Re: [jose] JOSE and PKCS11

"Stefan Berger" <stefanb@us.ibm.com> Fri, 02 November 2018 00:06 UTC

Return-Path: <stefanb@us.ibm.com>
X-Original-To: jose@ietfa.amsl.com
Delivered-To: jose@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 46ABF128D09 for <jose@ietfa.amsl.com>; Thu, 1 Nov 2018 17:06:10 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -0.601
X-Spam-Level:
X-Spam-Status: No, score=-0.601 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, HTML_MESSAGE=0.001, KHOP_DYNAMIC=1.999, RCVD_IN_DNSWL_LOW=-0.7, SPF_PASS=-0.001] autolearn=no autolearn_force=no
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id e1bJbYuHPMUI for <jose@ietfa.amsl.com>; Thu, 1 Nov 2018 17:06:08 -0700 (PDT)
Received: from mx0a-001b2d01.pphosted.com (mx0a-001b2d01.pphosted.com [148.163.156.1]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id C7AC91271FF for <jose@ietf.org>; Thu, 1 Nov 2018 17:06:08 -0700 (PDT)
Received: from pps.filterd (m0098393.ppops.net [127.0.0.1]) by mx0a-001b2d01.pphosted.com (8.16.0.22/8.16.0.22) with SMTP id wA1NwueM139248 for <jose@ietf.org>; Thu, 1 Nov 2018 20:06:08 -0400
Received: from smtp.notes.na.collabserv.com (smtp.notes.na.collabserv.com [192.155.248.73]) by mx0a-001b2d01.pphosted.com with ESMTP id 2ng7vc8yhb-1 (version=TLSv1.2 cipher=ECDHE-RSA-AES256-GCM-SHA384 bits=256 verify=NOT) for <jose@ietf.org>; Thu, 01 Nov 2018 20:06:08 -0400
Received: from localhost by smtp.notes.na.collabserv.com with smtp.notes.na.collabserv.com ESMTP for <jose@ietf.org> from <stefanb@us.ibm.com>; Fri, 2 Nov 2018 00:06:07 -0000
Received: from us1a3-smtp06.a3.dal06.isc4sb.com (10.146.103.243) by smtp.notes.na.collabserv.com (10.106.227.90) with smtp.notes.na.collabserv.com ESMTP; Fri, 2 Nov 2018 00:06:02 -0000
Received: from us1a3-mail155.a3.dal06.isc4sb.com ([10.146.38.88]) by us1a3-smtp06.a3.dal06.isc4sb.com with ESMTP id 2018110200060207-1134983 ; Fri, 2 Nov 2018 00:06:02 +0000
In-Reply-To: <CAOASepMU3waryT=TKpw7sKFw-FT+JE3h-3xWUS7AZQwGgp8X5A@mail.gmail.com>
To: Nathaniel McCallum <npmccallum@redhat.com>
Cc: jose@ietf.org, jose <jose-bounces@ietf.org>
From: Stefan Berger <stefanb@us.ibm.com>
Date: Thu, 01 Nov 2018 19:06:03 -0500
References: <OF5CBAD5FA.DA05866D-ON00258338.007B994B-00258338.007BD260@notes.na.collabserv.com> <CAOASepMU3waryT=TKpw7sKFw-FT+JE3h-3xWUS7AZQwGgp8X5A@mail.gmail.com>
X-KeepSent: 17F955FA:9180BE33-00258339:0000071D; type=4; name=$KeepSent
X-Mailer: IBM Notes Release 9.0.1FP10 SHF68 March 06, 2018
X-LLNOutbound: False
X-Disclaimed: 60499
X-TNEFEvaluated: 1
x-cbid: 18110200-3107-0000-0000-000008C7E7ED
X-IBM-SpamModules-Scores: BY=0.01981; FL=0; FP=0; FZ=0; HX=0; KW=0; PH=0; SC=0.394815; ST=0; TS=0; UL=0; ISC=; MB=0.000153
X-IBM-SpamModules-Versions: BY=3.00009968; HX=3.00000242; KW=3.00000007; PH=3.00000004; SC=3.00000268; SDB=6.01111319; UDB=6.00575908; IPR=6.00891411; BA=6.00006135; NDR=6.00000001; ZLA=6.00000005; ZF=6.00000009; ZB=6.00000000; ZP=6.00000000; ZH=6.00000000; ZU=6.00000002; MB=3.00023997; XFM=3.00000015; UTC=2018-11-02 00:06:04
X-IBM-AV-DETECTION: SAVI=unsuspicious REMOTE=unsuspicious XFE=unused
X-IBM-AV-VERSION: SAVI=2018-11-01 23:24:03 - 6.00009167
x-cbparentid: 18110200-3108-0000-0000-00001E203165
Message-Id: <OF17F955FA.9180BE33-ON00258339.0000071D-85258339.00008E14@notes.na.collabserv.com>
Content-type: multipart/alternative; boundary="0__=8FBB09AADF93818D8f9e8a93df938690918c8FBB09AADF93818D"
Content-Disposition: inline
MIME-Version: 1.0
X-Proofpoint-Virus-Version: vendor=fsecure engine=2.50.10434:, , definitions=2018-11-01_17:, , signatures=0
X-Proofpoint-Spam-Reason: safe
Archived-At: <https://mailarchive.ietf.org/arch/msg/jose/rvJKy_n7LE5SEkWlRhGnXkRErbY>
Subject: Re: [jose] JOSE and PKCS11
X-BeenThere: jose@ietf.org
X-Mailman-Version: 2.1.29
Precedence: list
List-Id: Javascript Object Signing and Encryption <jose.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/jose>, <mailto:jose-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/jose/>
List-Post: <mailto:jose@ietf.org>
List-Help: <mailto:jose-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/jose>, <mailto:jose-request@ietf.org?subject=subscribe>
X-List-Received-Date: Fri, 02 Nov 2018 00:06:10 -0000

"jose" <jose-bounces@ietf.org> wrote on 11/01/2018 07:07:55 PM:
>
> https://tools.ietf.org/html/draft-mccallum-jose-pkcs11-jwk-00

Ah, didn't know about it.

>
> I plan to update this in the upcoming months and publish it as an
> independent draft. Likewise, we are implementing it here:
>
> https://github.com/latchset/jose
>
> Your contributions are welcome!

:-) I wished... But I may need it in a different language with less pkcs
stuff in place as it seems )-: https://github.com/square/go-jose/tree/v2

>
> On Thu, Nov 1, 2018, 6:32 PM Stefan Berger <stefanb@us.ibm.com wrote:
> I was wondering whether the integration of JOSE with PKCS11 was not
> considered for some reason or it was an omission. One could describe
> private keys of hardware devices using the PKCS 11 URI scheme (
> https://tools.ietf.org/html/rfc7512)  and reflect those in the JWE
> recipients header, for example, to use such a device for key
> unwrapping. It may be as easy as adding pkcs11 field(s) to the JOSE
> parameters (https://www.iana.org/assignments/jose/jose.xhtml)
>
> Regards,
>    Stefan
>
> _______________________________________________
> jose mailing list
> jose@ietf.org
> https://www.ietf.org/mailman/listinfo/jose
> _______________________________________________
> jose mailing list
> jose@ietf.org
> INVALID URI REMOVED
> u=https-3A__www.ietf.org_mailman_listinfo_jose&d=DwICAg&c=jf_iaSHvJObTbx-
>
siA1ZOg&r=1v27re_HJcPTJPkwTHXQYpTrbS_E7w3vBoyF3b2lE60&m=fwh9lQdx7kzAri5bGGDtLW6I138IRWSED_2pORvlFx4&s=JrLX5G13EPoinNwTbGVxqCbTThkhRzvoPNoGVJyv67w&e=