Ballot for draft-ietf-jose-hpke-encrypt
Yes
No Objection
No Record
Summary: Has enough positions to pass.
* In section 7.1, step 10, you generate a random IV. Should this IV also follow the guidance from 8937? It appears to be a nonce. Maybe a few more words beyond than "Generate a random" would be appropriate.
Thanks to Paul Kyzivat for the ARTART review.
Thanks to all involved for this clear, well-written document. Thanks to Paul Kyzivat for the ARTART review.
Thanks for the work done in this document. Only 1 minor non-blocking COMMENT though ### Section 11.1 A table with all atomic registrations from sections 11.1.* would have been easier to read and made the I-D shorter.
# IESG review of draft-ietf-jose-hpke-encrypt-20 CC @MikeBishop ## Comments ### Section 3, paragraph 14 I appreciate the thorough Terminology section. ### Section 4, paragraph 6 This suggests that if another KMM were defined in the future which didn't require "enc", it too would need to update 7516. Would it be better to mandate its exclusion if the KMM doesn't define a use for it? Or is the point that Integrated Encryption encompasses every case where an algorithm provides encryption itself? ### Section 6.1, paragraph 2 It's reasonably clear from context what these notations mean, but is this intended to be following any specified encoding language? It's not ABNF, TLS, or QUIC notation, but if you're following a particular format, it would be worth referencing it. ### Section 12, paragraph 5 While you're implementing it by wholesale replacement of the procedures, the net effect of the update is to add support for Integrated Encryption to the procedures. I'd suggest using that as the summary, so it's clear what the impact of the change is. ## Nits All comments below are about very minor potential issues that you may choose to address in some way - or ignore - as you see fit. There is no need to let me know what you did with these suggestions. ### Typos #### Section 10, paragraph 2 ``` - of public key distribution mechanism is assumed to exist but outside + of public key distribution mechanism is assumed to exist but is outside + +++ ``` ### Section 11.1, paragraph 2 This section would be considerably shorter as a table, rather than a subsection per registration.
Thank you to Peter Yee for the GENART review.