Re: [jose] Gen-ART LC review of draft-ietf-jose-json-web-algorithms-31

Mike Jones <Michael.Jones@microsoft.com> Thu, 04 September 2014 19:31 UTC

Return-Path: <Michael.Jones@microsoft.com>
X-Original-To: jose@ietfa.amsl.com
Delivered-To: jose@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id D0CE21A0013; Thu, 4 Sep 2014 12:31:49 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.901
X-Spam-Level:
X-Spam-Status: No, score=-1.901 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, HTML_MESSAGE=0.001, RCVD_IN_DNSWL_NONE=-0.0001, SPF_HELO_PASS=-0.001, SPF_PASS=-0.001] autolearn=ham
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id Z4aWRVJ7AnsW; Thu, 4 Sep 2014 12:31:46 -0700 (PDT)
Received: from na01-bn1-obe.outbound.protection.outlook.com (mail-bn1blp0186.outbound.protection.outlook.com [207.46.163.186]) (using TLSv1 with cipher ECDHE-RSA-AES256-SHA (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 738B51A0033; Thu, 4 Sep 2014 12:31:11 -0700 (PDT)
Received: from BN3PR0301CA0049.namprd03.prod.outlook.com (25.160.152.145) by BL2PR03MB616.namprd03.prod.outlook.com (10.255.109.41) with Microsoft SMTP Server (TLS) id 15.0.1019.16; Thu, 4 Sep 2014 19:31:08 +0000
Received: from BN1AFFO11FD012.protection.gbl (2a01:111:f400:7c10::157) by BN3PR0301CA0049.outlook.office365.com (2a01:111:e400:401e::17) with Microsoft SMTP Server (TLS) id 15.0.1019.16 via Frontend Transport; Thu, 4 Sep 2014 19:31:09 +0000
Received: from mail.microsoft.com (131.107.125.37) by BN1AFFO11FD012.mail.protection.outlook.com (10.58.52.72) with Microsoft SMTP Server (TLS) id 15.0.1010.11 via Frontend Transport; Thu, 4 Sep 2014 19:31:08 +0000
Received: from TK5EX14MBXC294.redmond.corp.microsoft.com ([169.254.3.78]) by TK5EX14HUBC101.redmond.corp.microsoft.com ([157.54.7.153]) with mapi id 14.03.0195.002; Thu, 4 Sep 2014 19:30:57 +0000
From: Mike Jones <Michael.Jones@microsoft.com>
To: Roni Even <ron.even.tlv@gmail.com>, "draft-ietf-jose-json-web-algorithms.all@tools.ietf.org" <draft-ietf-jose-json-web-algorithms.all@tools.ietf.org>, "gen-art@ietf.org" <gen-art@ietf.org>
Thread-Topic: Gen-ART LC review of draft-ietf-jose-json-web-algorithms-31
Thread-Index: Ac/F2mpuDG6JcxI/SbuImTKmZa3+rwCmp0KQ
Date: Thu, 04 Sep 2014 19:30:57 +0000
Message-ID: <4E1F6AAD24975D4BA5B16804296739439AE82354@TK5EX14MBXC294.redmond.corp.microsoft.com>
References: <013201cfc5da$6c34dd60$449e9820$@gmail.com>
In-Reply-To: <013201cfc5da$6c34dd60$449e9820$@gmail.com>
Accept-Language: en-US
Content-Language: en-US
X-MS-Has-Attach:
X-MS-TNEF-Correlator:
x-originating-ip: [157.54.51.72]
Content-Type: multipart/alternative; boundary="_000_4E1F6AAD24975D4BA5B16804296739439AE82354TK5EX14MBXC294r_"
MIME-Version: 1.0
X-EOPAttributedMessage: 0
X-Forefront-Antispam-Report: CIP:131.107.125.37; CTRY:US; IPV:CAL; IPV:NLI; IPV:NLI; EFV:NLI; SFV:NSPM; SFS:(438002)(199003)(189002)(51914003)(43784003)(377424004)(377454003)(4396001)(26826002)(74662001)(77982001)(20776003)(92566001)(104016003)(50986999)(2201001)(74502001)(83322001)(85852003)(86362001)(33656002)(92726001)(19300405004)(86612001)(55846006)(76482001)(87936001)(79102001)(230783001)(19580395003)(19625215002)(46102001)(83072002)(95666004)(6806004)(19580405001)(76176999)(80022001)(54356999)(69596002)(77096002)(15975445006)(84676001)(81342001)(15202345003)(107046002)(512954002)(2656002)(21056001)(68736004)(85306004)(16236675004)(90102001)(106466001)(84326002)(97736001)(19617315012)(81542001)(64706001)(99396002)(66066001)(81156004)(44976005)(31966008)(71186001); DIR:OUT; SFP:; SCL:1; SRVR:BL2PR03MB616; H:mail.microsoft.com; FPR:; MLV:ovrnspm; PTR:InfoDomainNonexistent; A:1; MX:1; LANG:en;
X-Microsoft-Antispam: BCL:0;PCL:0;RULEID:;UriScan:;
X-O365ENT-EOP-Header: Message processed by - O365_ENT: Allow from ranges (Engineering ONLY)
X-Forefront-PRVS: 0324C2C0E2
Received-SPF: Pass (protection.outlook.com: domain of microsoft.com designates 131.107.125.37 as permitted sender) receiver=protection.outlook.com; client-ip=131.107.125.37; helo=mail.microsoft.com;
Authentication-Results: spf=pass (sender IP is 131.107.125.37) smtp.mailfrom=Michael.Jones@microsoft.com;
X-OriginatorOrg: microsoft.onmicrosoft.com
Archived-At: http://mailarchive.ietf.org/arch/msg/jose/eYYx_YdhrA0S2k_lyBL0wXBV8do
Cc: "ietf@ietf.org" <ietf@ietf.org>, "jose@ietf.org" <jose@ietf.org>
Subject: Re: [jose] Gen-ART LC review of draft-ietf-jose-json-web-algorithms-31
X-BeenThere: jose@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: Javascript Object Signing and Encryption <jose.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/jose>, <mailto:jose-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/jose/>
List-Post: <mailto:jose@ietf.org>
List-Help: <mailto:jose-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/jose>, <mailto:jose-request@ietf.org?subject=subscribe>
X-List-Received-Date: Thu, 04 Sep 2014 19:31:50 -0000

Thanks for the review, Roni.  I'm also cc'ing the working group so they're aware of your review.  Replies are inline below...

From: Roni Even [mailto:ron.even.tlv@gmail.com]
Sent: Monday, September 01, 2014 4:47 AM
To: draft-ietf-jose-json-web-algorithms.all@tools.ietf.org; gen-art@ietf.org
Cc: ietf@ietf.org
Subject: Gen-ART LC review of draft-ietf-jose-json-web-algorithms-31

I am the assigned Gen-ART reviewer for this draft. For background on Gen-ART, please see the FAQ at <http://wiki.tools.ietf.org/area/gen/trac/wiki/GenArtfaq>.
Please resolve these comments along with any other Last Call comments you may receive.

Document:  draft-ietf-jose-json-web-algorithms-31

Reviewer: Roni Even

Review Date:2014-9-1

IETF LC End Date: 2014-9-3

IESG Telechat date:



Summary: This draft is ready for publication as a standard track RFC.





Major issues:



Minor issues:




Nits/editorial comments:

  1.  Section 4.8 "This section defines the specifies" should be "specifics"

Thanks


  1.  Section 5.2.2 "Section 5.2.3 and Section 5.2.5" should be "through" since 5.2.4 also defines instances.

Agreed


  1.  Section 5.2.2.1 in bullet 1 "the values of these parameters are specified by the AEAD algorithms (in Section 5.2.3 and Section 5.2.5)". Did you mean AEAD in which case is should be expanded and a reference is probably needed or do you need to change it to Authenticated Encryption? Also the "and" should be "through" same as previous comment.

Yes, the "AEAD" should become "Authenticated Encryption" to be consistent with the rest of the spec.  And agreed about "through".


  1.  In section 5.2.2.1 bullet 4 for "number of bits in A" I had to go to bullet 5 to see what A is. Maybe add also here "additional authenticated data"

"A" is defined in the first sentence of 5.2.2.1 as "additional authenticated data".  But there would be no harm the addition you propose.  Knowing that it's defined in the first sentence, do you still want to see the addition?

                                                                Thanks again,
                                                                -- Mike