Re: [jose] Calls for adoption: Web Proof Drafts

Brent Kimberley <Brent.Kimberley@Durham.ca> Thu, 30 March 2023 02:22 UTC

Return-Path: <Brent.Kimberley@Durham.ca>
X-Original-To: jose@ietfa.amsl.com
Delivered-To: jose@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 8E451C19E11B for <jose@ietfa.amsl.com>; Wed, 29 Mar 2023 19:22:39 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.995
X-Spam-Level:
X-Spam-Status: No, score=-1.995 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, HTML_MESSAGE=0.001, HTTPS_HTTP_MISMATCH=0.1, RCVD_IN_DNSWL_BLOCKED=0.001, RCVD_IN_ZEN_BLOCKED_OPENDNS=0.001, SPF_PASS=-0.001, URIBL_BLOCKED=0.001, URIBL_DBL_BLOCKED_OPENDNS=0.001, URIBL_ZEN_BLOCKED_OPENDNS=0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (2048-bit key) header.d=durham.ca
Received: from mail.ietf.org ([50.223.129.194]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id dBSikSZI_qSH for <jose@ietfa.amsl.com>; Wed, 29 Mar 2023 19:22:35 -0700 (PDT)
Received: from CAN01-YQB-obe.outbound.protection.outlook.com (mail-yqbcan01on20608.outbound.protection.outlook.com [IPv6:2a01:111:f403:7052::608]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 86B1BC153CBF for <jose@ietf.org>; Wed, 29 Mar 2023 19:22:13 -0700 (PDT)
ARC-Seal: i=1; a=rsa-sha256; s=arcselector9901; d=microsoft.com; cv=none; b=PdV0jWM81QwAk1H4XUVr1nEntVpRRtKH0EePjiosqx7cxH62+Ipt9QVrHcwPHDS7woNWU+8+lSZfxP0FrgUxbn0TjY+Val4fBXL5ELf7drNmVdWdI3zLUD9g+G77atNhkRcTpS7YG1lUskP9cb5XlNwlMZty5SwbKLqmUhqvq9x/l9QzgE9m8LfZOuFvkV+8isYrSLe/U3Xw/Z7zZ5Rpxzt1tmFURFP0PcMjdOx3j37jzVfobxhw4JdIqn5i1UpZJlSgPEtaw6sTJLOKpy0XEJv9NYp//EQe7/AVxZbzYFeMbjZOTKoEwcvvSngQcUqALq6VX9hxL4H++Xfy19la0A==
ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=microsoft.com; s=arcselector9901; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-AntiSpam-MessageData-ChunkCount:X-MS-Exchange-AntiSpam-MessageData-0:X-MS-Exchange-AntiSpam-MessageData-1; bh=uQ79+e0vgAQDVB6rCqplQmYs4Zno8TBuG/2ysGcHbD4=; b=FHuTAgfblWC2DwZZCnlg4LrIuzLSoj2lmQ9TCJbFNkT87It7H2ZyxAgBVg9XJsckpl/COGizrowVP1P/a6wPjhCuEGZ9m075rDw/5pzaOxAkh6O3SffpYnchRnYYQYmovadoyOfiyN5vqxXjvinQk6tbB/IgquZzILR0dVWcPRcmaOi+daXxV72Ar+clqrpvYIzkyruVPIQLerw+Nc71uB5/6R5MsvxzA7aWkeD8JCZT30+77dXAcmLURoGd0/ZDF4DltCRXYEz9fpRCuLWjiWcKEAY2W575Uu3Fs/HRzF1f9WYC56u60wLiyTMGESDKSYRCTNk+SKFW6PO+kqzYmg==
ARC-Authentication-Results: i=1; mx.microsoft.com 1; spf=pass smtp.mailfrom=durham.ca; dmarc=pass action=none header.from=durham.ca; dkim=pass header.d=durham.ca; arc=none
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=durham.ca; s=selector2; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-SenderADCheck; bh=uQ79+e0vgAQDVB6rCqplQmYs4Zno8TBuG/2ysGcHbD4=; b=nnYsIe/gjuK7JwdgAPsLfInEFQe9KiyA7LVI/HFuJr3FYlcE5QHeeAQHgMmP2fTrDMu+ieA/13PFBMVGWj08Jn5e0IgkBOjPyluhmghKgmPHkGhEVvGSf6G/g8DprajcyAyOjff9wvmsJzp1wzUWY4vZdcfPEozszGPD9BGU7jaPXqIjQjUkyTE9njQEGQo+VDr2NcysmJUiWJ2Zd9OuEpRZSDWwUJVdJbx30y+5d6X8EWScPKXON3ZAzj8kcOaF/ecpB9ZHoGpAdTsG1R3IIMkKo+uIB5VeDgq+78UCCMgXWtR37oLlaO8u6rnEFZuRSmmH7s7OBYJbE3Vqdzx8Sg==
Received: from YT1PR01MB4187.CANPRD01.PROD.OUTLOOK.COM (2603:10b6:b01:2a::21) by YQBPR0101MB5925.CANPRD01.PROD.OUTLOOK.COM (2603:10b6:c01:34::9) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.20.6222.35; Thu, 30 Mar 2023 02:22:10 +0000
Received: from YT1PR01MB4187.CANPRD01.PROD.OUTLOOK.COM ([fe80::1f3b:9475:8d45:e935]) by YT1PR01MB4187.CANPRD01.PROD.OUTLOOK.COM ([fe80::1f3b:9475:8d45:e935%4]) with mapi id 15.20.6222.030; Thu, 30 Mar 2023 02:22:09 +0000
From: Brent Kimberley <Brent.Kimberley@Durham.ca>
To: Brent Zundel <Brent.Zundel@gendigital.com>, Karen O'Donoghue <odonoghue=40isoc.org@dmarc.ietf.org>, "jose@ietf.org" <jose@ietf.org>
Thread-Topic: [jose] Calls for adoption: Web Proof Drafts
Thread-Index: AQHZYnDwXJVgo+TslUK9vynZm3VnuK8SIL2wgAB1ESw=
Date: Thu, 30 Mar 2023 02:22:09 +0000
Message-ID: <YT1PR01MB41871456507C69E49BD4C7BDFA8E9@YT1PR01MB4187.CANPRD01.PROD.OUTLOOK.COM>
References: <PH0PR06MB706176DD204231811C0271D7C2889@PH0PR06MB7061.namprd06.prod.outlook.com> <SJ0PR13MB59688703D85337B6D39023F4EE899@SJ0PR13MB5968.namprd13.prod.outlook.com> <YT1PR01MB41871264924A9CF4FAEFC589FA899@YT1PR01MB4187.CANPRD01.PROD.OUTLOOK.COM>
In-Reply-To: <YT1PR01MB41871264924A9CF4FAEFC589FA899@YT1PR01MB4187.CANPRD01.PROD.OUTLOOK.COM>
Accept-Language: en-CA, en-US
Content-Language: en-CA
X-MS-Has-Attach:
X-MS-TNEF-Correlator:
authentication-results: dkim=none (message not signed) header.d=none;dmarc=none action=none header.from=Durham.ca;
x-ms-publictraffictype: Email
x-ms-traffictypediagnostic: YT1PR01MB4187:EE_|YQBPR0101MB5925:EE_
x-ms-office365-filtering-correlation-id: 871d4b01-9a35-4e77-03f4-08db30c590cf
x-ms-exchange-senderadcheck: 1
x-ms-exchange-antispam-relay: 0
x-microsoft-antispam: BCL:0;
x-microsoft-antispam-message-info: FHhyNC68dBlN4BstzKdrkUHsekcevynfZx5dylIe2P5btobUsNAcxToQNGTNnkl1PPnYyWZhI9MZSbnHH48nqsXu7AVBr1FcfUnr9Fdutk07dRRA8lOM2gzcyk+t9b5guneNO94yOj7VHWSbSbnH6FgIhO4u5D0rx/1Inc0PHzRSA8rPP8HgYl/pIdcQPEDv0ub3a0ub7puRaPyAac2kiu11VR5zBlCPYsrsKF1q13VhUglprWWg9WPkehp18dIxUmtMp8CIgFjGoPw7wBZz+0Y9dOACRDaoYOQiAwCZ6O5QBm+9UITrDWWFSEXra/7+Va1p04b/0LJ9Tco+z8MrBBclujPXHLKMJwUHzd0nUCnZFC0Yw8+5tdwTW2SRA2dtuNwmyMVnpKHMwKlAEDXqaLlSjTxOBZtkWMOfcbeAXnCdf8KZsWZ1l7C+fBotlvumy3bBK2bTVr0IBBmTeFQvHIni+YWv2JEbqmc5JQPMF6vZLIt2YjP1paW9iRKWPNsbviya4rO4+aCmhI72X0YMCklLrEocp4CJCbDlSIZwxZnJDtlK51L6Ah9r1I7M3wP8Zd2opt8weRpCWczVnX2dxSQv883hH7crG8Br/mqsqYs=
x-forefront-antispam-report: CIP:255.255.255.255; CTRY:; LANG:en; SCL:1; SRV:; IPV:NLI; SFV:NSPM; H:YT1PR01MB4187.CANPRD01.PROD.OUTLOOK.COM; PTR:; CAT:NONE; SFS:(13230028)(4636009)(346002)(39860400002)(366004)(376002)(136003)(396003)(451199021)(9686003)(6506007)(83380400001)(53546011)(71200400001)(45080400002)(7696005)(478600001)(64756008)(110136005)(26005)(66446008)(316002)(66556008)(186003)(66946007)(8676002)(19627235002)(66476007)(41300700001)(76116006)(2906002)(5660300002)(8936002)(166002)(122000001)(38070700005)(38100700002)(966005)(52536014)(86362001)(33656002)(66899021)(55016003); DIR:OUT; SFP:1101;
x-ms-exchange-antispam-messagedata-chunkcount: 1
x-ms-exchange-antispam-messagedata-0: KMztmWurLOfIUQf+ORmSXVIO+hIkEUDY2MI35PhdU494ginRkh7zDnfYeFfGh7MmuX0nGY36AIzzydG//gsoEQiSpR89pEa+YwC9OBhAQQ0YnP9JsaIiJakEUkPYqpC1SIEegllgRxzaRyrHoMI6NGKsRSLxjHVN27iSk3iJoZK2ef9b5oKkSooJcKQBBDN20M4ra4CGB5jxFViytkCO4BVW1wQ3W10Dd51tBq8SHA42U05/Ttwf2PnFYYrvSXleMwlxkZEVijo794lKrDMAItBE0Gbw7E0bUfqsly4MkDeN8TOsfBQ26qbgp4rmOqw/We89MQb7vPV5l1mrJHljAKZ3s2bj2OM5Nk6huWOsmhMkldvAl8s0X8/D2Ja8rTmLLATQLAdIi2aA87vdte3Tplab657Jdqgtir0N2CGXcwtLIFbzQGkb0Nbf+e3cyVW53LgbhrdcwFFDFNmk1jBi7qxsRTtX7J50Cy9WlBvgB2OEUtVpaI72Sbwo2OOCiTkycNQEenBmCy+VkPEAPqk9yXYKEEfloBn66Dx8gyuqBYYhYeeDwGA3sLhH1cOt6QO/VYDubS44uRJ9BiJnM1bMhNoy2bXGL7A+r9XyyyJ4pAxor3MkY0OXzD7A33lZi3itOzy+ugrs9IH7c4mghAfScVA4VDF+15luMv96L5JKN/c79K5wllNRKOrXXHtlDEMPtoLowcgA2dj0cPj5rJqt/RCZlvGgwzHIDoTMCR9raygGB/3nenhaQu9gICfEC5PqEOAxkxEo7Ujl3Qp3wT3Hcr6XxtaxULW0EwR/6t3hoYAL5vTupELyyTuxL/WOamCaeIDP0Xt4bZkxBEO4hApTXneJw57E3s7ogcWIAGoibq1t2vTgmykRgCDGL75/sbuJyUNzpwSfKjRYVCAYA6vuIOYYc0ydgAhYzyIR07QLqGmaUQ4O8XzLmo8LPcHrnlNRUeqDBsgU++ren2gVHzoPcbAaTFSXvhG0otYnwl4YL1iDjGwYV1Bu38r2NxglF1Z1OOTAUaygg9nXYWSfqiP0ej+EaMn5UdmowzXhUz5i/h+9WEgWpsO2/kFuneGNaFoFD6V4gyGSkVWIYi3u8dYghDyU1GsOqLI8wt6Xk2Ent7MrKJz0Nj4EKGPnGzT2kPmdz4vARrSMWHa+mVE1//J2zg2j0dlwo2W0XBnxWRBbrJUgHQzeXQl4sPrBcU3L/pUoiSKzuiMDGyibmOsjWdqpW8dWzFe6VbfBxu0XjiSQng7+jL+3IjoryyNc9jNDnPsN1tpw17AOThQ+73bFO5yooaucPRrbnVeaGrAHEhRPj13yOrnxawk6p1+YnlsfBhyyGY5FiViudMyrrTegPizaErIds4q7uTvFh+SrFt+3WJJajKhmmwm5bZR60PdsK7DXMwLW8lfqJK/qJDAnZGrOnRkS9u9S+tD53WsG4xTwC9jMDg6pBKCqkNHBtpd8DQBzS4neoFiKJuW+q+uTGxFlBFYo/XEjZ/Q1azsRyYVeR9Hcc/abb9fgEwwvElHtqIsK7azZ3LcA1azgc2IYqGF6/LaAx6eTtX6rlcRCb+G/p9wd3ZecT0RwH3yvzoGwDHdU0+KY5hN2e3wiLYfNnahvaFlTRGdwbDpz+G8hg3G/Kps=
Content-Type: multipart/alternative; boundary="_000_YT1PR01MB41871456507C69E49BD4C7BDFA8E9YT1PR01MB4187CANP_"
MIME-Version: 1.0
X-OriginatorOrg: durham.ca
X-MS-Exchange-CrossTenant-AuthAs: Internal
X-MS-Exchange-CrossTenant-AuthSource: YT1PR01MB4187.CANPRD01.PROD.OUTLOOK.COM
X-MS-Exchange-CrossTenant-Network-Message-Id: 871d4b01-9a35-4e77-03f4-08db30c590cf
X-MS-Exchange-CrossTenant-originalarrivaltime: 30 Mar 2023 02:22:09.8887 (UTC)
X-MS-Exchange-CrossTenant-fromentityheader: Hosted
X-MS-Exchange-CrossTenant-id: 52d7c9c2-d549-41b6-9b1f-9da198dc3f16
X-MS-Exchange-CrossTenant-mailboxtype: HOSTED
X-MS-Exchange-CrossTenant-userprincipalname: 04tDyWavSO+phP1Fi6VfXkRyfCzrRQU4sCKE8AvCwfN6TrI7mEkk/YVAgBAUs617CuU80s+EEeh0DSnWBQsprwHkChBoFr+vGwzWendW7/M=
X-MS-Exchange-Transport-CrossTenantHeadersStamped: YQBPR0101MB5925
Archived-At: <https://mailarchive.ietf.org/arch/msg/jose/aevwhjNzCgPi6bWv00cf54ht_ko>
Subject: Re: [jose] Calls for adoption: Web Proof Drafts
X-BeenThere: jose@ietf.org
X-Mailman-Version: 2.1.39
Precedence: list
List-Id: Javascript Object Signing and Encryption <jose.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/jose>, <mailto:jose-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/jose/>
List-Post: <mailto:jose@ietf.org>
List-Help: <mailto:jose-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/jose>, <mailto:jose-request@ietf.org?subject=subscribe>
X-List-Received-Date: Thu, 30 Mar 2023 02:22:40 -0000

Please disregard.  If SHAKE128 is as strong as sha256 and if SHAKE256 is stronger than sha384 then nothing to see, let's move along

https://www.ietf.org/archive/id/draft-jmiller-jose-json-proof-algorithms-01.html
________________________________
From: Brent Kimberley
Sent: Wednesday, March 29, 2023 3:22:25 PM
To: Brent Zundel <Brent.Zundel@gendigital.com>; Karen O'Donoghue <odonoghue=40isoc.org@dmarc.ietf.org>; jose@ietf.org <jose@ietf.org>
Subject: RE: [jose] Calls for adoption: Web Proof Drafts


I’m about a week late, but I feel compelled to ask…



Earlier this week or late last week, I saw what looked like a proposal to couple “strong” encryption with “weak” integrity.



If my memory serves me right: the proposal was along the lines of coupling:

ed448  with SHA-256  (as ed448 with SHA384)

ed22519 with SHA-128 (as opposed to SHA256)

And so on.



What was the decision / disposition?

Was it a strawman to stimulate discussion?



Best Regards,

Brent



From: Brent Zundel <Brent.Zundel@gendigital.com>
Sent: March 29, 2023 10:18 AM
To: Karen O'Donoghue <odonoghue=40isoc.org@dmarc.ietf.org>; jose@ietf.org
Subject: Re: [jose] Calls for adoption: Web Proof Drafts



I support adoption and volunteer to review and help write.



Sent from my T-Mobile 5G Device
Get Outlook for Android<https://aka.ms/AAb9ysg>

________________________________

From: jose <jose-bounces@ietf.org<mailto:jose-bounces@ietf.org>> on behalf of Karen O'Donoghue <odonoghue=40isoc.org@dmarc.ietf.org<mailto:odonoghue=40isoc.org@dmarc.ietf.org>>
Sent: Tuesday, March 28, 2023 12:54:06 PM
To: jose@ietf.org<mailto:jose@ietf.org> <jose@ietf.org<mailto:jose@ietf.org>>
Subject: [jose] Calls for adoption: Web Proof Drafts



jose working group…



Yesterday during the jose meeting @ IETF 116, we did a consensus call on the adoption of the three web proof drafts:

JSON Web Proofs https://datatracker.ietf.org/doc/draft-jmiller-jose-json-proof-algorithms/<https://nam04.safelinks.protection.outlook.com/?url=https%3A%2F%2Fdatatracker.ietf.org%2Fdoc%2Fdraft-jmiller-jose-json-proof-algorithms%2F&data=05%7C01%7Cbrent.zundel%40gendigital.com%7C04745884307c42d2641a08db2f401b19%7C94986b1d466f4fc0ab4b5c725603deab%7C0%7C0%7C638155724618796427%7CUnknown%7CTWFpbGZsb3d8eyJWIjoiMC4wLjAwMDAiLCJQIjoiV2luMzIiLCJBTiI6Ik1haWwiLCJXVCI6Mn0%3D%7C3000%7C%7C%7C&sdata=Ao6ZkIxDgTl6KNHS2DLpMUKzM%2FoxxPnE8IrDlqBHdjU%3D&reserved=0>
JSON Proof Algorithms https://datatracker.ietf.org/doc/draft-jmiller-jose-json-proof-algorithms/<https://nam04.safelinks.protection.outlook.com/?url=https%3A%2F%2Fdatatracker.ietf.org%2Fdoc%2Fdraft-jmiller-jose-json-proof-algorithms%2F&data=05%7C01%7Cbrent.zundel%40gendigital.com%7C04745884307c42d2641a08db2f401b19%7C94986b1d466f4fc0ab4b5c725603deab%7C0%7C0%7C638155724618796427%7CUnknown%7CTWFpbGZsb3d8eyJWIjoiMC4wLjAwMDAiLCJQIjoiV2luMzIiLCJBTiI6Ik1haWwiLCJXVCI6Mn0%3D%7C3000%7C%7C%7C&sdata=Ao6ZkIxDgTl6KNHS2DLpMUKzM%2FoxxPnE8IrDlqBHdjU%3D&reserved=0>
JSON Proof Token https://datatracker.ietf.org/doc/draft-jmiller-jose-json-proof-token/<https://nam04.safelinks.protection.outlook.com/?url=https%3A%2F%2Fdatatracker.ietf.org%2Fdoc%2Fdraft-jmiller-jose-json-proof-token%2F&data=05%7C01%7Cbrent.zundel%40gendigital.com%7C04745884307c42d2641a08db2f401b19%7C94986b1d466f4fc0ab4b5c725603deab%7C0%7C0%7C638155724618796427%7CUnknown%7CTWFpbGZsb3d8eyJWIjoiMC4wLjAwMDAiLCJQIjoiV2luMzIiLCJBTiI6Ik1haWwiLCJXVCI6Mn0%3D%7C3000%7C%7C%7C&sdata=%2Fg0FQk4Ss%2FrUUh1ZIPCgZSgs%2BMLvYnLgjj8%2FR%2BZNY48%3D&reserved=0>

The result was unanimous in favor of adopting the three drafts. With this message, I am asking the mailing list for any thoughts on adopting these three drafts. This call will close on Wednesday 19 April.



Also, this is an excellent time to read the drafts and start providing comments.



Karen (for the three jose chairs)

THIS MESSAGE IS FOR THE USE OF THE INTENDED RECIPIENT(S) ONLY AND MAY CONTAIN INFORMATION THAT IS PRIVILEGED, PROPRIETARY, CONFIDENTIAL, AND/OR EXEMPT FROM DISCLOSURE UNDER ANY RELEVANT PRIVACY LEGISLATION. No rights to any privilege have been waived. If you are not the intended recipient, you are hereby notified that any review, re-transmission, dissemination, distribution, copying, conversion to hard copy, taking of action in reliance on or other use of this communication is strictly prohibited. If you are not the intended recipient and have received this message in error, please notify me by return e-mail and delete or destroy all copies of this message.