Re: [Ace] I-D Action: draft-ietf-ace-revoked-token-notification-05.txt

Marco Tiloca <marco.tiloca@ri.se> Thu, 20 April 2023 14:13 UTC

Return-Path: <marco.tiloca@ri.se>
X-Original-To: ace@ietfa.amsl.com
Delivered-To: ace@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id D5BB7C14CEF9 for <ace@ietfa.amsl.com>; Thu, 20 Apr 2023 07:13:59 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.097
X-Spam-Level:
X-Spam-Status: No, score=-2.097 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, HTML_MESSAGE=0.001, NICE_REPLY_A=-0.001, RCVD_IN_ZEN_BLOCKED_OPENDNS=0.001, SPF_PASS=-0.001, URIBL_BLOCKED=0.001, URIBL_DBL_BLOCKED_OPENDNS=0.001, URIBL_ZEN_BLOCKED_OPENDNS=0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (1024-bit key) header.d=ri.se
Received: from mail.ietf.org ([50.223.129.194]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id Q5kWo7ety4xo for <ace@ietfa.amsl.com>; Thu, 20 Apr 2023 07:13:54 -0700 (PDT)
Received: from NAM06-DM3-obe.outbound.protection.outlook.com (mail-dm3nam06on0611.outbound.protection.outlook.com [IPv6:2a01:111:f400:fe56::611]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id C04EDC14CF18 for <ace@ietf.org>; Thu, 20 Apr 2023 07:13:26 -0700 (PDT)
ARC-Seal: i=1; a=rsa-sha256; s=arcselector9901; d=microsoft.com; cv=none; b=HB0AGC6X4Pi+qFyrg+36Py1lyASrgknPkEB4RVP4WMCzZRGdNzmr3zgqNeXBXDDO6DrWjGq23xl2T+b/TaxxFpngEFE0J1kELjfsUw4Z6vR+1PZKZ76nzogFKK50YPze0CdYD+grPQRQLF+sh0gCxjBW6rVCeKk0I/zRTuTaNDgOxawZo2ZlYinLCPksZOJCWm+ysqaecW/JHds15niocgLf+Qp4JqZf17NSSGSJNYWq63VbDf/ptjsjb/h8mVREPoVIXWvQ66xAp1CwUGj4D/J5Jb/7NufRS2hALp9ccS6Bai527ML0HhKK0Qi+7uBNCemsEfajkycP1Sq440bHWw==
ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=microsoft.com; s=arcselector9901; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-AntiSpam-MessageData-ChunkCount:X-MS-Exchange-AntiSpam-MessageData-0:X-MS-Exchange-AntiSpam-MessageData-1; bh=BvNYz1E3J/RvNSQtfkU4DEB2j6ydW9QTUkCzxY0AvGo=; b=H/jZk0aDUzrrATfBEZFBQsww1W/6uFD6oYmC/EL+iTBOfIX8hoVYf85LUsa9m7m1uGGuIw4j/HSs7479/YIw+qIzCEDnOXHQLDb3OG1HwtVM9yPtAY7c3sPkYBd14VcMbqpAjXyFT9mrsvdzlV+agG7Mgwr6+/HroB+CGC+BnDmZHQin7+jOGIXhwhkiIuJo1SnIVjhTIdEcTObNhffX4K6dOkvR/M5/SzW6nNPacNs3DnGW3Y7Eo8eoExZgK3b3IVpOUB6FzD3nnpndJOJ50L96dJagS8XE5axAlRRyx0iTiN8RFuIhOFncwNu8b9BAQnUSmDIQBPy/H9BCatTG7A==
ARC-Authentication-Results: i=1; mx.microsoft.com 1; spf=pass smtp.mailfrom=ri.se; dmarc=pass action=none header.from=ri.se; dkim=pass header.d=ri.se; arc=none
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=ri.se; s=selector1; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-SenderADCheck; bh=BvNYz1E3J/RvNSQtfkU4DEB2j6ydW9QTUkCzxY0AvGo=; b=dx8FfAWEtHaiR/0dej9L6CxAHRpFWBqliogfMkkUE73YPPM1COxFYi+nDFXCN8JiaU9o501kjB+4Y09/mFQ4sCeLeL7jg8TroiaGimi5E9UqUe+hqjFY6luCWyCb7vszyhmigB61oRun1PaJAKhEGUJSnvF4PBbP8UMTVIvg0zE=
Authentication-Results: dkim=none (message not signed) header.d=none;dmarc=none action=none header.from=ri.se;
Received: from GVYP280MB0464.SWEP280.PROD.OUTLOOK.COM (2603:10a6:150:37::17) by MM1PPF186020CEC.SWEP280.PROD.OUTLOOK.COM (2603:10a6:184::10) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.20.6002.13; Thu, 20 Apr 2023 14:13:23 +0000
Received: from GVYP280MB0464.SWEP280.PROD.OUTLOOK.COM ([fe80::c0b1:e5f:ef9b:2dde]) by GVYP280MB0464.SWEP280.PROD.OUTLOOK.COM ([fe80::c0b1:e5f:ef9b:2dde%6]) with mapi id 15.20.6319.022; Thu, 20 Apr 2023 14:13:23 +0000
Message-ID: <e9dd8486-28c9-5535-a197-dfc538e9c09f@ri.se>
Date: Thu, 20 Apr 2023 16:13:21 +0200
User-Agent: Mozilla/5.0 (X11; Linux x86_64; rv:102.0) Gecko/20100101 Thunderbird/102.10.0
Content-Language: en-US
To: ace@ietf.org
References: <168199974111.30093.1411853034528643745@ietfa.amsl.com>
From: Marco Tiloca <marco.tiloca@ri.se>
In-Reply-To: <168199974111.30093.1411853034528643745@ietfa.amsl.com>
Content-Type: multipart/signed; micalg="pgp-sha256"; protocol="application/pgp-signature"; boundary="------------mklNfaGi27pJze6VBgeeelBe"
X-ClientProxiedBy: GV3PEPF000000D4.SWEP280.PROD.OUTLOOK.COM (2603:10a6:144:1:0:2:0:16) To GVYP280MB0464.SWEP280.PROD.OUTLOOK.COM (2603:10a6:150:37::17)
MIME-Version: 1.0
X-MS-PublicTrafficType: Email
X-MS-TrafficTypeDiagnostic: GVYP280MB0464:EE_|MM1PPF186020CEC:EE_
X-MS-Office365-Filtering-Correlation-Id: f6d42141-c64f-4a29-29b6-08db41a966b7
X-MS-Exchange-SenderADCheck: 1
X-MS-Exchange-AntiSpam-Relay: 0
X-Microsoft-Antispam: BCL:0;
X-Microsoft-Antispam-Message-Info: jC6XY+1yIK+d2RTpQH6boprCkY3h4qWmCOL/PubzyPOoYQTOery+PT4EFMZuOIImlO3AlVqZC/rokBxpSmspuVos23pLH4np7QpWihiqfz8xwHoVhIUJQd/xwb3FTSRpFdsJi4wWJYGlljgijiTvJsNgZ6fQ5KmxXFL8CepuLXGUyvsOaIauxYpsqcXf1RiYQmVfQx/fFiyRzMBCTAdNfCE984k0FT8WXCL/FGvmfR/PAEmH/YekCPF5bDaE8v56X8nT0+a1Pqe8NqEoegMZdaGBv8yJJ9tcFAfQQxIEcfNRHSofEalvC4ldeyOG6iTG/ZiVWtQmr+JU89WBrCScdUEXYJ+CMI6ivcVDuokq83wlUhVTlLzoRUlSBTTC2OVqPyaVD9x6uGN/AeHs91JPQosOgIEKFtFPx5ifUtM+Asne6ghlESG/dVyjIPxx8/eMhPC20Nj1q+TZwsTGMUZK51pZ1ZKyPUpjmwVGFXD/DwzrGMmB1rf2WWf6FaMIMq2V5ibcA8jIUObp6rCtMKfInDpAeXGsI2eXK8MvkhxkkRuwASqit6+w2r4H/M/iDXSISq0c/9KYFOScpF0aeamzZNeZvuDXeLjVI1Ju8ip6ukGnadlnEXQxWaItaX1SyIo3w/xsEV2eWuj0SgcXf3yJzg==
X-Forefront-Antispam-Report: CIP:255.255.255.255; CTRY:; LANG:en; SCL:1; SRV:; IPV:NLI; SFV:NSPM; H:GVYP280MB0464.SWEP280.PROD.OUTLOOK.COM; PTR:; CAT:NONE; SFS:(13230028)(4636009)(346002)(39850400004)(366004)(396003)(376002)(136003)(451199021)(166002)(21480400003)(53546011)(66946007)(8676002)(44832011)(83380400001)(15650500001)(186003)(36756003)(8936002)(66574015)(316002)(5660300002)(966005)(31696002)(6486002)(235185007)(86362001)(38100700002)(66556008)(6506007)(478600001)(6916009)(26005)(2616005)(66476007)(31686004)(2906002)(45080400002)(6512007)(33964004)(41300700001)(45980500001)(43740500002); DIR:OUT; SFP:1101;
X-MS-Exchange-AntiSpam-MessageData-ChunkCount: 1
X-MS-Exchange-AntiSpam-MessageData-0: qG5EEhLKuDb9NrWrM3Pw1vqOFUcDrnlJLQefeYUrcDf+qrDhLrzA3XVZgBwU0ygUr9eSG6qzIP+fHt3n4Rrd8w8+VrpkpbSLIk27Irp4hT5NVfkIcBE1aW4EGnD/AEaEyEi7YVfxXjxefB1ftIhDFDlzn6sDOYVYebt6K9WHeFbe2OkE2UPwWKyB9J1zVuUTJmaU/m5nzDA6t9uuhM9OML5xiWogOzx6QaH5jczY2u+UtOsh00fJB5Tc7BYhIHnxnbSNRFy+c8Vi2AIFr9cJbbGhOZntGM7+pjhlOCyNMGz+s4VelbP+bMxPaHp5tv8iMBpfKt0Cw3CJYhU7ASHNakbmLW/D4MAg/MOg0Runlexi5sSAIpbu/VDKz47+eAHgRW0OOrYXvC6xWm8T2zSLPNcRUJL2EX01z1+L7ykfXYGA+AgVyEXB2RIlQ0MOmse8LeMwYba1GL/VFYH0m3R2a4izDWCdlGhUqdmsW92mPb5F64seCJiO5JmcwD5kbgiCRJwluYNZ4I8MCCTq9DptikbFkH3dt2f0ZIaRtZnhezSrNKF7NqVkXtxgFVb5pgigf2kFqI59PeqAfsr7gBRO4aYD2x2RLy1I8KDBI1srNq5iswrUNMjxc0LJ3CzTC+nJuy8jT1oxlYpowpgOPxAicmxhHiyNCUpDult88SkXqc+644ggPcUfJGYykt40cKflehlUQDs9DYvhUT3DDCFlXpuQ1tSPU6zrnDUU1DolLrkX3UKgsAWRtQ5oBxqAgQLqZ06eVg+ytgFPMk34Jn+DAZpGTkW5mgNIsEmgWk4iBbDWxFF+My4PLafz8o5OFCtko/uGhvrWV19/LfRv5jxdSEK6Ub+9IlocaxGJixyl8Xj29+bBSrx0USvXsANmw2wdAUTT8E/Lwy78x1UdTtT749pzymMBXVmGrPDyMM/9ATsfbaOe6DwX1bVRA8jc135p2PaEj8dqJ+yZcd2hfQIBQbulqdktrcrRFkNDvgUxs6wyZEjjY7wm/zmFv4qoOr/sJUaYKZKr7r3t69l07Izd/bupZlqPHrPXrEYuoCMHALijWT54GDPpzbkdo1/IhBlvlMVE1uxcGPIU8JSXoMTzXLSRKlfZu70/5ZahbZr8MBFvI/cFioR6b/31qB175NcozhpnyY5i+9cdemZ1DG22OvZRg4qs95VcOvFhssAHNk5DyIYWFEEwIwBMOUr9LdH1r1vgvCxZ/qfz/D//S/mRLkMJn9vCGGhFqyxM3tM6eJe34b8O/d7VinGGlJ4mnQXzHn8H7cyaSpFZhAj8ubz0/ek39Tyj1spW1Xv79zKCLDJWngPZefuzhx9TDifNKJ7JIQFkISAjiLGaLaJaDWaV2zeEZKYrF4M9CQexDgypHySdWgjpIs99JmSp3secpkWJ+90zynucP32Ayprg+unmcCD5ThuUVmT+HP99tFQpuicXYQmSYB+pHPmCyrZPGvlPAi9FILJGgK7lF0vLRFerq8+FA8OvHZjWoyfRY3etw4ZYIQNu8Fi+1MjERFlkn/JMrlu0PohfRzt1CPBkZDjp9u8gaanfejq6G04DzLenoi0RlPMH6lKCYUdyh5Wf4Xik
X-OriginatorOrg: ri.se
X-MS-Exchange-CrossTenant-Network-Message-Id: f6d42141-c64f-4a29-29b6-08db41a966b7
X-MS-Exchange-CrossTenant-AuthSource: GVYP280MB0464.SWEP280.PROD.OUTLOOK.COM
X-MS-Exchange-CrossTenant-AuthAs: Internal
X-MS-Exchange-CrossTenant-OriginalArrivalTime: 20 Apr 2023 14:13:23.2724 (UTC)
X-MS-Exchange-CrossTenant-FromEntityHeader: Hosted
X-MS-Exchange-CrossTenant-Id: 5a9809cf-0bcb-413a-838a-09ecc40cc9e8
X-MS-Exchange-CrossTenant-MailboxType: HOSTED
X-MS-Exchange-CrossTenant-UserPrincipalName: aas8vV4LM09tx8jpPjgMpd7zh4prRiqtCzYz4Op76eTXa3kF9DntaScnMlH9J2d1sOiwh+A1GwifsdKe03DDrA==
X-MS-Exchange-Transport-CrossTenantHeadersStamped: MM1PPF186020CEC
Archived-At: <https://mailarchive.ietf.org/arch/msg/ace/8q0v-ND8tVAkPojPBPUwAvCxeKE>
Subject: Re: [Ace] I-D Action: draft-ietf-ace-revoked-token-notification-05.txt
X-BeenThere: ace@ietf.org
X-Mailman-Version: 2.1.39
Precedence: list
List-Id: "Authentication and Authorization for Constrained Environments \(ace\)" <ace.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/ace>, <mailto:ace-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/ace/>
List-Post: <mailto:ace@ietf.org>
List-Help: <mailto:ace-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/ace>, <mailto:ace-request@ietf.org?subject=subscribe>
X-List-Received-Date: Thu, 20 Apr 2023 14:13:59 -0000

Hello ACE,

This latest version -05 addresses the comments received during the WG 
Last Call from Marco and Rikard (thanks!).

Best,
/Marco

On 2023-04-20 16:09, internet-drafts@ietf.org wrote:
> A New Internet-Draft is available from the on-line Internet-Drafts
> directories. This Internet-Draft is a work item of the Authentication and
> Authorization for Constrained Environments (ACE) WG of the IETF.
>
>     Title           : Notification of Revoked Access Tokens in the Authentication and Authorization for Constrained Environments (ACE) Framework
>     Authors         : Marco Tiloca
>                       Francesca Palombini
>                       Sebastian Echeverria
>                       Grace Lewis
>     Filename        : draft-ietf-ace-revoked-token-notification-05.txt
>     Pages           : 60
>     Date            : 2023-04-20
>
> Abstract:
>     This document specifies a method of the Authentication and
>     Authorization for Constrained Environments (ACE) framework, which
>     allows an Authorization Server to notify Clients and Resource Servers
>     (i.e., registered devices) about revoked access tokens.  As specified
>     in this document, the method allows Clients and Resource Servers to
>     access a Token Revocation List on the Authorization Server by using
>     the Constrained Application Protocol (CoAP), with the possible
>     additional use of resource observation.  Resulting (unsolicited)
>     notifications of revoked access tokens complement alternative
>     approaches such as token introspection, while not requiring
>     additional endpoints on Clients and Resource Servers.
>
> The IETF datatracker status page for this Internet-Draft is:
> https://eur05.safelinks.protection.outlook.com/?url=https%3A%2F%2Fdatatracker.ietf.org%2Fdoc%2Fdraft-ietf-ace-revoked-token-notification%2F&data=05%7C01%7Cmarco.tiloca%40ri.se%7Ca72a0ccde3ab46c69f3f08db41a8cf65%7C5a9809cf0bcb413a838a09ecc40cc9e8%7C0%7C0%7C638175965526160376%7CUnknown%7CTWFpbGZsb3d8eyJWIjoiMC4wLjAwMDAiLCJQIjoiV2luMzIiLCJBTiI6Ik1haWwiLCJXVCI6Mn0%3D%7C3000%7C%7C%7C&sdata=7IV7djlipibPZA4pQg%2B79qhFPYGhvzmPeeMBS7mqP7U%3D&reserved=0
>
> There is also an HTML version available at:
> https://eur05.safelinks.protection.outlook.com/?url=https%3A%2F%2Fwww.ietf.org%2Farchive%2Fid%2Fdraft-ietf-ace-revoked-token-notification-05.html&data=05%7C01%7Cmarco.tiloca%40ri.se%7Ca72a0ccde3ab46c69f3f08db41a8cf65%7C5a9809cf0bcb413a838a09ecc40cc9e8%7C0%7C0%7C638175965526160376%7CUnknown%7CTWFpbGZsb3d8eyJWIjoiMC4wLjAwMDAiLCJQIjoiV2luMzIiLCJBTiI6Ik1haWwiLCJXVCI6Mn0%3D%7C3000%7C%7C%7C&sdata=tHORfEXmKmgSzseeg%2FzXvdgTHzLTB7IrxG2VDFZV1%2Bw%3D&reserved=0
>
> A diff from the previous version is available at:
> https://eur05.safelinks.protection.outlook.com/?url=https%3A%2F%2Fauthor-tools.ietf.org%2Fiddiff%3Furl2%3Ddraft-ietf-ace-revoked-token-notification-05&data=05%7C01%7Cmarco.tiloca%40ri.se%7Ca72a0ccde3ab46c69f3f08db41a8cf65%7C5a9809cf0bcb413a838a09ecc40cc9e8%7C0%7C0%7C638175965526160376%7CUnknown%7CTWFpbGZsb3d8eyJWIjoiMC4wLjAwMDAiLCJQIjoiV2luMzIiLCJBTiI6Ik1haWwiLCJXVCI6Mn0%3D%7C3000%7C%7C%7C&sdata=4RZqgr%2FHhsxZyYPqLm6AjZ1xs3e8VICd0Z9g6Nczfoc%3D&reserved=0
>
> Internet-Drafts are also available by rsync at rsync.ietf.org::internet-drafts
>
>
> _______________________________________________
> Ace mailing list
> Ace@ietf.org
> https://eur05.safelinks.protection.outlook.com/?url=https%3A%2F%2Fwww.ietf.org%2Fmailman%2Flistinfo%2Face&data=05%7C01%7Cmarco.tiloca%40ri.se%7Ca72a0ccde3ab46c69f3f08db41a8cf65%7C5a9809cf0bcb413a838a09ecc40cc9e8%7C0%7C0%7C638175965526160376%7CUnknown%7CTWFpbGZsb3d8eyJWIjoiMC4wLjAwMDAiLCJQIjoiV2luMzIiLCJBTiI6Ik1haWwiLCJXVCI6Mn0%3D%7C3000%7C%7C%7C&sdata=d%2BWjt1M8XIMCD2dLh74dA2LxYCGtM3Pfhio1ThRKUGk%3D&reserved=0

-- 
Marco Tiloca
Ph.D., Senior Researcher

Phone: +46 (0)70 60 46 501

RISE Research Institutes of Sweden AB
Box 1263
164 29 Kista (Sweden)

Division: Digital Systems
Department: Computer Science
Unit: Cybersecurity

https://www.ri.se