
	font-family:"Calibri","sans-serif";
	color:#1F497D;}
.MsoChpDefault
	{mso-style-type:export-only;
	font-family:"Calibri","sans-serif";}
@page WordSection1
	{size:8.5in 11.0in;
	margin:1.0in 1.0in 1.0in 1.0in;}
div.WordSection1
	{page:WordSection1;}
--></style><!--[if gte mso 9]><xml>
<o:shapedefaults v:ext=3D"edit" spidmax=3D"1026" />
</xml><![endif]--><!--[if gte mso 9]><xml>
<o:shapelayout v:ext=3D"edit">
<o:idmap v:ext=3D"edit" data=3D"1" />
</o:shapelayout></xml><![endif]--></head><body lang=3DEN-US link=3Dblue =
vlink=3Dpurple><div class=3DWordSection1><p class=3DMsoNormal><span =
style=3D'font-size:11.0pt;font-family:"Calibri","sans-serif";color:#1F497=
D'>A side question from this discussion that I would like to see =
addressed is should we state any recommendations about mixing different =
types of signatures algorithms in the same =
message.<o:p></o:p></span></p><p class=3DMsoNormal><span =
style=3D'font-size:11.0pt;font-family:"Calibri","sans-serif";color:#1F497=
D'><o:p>&nbsp;</o:p></span></p><p class=3DMsoNormal><span =
style=3D'font-size:11.0pt;font-family:"Calibri","sans-serif";color:#1F497=
D'>I would think that it makes sense to say that type types =
&#8220;none&#8221;, &#8220;mac&#8221; and =
&#8220;asymmetric-Signature&#8221; should never be mixed in the same =
message because these different types of algorithms have significantly =
different security properties.<o:p></o:p></span></p><p =
class=3DMsoNormal><span =
style=3D'font-size:11.0pt;font-family:"Calibri","sans-serif";color:#1F497=
D'><o:p>&nbsp;</o:p></span></p><p class=3DMsoNormal><span =
style=3D'font-size:11.0pt;font-family:"Calibri","sans-serif";color:#1F497=
D'><o:p>&nbsp;</o:p></span></p><div =
style=3D'border:none;border-left:solid blue 1.5pt;padding:0in 0in 0in =
4.0pt'><div><div style=3D'border:none;border-top:solid #B5C4DF =
1.0pt;padding:3.0pt 0in 0in 0in'><p class=3DMsoNormal><b><span =
style=3D'font-size:10.0pt;font-family:"Tahoma","sans-serif"'>From:</span>=
</b><span style=3D'font-size:10.0pt;font-family:"Tahoma","sans-serif"'> =
jose-bounces@ietf.org [mailto:jose-bounces@ietf.org] <b>On Behalf Of =
</b>Richard Barnes<br><b>Sent:</b> Tuesday, September 03, 2013 1:33 =
PM<br><b>To:</b> Mike Jones<br><b>Cc:</b> =
jose@ietf.org<br><b>Subject:</b> Re: [jose] Text about applications and =
&quot;alg&quot;:&quot;none&quot;<o:p></o:p></span></p></div></div><p =
class=3DMsoNormal><o:p>&nbsp;</o:p></p><div><p class=3DMsoNormal>This =
text is still far too weak, and does not reflect what I remember EKR =
saying (in particular, there is no MUST). &nbsp;It does not address the =
attack where an application may, in general, be willing to accept both =
signed and unsigned content, but each in specific contexts. =
&nbsp;Proposed text:<o:p></o:p></p><div><p =
class=3DMsoNormal><o:p>&nbsp;</o:p></p></div><div><p =
class=3DMsoNormal>&quot;&quot;&quot;<o:p></o:p></p></div><div><p =
class=3DMsoNormal>JWS implementations MUST provide an interface for =
applications to specify a list of &quot;alg&quot; values that are =
acceptable for the validation of a given JWS object. &nbsp;JWS =
implementations MUST NOT indicate that a JWS object is valid if the =
&quot;alg&quot; value for the object is &quot;none&quot;, unless the =
application has specifically indicated that the value &quot;none&quot; =
is acceptable for the particular JWS object being validated. =
&nbsp;Applications using &quot;none&quot; MUST indicate support on a =
per-object basis, in order to avoid downgrade attacks that arise if more =
broadly-applicable preferences are =
specified.<o:p></o:p></p></div><div><p =
class=3DMsoNormal>&quot;&quot;&quot;<o:p></o:p></p></div><div><p =
class=3DMsoNormal><o:p>&nbsp;</o:p></p></div><div><p class=3DMsoNormal>I =
continue to believe that this is far too subtle, and that applications =
are very likely to get it wrong. &nbsp;It is far simpler and safer to =
require that a JWS implementation MUST reject an object with =
&quot;alg&quot;:&quot;none&quot;, and have another content type for =
unsigned content.<o:p></o:p></p></div><div><p =
class=3DMsoNormal><o:p>&nbsp;</o:p></p></div><div><p =
class=3DMsoNormal>Also, if &quot;none&quot; is going to remain, then it =
needs to be OPTIONAL. &nbsp;Given all the above limitations, I don't see =
how you could justify it being mandatory.<o:p></o:p></p></div><div><p =
class=3DMsoNormal><o:p>&nbsp;</o:p></p></div><div><p =
class=3DMsoNormal>--Richard<o:p></o:p></p></div><div><p =
class=3DMsoNormal><o:p>&nbsp;</o:p></p></div></div><div><p =
class=3DMsoNormal =
style=3D'margin-bottom:12.0pt'><o:p>&nbsp;</o:p></p><div><p =
class=3DMsoNormal>On Tue, Sep 3, 2013 at 2:02 PM, Mike Jones &lt;<a =
href=3D"mailto:Michael.Jones@microsoft.com" =
target=3D"_blank">Michael.Jones@microsoft.com</a>&gt; =
wrote:<o:p></o:p></p><div><div><p class=3DMsoNormal =
style=3D'mso-margin-top-alt:auto;mso-margin-bottom-alt:auto'>I took an =
action item during the last call to write text along the lines suggested =
by ekr about applications and &quot;alg&quot;:&quot;none&quot;.&nbsp; I =
propose that the following text be included:<o:p></o:p></p><p =
class=3DMsoNormal =
style=3D'mso-margin-top-alt:auto;mso-margin-bottom-alt:auto'>&nbsp;<o:p><=
/o:p></p><p class=3DMsoNormal =
style=3D'mso-margin-top-alt:auto;mso-margin-bottom-alt:auto;margin-left:.=
5in'>It is RECOMMENDED that libraries provide applications a means of =
specifying the list of acceptable algorithms used in a JWS object in a =
way that causes inputs using algorithms outside the specified set to be =
rejected.&nbsp; In particular, it is intended for applications to use =
this mechanism to exclude accepting inputs using =
&quot;alg&quot;:&quot;none&quot; in security contexts where =
non-integrity protected inputs are not acceptable.<o:p></o:p></p><p =
class=3DMsoNormal =
style=3D'mso-margin-top-alt:auto;mso-margin-bottom-alt:auto'>&nbsp;<o:p><=
/o:p></p><p class=3DMsoNormal =
style=3D'mso-margin-top-alt:auto;mso-margin-bottom-alt:auto'>Feedback/pro=
posed wording refinements welcomed.<o:p></o:p></p><p class=3DMsoNormal =
style=3D'mso-margin-top-alt:auto;mso-margin-bottom-alt:auto'><span =
style=3D'color:#888888'>&nbsp;<o:p></o:p></span></p><p class=3DMsoNormal =
style=3D'mso-margin-top-alt:auto;mso-margin-bottom-alt:auto'><span =
style=3D'color:#888888'>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&=
nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&n=
bsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nb=
sp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbs=
p;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp=
;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; -- Mike<o:p></o:p></span></p><p =
class=3DMsoNormal =
style=3D'mso-margin-top-alt:auto;mso-margin-bottom-alt:auto'><span =
style=3D'color:#888888'>&nbsp;<o:p></o:p></span></p></div></div><p =
class=3DMsoNormal =
style=3D'margin-bottom:12.0pt'><br>______________________________________=
_________<br>jose mailing list<br><a =
href=3D"mailto:jose@ietf.org">jose@ietf.org</a><br><a =
href=3D"https://www.ietf.org/mailman/listinfo/jose" =
target=3D"_blank">https://www.ietf.org/mailman/listinfo/jose</a><o:p></o:=
p></p></div><p =
class=3DMsoNormal><o:p>&nbsp;</o:p></p></div></div></div></body></html>
------=_NextPart_000_02D1_01CEA8B8.4A8BD550--

