Re: [jose] DISCUSS: Nonce/Timestamp parameter

<Axel.Nennker@telekom.de> Mon, 27 August 2012 08:37 UTC

Return-Path: <Axel.Nennker@telekom.de>
X-Original-To: jose@ietfa.amsl.com
Delivered-To: jose@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id EE85821F84BF for <jose@ietfa.amsl.com>; Mon, 27 Aug 2012 01:37:29 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -3.249
X-Spam-Level:
X-Spam-Status: No, score=-3.249 tagged_above=-999 required=5 tests=[BAYES_00=-2.599, HELO_EQ_DE=0.35, RCVD_IN_DNSWL_LOW=-1]
Received: from mail.ietf.org ([64.170.98.30]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id qtMUQ+GWOo3g for <jose@ietfa.amsl.com>; Mon, 27 Aug 2012 01:37:29 -0700 (PDT)
Received: from tcmail73.telekom.de (tcmail73.telekom.de [217.243.239.135]) by ietfa.amsl.com (Postfix) with ESMTP id 31AE621F84A7 for <jose@ietf.org>; Mon, 27 Aug 2012 01:37:29 -0700 (PDT)
Received: from he113415.emea1.cds.t-internal.com ([10.125.65.81]) by tcmail71.telekom.de with ESMTP/TLS/AES128-SHA; 27 Aug 2012 10:37:27 +0200
Received: from HE111541.emea1.cds.t-internal.com ([169.254.2.25]) by HE113415.emea1.cds.t-internal.com ([2002:7cd:4151::7cd:4151]) with mapi; Mon, 27 Aug 2012 10:37:21 +0200
From: Axel.Nennker@telekom.de
To: ietf@augustcellars.com, jose@ietf.org
Date: Mon, 27 Aug 2012 10:37:21 +0200
Thread-Topic: [jose] DISCUSS: Nonce/Timestamp parameter
Thread-Index: Ac2ELoc7u5wC+hIARhuRuZsuq8qwFA==
Message-ID: <CE8995AB5D178F44A2154F5C9A97CAF402517E00B8B5@HE111541.emea1.cds.t-internal.com>
Accept-Language: de-DE
Content-Language: en-US
X-MS-Has-Attach:
X-MS-TNEF-Correlator:
acceptlanguage: de-DE
Content-Type: text/plain; charset="us-ascii"
Content-Transfer-Encoding: quoted-printable
MIME-Version: 1.0
Subject: Re: [jose] DISCUSS: Nonce/Timestamp parameter
X-BeenThere: jose@ietf.org
X-Mailman-Version: 2.1.12
Precedence: list
List-Id: Javascript Object Signing and Encryption <jose.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/jose>, <mailto:jose-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/jose>
List-Post: <mailto:jose@ietf.org>
List-Help: <mailto:jose-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/jose>, <mailto:jose-request@ietf.org?subject=subscribe>
X-List-Received-Date: Mon, 27 Aug 2012 08:37:30 -0000

What is the base specification? https://tools.ietf.org/html/draft-ietf-oauth-json-web-token-03 ?
I think that nonce and timestamp are protocol specific fields and that JOSE is not about protocols. There are no round-trips in JOSE.
The cryptographic algorithms used in JOSE are secure enough without nounce and timestamp.

Axel

-----Original Message-----
From: jose-bounces@ietf.org [mailto:jose-bounces@ietf.org] On Behalf Of Jim Schaad
Sent: Friday, August 17, 2012 9:05 AM
To: jose@ietf.org
Subject: [jose] POLL: Nonce/Timestamp parameter

<CHAIR>

If you voted at the face-2-face please do not vote again.  If you want to provide comments please change the title from POLL to DISCUSS.

Do we need to define a nonce/timestamp parameter in the base specification?



Room vote:  6 yes, 0 no, 1 discuss


_______________________________________________
jose mailing list
jose@ietf.org
https://www.ietf.org/mailman/listinfo/jose