First pass at HAIP HPKE section - #362
Conversation
|
|
||
| ### Response Encryption using HPKE with JWE | ||
|
|
||
| Response encryption MUST be performed as specified in [@!OIDF.OID4VP, section 8.3.1]. The JWE `alg` (algorithm) header parameter (see [@!RFC7516, section 4.1.1]) value `HPKE-0` (as defined in [@I-D.ietf-jose-hpke-encrypt]). The JWE `enc` (encryption algorithm) header parameter (see [@!RFC7516, section 4.1.2]) value `A128GCM` (as defined in [@!RFC7518, section 5.3]) MUST be supported by Verifiers and Wallets. |
There was a problem hiding this comment.
need to omit enc.
Co-authored-by: Kristina <52878547+Sakurann@users.noreply.github.com>
GarethCOliver
left a comment
There was a problem hiding this comment.
lgtm with the suggested change.
Co-authored-by: Kristina <52878547+Sakurann@users.noreply.github.com> Co-authored-by: Jan Vereecken <ciao@janvereecken.com>
|
|
||
| ### Response Encryption using HPKE with JWE | ||
|
|
||
| Response encryption MUST be performed as specified in [@!OIDF.OID4VP, section 8.3.1] using JOSE HPKE integrated encryption. The JWE `alg` (algorithm) header parameter (see [@!RFC7516, section 4.1.1]) value `HPKE-0` (as defined in [@I-D.ietf-jose-hpke-encrypt]) MUST be supported by Wallets and Verifiers. `psk_id` (pre-shared key id) header parameter MUST NOT be present. The JWE `enc` (encryption algorithm) header parameter (see [@!RFC7516, section 4.1.2]) MUST NOT be present. |
There was a problem hiding this comment.
psk_id(pre-shared key id) header parameter MUST NOT be present
The JWE
enc(encryption algorithm) header parameter (see [@!RFC7516, section 4.1.2]) MUST NOT be present.
It would probably be helpful to clarify where/when they must not be present.
|
I think this needs to be rebased before merging, and also we should probably check that section number references are still accurate. |
|
discussed in WG: @c2bo will review |
Co-authored-by: Frederik Krogsdal Jacobsen <fkj@users.noreply.github.com> Co-authored-by: Kristina <52878547+Sakurann@users.noreply.github.com>
|
|
||
| ### Response Encryption using ECDH-ES with JWE | ||
|
|
||
| Response encryption MUST be performed as specified in [@!OIDF.OID4VP, section 8.3]. The JWE `alg` (algorithm) header parameter (see [@!RFC7516, section 4.1.1]) value `ECDH-ES` (as defined in [@!RFC7518, section 4.6]), with key agreement utilizing keys on the `P-256` curve (see [@!RFC7518, section 6.2.1.1]) MUST be supported. The JWE `enc` (encryption algorithm) header parameter (see [@!RFC7516, section 4.1.2]) values `A128GCM` and `A256GCM` (as defined in [@!RFC7518, section 5.3]) MUST be supported by Verifiers. Wallets MUST support `A128GCM` or `A256GCM` or both. If the Wallet supports both, it SHOULD use `A256GCM` for the JWE `enc`. Verifiers MUST list both `A128GCM` and `A256GCM` in `encrypted_response_enc_values_supported` in their client metadata. |
There was a problem hiding this comment.
We are pointing to OpenID4VP 1.0, so these links will currently be broken. I guess that is fine and we don't have to change the link 1.1 editor's draft, but will create broken references for the time being.
|
Discussed today. @c2bo will raise an issue to track the reference to VP 1.1 |
Co-authored-by: Christian Bormann <chris.bormann@gmx.de>
|
@bhjelm this has been updated and is now ready for your review |
|
Discussed today. @bhjelm will review. Looks ready to merge after. |
PR approved. |
resolves #356
resolves #357
builds up on #361 (#361 needs to be merged first)