Re: [jose] Platform Support for JWA Crypto Algorithms

Wan-Teh Chang <wtc@google.com> Wed, 31 October 2012 17:00 UTC

Return-Path: <wtc@google.com>
X-Original-To: jose@ietfa.amsl.com
Delivered-To: jose@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id DF89221F877B for <jose@ietfa.amsl.com>; Wed, 31 Oct 2012 10:00:52 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -102.977
X-Spam-Level:
X-Spam-Status: No, score=-102.977 tagged_above=-999 required=5 tests=[BAYES_00=-2.599, FM_FORGED_GMAIL=0.622, RCVD_IN_DNSWL_LOW=-1, USER_IN_WHITELIST=-100]
Received: from mail.ietf.org ([64.170.98.30]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id MkFPlUazkgic for <jose@ietfa.amsl.com>; Wed, 31 Oct 2012 10:00:52 -0700 (PDT)
Received: from mail-ie0-f172.google.com (mail-ie0-f172.google.com [209.85.223.172]) by ietfa.amsl.com (Postfix) with ESMTP id 382D321F872C for <jose@ietf.org>; Wed, 31 Oct 2012 10:00:46 -0700 (PDT)
Received: by mail-ie0-f172.google.com with SMTP id 9so2738299iec.31 for <jose@ietf.org>; Wed, 31 Oct 2012 10:00:45 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=20120113; h=mime-version:in-reply-to:references:date:message-id:subject:from:to :cc:content-type:x-system-of-record; bh=6pvfWbocKoggoVdY0lYe6dzSK/YV395euScaw3bmjZc=; b=YsjkYA9zAhoP3y80kTaqOn+Ln1G+vQo+mdZDJqQ0NDJ2jUgWIT4lW9jGZbIoK7oV9z XwsbILIk+OTKM+SWsxbAeIgBO7N/CkvcU2rpA9iMqeN4eNFfV7sqgVmrf75SRpyDIrEy dJREPyJ7CC/nfpo80gtPMl9727UJwaBSX8jcFdhq8etOWQfijVXh7Yfqi6ATowLfMnyn z98cMt57Y+pkde3+Hgn+EnLLUSzal2l9mPy6SqWeT4QFLFyuywB8RW1pLdBnO6gvBP7f kC9mTFZoPjs+U2mwodsSv4u5gRjyk+pvbCuNr/G7sIjTwcxokqG6mFfisIavv7L951+u d6LA==
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=20120113; h=mime-version:in-reply-to:references:date:message-id:subject:from:to :cc:content-type:x-system-of-record:x-gm-message-state; bh=6pvfWbocKoggoVdY0lYe6dzSK/YV395euScaw3bmjZc=; b=lnm1j1UOU3DsfAIC042DNvvIbAkuasAYduot2CtHyu/P/21JPqCbVromYIiSfMOewt P8nzkPkFMzTBd5TckL+HzpbX2+c8Jrx8WCaXv+xGvSDS2+lY3Pmog5q1AZRzlo3L4iwD EDbN6kvBQp920dzg2XbdEdL/AZX4LOzCv42HHz7xNBtmJ1dNlPuv1Z4lC4C3gQee5FSl m+6a/tplwr/btU2SYSpz2Xp6Y1HggEG4UVw12tCnHahoDx9BnACJop+O23MHpmO7XYiD I6FpbcTX80G1tQnAD0RTAMqRCe3Q/mccYQgohjYmvgJEPsCoCIXmdILIegOx0UkYBzIc bK2g==
MIME-Version: 1.0
Received: by 10.50.5.239 with SMTP id v15mr2272657igv.41.1351702845763; Wed, 31 Oct 2012 10:00:45 -0700 (PDT)
Received: by 10.231.6.83 with HTTP; Wed, 31 Oct 2012 10:00:45 -0700 (PDT)
In-Reply-To: <CACvaWvZaBgsBsMMLY0CXr4nAPgYkC9GqJr1Y5y9gQH_d4OWcJA@mail.gmail.com>
References: <4E1F6AAD24975D4BA5B168042967394366880D09@TK5EX14MBXC285.redmond.corp.microsoft.com> <CE8995AB5D178F44A2154F5C9A97CAF40252198DCF55@HE111541.emea1.cds.t-internal.com> <4E1F6AAD24975D4BA5B16804296739436688123A@TK5EX14MBXC285.redmond.corp.microsoft.com> <CE8995AB5D178F44A2154F5C9A97CAF40252199B9114@HE111541.emea1.cds.t-internal.com> <CACvaWvZaBgsBsMMLY0CXr4nAPgYkC9GqJr1Y5y9gQH_d4OWcJA@mail.gmail.com>
Date: Wed, 31 Oct 2012 10:00:45 -0700
Message-ID: <CALTJjxF80RCv-b=GGJo6VQnUY8JSP6QP4AAE0FrU0DwORktbjw@mail.gmail.com>
From: Wan-Teh Chang <wtc@google.com>
To: Ryan Sleevi <sleevi@google.com>
Content-Type: text/plain; charset="ISO-8859-1"
X-System-Of-Record: true
X-Gm-Message-State: ALoCoQlXf218TWz5n/1ueUOclgJk3ItvtkSAkrcERSeu54GsCHhosd6zBKQ0lap818xL9kKRTPeBoapuHLR/ieil9j7t+ARu/MU7vAjjSrnXdbIz0kX7A6IQfv0+gexqCdHpDc2cQgSjr5k1keEIC++rYKBZydx8SehxTZY09U/YeLiE6QProISzSlQl2jwrS39Mtxi+TNLP
X-Mailman-Approved-At: Wed, 31 Oct 2012 13:34:29 -0700
Cc: Michael.Jones@microsoft.com, jose@ietf.org, Axel.Nennker@telekom.de, public-webcrypto@w3.org
Subject: Re: [jose] Platform Support for JWA Crypto Algorithms
X-BeenThere: jose@ietf.org
X-Mailman-Version: 2.1.12
Precedence: list
List-Id: Javascript Object Signing and Encryption <jose.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/jose>, <mailto:jose-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/jose>
List-Post: <mailto:jose@ietf.org>
List-Help: <mailto:jose-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/jose>, <mailto:jose-request@ietf.org?subject=subscribe>
X-List-Received-Date: Wed, 31 Oct 2012 17:00:53 -0000

On Mon, Oct 29, 2012 at 4:23 PM, Ryan Sleevi <sleevi@google.com> wrote:
>
> However, as an NSS developer, I do not see your presented argument as a
> reason not to use Concat-KDF, and Concat-KDF would be more preferable, as a
> NIST-blessed KDF, since NSS cares especially for NIST-blessed algorithms.

I think HKDF (hash-based key derivation function) is also worth considering.
It is specified in RFC 5869 and is also blessed by NIST in SP 800-56C.

Wan-Teh