[Ace] CBOR Web Token (CWT) draft addressing IETF last call comments

Mike Jones <Michael.Jones@microsoft.com> Mon, 05 March 2018 21:33 UTC

Return-Path: <Michael.Jones@microsoft.com>
X-Original-To: ace@ietfa.amsl.com
Delivered-To: ace@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id B1FAE126CB6 for <ace@ietfa.amsl.com>; Mon, 5 Mar 2018 13:33:55 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.019
X-Spam-Level:
X-Spam-Status: No, score=-2.019 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, HTML_MESSAGE=0.001, RCVD_IN_DNSWL_NONE=-0.0001, RCVD_IN_MSPIKE_H4=-0.01, RCVD_IN_MSPIKE_WL=-0.01, SPF_PASS=-0.001, URIBL_BLOCKED=0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (1024-bit key) header.d=microsoft.com
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id d_AhT1-_wvj1 for <ace@ietfa.amsl.com>; Mon, 5 Mar 2018 13:33:53 -0800 (PST)
Received: from NAM01-BY2-obe.outbound.protection.outlook.com (mail-by2nam01on0130.outbound.protection.outlook.com [104.47.34.130]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 91243126C0F for <ace@ietf.org>; Mon, 5 Mar 2018 13:33:53 -0800 (PST)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=microsoft.com; s=selector1; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version; bh=eJjLjmf//p5vi4YFTC1xBEusKUYimnxlZDGN1O9N0Ao=; b=Pcz187vfnRkcXFBPvepyIArCXQz/OKiicO9PiT3huls32ZVEYBIlVsbfZQQ49M5Ha2uyvosJJXxSudpc9KKXwLHbyiVQdtFsKCVFFZ+M4wtJpRFeJh/5t98nZXTUtnNnDcPOoQaRoilpjQCNJfhp/W1b21Dh77Ebb/Rr8o3ArMw=
Received: from SN6PR2101MB0943.namprd21.prod.outlook.com (52.132.114.20) by SN6PR2101MB1022.namprd21.prod.outlook.com (52.132.117.30) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.20.588.3; Mon, 5 Mar 2018 21:33:52 +0000
Received: from SN6PR2101MB0943.namprd21.prod.outlook.com ([fe80::9866:f6b5:e2d6:50]) by SN6PR2101MB0943.namprd21.prod.outlook.com ([fe80::9866:f6b5:e2d6:50%2]) with mapi id 15.20.0588.001; Mon, 5 Mar 2018 21:33:52 +0000
From: Mike Jones <Michael.Jones@microsoft.com>
To: "ace@ietf.org" <ace@ietf.org>
CC: Dan Romascanu <dromasca@gmail.com>, Kyle Rose <krose@krose.org>, Benjamin Kaduk <kaduk@mit.edu>, Kathleen Moriarty <kathleen.moriarty.ietf@gmail.com>
Thread-Topic: CBOR Web Token (CWT) draft addressing IETF last call comments
Thread-Index: AdO0xn2uZbj88ndARQSoQaJi7C+W1g==
Date: Mon, 05 Mar 2018 21:33:51 +0000
Message-ID: <SN6PR2101MB0943D068F03621252BBAFBB6F5DA0@SN6PR2101MB0943.namprd21.prod.outlook.com>
Accept-Language: en-US
Content-Language: en-US
X-MS-Has-Attach:
X-MS-TNEF-Correlator:
msip_labels: MSIP_Label_f42aa342-8706-4288-bd11-ebb85995028c_Enabled=True; MSIP_Label_f42aa342-8706-4288-bd11-ebb85995028c_SiteId=72f988bf-86f1-41af-91ab-2d7cd011db47; MSIP_Label_f42aa342-8706-4288-bd11-ebb85995028c_Owner=mbj@microsoft.com; MSIP_Label_f42aa342-8706-4288-bd11-ebb85995028c_SetDate=2018-03-05T21:33:50.4346121Z; MSIP_Label_f42aa342-8706-4288-bd11-ebb85995028c_Name=General; MSIP_Label_f42aa342-8706-4288-bd11-ebb85995028c_Application=Microsoft Azure Information Protection; MSIP_Label_f42aa342-8706-4288-bd11-ebb85995028c_Extended_MSFT_Method=Automatic; Sensitivity=General
x-originating-ip: [2001:4898:80e8:b::36]
x-ms-publictraffictype: Email
x-microsoft-exchange-diagnostics: 1; SN6PR2101MB1022; 7:6M3PUG7cjB9zCDXFjwBHWzWhcZ7XQH6t/mOVVYqDVKYqgw9zBjQwNveTBHfwgUwiRuymL1PTWb9faSUeVB/sAPRtONXGEUVXMnm1Wu/A1hePTHAM01I+A4Bkc3LZafvuSS257zo6WuTo8V3aoH5JmCqr48uiuS8Yebdkn71vptJXs1yjCrQWhphPmUXLEeWIOjNYrjrKEDO8PIe/IscaCU4jx0O7Dp/Ze2k9XOWS+VP8GknJHHUzxMlb1ukw6kAy; 20:YbAzdnP3/z0q8cCQIIBMhv5kkNh9VDSPJhAHCqdduDL1qQerFvqKZeV6Qu+DRQ+cnelrpg3wICZ79/QNelQyM/GIOp8mxqeV/h+P30ANBo5Aumw6v3Sz6Z0/KpkUwPhS2Zt9LH4xLgnC/72PXfaHdqNYahjWSXFEZzE4vmevidY=
x-ms-exchange-antispam-srfa-diagnostics: SOS;
x-ms-office365-filtering-ht: Tenant
x-ms-office365-filtering-correlation-id: 385e89a6-1ce0-4de2-0533-08d582e0ca52
x-microsoft-antispam: UriScan:; BCL:0; PCL:0; RULEID:(7020095)(4652020)(48565401081)(5600026)(4604075)(3008032)(4534165)(4627221)(201703031133081)(201702281549075)(2017052603322)(7193020); SRVR:SN6PR2101MB1022;
x-ms-traffictypediagnostic: SN6PR2101MB1022:
authentication-results: spf=none (sender IP is ) smtp.mailfrom=Michael.Jones@microsoft.com;
x-microsoft-antispam-prvs: <SN6PR2101MB1022A92F264FD5807AE70FCFF5DA0@SN6PR2101MB1022.namprd21.prod.outlook.com>
x-exchange-antispam-report-test: UriScan:(28532068793085)(31418570063057)(21748063052155);
x-exchange-antispam-report-cfa-test: BCL:0; PCL:0; RULEID:(8211001083)(61425038)(6040501)(2401047)(5005006)(8121501046)(3002001)(3231220)(944501244)(52105095)(10201501046)(93006095)(93001095)(6055026)(61426038)(61427038)(6041288)(201703131423095)(201702281528075)(20161123555045)(201703061421075)(201703061406153)(20161123560045)(20161123564045)(20161123558120)(20161123562045)(6072148)(201708071742011); SRVR:SN6PR2101MB1022; BCL:0; PCL:0; RULEID:; SRVR:SN6PR2101MB1022;
x-forefront-prvs: 06022AA85F
x-forefront-antispam-report: SFV:NSPM; SFS:(10019020)(39860400002)(396003)(366004)(376002)(346002)(39380400002)(209900001)(189003)(199004)(86612001)(74316002)(2906002)(25786009)(4326008)(6436002)(186003)(478600001)(53936002)(8990500004)(966005)(7736002)(3280700002)(14454004)(72206003)(10290500003)(53376002)(5640700003)(81156014)(6506007)(1730700003)(106356001)(68736007)(7696005)(5630700001)(8676002)(46003)(81166006)(33656002)(59450400001)(99286004)(10090500001)(316002)(3660700001)(22452003)(55016002)(2351001)(790700001)(2900100001)(6116002)(105586002)(606006)(39060400002)(5660300001)(54906003)(236005)(97736004)(5250100002)(9686003)(86362001)(102836004)(54896002)(2501003)(6306002)(8936002)(6916009)(6606295002); DIR:OUT; SFP:1102; SCL:1; SRVR:SN6PR2101MB1022; H:SN6PR2101MB0943.namprd21.prod.outlook.com; FPR:; SPF:None; PTR:InfoNoRecords; MX:1; A:1; LANG:en;
received-spf: None (protection.outlook.com: microsoft.com does not designate permitted sender hosts)
x-microsoft-antispam-message-info: lo5yXDNubdjVO0JhEMxlhV92+ZsBIurL9mjdqvkwAcDwcDC/9i0acN4RnBk91q63Tlh8QTsPdr+boD8YDi0bdU5BhjchsrMC8EyUC2GLnItLRCPz/loryAzckI0XXuNQ7OFxlUUBVBki1IR8KerJFAlXj3Fh/ePZuWwouYeJ2utteLpPE24YaWQ+FUD3T8S22KfRO2eWhRiCocBxR6toJDEm5TrrkOG8fs36LH3hVuuwG78Dj0NibDtDFmRx+u3+2IIBZlPlJgpXuKohdr/O0TOA1fIj/GHUYcAcnGC8vNSn3BpfTnvwGt256VB+yxl+Hh+ddoovMtE89Ku8prGmCQ==
spamdiagnosticoutput: 1:99
spamdiagnosticmetadata: NSPM
Content-Type: multipart/alternative; boundary="_000_SN6PR2101MB0943D068F03621252BBAFBB6F5DA0SN6PR2101MB0943_"
MIME-Version: 1.0
X-OriginatorOrg: microsoft.com
X-MS-Exchange-CrossTenant-Network-Message-Id: 385e89a6-1ce0-4de2-0533-08d582e0ca52
X-MS-Exchange-CrossTenant-originalarrivaltime: 05 Mar 2018 21:33:51.9700 (UTC)
X-MS-Exchange-CrossTenant-fromentityheader: Hosted
X-MS-Exchange-CrossTenant-id: 72f988bf-86f1-41af-91ab-2d7cd011db47
X-MS-Exchange-Transport-CrossTenantHeadersStamped: SN6PR2101MB1022
Archived-At: <https://mailarchive.ietf.org/arch/msg/ace/U9pDpjTpCbfUGbH0qtFvsai4O_U>
Subject: [Ace] CBOR Web Token (CWT) draft addressing IETF last call comments
X-BeenThere: ace@ietf.org
X-Mailman-Version: 2.1.22
Precedence: list
List-Id: "Authentication and Authorization for Constrained Environments \(ace\)" <ace.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/ace>, <mailto:ace-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/ace/>
List-Post: <mailto:ace@ietf.org>
List-Help: <mailto:ace-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/ace>, <mailto:ace-request@ietf.org?subject=subscribe>
X-List-Received-Date: Mon, 05 Mar 2018 21:33:56 -0000

The CBOR Web Token (CWT) specification has been updated to address IETF last call comments received to date, including GenArt, SecDir, Area Director, and additional shepherd comments.  Changes were:

  *   Clarified the registration criteria applied to different ranges of Claim Key values, as suggested by Kathleen Moriarty and Dan Romascanu.
  *   No longer describe the syntax of CWT claims as being the same as that of the corresponding JWT claims, as suggested by Kyle Rose.
  *   Added guidance about the selection of the Designated Experts, as suggested by Benjamin Kaduk.
  *   Acknowledged additional reviewers.

The specification is available at:

  *   https://tools.ietf.org/html/draft-ietf-ace-cbor-web-token-13

An HTML-formatted version is also available at:

  *   http://self-issued.info/docs/draft-ietf-ace-cbor-web-token-13.html

                                                                -- Mike

P.S.  This notice was also posted at http://self-issued.info/?p=1789 and as @selfissued<https://twitter.com/selfissued>.