openid / openid/OpenID4VP

HPKE algorithm clarification

Open
#781 3 comments 0 reactions 0 assignees View on GitHub

Nobody has claimed this yet.

discuss
Dominant language
Shell
Stars
112
Forks
38
Avg merge
12d 19h
Merged PRs (30d)
4

Description

Section 8.3.1 says:
Hybrid Public Key Encryption (HPKE) may be used for encrypted responses. If HPKE is used, the alg value MUST be specified according to [[I-D.ietf-jose-hpke-encrypt].

Does this mean that when using HPKE one of the algorithms specified in ietf-jose-hpke-encrypt MUST be used and other HPKE algorithms are not allowed? Or does it mean the algorithm MUST be a HPKE JWE algorithm?

Contributor guide

Open the contributing guide

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

Research direction

Review Section 8.3.1 and the referenced ietf-jose-hpke-encrypt draft first. Compare the two interpretations of the alg requirement and confirm the intended interoperability rule with the specification maintainers. Done means the section's wording and permitted algorithm scope are unambiguous.

Written by the indexing model from the issue text.

Assessment

Domain
cryptography, documentation
Issue type
Documentation
Difficulty
5/5
Estimated time
Over a week
Activity status
Active
Clarity
Needs clarification
Newbie friendliness
35/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.