[Ace] OSCORE Profile IANA questions

Francesca Palombini <francesca.palombini@ericsson.com> Mon, 31 August 2020 12:53 UTC

Return-Path: <francesca.palombini@ericsson.com>
X-Original-To: ace@ietfa.amsl.com
Delivered-To: ace@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 1B96F3A134A; Mon, 31 Aug 2020 05:53:25 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.102
X-Spam-Level:
X-Spam-Status: No, score=-2.102 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIMWL_WL_HIGH=-0.001, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, RCVD_IN_MSPIKE_H2=-0.001, SPF_PASS=-0.001, URIBL_BLOCKED=0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (1024-bit key) header.d=ericsson.com
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id XaZ2mQBPNiUM; Mon, 31 Aug 2020 05:53:23 -0700 (PDT)
Received: from EUR02-VE1-obe.outbound.protection.outlook.com (mail-eopbgr20068.outbound.protection.outlook.com [40.107.2.68]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id A775A3A1349; Mon, 31 Aug 2020 05:53:22 -0700 (PDT)
ARC-Seal: i=1; a=rsa-sha256; s=arcselector9901; d=microsoft.com; cv=none; b=cQLnwdfJQnIYSdj0f/Ymq52LFvDoIT+I/lr7r02PoULonxS042XT7BNyNW4jXLqOfoRukcG0ujPfYfPOrXFLhz+zCPQ4jxBNISCKbwE4/zwoZ8Q+8sH4a8GJ1VNhDkArV0OMCYEJM37SMURWl4XyYYxzE35bNJ7B36PWxEjuPfsdaaNUQjWaE9O8STkm/YhHlq6Dow9WlfVgEGHE9hUEcQoNlE8hMp7FGVR+ZYDmhwI6yDyGTwVawJRjXhmUzoAHV6GuwEueaTOLNUZOHsWnWPNHgwPUupHplJ/JHeQDiTR0G2fVk9qBukV2CdZTfm0rNlj+TYDFUb1LBOxPeJyEdg==
ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=microsoft.com; s=arcselector9901; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-SenderADCheck; bh=2hiKDnrmoHdCHna1OjhEYmR2X4OqBQfUeLHx5BURLXQ=; b=l33oUQJte5XS+LkW6w/LjX+pxO8BiMFlekibZpw06o+tFEk74GJwzBFed+mvvTPoiBKE1mmrYMhe5liG5q2OJHgqdhbnokU8s5WX2Bjfjn20FvtYfMEJp7CO7p3oBSA6GXkfjgmlMTI2RSgfkJjWn8/Jj6ijrrwEdKbTr7vFLu+blx1eKnz6bTIa6KgB4wSVa6Dz96/8G3uvlfmbeOX04/qbPa4N1CNHblAWIsOs3D1PTQ59WwifA/6G6bjFm99ECVU4Tu8cdbyN6DOoStskDxWBq5e2tq8rqrTLk1pEb4NRiRMKSRcVTdTND2xWk3+5WPxKwsDNgVXY2FRapyQe3g==
ARC-Authentication-Results: i=1; mx.microsoft.com 1; spf=pass smtp.mailfrom=ericsson.com; dmarc=pass action=none header.from=ericsson.com; dkim=pass header.d=ericsson.com; arc=none
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=ericsson.com; s=selector1; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-SenderADCheck; bh=2hiKDnrmoHdCHna1OjhEYmR2X4OqBQfUeLHx5BURLXQ=; b=NQ2aIL8/puAJkWlMfCSnzJoNYI45Hwvq13qDdahFNrtVIQ+lCw242Fa0UbwBftF+Ri476YrdfSfCPRVhuDYFsTk+ZGL1Sila2V+8p+WYZVYop8QqA8BR0/xW4wpJ4Xqis4yAfskCvpdF+n/fAtuQf1n54ZiItSuzIL9N3Xp5N0M=
Received: from VI1PR07MB4477.eurprd07.prod.outlook.com (2603:10a6:803:74::33) by VI1PR0701MB6765.eurprd07.prod.outlook.com (2603:10a6:800:192::7) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.20.3348.5; Mon, 31 Aug 2020 12:53:20 +0000
Received: from VI1PR07MB4477.eurprd07.prod.outlook.com ([fe80::cba:ac03:353c:2d1f]) by VI1PR07MB4477.eurprd07.prod.outlook.com ([fe80::cba:ac03:353c:2d1f%7]) with mapi id 15.20.3348.013; Mon, 31 Aug 2020 12:53:20 +0000
From: Francesca Palombini <francesca.palombini@ericsson.com>
To: Ace Wg <ace@ietf.org>
CC: "ace-chairs@ietf.org" <ace-chairs@ietf.org>
Thread-Topic: OSCORE Profile IANA questions
Thread-Index: AQHWf5W01luwmoZHhU++qk7AvzRo4Q==
Date: Mon, 31 Aug 2020 12:53:20 +0000
Message-ID: <40F43BA8-1127-4066-8A5E-6929F962B052@ericsson.com>
Accept-Language: en-GB, en-US
Content-Language: en-GB
X-MS-Has-Attach:
X-MS-TNEF-Correlator:
user-agent: Microsoft-MacOutlook/16.40.20081000
authentication-results: ietf.org; dkim=none (message not signed) header.d=none;ietf.org; dmarc=none action=none header.from=ericsson.com;
x-originating-ip: [158.174.219.143]
x-ms-publictraffictype: Email
x-ms-office365-filtering-correlation-id: 2f93b18b-dd6f-42d7-224a-08d84dacd6b1
x-ms-traffictypediagnostic: VI1PR0701MB6765:
x-microsoft-antispam-prvs: <VI1PR0701MB6765043AF9C5648A9B22885698510@VI1PR0701MB6765.eurprd07.prod.outlook.com>
x-ms-oob-tlc-oobclassifiers: OLM:10000;
x-ms-exchange-senderadcheck: 1
x-microsoft-antispam: BCL:0;
x-microsoft-antispam-message-info: IxHGUnK0E7fJGtj25z+Q6soIvsROFGBhkDmc2Dh102lDbtF036bQYIBk+IoDD2O2gqnfAxKXyoPw7kNJ0ti1yw/AYMuMkKZC8l4W45TDW5WyJBVz7bFt0rYWiLPLCmcEbWAeizXJFxW87dZdtYXf5lZfDehLCB7NpeFBfi1wHZsXSk1qCNGUWhdyb5pCqz508Qo+Fre+NUG+B/AwuCGaLX6L/o8G2azfPp2rGq+saruUnFTAqUBhESvab468X9ZnngGLHHKszqHu6zOor8y2VEhh+Yd20OodcPUYPZJr+ycLUrqHxrxAbQP/x8sUvHlYCWbmHC6logzkkuD49VnCPbGaDyoPahAZgt5/xf+LL58n61Q93MjXz8v1eLyckGKuOMoYWAYmZkzBrgzuO9OjyG+K59/JhKkdPC96a9FHpPRD+m9KMKyRjZb5YzXeOPClE7S3Gkp3tEkl7fhkJoK7Nq6gYgLcwDZHiDMXmLNcvcg=
x-forefront-antispam-report: CIP:255.255.255.255; CTRY:; LANG:en; SCL:1; SRV:; IPV:NLI; SFV:NSPM; H:VI1PR07MB4477.eurprd07.prod.outlook.com; PTR:; CAT:NONE; SFS:(4636009)(39860400002)(396003)(366004)(376002)(346002)(136003)(66946007)(8676002)(66556008)(64756008)(66476007)(2906002)(36756003)(66446008)(2616005)(4326008)(26005)(71200400001)(478600001)(186003)(450100002)(966005)(316002)(76116006)(33656002)(83380400001)(6512007)(44832011)(91956017)(6506007)(86362001)(5660300002)(3480700007)(6486002)(8936002)(6916009); DIR:OUT; SFP:1101;
x-ms-exchange-antispam-messagedata: ow6asz1eQNHm7pcfb+o2q9UOhoMxGj93IBRMuHXMyvVMSOaMcRWmgrCzCukeTjNAZJ9seuiWagvp5T/ZF7MxEDe7OgC0CHWGJkliZnHwegzoNqFbq2E4eKZ1T2yKaqykTQoVImXkACtuOaFRdQzo0v1X/LTr6K3zKmEHTuAEmDUHBOQUPJ1x2vJ4wk5l18RrsE+Ln6io4M/boLPW0TuMOc/w9JNP+1Vvq0gxQXvfM/F6dhTfL6nchqiFynas4JyUlXAaS+TCZ3hgKqo6tc0oItwEW69PcS6ar1QGsyf5bdg6vW3cbFy3aUmcIkITBDqq6q0wWTPqsDYUyobQCN/qPKLK/Rtpq1sUggNkEcD/5DXgy9YYxDgSR6DO18P8Kko9qNfNqxcpbaj+NJsw9XO8dRyiyquXO3LSdQo59DnLDRIJzFX0kT5PS89r0XQx3NrxHAjYhEOBKdFm9SZkRgng9zmVqH1czrMje/7eX7sGb9rNaKVIQNyjEaaTQsbk/bTokmm0bWHqo3t6DGKep+uU1nFZ+h3HeynS+Zmu3KVx3QC5LbLot4QP8IEDnc2Vz8kBRnNTDP0RbPS3OQ8bR4HyPtkQBzS95QzbuVDyTTRmSAo7oawH670/vMQZT06gWNfgrawXuIAFsvxw2l0gLnKldA==
x-ms-exchange-transport-forked: True
Content-Type: text/plain; charset="utf-8"
Content-ID: <73045E1659E48E4883170D0CC6AC451B@eurprd07.prod.outlook.com>
Content-Transfer-Encoding: base64
MIME-Version: 1.0
X-OriginatorOrg: ericsson.com
X-MS-Exchange-CrossTenant-AuthAs: Internal
X-MS-Exchange-CrossTenant-AuthSource: VI1PR07MB4477.eurprd07.prod.outlook.com
X-MS-Exchange-CrossTenant-Network-Message-Id: 2f93b18b-dd6f-42d7-224a-08d84dacd6b1
X-MS-Exchange-CrossTenant-originalarrivaltime: 31 Aug 2020 12:53:20.3602 (UTC)
X-MS-Exchange-CrossTenant-fromentityheader: Hosted
X-MS-Exchange-CrossTenant-id: 92e84ceb-fbfd-47ab-be52-080c6b87953f
X-MS-Exchange-CrossTenant-mailboxtype: HOSTED
X-MS-Exchange-CrossTenant-userprincipalname: fXMwMCJzbdsEa8C1n3jlRpzAJE9+zc2tVBPTxbmDpzb+z0uEM84fBJQJUuEScrPpFd/bhDedaAbCKotqN4G2i1hH8gd3gKKd6yNG3u8jwdafkc8KscNO3Fi8EwFLJ/Ny
X-MS-Exchange-Transport-CrossTenantHeadersStamped: VI1PR0701MB6765
Archived-At: <https://mailarchive.ietf.org/arch/msg/ace/5IBR5CNBDtEQIfAqMw4CRiirSG8>
Subject: [Ace] OSCORE Profile IANA questions
X-BeenThere: ace@ietf.org
X-Mailman-Version: 2.1.29
Precedence: list
List-Id: "Authentication and Authorization for Constrained Environments \(ace\)" <ace.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/ace>, <mailto:ace-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/ace/>
List-Post: <mailto:ace@ietf.org>
List-Help: <mailto:ace-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/ace>, <mailto:ace-request@ietf.org?subject=subscribe>
X-List-Received-Date: Mon, 31 Aug 2020 12:53:25 -0000

Hi all,

I have two quick questions concerning IANA actions to be done for the OSCORE profile:

1) The framework (-params) and the profile are currently conflicting on the registration of parameters, and we need to fix that.
In the framework, parameters that are sent from Client to AS (such as req_cnf) are registered in the OAuth Parameters Registry as having "Parameter Usage Location: token request". The OSCORE profile registers parameters sent from Client to RS (such as nonce1) with "Parameter Usage Location: token request". The possible "Parameter Usage Location" are "token request" "token response" "authorization request" "authorization response" (see https://tools.ietf.org/html/rfc6749#section-11.2.1 ). It seems that "authorization request/response" are to the Resource Owner, and "token request/response" are to the Authorization Server. I think the framework is using the right names, but I am not sure what other location to put there, I think there is no name for Client-to-RS and RS-to-Client in the registry right now.

2) The OSCORE profile defines a new registry, the OSCORE Security Context Parameters registry. The question is where to put this registry? My proposal is to put it under https://www.iana.org/assignments/core-parameters/core-parameters.xhtml . Any objections?

Thanks,
Francesca