Hi,
this document describes the current Persona formats and the differences to
JOSE.
My understanding from the dev-identity emails is that Persona and FxA want
to align with JOSE and get rid of the differences:
https://github.com/djc/id-specs/blob/prod/browserid/json-formats.md

As a developer I don't buy the Anti-base64-encoding / simplicity argument
because I only have to output the decoded message to my payment-server's
logs. I never sniff the messages from the wire which  would be much harder
because they come through an SSL channel anyway.

I think that canonicalization / normalization of the to-be-signed payment
message is a HUGE mistake. That was a major pain with xmldsig in the past.
base64 encoding stuff and working on that is MUCH better for
interoperability.


-Axel


2013/12/24 Luke Howard <[email protected]>

>
> On 24 Dec 2013, at 12:13 pm, Manu Sporny <[email protected]>
> wrote:
>
> > If the base64 issue was the only issue, I'd agree with you. However, the
> > review that was done outlined a number of other issues[1] that IMHO,
> > when combined with the goals of Persona, make JOSE a questionable fit.
> > JOSE was picked at the time because there really wasn't a viable
> > alternative. Now that there may be one, things might change.
>
> Off-topic for this mailing list, but I'd certainly be interested to see a
> discussion on dev-identity about this, particularly as the Persona team are
> (last I heard) busy aligning with the current JOSE data formats.
>
> > Persona doesn't seem to need any of the more complex functionality
> > brought by JOSE (resulting in unnecessarily complex and hard to debug
> > messages). Secure Messaging could achieve the same level of
> > functionality, more simply, for Web developers.
>
> In the document you refer to, it's unclear where the signature for
> EncryptedMessage2012 is placed -- is there a specification for this?
>
> -- Luke
> _______________________________________________
> jose mailing list
> [email protected]
> https://www.ietf.org/mailman/listinfo/jose
>
_______________________________________________
jose mailing list
[email protected]
https://www.ietf.org/mailman/listinfo/jose

Reply via email to