[media-types] Re: Media type for SUIT_Report_Protected
Brendan Moran <[email protected]>
| Newsgroups | gmane.ietf.types |
|---|---|
| Message-ID | <CAPmVn1NjKvPSa-=_Kcp_cpHy2HVMMzuaHkAcc1o057JSfepcKA@mail.gmail.com> |
Hi Murray, Would the following update clear things up? application/suit-report+cose Type name: application Subtype name: suit-report+cose Required parameters: n/a Optional parameters: n/a Encoding considerations: binary (CBOR) Security considerations: Section 10 of https://datatracker.ietf.org/doc/draft-ietf-suit-report/ Interoperability considerations: SUIT Reports are encoded as CBOR and optionally wrapped in any COSE structure (e.g., COSE_Sign1, COSE_Mac0, COSE_Encrypt0). Receivers must be able to identify and process the COSE envelope used and support compatible COSE algorithms for validation or decryption. All versioning and structure are self-describing within the CBOR SUIT_Report format, and no media-type parameters are used for negotiation. Interoperability therefore depends on shared deployment profiles that specify the expected COSE protections and algorithms. Comprehension of a SUIT Report is dependent on obtaining a matching SUIT Manifest. The structure is effectively opaque if the matching SUIT Manifest cannot be sourced. Published specification: https://datatracker.ietf.org/doc/draft-ietf-suit-report/ Applications that use this media type: SUIT Manifest Processor, SUIT Manifest Distributor, SUIT Manifest Author, RATS Attesters, RATS Verifiers Fragment identifier considerations: The syntax and semantics of fragment identifiers are as specified for "application/cose". Person & email address to contact for further information: SUIT WG mailing list ([email protected]) Intended usage: COMMON Restrictions on usage: none Author/Change controller: IETF Provisional registration: no On Sun, Aug 10, 2025 at 6:18 PM Murray S. Kucherawy <[email protected]> wrote: > On Tue, Jul 29, 2025 at 8:46 AM Brendan Moran < > [email protected]> wrote: > >> As part of the SUIT working group, we have been developing a reporting >> format for firmware updates. This reporting format is defined in: >> https://datatracker.ietf.org/doc/draft-ietf-suit-report/ >> >> In this draft we have proposed a media type registration: >> >> application/suit-report+cose >> >> Type name: application >> Subtype name: suit-report+cose >> Required parameters: n/a >> > > Where'd "Optional Parameters" go? > > >> Encoding considerations: binary (CBOR) >> Security considerations: Section 10 of >> https://datatracker.ietf.org/doc/draft-ietf-suit-report/ >> Interoperability considerations: n/a >> > > Why is this N/A? > > >> Published specification: >> https://datatracker.ietf.org/doc/draft-ietf-suit-report/ >> Applications that use this media type: SUIT Manifest Processor, SUIT >> Manifest Distributor, SUIT Manifest Author, RATS Attesters, RATS >> Verifiers >> Fragment identifier considerations: The syntax and semantics of >> fragment identifiers are as specified for "application/cose". >> Person & email address to contact for further information: SUIT WG >> mailing list ([email protected]) >> Intended usage: COMMON >> Restrictions on usage: none >> Author/Change controller: IETF >> Provisional registration: no >> > > -MSK > > <https://www.norton.com> Virus-free.www.norton.com > <#m_-4518444868643827488_DAB4FAD8-2DD7-40BB-A1B8-4E2AA1F9FDF2> > _______________________________________________ media-types mailing list -- [email protected] To unsubscribe send an email to [email protected]