[media-types] Re: Media type for SUIT_Report_Protected

Brendan Moran <[email protected]>
Newsgroups gmane.ietf.types
Message-ID <CAPmVn1NjKvPSa-=_Kcp_cpHy2HVMMzuaHkAcc1o057JSfepcKA@mail.gmail.com>
Hi Murray,

Would the following update clear things up?

application/suit-report+cose

Type name: application
Subtype name: suit-report+cose
Required parameters: n/a
Optional parameters: n/a
Encoding considerations: binary (CBOR)
Security considerations: Section 10 of
https://datatracker.ietf.org/doc/draft-ietf-suit-report/

Interoperability considerations: SUIT Reports are encoded as CBOR and
optionally wrapped in any COSE structure (e.g., COSE_Sign1, COSE_Mac0,
COSE_Encrypt0). Receivers must be able to identify and process the COSE
envelope used and support compatible COSE algorithms for validation or
decryption. All versioning and structure are self-describing within the
CBOR SUIT_Report format, and no media-type parameters are used for
negotiation. Interoperability therefore depends on shared deployment
profiles that specify the expected COSE protections and algorithms.
Comprehension of a SUIT Report is dependent on obtaining a matching SUIT
Manifest. The structure is effectively opaque if the matching SUIT Manifest
cannot be sourced.

Published specification:
https://datatracker.ietf.org/doc/draft-ietf-suit-report/
Applications that use this media type: SUIT Manifest Processor, SUIT
Manifest Distributor, SUIT Manifest Author, RATS Attesters, RATS
Verifiers
Fragment identifier considerations: The syntax and semantics of
fragment identifiers are as specified for "application/cose".
Person & email address to contact for further information: SUIT WG
mailing list ([email protected])
Intended usage: COMMON
Restrictions on usage: none
Author/Change controller: IETF
Provisional registration: no

On Sun, Aug 10, 2025 at 6:18 PM Murray S. Kucherawy <[email protected]>
wrote:

> On Tue, Jul 29, 2025 at 8:46 AM Brendan Moran <
> [email protected]> wrote:
>
>> As part of the SUIT working group, we have been developing a reporting
>> format for firmware updates. This reporting format is defined in:
>> https://datatracker.ietf.org/doc/draft-ietf-suit-report/
>>
>> In this draft we have proposed a media type registration:
>>
>> application/suit-report+cose
>>
>> Type name: application
>> Subtype name: suit-report+cose
>> Required parameters: n/a
>>
>
> Where'd "Optional Parameters" go?
>
>
>> Encoding considerations: binary (CBOR)
>> Security considerations: Section 10 of
>> https://datatracker.ietf.org/doc/draft-ietf-suit-report/
>> Interoperability considerations: n/a
>>
>
> Why is this N/A?
>
>
>> Published specification:
>> https://datatracker.ietf.org/doc/draft-ietf-suit-report/
>> Applications that use this media type: SUIT Manifest Processor, SUIT
>> Manifest Distributor, SUIT Manifest Author, RATS Attesters, RATS
>> Verifiers
>> Fragment identifier considerations: The syntax and semantics of
>> fragment identifiers are as specified for "application/cose".
>> Person & email address to contact for further information: SUIT WG
>> mailing list ([email protected])
>> Intended usage: COMMON
>> Restrictions on usage: none
>> Author/Change controller: IETF
>> Provisional registration: no
>>
>
> -MSK
>
> <https://www.norton.com> Virus-free.www.norton.com
> <#m_-4518444868643827488_DAB4FAD8-2DD7-40BB-A1B8-4E2AA1F9FDF2>
>

_______________________________________________
media-types mailing list -- [email protected]
To unsubscribe send an email to [email protected]
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.