Re: [jose] draft-jones-cose-rsa

Mike Jones <Michael.Jones@microsoft.com> Fri, 13 January 2017 22:56 UTC

Return-Path: <Michael.Jones@microsoft.com>
X-Original-To: jose@ietfa.amsl.com
Delivered-To: jose@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 9A5CC129F01 for <jose@ietfa.amsl.com>; Fri, 13 Jan 2017 14:56:53 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.022
X-Spam-Level:
X-Spam-Status: No, score=-2.022 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, RCVD_IN_DNSWL_NONE=-0.0001, RCVD_IN_MSPIKE_H4=-0.01, RCVD_IN_MSPIKE_WL=-0.01, SPF_HELO_PASS=-0.001, SPF_PASS=-0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (1024-bit key) header.d=microsoft.com
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id lHoCrjGq9HiB for <jose@ietfa.amsl.com>; Fri, 13 Jan 2017 14:56:51 -0800 (PST)
Received: from NAM03-DM3-obe.outbound.protection.outlook.com (mail-dm3nam03on0100.outbound.protection.outlook.com [104.47.41.100]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id BBD4A129972 for <jose@ietf.org>; Fri, 13 Jan 2017 14:56:51 -0800 (PST)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=microsoft.com; s=selector1; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version; bh=lAi6+WpnVsQ0kPJ6RwlBYFBl8CISnU4rt1k+vr/pTN4=; b=fKULLuut4Fgx16AoVrRms6nwT0LmYnCZ5A57+Et+8PB4+c312t/d6teLFJI6Vp0AmKfGnwJ20IMq36mn7SR9bRWMnwX4NvN8TF0j8MiJS005bkBZB7v+2ypZsvKO1yz2iFdDMnGCMz3ZQv8NOSYHGi3vTMRCHAFN90UBrUuktGw=
Received: from BN3PR03MB2355.namprd03.prod.outlook.com (10.166.74.150) by BN3PR03MB2355.namprd03.prod.outlook.com (10.166.74.150) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_CBC_SHA384_P384) id 15.1.845.12; Fri, 13 Jan 2017 22:56:50 +0000
Received: from BN3PR03MB2355.namprd03.prod.outlook.com ([10.166.74.150]) by BN3PR03MB2355.namprd03.prod.outlook.com ([10.166.74.150]) with mapi id 15.01.0845.013; Fri, 13 Jan 2017 22:56:50 +0000
From: Mike Jones <Michael.Jones@microsoft.com>
To: Jim Schaad <ietf@augustcellars.com>, "draft-jones-cose-rsa@tools.ietf.org" <draft-jones-cose-rsa@tools.ietf.org>
Thread-Topic: [jose] draft-jones-cose-rsa
Thread-Index: AdJj3G5A8Mg3MokbT1CbCGHSigaDpAKE9UzA
Date: Fri, 13 Jan 2017 22:56:49 +0000
Message-ID: <BN3PR03MB2355749014ECDDD53EF9DDA3F5780@BN3PR03MB2355.namprd03.prod.outlook.com>
References: <012d01d26487$8fb4d080$af1e7180$@augustcellars.com>
In-Reply-To: <012d01d26487$8fb4d080$af1e7180$@augustcellars.com>
Accept-Language: en-US
Content-Language: en-US
X-MS-Has-Attach:
X-MS-TNEF-Correlator:
authentication-results: spf=none (sender IP is ) smtp.mailfrom=Michael.Jones@microsoft.com;
x-originating-ip: [2001:4898:80e8:f::7c0]
x-ms-office365-filtering-correlation-id: 6eea074a-a223-4320-637e-08d43c07758f
x-microsoft-antispam: UriScan:;BCL:0;PCL:0;RULEID:(22001);SRVR:BN3PR03MB2355;
x-microsoft-exchange-diagnostics: 1; BN3PR03MB2355; 7:ncMAt1RYF9ClM3NwRCkgbzuVA2lkpX5b00xB8Y8Rwg08gJX/5n6vzopyKSrHakG/8LGGdzGQkgCHUAxzJr5Fe9RFaoU/ojRnipDdJnEoGeqSN/3TlRltUXqbPuXZPzSKazx0g65iK6VRobGF7leBVwdZMnjwPeCWA868jiddLYsSSMRAbnVUrtM1kRn/4piL6r9t5sqHdJOOylidkR2NBcam7nexKd0yFymG35DsAGDZqqezb7viHabVzjYXO9zgS33nY9G1rJnTyLd3sTBWUmvLMB6QCa0wS89InL7mOgFE2tsLDrK1j23G5o46JdZPZPY4iQ6U7gW/zjEcZA8FDuodNThh0H+ofTZCEyGG9+acNfBNapzp1gM1acl9eJ4Xwv9U1xHkCw2Az2a4tZ9P6LSxNFpEruay6U/HrVljdok2vviUggNvM1QfDfcJ6dtF1mg65aUtpMrUMKVhlx8mdMimIR97rWmP/Uf1SGs8X3c=
x-microsoft-antispam-prvs: <BN3PR03MB235552CC1270A124212836B1F5780@BN3PR03MB2355.namprd03.prod.outlook.com>
x-exchange-antispam-report-test: UriScan:(192374486261705);
x-exchange-antispam-report-cfa-test: BCL:0; PCL:0; RULEID:(61425038)(6040375)(601004)(2401047)(5005006)(8121501046)(3002001)(10201501046)(6055026)(61426038)(61427038)(6041248)(20161123562025)(20161123555025)(20161123564025)(20161123560025)(6072148)(6047074)(6042181); SRVR:BN3PR03MB2355; BCL:0; PCL:0; RULEID:; SRVR:BN3PR03MB2355;
x-forefront-prvs: 018632C080
x-forefront-antispam-report: SFV:NSPM; SFS:(10019020)(6009001)(7916002)(377454003)(199003)(189002)(69234005)(13464003)(97736004)(2900100001)(6306002)(99286003)(189998001)(68736007)(6436002)(38730400001)(55016002)(77096006)(5001770100001)(10090500001)(25786008)(92566002)(3280700002)(9686003)(5660300001)(229853002)(2906002)(81156014)(7736002)(2950100002)(305945005)(81166006)(86362001)(122556002)(6116002)(230783001)(4326007)(2501003)(3660700001)(33656002)(74316002)(5005710100001)(8936002)(101416001)(8990500004)(6506006)(8676002)(86612001)(102836003)(54356999)(50986999)(76176999)(106356001)(105586002)(7696004)(27001)(10290500002); DIR:OUT; SFP:1102; SCL:1; SRVR:BN3PR03MB2355; H:BN3PR03MB2355.namprd03.prod.outlook.com; FPR:; SPF:None; PTR:InfoNoRecords; A:1; MX:1; LANG:en;
received-spf: None (protection.outlook.com: microsoft.com does not designate permitted sender hosts)
spamdiagnosticoutput: 1:99
spamdiagnosticmetadata: NSPM
Content-Type: text/plain; charset="us-ascii"
Content-Transfer-Encoding: quoted-printable
MIME-Version: 1.0
X-OriginatorOrg: microsoft.com
X-MS-Exchange-CrossTenant-originalarrivaltime: 13 Jan 2017 22:56:49.9130 (UTC)
X-MS-Exchange-CrossTenant-fromentityheader: Hosted
X-MS-Exchange-CrossTenant-id: 72f988bf-86f1-41af-91ab-2d7cd011db47
X-MS-Exchange-Transport-CrossTenantHeadersStamped: BN3PR03MB2355
Archived-At: <https://mailarchive.ietf.org/arch/msg/jose/Y8Vg39SMoWhulUtYJJsmaeK7Bug>
Cc: "jose@ietf.org" <jose@ietf.org>
Subject: Re: [jose] draft-jones-cose-rsa
X-BeenThere: jose@ietf.org
X-Mailman-Version: 2.1.17
Precedence: list
List-Id: Javascript Object Signing and Encryption <jose.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/jose>, <mailto:jose-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/jose/>
List-Post: <mailto:jose@ietf.org>
List-Help: <mailto:jose-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/jose>, <mailto:jose-request@ietf.org?subject=subscribe>
X-List-Received-Date: Fri, 13 Jan 2017 22:56:53 -0000

FYI, I replied to this on the COSE mailing list.

				-- Mike

-----Original Message-----
From: jose [mailto:jose-bounces@ietf.org] On Behalf Of Jim Schaad
Sent: Sunday, January 01, 2017 3:34 PM
To: draft-jones-cose-rsa@tools.ietf.org
Cc: jose@ietf.org
Subject: [jose] draft-jones-cose-rsa

Comments:

0.  Should this be done in curdle rather than as AD sponsored?

1.  As per previous mail, remove values assignments in tables 1, 2, and 3 unless you have cleared them with the appropriate registry experts.  I am less worried about table 4 but you should clear that as well.

2.  Kill RSAES-OAP w/ SHA-1.  We are not doing SHA-1 currently with any of the CBOR algorithms.  In section 3.1.1.1 - what are the properties that are needed here for SHA-1 so we can ensure that the statement is true.  Also, rename this to be s/ SHA-1 not w/ Default.  There are no defaults for COSE.

3.  Text in 3.1.1.1 and 2.1.1 should be more consistent in how it is written.

4. in the abstract be more specific about which RSA algorithms are being supported.  For example, you are not doing 1.5 or KEM.

5.  Why does 3.1.1.1 have a size and 2.1.1 not have one.  This should be consistent.

6.  section 3.1.1.1 should be encryption operation not decryption operation.

7.  Section 3.1.1.1 - this text does not make sense "One potential denial of service
   operation is to provide encrypted objects using either abnormally
   long or oddly sized RSA modulus values."   Should probably refer to keys
not encrypted objects.

8.  There is a requirement of minimum encoding lengths - what purpose does this serve?  Is there a security problem here or is it just a nice to have because of message size?

9. Missing some security considerations.

10 Section 2.1.1 s/hash functions are not truncated/hash function outputs are not truncated/




_______________________________________________
jose mailing list
jose@ietf.org
https://www.ietf.org/mailman/listinfo/jose