Tag: RFC
-
What the six digits of a TOTP code actually are
A time-based one-time password is a truncated HMAC of the current half-minute. Understanding that explains every design decision you have to make around it.
-
Certificates in PHP, or what ASN.1 asks of you
X.509 is a data structure before it is a trust model. Reading one properly means meeting ASN.1, DER, and a few decisions made in 1988.
-
CBOR, and why Webauthn insisted on it
A binary format that looks like JSON but is not. If you touch Webauthn, you will meet it, and it helps to know why it is there.
-
Understanding JSON Web Tokens: verifying properly
A valid signature is the first check, not the last. The claims that must be verified, the ones people forget, and the order to do it in.
-
AES-GCM, and the one thing you must never do with it
Galois Counter Mode gives you encryption and authentication in one pass. Reuse a nonce once and you lose both, permanently.
-
Understanding JSON Web Tokens: choosing an algorithm
RFC 7518 lists dozens of algorithms. In practice the choice comes down to three questions, and a couple of names you should stop using.
-
Wrapping a key is not the same as encrypting it
AES Key Wrap exists because encrypting a key has requirements that encrypting a message does not. RFC 3394 and RFC 5649, in practice.
-
Understanding JSON Web Tokens: the keys, with JWK
A key format that travels as JSON, key sets you can publish, thumbprints that identify a key by its content, and rotation without downtime.
-
Understanding JSON Web Tokens: encrypting with JWE
Encryption hides the payload from everyone but its recipient. Five parts instead of three, two keys instead of one, and a vocabulary worth learning once.
-
Understanding JSON Web Tokens: signing with JWS
A signature turns two JSON objects into something a recipient can trust. How JWS works, what the three parts of a compact token are, and why the header is protected.
-
Understanding JSON Web Tokens: structure
What a JWT actually is, why the format exists, which standards describe it, and what its two JSON objects contain.