Mike:

> I can add a sentence along the lines of the following to make Jim’s points 
> below clearer to non-expert readers:
>  
> “The specific identifiers used to tie the key derivation to the sender (Party 
> U) and the receiver (Party V) are application specific and beyond the scope 
> of this specification.”

I see the attraction of this approach, but I wonder if it would be possible to 
also include some advice to applications that make use of JOSE.

If the parties that are trying to form a pairwise key make different 
assumptions, then we do not get interoperability.  I am just trying to improve 
the likelihood of interoperability.

Russ

_______________________________________________
jose mailing list
[email protected]
https://www.ietf.org/mailman/listinfo/jose

Reply via email to