Re: [secdir] [jose] JWK member names, was: SECDIR review of draft-ietf-jose-json-web-key-31

Richard Barnes <rlb@ipv.sx> Wed, 17 September 2014 16:52 UTC

Return-Path: <rlb@ipv.sx>
X-Original-To: secdir@ietfa.amsl.com
Delivered-To: secdir@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id DEF541A06B4 for <secdir@ietfa.amsl.com>; Wed, 17 Sep 2014 09:52:46 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.977
X-Spam-Level:
X-Spam-Status: No, score=-1.977 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, FM_FORGED_GMAIL=0.622, HTML_MESSAGE=0.001, RCVD_IN_DNSWL_LOW=-0.7] autolearn=ham
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id FUewTyiqSRoP for <secdir@ietfa.amsl.com>; Wed, 17 Sep 2014 09:52:44 -0700 (PDT)
Received: from mail-lb0-f173.google.com (mail-lb0-f173.google.com [209.85.217.173]) (using TLSv1 with cipher ECDHE-RSA-RC4-SHA (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 9B4341A06BD for <secdir@ietf.org>; Wed, 17 Sep 2014 09:52:43 -0700 (PDT)
Received: by mail-lb0-f173.google.com with SMTP id w7so2218642lbi.32 for <secdir@ietf.org>; Wed, 17 Sep 2014 09:52:41 -0700 (PDT)
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20130820; h=x-gm-message-state:mime-version:in-reply-to:references:date :message-id:subject:from:to:cc:content-type; bh=P6gFYXyO6C8WRiFGAhX5qtD9re6V014jQJuyVuddsJw=; b=H8f3UIWBhrqwuIc40/w4lxDOInLwizEH3mmzLSYnQeJFJVjsOeYBQvFCfUvd1Yfnac 0VOSUVhcDbh39oXvMs0ib0EJP6/NxF45DGKw8VKbtpa1KjyzOsvqYf+I45ASpseDDciY Bp1Tnp4lFvNLzeTZs/vU1ulpz2UGbZrbPzDHVrM423Er6fagJ5Cd2H50r3hEF9Nn4sTq zrXImVCfacdNjKCcBGtUl0ARQYOcQUBxtWBkGvL8Yf7W7V12VKsWt7bF1Eq8uTTpTGWq p/+CgoNXylBKCOCqzmkpjSMX9Tbz+Ab/eel+cv2kA5KzwY2OS2sziy4BcmU4cNPJr53F RPRw==
X-Gm-Message-State: ALoCoQnQSWl2reZm4Oc4usTx/uh207vAfhP9ghWuCIfuZryB4U0rzMky0fpFabv9Y9MGkN9EbXZ4
MIME-Version: 1.0
X-Received: by 10.152.234.76 with SMTP id uc12mr46079292lac.50.1410972761622; Wed, 17 Sep 2014 09:52:41 -0700 (PDT)
Received: by 10.25.159.84 with HTTP; Wed, 17 Sep 2014 09:52:41 -0700 (PDT)
In-Reply-To: <CAHBU6ivJ+mQZetWDDkRjP1nB+XOCLyXatq4k9bv4y7onAgu=ug@mail.gmail.com>
References: <CAHbuEH4Ccn2Z=8kEECzvgjmtshwsFoa-EH_NpkJPos7zirGeaQ@mail.gmail.com> <4E1F6AAD24975D4BA5B16804296739439AEC00DB@TK5EX14MBXC292.redmond.corp.microsoft.com> <5416FE10.3060608@bbn.com> <CAHBU6iu3GfsLCAint3z7risZUnVW4EK0WrGVW6Dv=gvppiHSxQ@mail.gmail.com> <4E1F6AAD24975D4BA5B16804296739439AECCCDD@TK5EX14MBXC292.redmond.corp.microsoft.com> <54173546.5000400@bbn.com> <CAHBU6ivb3BeEufcnJB+eSk8wgETMx+qzH3miE6Z1jtrQkXNR3w@mail.gmail.com> <4E1F6AAD24975D4BA5B16804296739439AECE40B@TK5EX14MBXC292.redmond.corp.microsoft.com> <54184EBA.3010109@bbn.com> <4E1F6AAD24975D4BA5B16804296739439AED1727@TK5EX14MBXC292.redmond.corp.microsoft.com> <5418987E.1060307@bbn.com> <CFD36394-E707-4D51-9689-DD8B1FD320D5@ve7jtb.com> <54199E11.1000809@bbn.com> <CAHBU6ivJ+mQZetWDDkRjP1nB+XOCLyXatq4k9bv4y7onAgu=ug@mail.gmail.com>
Date: Wed, 17 Sep 2014 12:52:41 -0400
Message-ID: <CAL02cgRrW7nSRiBRoUxGvgUN-cxhbRVbYbtZ=BUKVkDmfd8LEg@mail.gmail.com>
From: Richard Barnes <rlb@ipv.sx>
To: Tim Bray <tbray@textuality.com>
Content-Type: multipart/alternative; boundary=001a11340f123e9b22050345b214
Archived-At: http://mailarchive.ietf.org/arch/msg/secdir/7rH7Lyep3BYQQE0DB3QMgZ4BCYE
Cc: "jose-chairs@tools.ietf.org" <jose-chairs@tools.ietf.org>, "secdir@ietf.org" <secdir@ietf.org>, "draft-ietf-jose-json-web-key.all@tools.ietf.org" <draft-ietf-jose-json-web-key.all@tools.ietf.org>, Kathleen Moriarty <kathleen.moriarty.ietf@gmail.com>, Michael Jones <Michael.Jones@microsoft.com>, "jose@ietf.org" <jose@ietf.org>, John Bradley <ve7jtb@ve7jtb.com>
Subject: Re: [secdir] [jose] JWK member names, was: SECDIR review of draft-ietf-jose-json-web-key-31
X-BeenThere: secdir@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: Security Area Directorate <secdir.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/secdir>, <mailto:secdir-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/secdir/>
List-Post: <mailto:secdir@ietf.org>
List-Help: <mailto:secdir-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/secdir>, <mailto:secdir-request@ietf.org?subject=subscribe>
X-List-Received-Date: Wed, 17 Sep 2014 16:52:47 -0000

People are going to use off-the-shelf JSON parsers because they're the
obvious tool for the job.  It seems like a general maxim that if we
prohibit using the obvious tools without a really good reason (which I
don't really see here), people are just going to ignore the prohibition.

--Richard

On Wed, Sep 17, 2014 at 12:42 PM, Tim Bray <tbray@textuality.com> wrote:

> The chance  of the JOSE working group moving the vast world of deployed
> JSON infrastructure round to 0.00.   Thus putting a MUST reject in here
> would essentially say you can’t use well-debugged production software, and
> would be a really bad idea.
>
> On the other hand, if JOSE specified that producers’ messages MUST conform
> to I-JSON, and a couple other WGs climbed on that bandwagon, and the word
> started to get around, I wouldn’t be surprised if a few of the popular JSON
> implementations added an I-JSON mode.  That would be a good thing and
> lessen the attack surface of all JSON-based protocols (which these days, is
> a whole lot of them).
>
>
>
> On Wed, Sep 17, 2014 at 7:43 AM, Stephen Kent <kent@bbn.com> wrote:
>
>> OK, now I have a clear answer to the question I posed earlier, i.e., this
>> is a JSON parser problem, not specific to the JOSE-defined formats.
>>
>> I still believe it makes sense for the RFC(s) to mandate rejection of
>> duplicates,
>> as a way to "encourage" transition to better parsers, as others have
>> noted. And
>> I rely on Tero's judgement that the required changes are not onerous.
>>
>> Steve
>>
>
>
>
> --
> - Tim Bray (If you’d like to send me a private message, see
> https://keybase.io/timbray)
>
> _______________________________________________
> jose mailing list
> jose@ietf.org
> https://www.ietf.org/mailman/listinfo/jose
>
>