Re: [jose] #2: No key management for MAC

Eric Rescorla <ekr@rtfm.com> Tue, 22 January 2013 23:49 UTC

Return-Path: <ekr@rtfm.com>
X-Original-To: jose@ietfa.amsl.com
Delivered-To: jose@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 6BE2421F8B4C for <jose@ietfa.amsl.com>; Tue, 22 Jan 2013 15:49:32 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -102.976
X-Spam-Level:
X-Spam-Status: No, score=-102.976 tagged_above=-999 required=5 tests=[BAYES_00=-2.599, FM_FORGED_GMAIL=0.622, HTML_MESSAGE=0.001, RCVD_IN_DNSWL_LOW=-1, USER_IN_WHITELIST=-100]
Received: from mail.ietf.org ([64.170.98.30]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id Aed8quFZ4NMm for <jose@ietfa.amsl.com>; Tue, 22 Jan 2013 15:49:31 -0800 (PST)
Received: from mail-oa0-f51.google.com (mail-oa0-f51.google.com [209.85.219.51]) by ietfa.amsl.com (Postfix) with ESMTP id A70AF21F8B49 for <jose@ietf.org>; Tue, 22 Jan 2013 15:49:31 -0800 (PST)
Received: by mail-oa0-f51.google.com with SMTP id n12so7853906oag.38 for <jose@ietf.org>; Tue, 22 Jan 2013 15:49:31 -0800 (PST)
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=20120113; h=x-received:mime-version:x-originating-ip:in-reply-to:references :from:date:message-id:subject:to:cc:content-type:x-gm-message-state; bh=8UQbQmlgurvju4zfcPhxJ5Qx5oCmk+M2EfXwEZFMfQE=; b=nOX2ZbCAH6G7i11tgPIcbDd8IkWflChz3Ur+AX685pN+azKy7kF1+7J+3HOHp4zslK GGUm0k+E9+JFebYJyTM9/Gkf2l0scvxG7kmzfKYg6zntbUMlnj8fTYgeSt0PQtOP2bZD yArO/6+SoZW5p2/lg9A11YZR2yLp0GXXlLngk4B4M3f6y4GcMHMfu89X9yRtBIWR1bIQ mLCRk3UFYCPe2fbvp53kykxbUcBKeBvi5uUx5c91w6AMxKwRIIdaHd2aOThOjQ0X0VEK 0heCf7wfZ6Qeo2y1VXHrzLTuQxuTUkV4wQvbONNinlEVF1qkC0dBSOX6EKXsxiJcW1R4 MdHg==
X-Received: by 10.60.31.131 with SMTP id a3mr18083200oei.93.1358898571122; Tue, 22 Jan 2013 15:49:31 -0800 (PST)
MIME-Version: 1.0
Received: by 10.182.179.74 with HTTP; Tue, 22 Jan 2013 15:48:50 -0800 (PST)
X-Originating-IP: [74.95.2.173]
In-Reply-To: <054.c651e93bb72d1b02087aa116318b8d94@trac.tools.ietf.org>
References: <054.c651e93bb72d1b02087aa116318b8d94@trac.tools.ietf.org>
From: Eric Rescorla <ekr@rtfm.com>
Date: Tue, 22 Jan 2013 15:48:50 -0800
Message-ID: <CABcZeBNKPXnmoWC6FUia=g9HrNGbRQ+wkQPWeZDwbJagjc0OFA@mail.gmail.com>
To: jose issue tracker <trac+jose@trac.tools.ietf.org>
Content-Type: multipart/alternative; boundary=e89a8fb1f5949e169704d3e93a44
X-Gm-Message-State: ALoCoQlclaTRWspLZzpNriYkRLG7Ut5/LgYQnXe5BcGxrRvTrg7mEN/DAo3N7gDeNe64hC9bc4Bw
Cc: rbarnes@bbn.com, jose@ietf.org, draft-ietf-jose-json-web-signature@tools.ietf.org
Subject: Re: [jose] #2: No key management for MAC
X-BeenThere: jose@ietf.org
X-Mailman-Version: 2.1.12
Precedence: list
List-Id: Javascript Object Signing and Encryption <jose.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/jose>, <mailto:jose-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/jose>
List-Post: <mailto:jose@ietf.org>
List-Help: <mailto:jose-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/jose>, <mailto:jose-request@ietf.org?subject=subscribe>
X-List-Received-Date: Tue, 22 Jan 2013 23:49:32 -0000

I tend to agree with this, if only for symmetry reasons.

On Fri, Jan 18, 2013 at 3:23 PM, jose issue tracker <
trac+jose@trac.tools.ietf.org> wrote:

> #2: No key management for MAC
>
>  The current JWS format does not provide real key management (key agreement
>  / key wrapping) for MAC-protected objects.  MAC can only be done  directly
>  under a pre-shared key.  JWS needs to add key management functions for
>  this case.
>
> --
> -------------------------+-------------------------------------------------
>  Reporter:               |      Owner:  draft-ietf-jose-json-web-
>   rbarnes@bbn.com        |  signature@tools.ietf.org
>      Type:  defect       |     Status:  new
>  Priority:  critical     |  Milestone:
> Component:  json-web-    |    Version:
>   signature              |   Keywords:
>  Severity:  Active WG    |
>   Document               |
> -------------------------+-------------------------------------------------
>
> Ticket URL: <http://trac.tools.ietf.org/wg/jose/trac/ticket/2>
> jose <http://tools.ietf.org/jose/>
>
> _______________________________________________
> jose mailing list
> jose@ietf.org
> https://www.ietf.org/mailman/listinfo/jose
>