Re: [Last-Call] CORRECTED Last Call: <draft-ietf-cose-key-thumbprint-04.txt> (CBOR Object Signing and Encryption (COSE) Key Thumbprint) to Proposed Standard

Michael Jones <michael_b_jones@hotmail.com> Wed, 20 March 2024 01:08 UTC

Return-Path: <michael_b_jones@hotmail.com>
X-Original-To: last-call@ietfa.amsl.com
Delivered-To: last-call@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 79071C1519BA; Tue, 19 Mar 2024 18:08:44 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -6.233
X-Spam-Level:
X-Spam-Status: No, score=-6.233 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, FORGED_HOTMAIL_RCVD2=0.874, FREEMAIL_FROM=0.001, RCVD_IN_DNSWL_HI=-5, RCVD_IN_MSPIKE_H2=-0.001, RCVD_IN_ZEN_BLOCKED_OPENDNS=0.001, SPF_PASS=-0.001, T_SCC_BODY_TEXT_LINE=-0.01, URIBL_BLOCKED=0.001, URIBL_DBL_BLOCKED_OPENDNS=0.001, URIBL_ZEN_BLOCKED_OPENDNS=0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (2048-bit key) header.d=hotmail.com
Received: from mail.ietf.org ([50.223.129.194]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id DPactq7WbR-u; Tue, 19 Mar 2024 18:08:40 -0700 (PDT)
Received: from NAM11-DM6-obe.outbound.protection.outlook.com (mail-dm6nam11olkn2025.outbound.protection.outlook.com [40.92.19.25]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id C3BBCC180B5A; Tue, 19 Mar 2024 18:08:19 -0700 (PDT)
ARC-Seal: i=1; a=rsa-sha256; s=arcselector9901; d=microsoft.com; cv=none; b=kYfb5C0jSlDiJHNBy642cTb5GG/5+8oAEZYygYSNGOJThIsmxDBWKUY4Xi54QW9Oaa/nwtEKGmrbV191XU6jJXv8NoGAUYrJOKVFMB4ezZExfIDnUj3bVAvz6uUkGLwE5rsU6DpA2CkhTp26Hi3PF9UoCnkx2vRb8eqZD3ZFfsebt+1ZPTupNqFTxGqQZ7rWviSfVS4NpzSBszSFwfVIvDLWxuIugNzjGcBhC+TeWxh6FuwrtPt7gxdDweqk6+3Vh921YbzhsTZy0fU+M+jVSKWNAvpI7DZyjQ2IIZCs16Rv5jheXi53mJMS9cPH5yB8d7XY07aRfDWY1NWrXOniQw==
ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=microsoft.com; s=arcselector9901; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-AntiSpam-MessageData-ChunkCount:X-MS-Exchange-AntiSpam-MessageData-0:X-MS-Exchange-AntiSpam-MessageData-1; bh=LAOr6lxf6uq97Zv/yIZv0HYo6ZYbmYNRRr6sA+pKSc8=; b=X+tbBDOkI2Lr3vlE311un5gLlQ2bgwFM1SKLYXD3YLYCyXxRSH1gyQexo7W9CKR3EAABvsenKLJ4hCWhWg4Ufd5H1iTBv7iHbgReBsAf4eMJiPtcYtP7Zes17xt48cL9m0/xdG7bzYwmXjsgIVJ88C1xUnwfIK4pauBkuwCsF8u3aUrBmjESW1zX9sbQamgQB9J55Rl54yPpXqH1KvttvIGNEQzzoC2HRDbNkCo6Fh/TlNsmoEUH2CVFYy3IUMN4hh0DnUztgrjaOVi3D4KFOArFJJh8CU/jBUsQ4PvZ30C/csJ5KalPwbYaTf0EXHviX62FmJp13vqnQL/3bZqu2w==
ARC-Authentication-Results: i=1; mx.microsoft.com 1; spf=none; dmarc=none; dkim=none; arc=none
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=hotmail.com; s=selector1; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-SenderADCheck; bh=LAOr6lxf6uq97Zv/yIZv0HYo6ZYbmYNRRr6sA+pKSc8=; b=iMIerAlEAkycsH5LJ0FAgEiTSf4tBUs9Tgto8qlqHW+JX5GCQ2vVnvxARfNHHnch6bFCuKWvyim4eMS2/hZ7Hbd6hzDg5JetfrbTTWzdhk4UXNm8VdhGgoe5Dyshh7lLip+3sRHNHcdSfpvOG8+yWkb1gSPGxJclSJW7PLeYun5I/+dSMDdzRH38OsAT6EH3/c18FvZvjcORThPRxpjsBpKAaesBVS/YhgBrYnvdy1Di+WzjBH4GGUUId83LnCGXTRrmrPE2gILXdFnjrLOspCygA6yuVHBQIf7BIfT/eCL3tf4gEgIZRQI4KIPfVdFSBGwwE4GVTLOX2ktbuHK8jw==
Received: from SJ0PR02MB7439.namprd02.prod.outlook.com (2603:10b6:a03:295::14) by SA0PR02MB7500.namprd02.prod.outlook.com (2603:10b6:806:e9::24) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.20.7386.27; Wed, 20 Mar 2024 01:08:17 +0000
Received: from SJ0PR02MB7439.namprd02.prod.outlook.com ([fe80::7c2c:4b2:7be3:4f66]) by SJ0PR02MB7439.namprd02.prod.outlook.com ([fe80::7c2c:4b2:7be3:4f66%4]) with mapi id 15.20.7386.025; Wed, 20 Mar 2024 01:08:17 +0000
From: Michael Jones <michael_b_jones@hotmail.com>
To: "last-call@ietf.org" <last-call@ietf.org>, IETF-Announce <ietf-announce@ietf.org>
CC: "cose-chairs@ietf.org" <cose-chairs@ietf.org>, "cose@ietf.org" <cose@ietf.org>, "draft-ietf-cose-key-thumbprint@ietf.org" <draft-ietf-cose-key-thumbprint@ietf.org>, "paul.wouters@aiven.io" <paul.wouters@aiven.io>
Thread-Topic: CORRECTED Last Call: <draft-ietf-cose-key-thumbprint-04.txt> (CBOR Object Signing and Encryption (COSE) Key Thumbprint) to Proposed Standard
Thread-Index: AQHadQheDfj37rV02UKHSPU9hpxvS7E/2hmg
Date: Wed, 20 Mar 2024 01:08:17 +0000
Message-ID: <SJ0PR02MB743984E1BAF35BFAD2E83DA1B7332@SJ0PR02MB7439.namprd02.prod.outlook.com>
References: <171030817401.20617.4690008873499642574@ietfa.amsl.com>
In-Reply-To: <171030817401.20617.4690008873499642574@ietfa.amsl.com>
Accept-Language: en-US
Content-Language: en-US
X-MS-Has-Attach:
X-MS-TNEF-Correlator:
x-tmn: [JkYtbQMnqBUihJ00MjsJaFeo4lYUAF/slrqnIvCKK1R5cvnh2E+eHWe1hgOmjuqX]
x-ms-publictraffictype: Email
x-ms-traffictypediagnostic: SJ0PR02MB7439:EE_|SA0PR02MB7500:EE_
x-ms-office365-filtering-correlation-id: 36fb3ebb-fc54-4d80-3d52-08dc487a39fc
x-ms-exchange-slblob-mailprops: ynsnEk/J89fiDJMZIuWwrgPJzTmLI9+VKGYFbMSrWXTTp+okPVn6cJAlF4EmjSKy4sqnWJxeJkdKi06UYdOSP/cNywfEA5c/snJl9fLl+FTmxUoaqalzqQRtwrtiIYu8OEqr5c6RaqtGBoGSg0vZGj9aXvD1AX20/Edne99cirK9fpREQAFekmWnllQFOVFYsZYQEiR8DNLVT233N+148vj/DT8ZSXedeZR7Qu/xYD/b/7n1bg2Ym1f+04TnBEEiY+k/bAV2a1MejMvWjUQ0eqzMSPYHWSHaHcG2JCNEdmU0Ku5Nu2LgT2/ZUqZ/Tz4pvN/OKSaeJcWhlJVqqBTvcKw8fl6k0Q10eC04Z6B8diWiHuSs4NQxs4yaNkrj3B4jAc4xyIaLdH6hLEnHjflmMwJ1cn26OUyM8VveD4BOHRGMKObwORMB7laEmGRke5psBSX3g2E+CBX4UBxl3F8Ediq0KLscQQMLX5v4RbeBHvzQP7RmLNoJPWHobSChyKcQzfu0aEk/ChRbV5EpuwZcJTxwpqUjHJADz3dbjBy+3yXd0VDI8cS/kdypcNwxko8Sk3qMbY769SNGM8QSKS1lEtLhWcS4Jk/QFctLqenovIijFetO+OkM6az6DyGLnBV+AAQzs6Yc6SPgu7YYP6WeooUgyaU1Q66W1vo9VDvqKVHEkPIFjuFNdqKmcAv+CqBzM39OKGk+PyPqwev+UcJcnKJukINulzboUolLeZZ2RZUWPsT1eEJPmFVIk+UD+sYelT9NtxFhAxeMXT0Zk0WTsChBXlekIG74gfqlQ/T7KxWIMieaYQd69N2t+MA4PyK+cMwslp529NbxH457oUsueXioW0Ke2b1mlUCaGX37IYSTPn2AFLN8WS5p/I1J+Y3b9W7RHeAKslb1DO6b961OjA==
x-microsoft-antispam: BCL:0;
x-microsoft-antispam-message-info: L9MVHEDyuVVrSlN60XhMHUwyFDWfyjnthUsRwlHVTX7yYlgpLTktP1u2eBIde24jC6yqxaST8N5A3nQTf6bbT4oSyhVtCH+JY3wSmCxPMzNqP8cobpi/LZu8lslIhMjTvj2+fmum6z8sm2TPbD7CkfLpdbBK/7bU0XuffLtDSm4YI4Gsiv4xqyIXbWpVTHeyujnoErcKOpSiEglya1HVN4MNOE+6wT3+3hLPWecq/HMtFBkFE5YBIae7v3BuVI//k6euCpk0400/w9z/wgIt942sBD6QlF2L5DWSc27HtI8BFVvrGuLSv3/TG1dZmvlA29vJPoTZWmVfpiN3YuzjUMqmgAzmykd9j60Aj9VmPU0rrhafo7OK4GpN5FKujezzZO9xTXaRwMjqopfkaX/xdGUFROgzEDn9auA3uhZfQPiuc5IvUl8NXFWPrK5nKlMD69La+WUJ/h97yG/W8Z4WVLUnXji2JftGGlJjC12IeHl//Y5ZNxubshXLTaQWewhzw9ors2p+DmV8Ajk0LtZmV9XjQMXzWHkgwahN0uxy+dW8E27ytEi1vnknsbaoH8Qy246PVXGjE02wYM/D/OxcmDZg1xGXtyylIVCuIZ6k8uGEV+P4K1gTsUSn2WhRND8pd8Ef2JYKK+ReHOHD6Q4Zg08Bb8wynJexMp7xqbT/o6U=
x-ms-exchange-antispam-messagedata-chunkcount: 1
x-ms-exchange-antispam-messagedata-0: FDJQT8Pxj2W4lyE6dZwUmp/0KaxgeEK0UyUbyBvlYRsQnTU8NdUqi7vbaNRfxlWHRFGmQ82mOktauPUeTkrCJ1TmC7wiCTy0bEF+NmA7Aj99fWXFjSMLRl2Dr/f/pbzwaRvLaPtEUffqzJTzwroVG7e6cJG/X4tn0cHu+dtBh/mTZcPrCfmQYAkk/SSmEBSvOLQXSHOVZC1zVvKalM1DVHw80HWvFUPZ3nwljolF+zUFAjhIPC49pnp+IZWQpmhZci56feE6Z+tndWRq1QVOKQ58N/XU568xI1VYa6pR3NlmFVaA4wTdEHmmDNRE6IFI9ER8DhV3y1EKDcnYoV4/gJSuWZvafPoVP9xjS9b0LzlD9WbfP6kuV9jcuclRRcp1p/4tMsuEK1UYfqwG2rt85tWNtn4Atnh55LmUseAb4w5QNgZggvZPZaBEQjDeGk5ZRa7AEC6BBEdxXQdsYyIELY5cBycu19eDbUGMK4/Lgl7ywqXY8GtKDmd7FiuyPXuIuY14vky565kbanaeqN3C+f3sNYNK7MJm9JgtwtmfV6aOqSw6V+e02hBSJK+Sh4rIfD4/O7o2JkICzSaMtCZTnwsXS5mikQc3yPXWy+XX8E+YkeipPT1FQvI8yvxfH2TtUvHFx1Il/IDmihDnsl7TpwxfPXG8quJW/1hN58ZCHcWSeDLOuHtNo2n+KZrxbu7chbtnBhJkNDGiukME9L1u0xeu+YPcLPQx5/r/Hy36PEriL86y2GMognqabp+Rpu2GqCnKL4fJ335R/ChiTHOosnuCGFciQ6oC5gMuE1F2rP3wiqCnQj7DntsiKVSNIDtiqcuw+MrI6y1woH2Cj+2/RvIKx97ausXubXc/cv8XSVZprXo2NVg6Ce10VTV3vsDk1GwwxVD1p7aC5/4Mb05/VMhJOkEU8wabXV94cXzmwkAe+BlDi4Qv/igm34Yo/2l1FNpDr72Psr4nkp12aizNGLi4Dwl2sCyBnKBlI4GhPPBxZWcXo+FbWeyqi9cET9AkakCmzpJQK8UIRA22KFk7Tof0SXxdI9/F1AJDDZFf4OP0Ll3w4U2HOBrESuXu+n5A2FoOXNldB1DuddpE4ay/OkybVAUpWfli7BZP7I/Ma8DsyI2rfM797LH/7W0Y5KfofeNZAaErIN96NaxAyN7UfWFfvP17jya39JqwrZz0Cjw+TSIiuquPl7x+9VR4C4gXQQ/rJ2fgDxV8Vepx9Yx8Ux1XsROMlukw1Zmwptx2sPtLFSk04wrkg5XxrW0X2FfBCa/SzRZbRNO1Z+XvosuaHDwmdw09i98F2nYYXMqgumc=
Content-Type: text/plain; charset="us-ascii"
Content-Transfer-Encoding: quoted-printable
MIME-Version: 1.0
X-OriginatorOrg: sct-15-20-4755-11-msonline-outlook-3d941.templateTenant
X-MS-Exchange-CrossTenant-AuthAs: Internal
X-MS-Exchange-CrossTenant-AuthSource: SJ0PR02MB7439.namprd02.prod.outlook.com
X-MS-Exchange-CrossTenant-RMS-PersistedConsumerOrg: 00000000-0000-0000-0000-000000000000
X-MS-Exchange-CrossTenant-Network-Message-Id: 36fb3ebb-fc54-4d80-3d52-08dc487a39fc
X-MS-Exchange-CrossTenant-rms-persistedconsumerorg: 00000000-0000-0000-0000-000000000000
X-MS-Exchange-CrossTenant-originalarrivaltime: 20 Mar 2024 01:08:17.5366 (UTC)
X-MS-Exchange-CrossTenant-fromentityheader: Hosted
X-MS-Exchange-CrossTenant-id: 84df9e7f-e9f6-40af-b435-aaaaaaaaaaaa
X-MS-Exchange-Transport-CrossTenantHeadersStamped: SA0PR02MB7500
Archived-At: <https://mailarchive.ietf.org/arch/msg/last-call/KkP6AR7M8E7iaVf-aM3g9pnczJs>
Subject: Re: [Last-Call] CORRECTED Last Call: <draft-ietf-cose-key-thumbprint-04.txt> (CBOR Object Signing and Encryption (COSE) Key Thumbprint) to Proposed Standard
X-BeenThere: last-call@ietf.org
X-Mailman-Version: 2.1.39
Precedence: list
List-Id: IETF Last Calls <last-call.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/last-call>, <mailto:last-call-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/last-call/>
List-Post: <mailto:last-call@ietf.org>
List-Help: <mailto:last-call-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/last-call>, <mailto:last-call-request@ietf.org?subject=subscribe>
X-List-Received-Date: Wed, 20 Mar 2024 01:08:44 -0000

The document currently requests registration of the "ckt" (COSE Key Thumbprint) confirmation method as follows:

   *  Confirmation Method Name: ckt
   *  Confirmation Method Description: COSE Key Thumbprint
   *  JWT Confirmation Method Name: jkt
   *  Confirmation Key: [[TBD1]]
   *  Confirmation Value Type(s): binary string
   *  Change Controller: IESG
   *  Specification Document(s): [[This document]]

This is not parallel to the "jkt" (JWK SHA-256 Thumbprint) registration at https://www.iana.org/assignments/jwt/jwt.xhtml#confirmation-methods, in that it doesn't include the hash function.

Please change "COSE Key Thumbprint" to "COSE Key Thumbprint using SHA-256 Hash Function".

                                Thanks,
                                -- Mike

-----Original Message-----
From: iesg-secretary@ietf.org <iesg-secretary@ietf.org>
Sent: Wednesday, March 13, 2024 3:36 PM
To: IETF-Announce <ietf-announce@ietf.org>
Cc: cose-chairs@ietf.org; cose@ietf.org; draft-ietf-cose-key-thumbprint@ietf.org; michael_b_jones@hotmail.com; paul.wouters@aiven.io
Subject: CORRECTED Last Call: <draft-ietf-cose-key-thumbprint-04.txt> (CBOR Object Signing and Encryption (COSE) Key Thumbprint) to Proposed Standard


The IESG has received a request from the CBOR Object Signing and Encryption WG (cose) to consider the following document: - 'CBOR Object Signing and Encryption (COSE) Key Thumbprint'
  <draft-ietf-cose-key-thumbprint-04.txt> as Proposed Standard

The IESG plans to make a decision in the next few weeks, and solicits final comments on this action. Please send substantive comments to the last-call@ietf.org mailing lists by 2024-04-02. Exceptionally, comments may be sent to iesg@ietf.org instead. In either case, please retain the beginning of the Subject line to allow automated sorting.

Abstract


   This specification defines a method for computing a hash value over a
   COSE Key. It defines which fields in a COSE Key structure are used in
   the hash computation, the method of creating a canonical form of the
   fields, and how to hash the byte sequence.  The resulting hash value
   can be used for identifying or selecting a key that is the subject of
   the thumbprint.




The file can be obtained via
https://datatracker.ietf.org/doc/draft-ietf-cose-key-thumbprint/



No IPR declarations have been submitted directly on this I-D.


The document contains these normative downward references.
See RFC 3967 for additional information:
    rfc9053: CBOR Object Signing and Encryption (COSE): Initial Algorithms (Informational - Internet Engineering Task Force (IETF))
    rfc6755: An IETF URN Sub-Namespace for OAuth (Informational - Internet Engineering Task Force (IETF))