[media-types] Re: [IANA #1421573] application/vc+sd-jw t registration request
Michael Jones <[email protected]>
| Newsgroups | gmane.ietf.types |
|---|---|
| Message-ID | <MW2PR12MB2508B3358F7D71C94E0BDA1DB7A1A@MW2PR12MB2508.namprd12.prod.outlook.com> |
Hi Murray,
As I pointed out a week ago in https://mailarchive.ietf.org/arch/msg/media-types/bpg0uXkro9HglzHEusyYFf10Hc0/, the IETF made an official liaison inquiry to the W3C about whether the security considerations for the "Securing Verifiable Credentials using JOSE and COSE" specification, in which this registration is requested, are complete and accurate. The official response from the W3C is that they are.
Therefore, I don't believe that there remain any reasonable grounds for delaying this registration. Please proceed.
Thank you,
-- Mike
-----Original Message-----
From: Amanda Baber via RT <[email protected]>
Sent: Wednesday, December 10, 2025 3:57 PM
Cc: [email protected]; [email protected]
Subject: [media-types] [IANA #1421573] application/vc+sd-jwt registration request
Hi Murray,
Sending a reminder for this one from October 1st. Mike Jones sent a response on behalf of W3C asking that the registration be approved as-is. See below for more.
thanks,
Amanda
On Wed Oct 01 08:05:36 2025, [email protected] wrote:
> Hi Murray,
>
> Sorry this slipped through the cracks. Responses to your questions
> and observations are inline below, prefixed by “Mike>”.
>
> I will note that the text requesting the registration is in a W3C
> Recommendation (a final specification)
> https://www.w/
> 3.org%2FTR%2Fvc-jose-&data=05%7C02%7C%7C262c16bfd7334a40a2f008de383f78
> 86%7C84df9e7fe9f640afb435aaaaaaaaaaaa%7C1%7C0%7C639010042424173559%7CU
> nknown%7CTWFpbGZsb3d8eyJFbXB0eU1hcGkiOnRydWUsIlYiOiIwLjAuMDAwMCIsIlAiO
> iJXaW4zMiIsIkFOIjoiTWFpbCIsIldUIjoyfQ%3D%3D%7C0%7C%7C%7C&sdata=tTtHlkr
> lm13LVr%2BP%2Bmb3AOvkYiX170Dr6pkR6FtXje8%3D&reserved=0
> cose/ and so not subject to modification. Therefore, I would request
> that the registration be approved based on the existing specification
> text.
>
> Thank you,
> -- Mike
>
> From: Murray S. Kucherawy <[email protected]>
> Sent: Wednesday, July 23, 2025 10:27 AM
> To: [email protected]
> Cc: [email protected]
> Subject: [media-types] Re: [IANA #1421573] application/vc+sd-jwt
> registration request
>
> Sorry for the delay here. A few minor things, otherwise this should
> be good to go.
>
> -MSK
>
> On Tue, Jun 24, 2025 at 9:10 PM Amanda Baber via RT <iana-mime-
> [email protected]<mailto:[email protected]>> wrote:
> Name: Ivan Herman
>
> Email: [email protected]<mailto:[email protected]>
>
> These aren't part of the template in RFC 6838.
>
> Media type name: application
>
> Media subtype name: vc+sd-jwt
>
> Required parameters: N/A
>
> Optional parameters: N/A
>
> Encoding considerations: binary
>
> application/sd-jwt values are a series of base64url-encoded values
> (some of which may be the empty string) separated by period ('.') and
> tilde ('~') characters.
>
> This seems out of place; it should be included in the referenced
> published specification.
>
> Mike> In fact, this text is included in the referenced published
> Mike> specification at https://www.w3.org/TR/vc-jose-cose/#vc-json-jwt.
> Mike> I’ll also note that other similar media type registrations, such
> Mike> as application/jwt at
> Mike> https://na01.safelinks.protection.outlook.com/?url=https%3A%2F%252
> Mike> Fwww.iana.org%2Fassignments%2Fmedia-&data=05%7C02%7C%7C262c16bfd
> Mike> 7334a40a2f008de383f7886%7C84df9e7fe9f640afb435aaaaaaaaaaaa%7C1%7
> Mike> C0%7C639010042424234169%7CUnknown%7CTWFpbGZsb3d8eyJFbXB0eU1hcGki
> Mike> OnRydWUsIlYiOiIwLjAuMDAwMCIsIlAiOiJXaW4zMiIsIkFOIjoiTWFpbCIsIldU
> Mike> IjoyfQ%3D%3D%7C0%7C%7C%7C&sdata=SHV2Uk4c2HmwZzscm6NLBAvPJslCWHjC
> Mike> 4Fb7C6wYUFM%3D&reserved=0 types/application/jwt also includes
> Mike> include similar encoding considerations language.
>
> Security considerations: As defined in
> https://www.w/
> 3.org%2FTR%2Fvc-jose-&data=05%7C02%7C%7C262c16bfd7334a40a2f008de383f78
> 86%7C84df9e7fe9f640afb435aaaaaaaaaaaa%7C1%7C0%7C639010042424260516%7CU
> nknown%7CTWFpbGZsb3d8eyJFbXB0eU1hcGkiOnRydWUsIlYiOiIwLjAuMDAwMCIsIlAiO
> iJXaW4zMiIsIkFOIjoiTWFpbCIsIldUIjoyfQ%3D%3D%7C0%7C%7C%7C&sdata=rb1qeV9
> XJZPbHemYL8ZHKSobmoY9fGUkwQHZzSkbLfw%3D&reserved=0
> cose/#security-considerations. See also the security considerations in
> Selective Disclosure for JWTs (SD-JWT)
> (https://data/
> tracker.ietf.org%2Fdoc%2Fhtml%2Fdraft-ietf-oauth-selective-&data=05%7C
> 02%7C%7C262c16bfd7334a40a2f008de383f7886%7C84df9e7fe9f640afb435aaaaaaa
> aaaaa%7C1%7C0%7C639010042424285708%7CUnknown%7CTWFpbGZsb3d8eyJFbXB0eU1
> hcGkiOnRydWUsIlYiOiIwLjAuMDAwMCIsIlAiOiJXaW4zMiIsIkFOIjoiTWFpbCIsIldUI
> joyfQ%3D%3D%7C0%7C%7C%7C&sdata=qPWDm%2FJU7VgO76pFRCcsbGdWoRF6P6TlNWuli
> mbKZbY%3D&reserved=0
> disclosure-jwt).
>
> Do either of those talk about whether the payload of this media type
> contains executable code? RFC 6838 Section 4.6 requires that to be
> covered explicitly one way or the other, and after a cursory read of
> those, I didn't see it either. Happy to be corrected if I missed
> something.
>
> Mike> The encoding considerations make it clear that these data
> Mike> structures are strings of URL-safe ASCII characters. These are
> Mike> not executable.
>
> Interoperability considerations: As defined in
> https://www.w3.org/TR/vc-jose-cose/#conformance.
>
> Published specification:
> https://www.w/
> 3.org%2FTR%2Fvc-jose-cose&data=05%7C02%7C%7C262c16bfd7334a40a2f008de38
> 3f7886%7C84df9e7fe9f640afb435aaaaaaaaaaaa%7C1%7C0%7C639010042424339813
> %7CUnknown%7CTWFpbGZsb3d8eyJFbXB0eU1hcGkiOnRydWUsIlYiOiIwLjAuMDAwMCIsI
> lAiOiJXaW4zMiIsIkFOIjoiTWFpbCIsIldUIjoyfQ%3D%3D%7C0%7C%7C%7C&sdata=inW
> QOZ5vlWmTn6qK7wvTPe6vAesVmF26iXsBj8NLq84%3D&reserved=0
>
> Applications which use this media: W3C Verifiable Credential issuer,
> holder, and verifier software, conforming to the [VC-DATA-MODEL-2.0]
> (https://www/.
> w3.org%2FTR%2Fvc-data-model-2.0%2F&data=05%7C02%7C%7C262c16bfd7334a40a
> 2f008de383f7886%7C84df9e7fe9f640afb435aaaaaaaaaaaa%7C1%7C0%7C639010042
> 424369064%7CUnknown%7CTWFpbGZsb3d8eyJFbXB0eU1hcGkiOnRydWUsIlYiOiIwLjAuMDAwMCIsIlAiOiJXaW4zMiIsIkFOIjoiTWFpbCIsIldUIjoyfQ%3D%3D%7C0%7C%7C%7C&sdata=nfqXVoI92%2BEd4p%2B0aeJbKXxl3TUM6ZHZuzNhgxaTNF4%3D&reserved=0), are among the applications that will use the media types. Conforming application types are described in https://www.w3.org/TR/vc-jose-cose/#conformance and https://www.w3.org/TR/vc-data-model-2.0/#conformance.
>
> Fragment identifier considerations: N/A
>
> Restrictions on usage: N/A
>
> Provisional registration? (standards tree only): No
>
> Additional information:
>
> 1. Deprecated alias names for this type: N/A 2. Magic number(s): N/A
> 3. File extension(s): N/A 4. Macintosh file type code: N/A 5. Object
> Identifiers: N/A
>
> Person to contact for further information:
>
> 1. Name: Ivan Herman
> 2. Email: [email protected]<mailto:[email protected]>
>
> Intended usage: COMMON
>
> Author/Change controller: W3C Verifiable Credentials Working Group
> [email protected]<mailto:[email protected]>
>
> -MSK
_______________________________________________
media-types mailing list -- [email protected] To unsubscribe send an email to [email protected]
_______________________________________________
media-types mailing list -- [email protected]
To unsubscribe send an email to [email protected]