Return-Path: <rlb@ipv.sx>
X-Original-To: jose@ietfa.amsl.com
Delivered-To: jose@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix)
 with ESMTP id 75D6811E8127 for <jose@ietfa.amsl.com>;
 Wed,  4 Sep 2013 15:51:10 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.976
X-Spam-Level: 
X-Spam-Status: No, score=-2.976 tagged_above=-999 required=5 tests=[AWL=-0.000,
 BAYES_00=-2.599, FM_FORGED_GMAIL=0.622, HTML_MESSAGE=0.001,
 RCVD_IN_DNSWL_LOW=-1]
Received: from mail.ietf.org ([12.22.58.30]) by localhost (ietfa.amsl.com
 [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id Rj5yiTMNTYql for
 <jose@ietfa.amsl.com>; Wed,  4 Sep 2013 15:51:01 -0700 (PDT)
Received: from mail-oa0-f45.google.com (mail-oa0-f45.google.com
 [209.85.219.45]) by ietfa.amsl.com (Postfix) with ESMTP id C7D6011E811E for
 <jose@ietf.org>; Wed,  4 Sep 2013 15:51:00 -0700 (PDT)
Received: by mail-oa0-f45.google.com with SMTP id m6so1317709oag.32 for
 <jose@ietf.org>; Wed, 04 Sep 2013 15:50:59 -0700 (PDT)
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net;
 s=20130820;
 h=x-gm-message-state:mime-version:in-reply-to:references:date
 :message-id:subject:from:to:cc:content-type;
 bh=cdNvmvLuUz5o2zT4s20b3WUYXjNw5nGHiW01twAUkrU=;
 b=dSobvE/DzQRipH+A2o/cbGKJbpJ/b2oJydC1OLSRz1kODF4Pf7CA+pdZHQNuzBv6+o
 2t65Ewdt6loaSaTd3ST1P8xgmas5fGmjET5RgUvFRCvQ4SMGtBEfpEAQVyJMzpHlq51J
 AIJoiod0QFlZtP9Mi7Vb2XlVsf0cwQpn/qaBT8wzJBnGYJew2XgIrtmzYKjbV58+W+zr
 aSa5U62lYZfBspPuMOgZd59DQd1DpMUeu54ltmTZbBwYb46dS+OvFLLOS1995Efp1n1+
 kIxBaqVOXKoqtixHTNliZoKdVyA+/x9r+HR3XlxHhjgmJa1RhRMtDge3tlBgNnrCzGZ1 7xkw==
X-Gm-Message-State: ALoCoQn1ITJpFCGAG8JyPU6C64dIat6Xco3/KL0ZSYI0SpYTAQVsMlePylqCiMr/+Yrkw3zKgUz5
MIME-Version: 1.0
X-Received: by 10.182.18.9 with SMTP id s9mr4092153obd.15.1378335059359;
 Wed, 04 Sep 2013 15:50:59 -0700 (PDT)
Received: by 10.60.31.74 with HTTP; Wed, 4 Sep 2013 15:50:59 -0700 (PDT)
In-Reply-To: <CAL02cgRVH4ZswzOXOCAG=g4_HtRJpKcnbPEsvP=TTadOkEuK8A@mail.gmail.com>
References: <4E1F6AAD24975D4BA5B16804296739436C2EA801@TK5EX14MBXC291.redmond.corp.microsoft.com>
 <CAL02cgRvnE+TwJxfxr_s5pdHjcxr5Z9zvTKxZKMTWKDvozeunQ@mail.gmail.com>
 <4E1F6AAD24975D4BA5B16804296739436C2EB1D4@TK5EX14MBXC291.redmond.corp.microsoft.com>
 <CAL02cgRVH4ZswzOXOCAG=g4_HtRJpKcnbPEsvP=TTadOkEuK8A@mail.gmail.com>
Date: Wed, 4 Sep 2013 18:50:59 -0400
Message-ID: <CAL02cgRmw8Fvs81oa_Ast41Xw7w88T7rK__tmHZN9WtE1CCQSg@mail.gmail.com>
From: Richard Barnes <rlb@ipv.sx>
To: Mike Jones <Michael.Jones@microsoft.com>
Content-Type: multipart/alternative; boundary=001a11c2d6a098405604e596a338
Cc: "jose@ietf.org" <jose@ietf.org>
Subject: Re: [jose] Text about applications and "alg":"none"
X-BeenThere: jose@ietf.org
X-Mailman-Version: 2.1.12
Precedence: list
List-Id: Javascript Object Signing and Encryption <jose.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/jose>,
 <mailto:jose-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/jose>
List-Post: <mailto:jose@ietf.org>
List-Help: <mailto:jose-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/jose>,
 <mailto:jose-request@ietf.org?subject=subscribe>
X-List-Received-Date: Wed, 04 Sep 2013 22:51:11 -0000

--001a11c2d6a098405604e596a338
Content-Type: text/plain; charset=windows-1252
Content-Transfer-Encoding: quoted-printable

Also, note this text needs to appear in JWS, not JWA, since it's a general
requirement on JWS implementations.  So in addition to requiring
implementations to be unnecessarily complex, it also breaks the clean
separation between those documents.


On Wed, Sep 4, 2013 at 6:45 PM, Richard Barnes <rlb@ipv.sx> wrote:

> I think it's important to emphasize that an implementation MUST NOT allow
> a global setting.  In fact, I would argue that if "none" is in the
> acceptable algorithm list, it MUST be the only thing in the list.  Any
> other way, and you end up with downgrade.
>
> --Richard
>
>
> On Tue, Sep 3, 2013 at 6:47 PM, Mike Jones <Michael.Jones@microsoft.com>w=
rote:
>
>>  Your proposed text seems overly verbose.  In particular, I believe
>> you=92ll find that the text I proposed already means the same thing / mo=
dulo
>> the difference between RECOMMENDED and MUST.  If the WG wants a MUST we
>> could do that instead of RECOMMENDED.  We can discuss that on tomorrow=
=92s
>> call.****
>>
>> ** **
>>
>> The correspondence is as follows:****
>>
>> Your sentence 1 is covered in my sentence 1.****
>>
>> Your sentence 2 is covered in my sentence 1.****
>>
>> Your sentence 3 is covered in my sentences 1 & 2.  In particular, the
>> =93per-object basis=94 is already covered by =93in a JWS object=94.  (If=
 it were
>> not on a per-object basis, it would have said something like =93in all J=
WS
>> objects=94.****
>>
>> ** **
>>
>>                                                                 Cheers,*=
*
>> **
>>
>>                                                                 -- Mike*=
*
>> **
>>
>> ** **
>>
>> *From:* Richard Barnes [mailto:rlb@ipv.sx]
>> *Sent:* Tuesday, September 03, 2013 1:33 PM
>> *To:* Mike Jones
>> *Cc:* jose@ietf.org
>> *Subject:* Re: [jose] Text about applications and "alg":"none"****
>>
>> ** **
>>
>> This text is still far too weak, and does not reflect what I remember EK=
R
>> saying (in particular, there is no MUST).  It does not address the attac=
k
>> where an application may, in general, be willing to accept both signed a=
nd
>> unsigned content, but each in specific contexts.  Proposed text:****
>>
>> ** **
>>
>> """****
>>
>> JWS implementations MUST provide an interface for applications to specif=
y
>> a list of "alg" values that are acceptable for the validation of a given
>> JWS object.  JWS implementations MUST NOT indicate that a JWS object is
>> valid if the "alg" value for the object is "none", unless the applicatio=
n
>> has specifically indicated that the value "none" is acceptable for the
>> particular JWS object being validated.  Applications using "none" MUST
>> indicate support on a per-object basis, in order to avoid downgrade atta=
cks
>> that arise if more broadly-applicable preferences are specified.****
>>
>> """****
>>
>> ** **
>>
>> I continue to believe that this is far too subtle, and that applications
>> are very likely to get it wrong.  It is far simpler and safer to require
>> that a JWS implementation MUST reject an object with "alg":"none", and h=
ave
>> another content type for unsigned content.****
>>
>> ** **
>>
>> Also, if "none" is going to remain, then it needs to be OPTIONAL.  Given
>> all the above limitations, I don't see how you could justify it being
>> mandatory.****
>>
>> ** **
>>
>> --Richard****
>>
>> ** **
>>
>> ** **
>>
>> On Tue, Sep 3, 2013 at 2:02 PM, Mike Jones <Michael.Jones@microsoft.com>
>> wrote:****
>>
>> I took an action item during the last call to write text along the lines
>> suggested by ekr about applications and "alg":"none".  I propose that th=
e
>> following text be included:****
>>
>>  ****
>>
>> It is RECOMMENDED that libraries provide applications a means of
>> specifying the list of acceptable algorithms used in a JWS object in a w=
ay
>> that causes inputs using algorithms outside the specified set to be
>> rejected.  In particular, it is intended for applications to use this
>> mechanism to exclude accepting inputs using "alg":"none" in security
>> contexts where non-integrity protected inputs are not acceptable.****
>>
>>  ****
>>
>> Feedback/proposed wording refinements welcomed.****
>>
>>  ****
>>
>>                                                                 -- Mike*=
*
>> **
>>
>>  ****
>>
>>
>> _______________________________________________
>> jose mailing list
>> jose@ietf.org
>> https://www.ietf.org/mailman/listinfo/jose****
>>
>> ** **
>>
>
>

--001a11c2d6a098405604e596a338
Content-Type: text/html; charset=windows-1252
Content-Transfer-Encoding: quoted-printable

<div dir=3D"ltr">Also, note this text needs to appear in JWS, not JWA, sinc=
e it&#39;s a general requirement on JWS implementations. =A0So in addition =
to requiring implementations to be unnecessarily complex, it also breaks th=
e clean separation between those documents. =A0</div>
<div class=3D"gmail_extra"><br><br><div class=3D"gmail_quote">On Wed, Sep 4=
, 2013 at 6:45 PM, Richard Barnes <span dir=3D"ltr">&lt;<a href=3D"mailto:r=
lb@ipv.sx" target=3D"_blank">rlb@ipv.sx</a>&gt;</span> wrote:<br><blockquot=
e class=3D"gmail_quote" style=3D"margin:0 0 0 .8ex;border-left:1px #ccc sol=
id;padding-left:1ex">
<div dir=3D"ltr">I think it&#39;s important to emphasize that an implementa=
tion MUST NOT allow a global setting. =A0In fact, I would argue that if &qu=
ot;none&quot; is in the acceptable algorithm list, it MUST be the only thin=
g in the list. =A0Any other way, and you end up with downgrade.<span class=
=3D"HOEnZb"><font color=3D"#888888"><div>

<br></div><div>--Richard</div></font></span></div><div class=3D"HOEnZb"><di=
v class=3D"h5"><div class=3D"gmail_extra"><br><br><div class=3D"gmail_quote=
">On Tue, Sep 3, 2013 at 6:47 PM, Mike Jones <span dir=3D"ltr">&lt;<a href=
=3D"mailto:Michael.Jones@microsoft.com" target=3D"_blank">Michael.Jones@mic=
rosoft.com</a>&gt;</span> wrote:<br>

<blockquote class=3D"gmail_quote" style=3D"margin:0 0 0 .8ex;border-left:1p=
x #ccc solid;padding-left:1ex">





<div lang=3D"EN-US" link=3D"blue" vlink=3D"purple">
<div>
<p class=3D"MsoNormal"><span style=3D"font-size:11.0pt;font-family:&quot;Ca=
libri&quot;,&quot;sans-serif&quot;;color:#1f497d">Your proposed text seems =
overly verbose.=A0 In particular, I believe you=92ll find that the text I p=
roposed already means the same thing / modulo the difference
 between RECOMMENDED and MUST.=A0 If the WG wants a MUST we could do that i=
nstead of RECOMMENDED.=A0 We can discuss that on tomorrow=92s call.<u></u><=
u></u></span></p>
<p class=3D"MsoNormal"><span style=3D"font-size:11.0pt;font-family:&quot;Ca=
libri&quot;,&quot;sans-serif&quot;;color:#1f497d"><u></u>=A0<u></u></span><=
/p>
<p class=3D"MsoNormal"><span style=3D"font-size:11.0pt;font-family:&quot;Ca=
libri&quot;,&quot;sans-serif&quot;;color:#1f497d">The correspondence is as =
follows:<u></u><u></u></span></p>
<p class=3D"MsoNormal"><span style=3D"font-size:11.0pt;font-family:&quot;Ca=
libri&quot;,&quot;sans-serif&quot;;color:#1f497d">Your sentence 1 is covere=
d in my sentence 1.<u></u><u></u></span></p>
<p class=3D"MsoNormal"><span style=3D"font-size:11.0pt;font-family:&quot;Ca=
libri&quot;,&quot;sans-serif&quot;;color:#1f497d">Your sentence 2 is covere=
d in my sentence 1.<u></u><u></u></span></p>
<p class=3D"MsoNormal"><span style=3D"font-size:11.0pt;font-family:&quot;Ca=
libri&quot;,&quot;sans-serif&quot;;color:#1f497d">Your sentence 3 is covere=
d in my sentences 1 &amp; 2.=A0 In particular, the =93per-object basis=94 i=
s already covered by =93in a JWS object=94.=A0 (If it were not on a per-obj=
ect
 basis, it would have said something like =93in all JWS objects=94.<u></u><=
u></u></span></p>
<p class=3D"MsoNormal"><span style=3D"font-size:11.0pt;font-family:&quot;Ca=
libri&quot;,&quot;sans-serif&quot;;color:#1f497d"><u></u>=A0<u></u></span><=
/p>
<p class=3D"MsoNormal"><span style=3D"font-size:11.0pt;font-family:&quot;Ca=
libri&quot;,&quot;sans-serif&quot;;color:#1f497d">=A0=A0=A0=A0=A0=A0=A0=A0=
=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=
=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=
=A0=A0=A0=A0=A0 Cheers,<u></u><u></u></span></p>
<p class=3D"MsoNormal"><span style=3D"font-size:11.0pt;font-family:&quot;Ca=
libri&quot;,&quot;sans-serif&quot;;color:#1f497d">=A0=A0=A0=A0=A0=A0=A0=A0=
=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=
=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=
=A0=A0=A0=A0=A0 -- Mike<u></u><u></u></span></p>
<p class=3D"MsoNormal"><span style=3D"font-size:11.0pt;font-family:&quot;Ca=
libri&quot;,&quot;sans-serif&quot;;color:#1f497d"><u></u>=A0<u></u></span><=
/p>
<p class=3D"MsoNormal"><b><span style=3D"font-size:10.0pt;font-family:&quot=
;Tahoma&quot;,&quot;sans-serif&quot;">From:</span></b><span style=3D"font-s=
ize:10.0pt;font-family:&quot;Tahoma&quot;,&quot;sans-serif&quot;"> Richard =
Barnes [mailto:<a href=3D"mailto:rlb@ipv.sx" target=3D"_blank">rlb@ipv.sx</=
a>]
<br>
<b>Sent:</b> Tuesday, September 03, 2013 1:33 PM<br>
<b>To:</b> Mike Jones<br>
<b>Cc:</b> <a href=3D"mailto:jose@ietf.org" target=3D"_blank">jose@ietf.org=
</a><br>
<b>Subject:</b> Re: [jose] Text about applications and &quot;alg&quot;:&quo=
t;none&quot;<u></u><u></u></span></p><div><div>
<p class=3D"MsoNormal"><u></u>=A0<u></u></p>
<div>
<p class=3D"MsoNormal">This text is still far too weak, and does not reflec=
t what I remember EKR saying (in particular, there is no MUST). =A0It does =
not address the attack where an application may, in general, be willing to =
accept both signed and unsigned content,
 but each in specific contexts. =A0Proposed text:<u></u><u></u></p>
<div>
<p class=3D"MsoNormal"><u></u>=A0<u></u></p>
</div>
<div>
<p class=3D"MsoNormal">&quot;&quot;&quot;<u></u><u></u></p>
</div>
<div>
<p class=3D"MsoNormal">JWS implementations MUST provide an interface for ap=
plications to specify a list of &quot;alg&quot; values that are acceptable =
for the validation of a given JWS object. =A0JWS implementations MUST NOT i=
ndicate that a JWS object is valid if the &quot;alg&quot;
 value for the object is &quot;none&quot;, unless the application has speci=
fically indicated that the value &quot;none&quot; is acceptable for the par=
ticular JWS object being validated. =A0Applications using &quot;none&quot; =
MUST indicate support on a per-object basis, in order to avoid downgrade
 attacks that arise if more broadly-applicable preferences are specified.<u=
></u><u></u></p>
</div>
<div>
<p class=3D"MsoNormal">&quot;&quot;&quot;<u></u><u></u></p>
</div>
<div>
<p class=3D"MsoNormal"><u></u>=A0<u></u></p>
</div>
<div>
<p class=3D"MsoNormal">I continue to believe that this is far too subtle, a=
nd that applications are very likely to get it wrong. =A0It is far simpler =
and safer to require that a JWS implementation MUST reject an object with &=
quot;alg&quot;:&quot;none&quot;, and have another content
 type for unsigned content.<u></u><u></u></p>
</div>
<div>
<p class=3D"MsoNormal"><u></u>=A0<u></u></p>
</div>
<div>
<p class=3D"MsoNormal">Also, if &quot;none&quot; is going to remain, then i=
t needs to be OPTIONAL. =A0Given all the above limitations, I don&#39;t see=
 how you could justify it being mandatory.<u></u><u></u></p>
</div>
<div>
<p class=3D"MsoNormal"><u></u>=A0<u></u></p>
</div>
<div>
<p class=3D"MsoNormal">--Richard<u></u><u></u></p>
</div>
<div>
<p class=3D"MsoNormal"><u></u>=A0<u></u></p>
</div>
</div>
<div>
<p class=3D"MsoNormal" style=3D"margin-bottom:12.0pt"><u></u>=A0<u></u></p>
<div>
<p class=3D"MsoNormal">On Tue, Sep 3, 2013 at 2:02 PM, Mike Jones &lt;<a hr=
ef=3D"mailto:Michael.Jones@microsoft.com" target=3D"_blank">Michael.Jones@m=
icrosoft.com</a>&gt; wrote:<u></u><u></u></p>
<div>
<div>
<p class=3D"MsoNormal">I took an action item during the last call to write =
text along the lines suggested by ekr about applications and &quot;alg&quot=
;:&quot;none&quot;.=A0 I propose that the following text be included:<u></u=
><u></u></p>


<p class=3D"MsoNormal">=A0<u></u><u></u></p>
<p class=3D"MsoNormal" style=3D"margin-left:.5in">
It is RECOMMENDED that libraries provide applications a means of specifying=
 the list of acceptable algorithms used in a JWS object in a way that cause=
s inputs using algorithms outside the specified set to be rejected.=A0 In p=
articular, it is intended for applications
 to use this mechanism to exclude accepting inputs using &quot;alg&quot;:&q=
uot;none&quot; in security contexts where non-integrity protected inputs ar=
e not acceptable.<u></u><u></u></p>
<p class=3D"MsoNormal">=A0<u></u><u></u></p>
<p class=3D"MsoNormal">Feedback/proposed wording refinements welcomed.<u></=
u><u></u></p>
<p class=3D"MsoNormal"><span style=3D"color:#888888">=A0<u></u><u></u></spa=
n></p>
<p class=3D"MsoNormal"><span style=3D"color:#888888">=A0=A0=A0=A0=A0=A0=A0=
=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=
=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=
=A0=A0=A0=A0=A0=A0 -- Mike<u></u><u></u></span></p>
<p class=3D"MsoNormal"><span style=3D"color:#888888">=A0<u></u><u></u></spa=
n></p>
</div>
</div>
<p class=3D"MsoNormal" style=3D"margin-bottom:12.0pt"><br>
_______________________________________________<br>
jose mailing list<br>
<a href=3D"mailto:jose@ietf.org" target=3D"_blank">jose@ietf.org</a><br>
<a href=3D"https://www.ietf.org/mailman/listinfo/jose" target=3D"_blank">ht=
tps://www.ietf.org/mailman/listinfo/jose</a><u></u><u></u></p>
</div>
<p class=3D"MsoNormal"><u></u>=A0<u></u></p>
</div>
</div></div></div>
</div>

</blockquote></div><br></div>
</div></div></blockquote></div><br></div>

--001a11c2d6a098405604e596a338--
