Summary

  • Revision 22 of the JOSE HPKE draft is scheduled for the 24 September IESG telechat as a Proposed Standard item. The public state is still IESG Evaluation; approval and IANA registrations are not complete.
  • A second Last Call removed HPKE-4-KE and HPKE-6-KE from Key Encryption because JOSE lacks a registered ChaCha20/Poly1305 content-encryption algorithm. HPKE-4 and HPKE-6 remain in the separate Integrated Encryption list.
  • The decision distinguishes where HPKE encrypts the message itself from where it only protects a content-encryption key. “HPKE supported” does not identify which JWE path a product can actually use.

The missing suffix matters. In the draft's first path, Integrated Encryption, HPKE encrypts the plaintext directly. There is exactly one recipient and the JWE header must omit enc, because there is no separate content cipher. The proposed HPKE-4 and HPKE-6 algorithm identifiers remain in that path; both use ChaCha20Poly1305 inside HPKE. Their continued presence rules out reading the revision as a blanket rejection of that AEAD.

The other path is Key Encryption. Here HPKE encrypts a content-encryption key, or CEK; JWE then uses a separate algorithm named by enc to encrypt the content. JSON serialization can carry multiple recipients, including a mixture of HPKE and other key-management mechanisms. The draft binds the enc choice into HPKE's recipient context and carries the encapsulated secret in ek. Its remaining proposed -KE set has six identifiers: HPKE-0-KE, HPKE-1-KE, HPKE-2-KE, HPKE-3-KE, HPKE-5-KE and HPKE-7-KE.

That split explains the unusual procedural loop. The IESG's second Last Call, ending 3 August, expressly sought consensus to remove HPKE-4-KE and HPKE-6-KE: JOSE has no ChaCha20/Poly1305 content-encryption algorithm registered for the Key Encryption pairing. The responsible Area Director described this removal as the only change in the second ballot. The draft itself still proposes the two unsuffixed Integrated Encryption algorithms. The internal HPKE AEAD and the separate JWE content cipher are not interchangeable registry entries.

Datatracker currently shows enough ballot positions to pass and places the document on today's agenda. Those are process signals, not an approval announcement. Its IANA status remains “OK – Actions Needed”; neither a future registration nor a production implementation should be narrated as accomplished. The practical question for an adopter is narrower than whether its library advertises HPKE: which key-management mode, alg identifier, enc pairing and recipient shape does it accept? The draft's second pass made that inventory harder to avoid.

Sources