Skip to content

Issue #350 - dropping algo strictness - #356

Open
appsdesh wants to merge 1 commit into
mainfrom
appsdesh/350-event-signature-alg
Open

appsdesh wants to merge 1 commit into
mainfrom
appsdesh/350-event-signature-alg

Conversation

@appsdesh

Copy link
Copy Markdown
Contributor

Closed #350

@appsdesh
appsdesh requested a review from a team as a code owner September 29, 2026 17:24
by other means such as TLS; the `none` algorithm MUST NOT be used or accepted.

The Transmitter and Receiver MUST use a mutually supported signing algorithm,
established by means outside the scope of this profile. Receivers MUST reject

@thomasdarimont thomasdarimont Sep 29, 2026 •

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Would that wording still allow SSF signature negotiation mechanisms as suggested by Joseph? #355

Copy link
Copy Markdown
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Signature negotiation is general aspect of JWKS based validations, imo, we should not take dependency on it and add any specific language around it

Comment on lines +355 to +356
established by means outside the scope of this profile. Receivers MUST reject
events signed with an algorithm they are not configured to accept.

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

This feel like it should be a part of the base spec, not the interop profile.

Copy link
Copy Markdown
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

base spec calls SET signatures as optional, we are making it mandatory in interop spec, hence added here

Comment on lines +504 to +505
{{event-signatures}}). This allows deployments to adopt stronger algorithms
and retire weaker ones. Receivers remain responsible for enforcing their own

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

This allows deployments to adopt stronger algorithms and retire weaker ones.

I think that's an over claim. It doesn't provide any mechanism at all for retiring apart from out-of-band negotiation, which is how you do it without the profile. Nor does it have any mechanism for showing a stronger algorithm is available.

Copy link
Copy Markdown
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Are you suggesting dropping this sentennce? I wanted to provide forward compatibility when I added it

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

CAEP Interop Profile: Event Signature Algorithm

3 participants