erwah / ietf

CBOR Web Token
0 stars 2 forks source link

Evaluate recomendation of AEAD in create section. #24

Closed erdtman closed 7 years ago

erdtman commented 7 years ago

Comment from Jim: "8. The note for step 5 in section 6.1 is problematic from a number of things. A) AEAD algorithms are required, so it is not clear that the recommendation makes sense. B) there is a big difference between signing and MACing in terms of the amount and type of integrity provided. Replacing signing w/ AEAD loses a lot."

selfissued commented 7 years ago

Let's just delete the note. I think it adds more confusion than clarity.

selfissued commented 7 years ago

The note was deleted in PR #31 .