Re: [Ace] Alexey Melnikov's No Objection on draft-ietf-ace-cbor-web-token-12: (with COMMENT)

Mike Jones <Michael.Jones@microsoft.com> Fri, 16 March 2018 10:13 UTC

Return-Path: <Michael.Jones@microsoft.com>
X-Original-To: ace@ietfa.amsl.com
Delivered-To: ace@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 356BC1204DA; Fri, 16 Mar 2018 03:13:47 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.021
X-Spam-Level:
X-Spam-Status: No, score=-2.021 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, RCVD_IN_DNSWL_NONE=-0.0001, RCVD_IN_MSPIKE_H3=-0.01, RCVD_IN_MSPIKE_WL=-0.01, SPF_PASS=-0.001] autolearn=unavailable autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (1024-bit key) header.d=microsoft.com
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id xU2Ol2qhJM95; Fri, 16 Mar 2018 03:13:45 -0700 (PDT)
Received: from NAM03-BY2-obe.outbound.protection.outlook.com (mail-by2nam03on0090.outbound.protection.outlook.com [104.47.42.90]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id B8B5E12025C; Fri, 16 Mar 2018 03:04:52 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=microsoft.com; s=selector1; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version; bh=Nl4VzV06uOlaDd/wqBfW9xAzwh2Yjp+g9VjnS194r/8=; b=l0WqBUdCmp1f/GNBBTWqhSePq4Q3HUajmQR6peIO2uF8ovHvuZ/Nvws+z7g6N6ECO1aMMbXa0hqxK1fgWK/yvbtjAo+kwCEYc29ZfdL76ctUFth5qRutuSw2RApgNhfZhiVhBPtSTra2MeiW1ST7m08X7ctCXLwA16XrOB9t5DA=
Received: from DM5PR00MB0296.namprd00.prod.outlook.com (52.132.128.37) by DM5PR00MB0293.namprd00.prod.outlook.com (52.132.128.34) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.20.630.0; Fri, 16 Mar 2018 10:04:51 +0000
Received: from DM5PR00MB0296.namprd00.prod.outlook.com ([fe80::e1c0:298f:7c10:4167]) by DM5PR00MB0296.namprd00.prod.outlook.com ([fe80::e1c0:298f:7c10:4167%2]) with mapi id 15.20.0634.000; Fri, 16 Mar 2018 10:04:51 +0000
From: Mike Jones <Michael.Jones@microsoft.com>
To: 'Alexey Melnikov' <aamelnikov@fastmail.fm>, Jim Schaad <ietf@augustcellars.com>, 'The IESG' <iesg@ietf.org>
CC: "draft-ietf-ace-cbor-web-token@ietf.org" <draft-ietf-ace-cbor-web-token@ietf.org>, "ace-chairs@ietf.org" <ace-chairs@ietf.org>, "kaduk@mit.edu" <kaduk@mit.edu>, "ace@ietf.org" <ace@ietf.org>
Thread-Topic: Alexey Melnikov's No Objection on draft-ietf-ace-cbor-web-token-12: (with COMMENT)
Thread-Index: AQHTs+2dNyJ9MBpLY0inXBZiAJsPgaPAeSQAgAAWygCAAAL4AIASIVZw
Date: Fri, 16 Mar 2018 10:04:50 +0000
Message-ID: <DM5PR00MB0296A74BE2425D65DDA986D7F5D70@DM5PR00MB0296.namprd00.prod.outlook.com>
References: <152019111919.11926.18305687218435545827.idtracker@ietfa.amsl.com> <01e001d3b3f0$821e1990$865a4cb0$@augustcellars.com> <1520197258.2705337.1291165960.6753CD94@webmail.messagingengine.com> <01e901d3b3fd$639fa120$2adee360$@augustcellars.com>
In-Reply-To: <01e901d3b3fd$639fa120$2adee360$@augustcellars.com>
Accept-Language: en-US
Content-Language: en-US
X-MS-Has-Attach:
X-MS-TNEF-Correlator:
x-originating-ip: [217.77.82.83]
x-ms-publictraffictype: Email
x-microsoft-exchange-diagnostics: 1; DM5PR00MB0293; 7:EW4BGiB6o5HEYfFe3a5gcxl7nazi+gJHEjtqERTTbbw/rNX+sSBhddHLTIWIR5W2kLK889xr3HjZI/QBN8g/XFKMng3juEwF6t9Gziegr09l5m8kv7pzpUnwKkajVH6ngoHjj+oseRki68LHK9akbbsvR/2Z6awzveqU7hyv66Mwc7y3hPPGy2KrgEbrhTn0Ydn7Xzvnb4s/9TtIbFEHs6tlhcE6BqVyfuMqOMreR40MfGSieMkyCCH2F6fTMFRd; 20:r9+qVPtZ5QPmPU6vv8X3H1oZzL0BzWh/crK5+t9tcGZBjcPrSCJlj0l12uePQZWlO5+VQ9ASJWNxdM4Csh8Yo9DintttEMAl+hxOxLH23fVSaoh7KWH9i7qgs/oMjGBpiWOtTk+lC8AfjXiSGyRYnsRkywHM9Ql1FT2GvoRtC/8=
x-ms-exchange-antispam-srfa-diagnostics: SOS;
x-ms-office365-filtering-ht: Tenant
x-ms-office365-filtering-correlation-id: 63504c4d-35e4-4841-c152-08d58b255ba5
x-microsoft-antispam: UriScan:; BCL:0; PCL:0; RULEID:(7020095)(4652020)(48565401081)(5600026)(4604075)(3008032)(4534165)(4627221)(201703031133081)(201702281549075)(2017052603328)(7193020); SRVR:DM5PR00MB0293;
x-ms-traffictypediagnostic: DM5PR00MB0293:
x-microsoft-antispam-prvs: <DM5PR00MB0293F590AF93F814FD746FD7F5D70@DM5PR00MB0293.namprd00.prod.outlook.com>
x-exchange-antispam-report-test: UriScan:(120809045254105)(240460790083961);
x-exchange-antispam-report-cfa-test: BCL:0; PCL:0; RULEID:(8211001083)(61425038)(6040522)(2401047)(5005006)(8121501046)(93006095)(93001095)(10201501046)(3231221)(944501281)(52105095)(3002001)(6055026)(61426038)(61427038)(6041310)(20161123562045)(20161123558120)(20161123564045)(20161123560045)(201703131423095)(201702281528075)(20161123555045)(201703061421075)(201703061406153)(6072148)(201708071742011); SRVR:DM5PR00MB0293; BCL:0; PCL:0; RULEID:; SRVR:DM5PR00MB0293;
x-forefront-prvs: 0613912E23
x-forefront-antispam-report: SFV:NSPM; SFS:(10019020)(366004)(39860400002)(346002)(39380400002)(376002)(396003)(199004)(13464003)(189003)(10090500001)(6246003)(86362001)(105586002)(22452003)(229853002)(4326008)(3660700001)(5660300001)(106356001)(99286004)(2950100002)(305945005)(110136005)(54906003)(316002)(7736002)(81166006)(7696005)(76176011)(26005)(8936002)(81156014)(8990500004)(6346003)(74316002)(33656002)(5250100002)(97736004)(186003)(68736007)(8676002)(14454004)(72206003)(66066001)(478600001)(9686003)(3280700002)(6306002)(25786009)(966005)(55016002)(2906002)(6436002)(93886005)(6506007)(53546011)(10290500003)(53936002)(8666007)(3846002)(6116002)(102836004)(2900100001)(86612001); DIR:OUT; SFP:1102; SCL:1; SRVR:DM5PR00MB0293; H:DM5PR00MB0296.namprd00.prod.outlook.com; FPR:; SPF:None; LANG:en; PTR:InfoNoRecords; A:1; MX:1;
received-spf: None (protection.outlook.com: microsoft.com does not designate permitted sender hosts)
authentication-results: spf=none (sender IP is ) smtp.mailfrom=Michael.Jones@microsoft.com;
x-microsoft-antispam-message-info: S4xMlLCkQNq1095opM+V+Z1Q6MN8axSHq7FClvCNX7YMLR9nTuMZX0ZOa/SGB+zXqVBrUveAPXF3J2nvgG3HjVqN0iKVkfpLKEAFxA5rUYeoMB2QTlIY15Z6dCaNZoeY78Gx3z7f1rXO9Z9dc54u/jS0CJc/omsezHfCpSZNnw55xfcUGjN8FzGxIuTwX70qLAcDfsFjrqKdj+t/az/434dRtVfbUJXLrkDV+YAzUzTNSHSFE3rmnX5yRAww+CHoLvgRLFWgTd/YHQvqyITaQjZTOphSTlzL0hWhaphkz+Kf7/N4whnlSaJeuKhnenOvDuNJMSWrJZsdgjJhZTLWEA==
spamdiagnosticoutput: 1:99
spamdiagnosticmetadata: NSPM
Content-Type: text/plain; charset="utf-8"
Content-Transfer-Encoding: base64
MIME-Version: 1.0
X-OriginatorOrg: microsoft.com
X-MS-Exchange-CrossTenant-Network-Message-Id: 63504c4d-35e4-4841-c152-08d58b255ba5
X-MS-Exchange-CrossTenant-originalarrivaltime: 16 Mar 2018 10:04:50.9302 (UTC)
X-MS-Exchange-CrossTenant-fromentityheader: Hosted
X-MS-Exchange-CrossTenant-id: 72f988bf-86f1-41af-91ab-2d7cd011db47
X-MS-Exchange-Transport-CrossTenantHeadersStamped: DM5PR00MB0293
Archived-At: <https://mailarchive.ietf.org/arch/msg/ace/I6o21Wmp0YyIh9i6pHJAr6ny9rM>
Subject: Re: [Ace] Alexey Melnikov's No Objection on draft-ietf-ace-cbor-web-token-12: (with COMMENT)
X-BeenThere: ace@ietf.org
X-Mailman-Version: 2.1.22
Precedence: list
List-Id: "Authentication and Authorization for Constrained Environments \(ace\)" <ace.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/ace>, <mailto:ace-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/ace/>
List-Post: <mailto:ace@ietf.org>
List-Help: <mailto:ace-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/ace>, <mailto:ace-request@ietf.org?subject=subscribe>
X-List-Received-Date: Fri, 16 Mar 2018 10:13:47 -0000

Hi Alexey,

https://tools.ietf.org/html/draft-ietf-ace-cbor-web-token-14 should address your comments.  Changes motivated by your comments were:
  - Added the text "IANA must only accept registry updates from the Designated Experts and should direct all requests for registration to the review mailing list" from RFC 7519, as suggested by Amanda Baber of IANA, which is also intended to address Alexey Melnikov's comment.

				Thanks again,
				-- Mike

-----Original Message-----
From: Jim Schaad <ietf@augustcellars.com> 
Sent: Sunday, March 4, 2018 1:12 PM
To: 'Alexey Melnikov' <aamelnikov@fastmail.fm>; 'The IESG' <iesg@ietf.org>
Cc: draft-ietf-ace-cbor-web-token@ietf.org; ace-chairs@ietf.org; kaduk@mit.edu; ace@ietf.org
Subject: RE: Alexey Melnikov's No Objection on draft-ietf-ace-cbor-web-token-12: (with COMMENT)



> -----Original Message-----
> From: Alexey Melnikov [mailto:aamelnikov@fastmail.fm]
> Sent: Sunday, March 4, 2018 1:01 PM
> To: Jim Schaad <ietf@augustcellars.com>; The IESG <iesg@ietf.org>
> Cc: draft-ietf-ace-cbor-web-token@ietf.org; ace-chairs@ietf.org; 
> kaduk@mit.edu; ace@ietf.org
> Subject: Re: Alexey Melnikov's No Objection on 
> draft-ietf-ace-cbor-web-
> token-12: (with COMMENT)
> 
> On Sun, Mar 4, 2018, at 7:39 PM, Jim Schaad wrote:
> > IANA does ask for the expert review as part of the processing it 
> > does even for standards track documents.  This is because, in part, 
> > they are responsible for doing the final number assignment.  That is 
> > which number in the range is actually used.  The interesting 
> > question would be what happens if the IESG and the DEs disagree about such things.
> 
> This is exactly why I am asking about this. It might also possible to 
> game the system to ask IESG approval of a Proposed Standard that 
> bypasses Expert Review.

Interesting.  The text that IANA and I finally agreed to for the COSE Algorithm registry is "Standards Action With Expert Review".

That would make sure that it cannot bypass the Expert Review.

Jim

> 
> >  I would
> > expect that this would result in a long discussion with some type of 
> > final agreement between them.
> >
> > Jim
> >
> >
> > > -----Original Message-----
> > > From: Alexey Melnikov [mailto:aamelnikov@fastmail.fm]
> > > Sent: Sunday, March 4, 2018 11:19 AM
> > > To: The IESG <iesg@ietf.org>
> > > Cc: draft-ietf-ace-cbor-web-token@ietf.org; ace-chairs@ietf.org; 
> > > kaduk@mit.edu; ace@ietf.org
> > > Subject: Alexey Melnikov's No Objection on
> > > draft-ietf-ace-cbor-web-token-
> > > 12: (with COMMENT)
> > >
> > > Alexey Melnikov has entered the following ballot position for
> > > draft-ietf-ace-cbor-web-token-12: No Objection
> > >
> > > When responding, please keep the subject line intact and reply to 
> > > all email addresses included in the To and CC lines. (Feel free to 
> > > cut this introductory paragraph, however.)
> > >
> > >
> > > Please refer to
> > > https://www.ietf.org/iesg/statement/discuss-criteria.html
> > > for more information about IESG DISCUSS and COMMENT positions.
> > >
> > >
> > > The document, along with other ballot positions, can be found here:
> > > https://datatracker.ietf.org/doc/draft-ietf-ace-cbor-web-token/
> > >
> > >
> > >
> > > ------------------------------------------------------------------
> > > --
> > > --
> > > COMMENT:
> > > ------------------------------------------------------------------
> > > --
> > > --
> > >
> > > Just to double check: a CWT claim registration from a Proposed 
> > > Standard still needs to be submitted to the review mailing list, 
> > > but it is not really subject to Expert Review, correct? You might 
> > > want to make
> it clearer.
> >
> >