There is one serious open issue with COSE-HPKE: 
https://github.com/cose-wg/draft-ietf-cose-hpke/issues/112. It’s the 
Recipient_structure, not the headers that MUST be encoded deterministically.

I also think there’s a lot of wording improvement needed in the section on 
"HPKE Key Encryption Mode”.

I’m working on a PR.

LL


> On Feb 7, 2026, at 8:25 AM, Orie <[email protected]> wrote:
> 
> I believe the JOSE/COSE HPKE documents are ready for wider IETF review.
> 
> Consider this my positive support for both WGLCs, (as an author / implementer)
> 
> OS
> 
> On Tue, Jan 27, 2026 at 12:57 PM Hannes Tschofenig <[email protected] 
> <mailto:[email protected]>> wrote:
>> I have tested my COSE HPKE implementation against Orie's implementation and 
>> successfully tested HPKE-7 and HPKE-7-KE in all variants (i.e. with and 
>> without externally provided aad and info). I will test other ciphersuites as 
>> soon as those algorithm implementations become available.
>> 
>> As an insight from those tests I will update the examples in the draft by 
>> adding externally provided aad and info. I will do this asap.
>> 
>> Regarding the JOSE HPKE I have tested my implementation against Filip 
>> Sokan's implementation for HPKE-0, HPKE-1, HPKE-2, HPKE-3 and HPKE-7 worked 
>> (and the corresponding key encryption modes). I also verified the examples 
>> in the draft.
>> 
>> In a nutshell: I believe the documents are in good shape.
>> 
>> Ciao
>> Hannes
>> 
>> Am 27.01.2026 um 19:13 schrieb Michael Jones:
>>> I believe this specification is ready for publication.  It incorporates 
>>> substantive working group feedback and I believe embodies solid consensus 
>>> decisions.  There are multiple independent interoperable implementations.
>>> 
>>>  
>>> 
>>> It is well aligned with the JOSE HPKE specification 
>>> https://datatracker.ietf.org/doc/draft-ietf-jose-hpke-encrypt/.
>>> 
>>>  
>>> 
>>> There are other specifications waiting for this one to finish.
>>> 
>>>  
>>> 
>>> Let's get it done!
>>> 
>>>  
>>> 
>>>                                                        -- Mike
>>> 
>>>  
>>> 
>>> From: Ivaylo Petrov <[email protected]> 
>>> <mailto:[email protected]> 
>>> Sent: Wednesday, January 21, 2026 12:14 PM
>>> To: cose <[email protected]> <mailto:[email protected]>; Cose Chairs Wg 
>>> <[email protected]> <mailto:[email protected]>; 
>>> [email protected] <mailto:[email protected]>
>>> Cc: [email protected] <mailto:[email protected]>
>>> Subject: WGLC: draft-ietf-cose-hpke-20 (Ends 2026-02-11)
>>> 
>>>  
>>> 
>>> Dear COSE WG members,
>>> 
>>> This message starts a WG Last Call (WGLC) for:
>>> https://datatracker.ietf.org/doc/draft-ietf-cose-hpke/
>>> 
>>> Please review and indicate your support or objection to proceeding with the
>>> publication of this document by replying to this email keeping 
>>> [email protected] <mailto:[email protected]>
>>> in copy. Please provide rationale for support and explanations or 
>>> suggestions
>>> for objections.
>>> 
>>> Please note there is a parallel call going on in JOSE working group for the 
>>> document:
>>> https://datatracker.ietf.org/doc/draft-ietf-jose-hpke-encrypt/
>>> 
>>> Please consider reviewing both documents.
>>> 
>>> This Working Group Last Call ends on 2026-02-11
>>> 
>>> 
>>>                                                                 Thank you,
>>> 
>>>                                                                 -- Mike and 
>>> Ivo
>>> 
>>>                                                                 COSE 
>>> co-chairs
>>> 
>>> 
>>> Please note:
>>> Authors, and WG participants in general, are reminded of the Intellectual
>>> Property Rights (IPR) disclosure obligations described in BCP 79 [1].
>>> Appropriate IPR disclosures required for full conformance with the 
>>> provisions
>>> of BCP 78 [1] and BCP 79 [2] must be filed, if you are aware of any.
>>> Sanctions available for application to violators of IETF IPR Policy can be
>>> found at [3].
>>> 
>>> [1] https://datatracker.ietf.org/doc/bcp78/
>>> [2] https://datatracker.ietf.org/doc/bcp79/
>>> [3] https://datatracker.ietf.org/doc/rfc6701/
>>> 
>>> 
>>> 
>>> _______________________________________________
>>> COSE mailing list -- [email protected] <mailto:[email protected]>
>>> To unsubscribe send an email to [email protected] 
>>> <mailto:[email protected]>

_______________________________________________
jose mailing list -- [email protected]
To unsubscribe send an email to [email protected]

Reply via email to