Closed jimsch closed 9 years ago
This is not a problem with the NIST documents as it would the same as doing ASN.1. I really hated doing the byte munging especially in JavaScript to get the concat done right. However probably the correct answer for this is to say no, do what is done for JOSE.
This issue went to the list and the concept of using CBOR arrays was not objected to.
the current KDF text about how to build the string to be hashed is a complete mess for JOSE.
It would be much simpler to define a CBOR structure to hold the individual fields, encode that structure and then hash it.