JOSE (JavaScript Object Signing and Encryption) WG 6 March 2014, 1700-1830 (UTC) =================================================== The jose wg meeting was convened by Karen O'Donoghue. Peter Yee volunteered to take minutes, and the note well was presented. Co-chair Jim Schaad participated remotely. A special thank you was made to Sean Turner as the outgoing Security AD. WG Status Š Karen OÕDonoghue ========================= The four core documents have completed WGLC with minor changes. These are -json-web-algorithms-21, -json-web-encryption-21, -json-web-key-21, and -json- web-signature-21. There is consensus on sending these documents on to the IESG/IETF LC. Cooking with JOSE Š Matt Miller ========================== The initial draft of this document is -cookbook-00 and has been out for nearly three months. The document gives examples of signing/verifying and encryption/decryption. It supplies the inputs, generated factors, operations, and outputs (both compact and JSON versions) for a variety of examples. The signature examples vary according to algorithm, key type, header protection level, whether signatures are detached, and whether multiple signatures are employed. For encryption algorithms, variation is supplied by the choice in key algorithm, content algorithm, key type, header protection level, use of explicit AAD, compression, and whether there are multiple recipients. The draft will be updated to match the latest versions of the four drafts noted above. That update should be done by the end of March if not earlier. Review by the WG and others would be most appreciated. Richard Barnes (BBN) doesnÕt think review of this document would be that useful, but thinks that implementers of various JW* implementations testing the examples would be really helpful. Brian Campbell says he will do this with his implementation. Jim Schaad asked for examples using non-ASCII content for signing and then checks be made for any missing use cases. Mike Jones (Microsoft) wants examples of nested signing and encryption. AOB ==== Richard Barnes said he didnÕt have a chance to review the primary documents during the WGLC but will do so during the IETF LC. Wendy Seltzer (W3C WebCrypto WG) will ask WebCrypto participants to look at the documents. The WG will also give input on how to use WebCryptoÕs APIs. Jim Schaad did notify the WebCrypto mailing list about the JOSE WGLCs. The meeting was adjourned at 17:30.