Re: [OAUTH-WG] More Criticism of JOSE

Carsten Bormann <cabo@tzi.org> Wed, 15 March 2017 21:16 UTC

Return-Path: <cabo@tzi.org>
X-Original-To: oauth@ietfa.amsl.com
Delivered-To: oauth@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 0435A131840 for <oauth@ietfa.amsl.com>; Wed, 15 Mar 2017 14:16:55 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -4.2
X-Spam-Level:
X-Spam-Status: No, score=-4.2 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, RCVD_IN_DNSWL_MED=-2.3] autolearn=ham autolearn_force=no
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id J404YsxCuk-2 for <oauth@ietfa.amsl.com>; Wed, 15 Mar 2017 14:16:54 -0700 (PDT)
Received: from mailhost.informatik.uni-bremen.de (mailhost.informatik.uni-bremen.de [IPv6:2001:638:708:30c9::12]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id C99E7131830 for <oauth@ietf.org>; Wed, 15 Mar 2017 14:16:53 -0700 (PDT)
X-Virus-Scanned: amavisd-new at informatik.uni-bremen.de
Received: from submithost.informatik.uni-bremen.de (submithost.informatik.uni-bremen.de [134.102.201.11]) by mailhost.informatik.uni-bremen.de (8.14.5/8.14.5) with ESMTP id v2FLGkks024022; Wed, 15 Mar 2017 22:16:46 +0100 (CET)
Received: from [192.168.217.124] (p5DCCCDC2.dip0.t-ipconnect.de [93.204.205.194]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by submithost.informatik.uni-bremen.de (Postfix) with ESMTPSA id 3vk4DG3mHKzDJ2W; Wed, 15 Mar 2017 22:16:46 +0100 (CET)
Content-Type: text/plain; charset="utf-8"
Mime-Version: 1.0 (Mac OS X Mail 10.2 \(3259\))
From: Carsten Bormann <cabo@tzi.org>
In-Reply-To: <CY4PR21MB0504E2A254D753F8BA3E99CBF5270@CY4PR21MB0504.namprd21.prod.outlook.com>
Date: Wed, 15 Mar 2017 22:16:45 +0100
Cc: Antonio Sanso <asanso@adobe.com>, "oauth@ietf.org" <oauth@ietf.org>
X-Mao-Original-Outgoing-Id: 511305405.565243-0a7a79e4db8077f38bd8fed93739e43c
Content-Transfer-Encoding: quoted-printable
Message-Id: <EAC67437-81C0-4246-9BF6-392B4C879100@tzi.org>
References: <mailman.539.1489455092.6649.oauth@ietf.org> <de3bdfc3f87fad59432f85f75db3d6b4@gluu.org> <814591e4-c21a-451b-cce9-e4f158f07c2e@gmail.com> <CY4PR21MB0504F80C01BF3378DE3794C6F5270@CY4PR21MB0504.namprd21.prod.outlook.com> <78BE56B7-0253-4635-AB46-F724A8536082@adobe.com> <CY4PR21MB0504E2A254D753F8BA3E99CBF5270@CY4PR21MB0504.namprd21.prod.outlook.com>
To: Mike Jones <Michael.Jones@microsoft.com>
X-Mailer: Apple Mail (2.3259)
Archived-At: <https://mailarchive.ietf.org/arch/msg/oauth/ufMenopZeGyrjpvRLJT5wCLC6aA>
Subject: Re: [OAUTH-WG] More Criticism of JOSE
X-BeenThere: oauth@ietf.org
X-Mailman-Version: 2.1.22
Precedence: list
List-Id: OAUTH WG <oauth.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/oauth>, <mailto:oauth-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/oauth/>
List-Post: <mailto:oauth@ietf.org>
List-Help: <mailto:oauth-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/oauth>, <mailto:oauth-request@ietf.org?subject=subscribe>
X-List-Received-Date: Wed, 15 Mar 2017 21:16:55 -0000

> On 15 Mar 2017, at 22:06, Mike Jones <Michael.Jones@microsoft.com> wrote:
> 
> Will you be in Chicago, Antonio?  If so, maybe you can sit down with us and work on advice to implementers.

And maybe we can also work out what part of that advice (and possibly which additional advice) applies to COSE.

Grüße, Carsten