Re: [jose] x5c, x5u, x5t don't apply to all key types

Mike Jones <Michael.Jones@microsoft.com> Wed, 17 July 2013 20:55 UTC

Return-Path: <Michael.Jones@microsoft.com>
X-Original-To: jose@ietfa.amsl.com
Delivered-To: jose@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id E5FFA21F9D56 for <jose@ietfa.amsl.com>; Wed, 17 Jul 2013 13:55:10 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -5.191
X-Spam-Level:
X-Spam-Status: No, score=-5.191 tagged_above=-999 required=5 tests=[AWL=1.407, BAYES_00=-2.599, HTML_MESSAGE=0.001, RCVD_IN_DNSWL_MED=-4]
Received: from mail.ietf.org ([12.22.58.30]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id GYsuXs26xRMv for <jose@ietfa.amsl.com>; Wed, 17 Jul 2013 13:55:05 -0700 (PDT)
Received: from co9outboundpool.messaging.microsoft.com (co9ehsobe002.messaging.microsoft.com [207.46.163.25]) by ietfa.amsl.com (Postfix) with ESMTP id AB90221F8B12 for <jose@ietf.org>; Wed, 17 Jul 2013 13:55:05 -0700 (PDT)
Received: from mail54-co9-R.bigfish.com (10.236.132.247) by CO9EHSOBE008.bigfish.com (10.236.130.71) with Microsoft SMTP Server id 14.1.225.22; Wed, 17 Jul 2013 20:55:05 +0000
Received: from mail54-co9 (localhost [127.0.0.1]) by mail54-co9-R.bigfish.com (Postfix) with ESMTP id 0C6C4280090; Wed, 17 Jul 2013 20:55:05 +0000 (UTC)
X-Forefront-Antispam-Report: CIP:131.107.125.8; KIP:(null); UIP:(null); IPV:NLI; H:TK5EX14HUBC101.redmond.corp.microsoft.com; RD:autodiscover.service.exchange.microsoft.com; EFVD:NLI
X-SpamScore: -9
X-BigFish: VS-9(z1091vz9371Ic85fh148cI111aIzz1f42h208ch1ee6h1de0h1fdah2073h1202h1e76h1d1ah1d2ah1fc6hzz1d7338h1de098h1033IL17326ah18c673h1de097h1de096h18de19h8275bh8275dhz2fh2a8h668h839hd25hf0ah1288h12a5h12bdh137ah1441h1504h1537h153bh15d0h162dh1631h1758h18e1h1946h19b5h19ceh1b0ah1bceh1d0ch1d2eh1d3fh1dfeh1dffh1e1dh1155h)
Received-SPF: pass (mail54-co9: domain of microsoft.com designates 131.107.125.8 as permitted sender) client-ip=131.107.125.8; envelope-from=Michael.Jones@microsoft.com; helo=TK5EX14HUBC101.redmond.corp.microsoft.com ; icrosoft.com ;
Received: from mail54-co9 (localhost.localdomain [127.0.0.1]) by mail54-co9 (MessageSwitch) id 1374094503923915_31223; Wed, 17 Jul 2013 20:55:03 +0000 (UTC)
Received: from CO9EHSMHS014.bigfish.com (unknown [10.236.132.252]) by mail54-co9.bigfish.com (Postfix) with ESMTP id D3DCF8C0047; Wed, 17 Jul 2013 20:55:03 +0000 (UTC)
Received: from TK5EX14HUBC101.redmond.corp.microsoft.com (131.107.125.8) by CO9EHSMHS014.bigfish.com (10.236.130.24) with Microsoft SMTP Server (TLS) id 14.16.227.3; Wed, 17 Jul 2013 20:55:03 +0000
Received: from TK5EX14MBXC283.redmond.corp.microsoft.com ([169.254.2.146]) by TK5EX14HUBC101.redmond.corp.microsoft.com ([157.54.7.153]) with mapi id 14.03.0136.001; Wed, 17 Jul 2013 20:54:54 +0000
From: Mike Jones <Michael.Jones@microsoft.com>
To: Brian Campbell <bcampbell@pingidentity.com>, "jose@ietf.org" <jose@ietf.org>
Thread-Topic: [jose] x5c, x5u, x5t don't apply to all key types
Thread-Index: AQHOgyS60Havk9WsUkqWqMQziqP9EplpWOdQ
Date: Wed, 17 Jul 2013 20:54:54 +0000
Message-ID: <4E1F6AAD24975D4BA5B16804296739436B6CDA90@TK5EX14MBXC283.redmond.corp.microsoft.com>
References: <CA+k3eCSDiV3mYxZsieR1o5ryTBWM=JnwBDRgbkifLbKs3tm11g@mail.gmail.com>
In-Reply-To: <CA+k3eCSDiV3mYxZsieR1o5ryTBWM=JnwBDRgbkifLbKs3tm11g@mail.gmail.com>
Accept-Language: en-US
Content-Language: en-US
X-MS-Has-Attach:
X-MS-TNEF-Correlator:
x-originating-ip: [157.54.51.34]
Content-Type: multipart/alternative; boundary="_000_4E1F6AAD24975D4BA5B16804296739436B6CDA90TK5EX14MBXC283r_"
MIME-Version: 1.0
X-OriginatorOrg: microsoft.com
X-FOPE-CONNECTOR: Id%0$Dn%*$RO%0$TLS%0$FQDN%$TlsDn%
Subject: Re: [jose] x5c, x5u, x5t don't apply to all key types
X-BeenThere: jose@ietf.org
X-Mailman-Version: 2.1.12
Precedence: list
List-Id: Javascript Object Signing and Encryption <jose.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/jose>, <mailto:jose-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/jose>
List-Post: <mailto:jose@ietf.org>
List-Help: <mailto:jose-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/jose>, <mailto:jose-request@ietf.org?subject=subscribe>
X-List-Received-Date: Wed, 17 Jul 2013 20:55:11 -0000

Thanks for noticing this.  How about "members that are common to all public key types"?

You're right about the section numbering.  I'll fix that.

                                                            Thanks again,
                                                            -- Mike

From: jose-bounces@ietf.org [mailto:jose-bounces@ietf.org] On Behalf Of Brian Campbell
Sent: Wednesday, July 17, 2013 12:34 PM
To: jose@ietf.org
Subject: [jose] x5c, x5u, x5t don't apply to all key types

Section 3 of JWK [1] defines "members that are common to all key types" and includes among those members x5c, x5u and x5t. However, the x5X parameters are relevant only for half the key types defined in JWA - they don't really make sense for "oct" [2] or "PBKDF2" [3].
Not sure the best way to address this but it seems kind of awkward as it is. Maybe move them into the EC and RSA type definitions (or something common to both) or somehow add some qualifying text saying that they can only be used with key types utilizing public keys?
As I was looking up the URLs below I noticed that the section alignment in section 5 of JWA is a little off. I think 5.3.3 and 5.3.4 should probably be 5.4 and 5.5 respectively. Right now they line up as though they were part of the RSA key type.

[1] http://tools.ietf.org/html/draft-ietf-jose-json-web-key-13#section-3
[2] http://tools.ietf.org/html/draft-ietf-jose-json-web-algorithms-13#section-5.3.3
[3] http://tools.ietf.org/html/draft-ietf-jose-json-web-algorithms-13#section-5.3.4