Re: Inclusion of rsaes-pkcs1

On Wed, Sep 5, 2012 at 12:07 PM, Arun Ranganathan <arun@mozilla.com> wrote:
> rsleevi,
>
> Given NSS support, I'm inclined to add "rsaes-pkcs1" to the list of recommended
> algorithms.

Since RSASSA-PKCS1-v1_5 using SHA-256 (as opposed to RSA-PSS using
SHA-256) is on the list of recommended algorithms, I think it is
reasonable extrapolation to add RSAES-PKCS1-v1_5 to the list as a
recommended key transport algorithm.

Note: in draft-ietf-jose-json-web-algorithms-05, RSAES-PKCS1-V1_5
(called "RSA1_5") is REQUIRED whereas RSA-OAEP is OPTIONAL.

Wan-Teh

Received on Wednesday, 5 September 2012 21:08:07 UTC