[jose] Stephen Farrell's Abstain on draft-ietf-jose-jwk-thumbprint-07: (with COMMENT)

"Stephen Farrell" <stephen.farrell@cs.tcd.ie> Tue, 07 July 2015 22:59 UTC

Return-Path: <stephen.farrell@cs.tcd.ie>
X-Original-To: jose@ietfa.amsl.com
Delivered-To: jose@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id BD3FA1B2A28; Tue, 7 Jul 2015 15:59:37 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.9
X-Spam-Level:
X-Spam-Status: No, score=-1.9 tagged_above=-999 required=5 tests=[BAYES_00=-1.9] autolearn=ham
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id h91yi74LwJKv; Tue, 7 Jul 2015 15:59:36 -0700 (PDT)
Received: from ietfa.amsl.com (localhost [IPv6:::1]) by ietfa.amsl.com (Postfix) with ESMTP id 5C45A1B2A27; Tue, 7 Jul 2015 15:59:36 -0700 (PDT)
MIME-Version: 1.0
Content-Type: text/plain; charset="utf-8"
Content-Transfer-Encoding: 7bit
From: Stephen Farrell <stephen.farrell@cs.tcd.ie>
To: The IESG <iesg@ietf.org>
X-Test-IDTracker: no
X-IETF-IDTracker: 6.0.4.p1
Auto-Submitted: auto-generated
Precedence: bulk
Message-ID: <20150707225936.23081.82181.idtracker@ietfa.amsl.com>
Date: Tue, 07 Jul 2015 15:59:36 -0700
Archived-At: <http://mailarchive.ietf.org/arch/msg/jose/nKMJk647w_TxZeZkeGXXgCuXg1Y>
Cc: jose@ietf.org, Karen O'Donoghue <odonoghue@isoc.org>
Subject: [jose] Stephen Farrell's Abstain on draft-ietf-jose-jwk-thumbprint-07: (with COMMENT)
X-BeenThere: jose@ietf.org
X-Mailman-Version: 2.1.15
List-Id: Javascript Object Signing and Encryption <jose.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/jose>, <mailto:jose-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/jose/>
List-Post: <mailto:jose@ietf.org>
List-Help: <mailto:jose-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/jose>, <mailto:jose-request@ietf.org?subject=subscribe>
X-List-Received-Date: Tue, 07 Jul 2015 22:59:37 -0000

Stephen Farrell has entered the following ballot position for
draft-ietf-jose-jwk-thumbprint-07: Abstain

When responding, please keep the subject line intact and reply to all
email addresses included in the To and CC lines. (Feel free to cut this
introductory paragraph, however.)


Please refer to https://www.ietf.org/iesg/statement/discuss-criteria.html
for more information about IESG DISCUSS and COMMENT positions.


The document, along with other ballot positions, can be found here:
https://datatracker.ietf.org/doc/draft-ietf-jose-jwk-thumbprint/



----------------------------------------------------------------------
COMMENT:
----------------------------------------------------------------------

This draft chooses the wrong input to the hash function. Other
specifications, even those that do not otherwise use ASN.1 use 
the SubjectPublicKeyInfo ASN.1 structure for that. I raised
that point in the WG and during IETF LC but was in the rough.
Nonetheless, this will I believe need to be done over later
when or if there is a need to identify a public key in a 
cross-protocol or similar context. That's a waste of effort
for no good reason. The world won't end though.