Re: [Ace] [EXTERNAL] Éric Vyncke's No Objection on draft-ietf-ace-oauth-authz-38: (with COMMENT)

"Eric Vyncke (evyncke)" <evyncke@cisco.com> Thu, 25 March 2021 12:58 UTC

Return-Path: <evyncke@cisco.com>
X-Original-To: ace@ietfa.amsl.com
Delivered-To: ace@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id CA2F93A20A2; Thu, 25 Mar 2021 05:58:51 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -11.896
X-Spam-Level:
X-Spam-Status: No, score=-11.896 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, RCVD_IN_DNSWL_MED=-2.3, RCVD_IN_MSPIKE_H3=0.001, RCVD_IN_MSPIKE_WL=0.001, SPF_NONE=0.001, URIBL_BLOCKED=0.001, USER_IN_DEF_DKIM_WL=-7.5] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (1024-bit key) header.d=cisco.com header.b=gMK6BdwD; dkim=pass (1024-bit key) header.d=cisco.onmicrosoft.com header.b=wIAfpBnG
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id U7aLDCJNKHIy; Thu, 25 Mar 2021 05:58:47 -0700 (PDT)
Received: from rcdn-iport-4.cisco.com (rcdn-iport-4.cisco.com [173.37.86.75]) (using TLSv1.2 with cipher DHE-RSA-SEED-SHA (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 9360A3A209F; Thu, 25 Mar 2021 05:58:45 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=cisco.com; i=@cisco.com; l=8798; q=dns/txt; s=iport; t=1616677125; x=1617886725; h=from:to:cc:subject:date:message-id:references: in-reply-to:content-id:content-transfer-encoding: mime-version; bh=z0h6nMbZQY68/XoBsia6jW+51OYqljlC881H3YhblKw=; b=gMK6BdwD1IfRpY0PwGpUh2l87f/gCgMtec99NXe3GuF5qO9HplJ6Bxmp tKXOtJdr1XDby6Ono9KXL+Iti6eIJVVscMBg4NZuq4uN+PEj1Titd5zvj zJUAJkp2PWi+oYOINzDFabHn6FwSbJGqwcJqaVj+1jZiydjt5JX+7esFO c=;
IronPort-PHdr: A9a23:qxFPJB3qHYiDXdxqsmDPUVBlVkAck7zpIg4Y7IYmgLtSc6Oluo7vJ1Hb+e4FpFTOWI/a9/9Pi6zNvvOoVW8B5MOHt3YPONxJWgQegMob1wonHIaeCEL9IfKrCk5yHMlLWFJ/uX3uN09TFZX1YFjYo2G/5j5UARisfQZwL/7+T4jVicn/3uuu+prVNgNPgjf1Yb57IBis6wvLscxDiop5IaF3wRzM8RN1
IronPort-HdrOrdr: A9a23:DwF2qaMYsx/1y8BcT9Dx55DYdL4zR+YMi2QD/3taDTRIb82VkN2vlvwH1RnyzA0cQm0khMroAsi9aFvm39pQ7ZMKNbmvGDPntmyhMZ144eLZrQHIMxbVstRQ3aIIScdDIfX7B1RikILe6A63D94vzLC8gd+VrM31pk0dKj1CQadm8gt/F0K6PyRNNUl7LLA+E4eR4dcCgjKmd2geYMjTPAh6Y8HoodrXmJX6JSMcDxk85wWUyR+u4rj2Ex+Xty1uEA9n67Ek7GTDjkjF9ryu2svLiyP0+k3yy9BtmNXnwsZeH8DksKgoAxjllwrAXvUbZ5SspzYwydvfjWoCsN6JmBs4OtQ21nW5RBDInTLI+y3NlAkj8GXjz1jwuwqgneXcSCghA8RMwaJ1GyGpkXYIh9133KJV02/xjfM+Znms8FWflrr1fipnmUaurX0pnfR7tQ0jbaIldLRToYYDlXkldqsoISPg5IgrVMloAc3MjcwmCW+yUnHDsmFjhOGrR3Q4dy32O3Qqh8r96UkzoFlJi28jgOAPlHYJ85wwD7Ne4f7fD6hunLZSCucLcKNUHo46MI6KI12IZSiJHHOZIFzhGq1CEWnKsYTL7LI84/zvUIAUzaE1hI/KXDpjxCoPUnOrLffL8IxA8xjLTmn4dy/q0Nti659wvaC5Y7b3LyuZShQLn9G7q/sSRu3XMszDf65+MrvGFy/DCIxJ1wrxV915Mn8FSvAYvd49RhaAucTOJor2tvHKcfraKbb3eAxUA1/XMz8mZnzeNc9A5kekVjvTmx7KQU7gfUT54NZxHcHhjrAu4blIErcJnhkeiFy/6M3OAyZFqLYKcEx3J66ilqu6oGKx7HvZ9mkBAGsHMm9lpJHbF19arw4DNE35NZwZvc+ERGxU1HybYhllT83XFwZbr09t+b2+KoGRwSxKMaPgDkuqy18o4F6aRZYVnaOOoe3/fIkjM5ogUKttURnQGwdtggZsomdbYAoCTkvSfwme05mNvdgxPqXyZtN8iACkLYposnrZr1ybvtxqbGAcRSSSXcmehhsOSzJYikZqybIWhKONlF+UWDYCqdV9FGcJSWyMRJpaEQyOZexv68HWUTA1aV3PuBu3pFUYfHHw+0Abm2r7RBfkCc3jMx56oXBX0qHj7VVuUH6SFngANkxSgMlaCXnMvGp13KutYKe+ulHhNGcq86U6LCzPZycUL0dV4+2PkDSRmDqECBwdt8oTF+TAEbUudKzS0HuxKIuO0boLBeNQ4YwNDqGdjsYWS+6FPweaIDTkYtlZqDC9tzIrPjJ5p2Ijlu6t0Br57HKg1Hp6GvbKJk96Lotrb+20/izhR/yS1o9+gs9wteysMn/pYtru89CcUxdTbhfSq3WxVecmtNRdur8zrqJ6G93eXSHT3H9KmBU4I8GcrjJSfI1rpLTAMJRoZcocZmZQ+Ucojs2GKA8zqRPta9VONG0FnjveJZeE8rDIob0gDgmIoxbxI0CW92lY8+3eVyWO2LYGA8sLUCtrQVl57G4n8PKJdoXWBgnvbe1F8VagOnK2cbNWSsG+aP4thwc/58vNk/6cdiL+1gyVoCByJbhW9X27Bcy1GwCBFIdzgpKHEEXJhrHv5sG9jD36E2TmL0sZgJBIbkwWYIBIjCI4gIg+zyi1Tej2ryse4ixjyCAikkSo3I6spHrfFwVBNwbSh51NRzldMnSSl63+gKCl/WW45CIAwIXJEUdbY8pHFNcRRJXmNisGE7llgJe4u640xjlZaBggD2QgmCnw0uNv07C+wujTUYTZeAHVEENE/yVECI5yljEqrm8Fc9HW1+PJXjkq
X-IronPort-Anti-Spam-Filtered: true
X-IronPort-Anti-Spam-Result: A0DWCQCyiFxg/5RdJa1aHgEBCxIMQIMjKSgHdlo2MYRCg0gDhTmIICUDjyOKEYJTA1QLAQEBDQEBMgIEAQGEUAIXgWUCJTgTAgMBAQsBAQUBAQECAQYEcYVhDYZEAQEBAwEjEQwBATcBCwQCAQgRAwECAwImAgICMBUFAwgCBAENBYJwAYJVAw4hAaAeAooed4EygwQBAQaFGRiCEwmBDyqCdoJxUEiCNR2DciYcgUlCgRInDBCCWT6EQIMWNYIrgVkQgUkNRRgJPSgTNAMFAQQoAw4ZGpBUG4M+iA6DHZlzgQsKgwaQb4tyAx+DSIpslhqFD493gg6bbQImIIRGAgQCBAUCDgEBBoFrI4FZcBUxDyUBVR2BIylQFwINhD2JYgwWFG0BCIJDillzOAIGAQkBAQMJAXuGbgEB
X-IronPort-AV: E=Sophos;i="5.81,277,1610409600"; d="scan'208";a="852686818"
Received: from rcdn-core-12.cisco.com ([173.37.93.148]) by rcdn-iport-4.cisco.com with ESMTP/TLS/DHE-RSA-SEED-SHA; 25 Mar 2021 12:58:43 +0000
Received: from mail.cisco.com (xbe-aln-007.cisco.com [173.36.7.22]) by rcdn-core-12.cisco.com (8.15.2/8.15.2) with ESMTPS id 12PCwhHB027568 (version=TLSv1.2 cipher=AES256-SHA bits=256 verify=OK); Thu, 25 Mar 2021 12:58:43 GMT
Received: from xfe-rcd-002.cisco.com (173.37.227.250) by xbe-aln-007.cisco.com (173.36.7.22) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.2.792.3; Thu, 25 Mar 2021 07:58:43 -0500
Received: from xfe-rcd-002.cisco.com (173.37.227.250) by xfe-rcd-002.cisco.com (173.37.227.250) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.2.792.3; Thu, 25 Mar 2021 07:58:43 -0500
Received: from NAM10-DM6-obe.outbound.protection.outlook.com (72.163.14.9) by xfe-rcd-002.cisco.com (173.37.227.250) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.2.792.3 via Frontend Transport; Thu, 25 Mar 2021 07:58:43 -0500
ARC-Seal: i=1; a=rsa-sha256; s=arcselector9901; d=microsoft.com; cv=none; b=jA0m99Z03/+OoObGUA7FBx3jPas0gBueihQiYHFuhjAOomcsosWZ7PgeZvXBctdg+qzC9INf1md2McVqjPSBzsG9yzAFOPODgAp26/TLQo04tWBiDWOSWMr0J57dxCneVrrT5BPz/Wn6bildp2j3dF49y4N1Ap4HIBMk7YTDfMMprpSFB/bTqTqyyeeyEuWTR1vOVQJ0qug24zpU1yDn6dEbi+iIR6PswYcZ83AL/Riq12qW6y/aVrmIsbT43xh6rSQiPr2otmPfUUz6rM4dgpjtqOEtoEwAOdkGKdXHF5JmuS8LQqbLM8Xkt7sDCW5K5huyC2msMv1Arn8zZm20bQ==
ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=microsoft.com; s=arcselector9901; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-SenderADCheck; bh=z0h6nMbZQY68/XoBsia6jW+51OYqljlC881H3YhblKw=; b=NuGzbQ2YRMTrN3VgHaWp0ic0ONsxsCt8mE/juoRZBEkrlxmr1Z500SuOmfzd1tnvi+bHwa2C6lOdFGww//2Q/eMocRGtUNGljpBfScnxylTQoWjEVAwTtoguuIbxr/6KJsxe4UHXWInnYlmBi20ZjcTnbRfIHbAoP1FI7YHhqfOoS1/mv/fzKKSPwRMlIihhAcEQa1hWymDdmoCdAEM3jsveExSPdpkjfVwZSQ0Ur1Zp0OKxQNM7FmER2Fanu6FxEfQXisW7niHdo/9fFPrEXBsfys2HaCixaZWSjiLLw8gTNwayXXQ0ciiy5k6poUri82uRDoqEUFisAkQxhhBHhQ==
ARC-Authentication-Results: i=1; mx.microsoft.com 1; spf=pass smtp.mailfrom=cisco.com; dmarc=pass action=none header.from=cisco.com; dkim=pass header.d=cisco.com; arc=none
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=cisco.onmicrosoft.com; s=selector2-cisco-onmicrosoft-com; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-SenderADCheck; bh=z0h6nMbZQY68/XoBsia6jW+51OYqljlC881H3YhblKw=; b=wIAfpBnGnvuTXXNwYxDvOfmXFPP5wnuC3v54PCvJo7XW1B0BbPvGQQn266dn49axaiF2Hon3wmlZ7CbwqaiVKbs9OGe7CWC1F9pb8PaPsj6JkrnoO/f/NSYtTZQ22lBdDWK5j61mr5bKXe+sRe9qX88UyhMtpjuOiKDEUSo4O28=
Received: from PH0PR11MB4966.namprd11.prod.outlook.com (2603:10b6:510:42::21) by PH0PR11MB4886.namprd11.prod.outlook.com (2603:10b6:510:33::22) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.20.3977.25; Thu, 25 Mar 2021 12:58:42 +0000
Received: from PH0PR11MB4966.namprd11.prod.outlook.com ([fe80::dcdf:3910:b85d:6eba]) by PH0PR11MB4966.namprd11.prod.outlook.com ([fe80::dcdf:3910:b85d:6eba%7]) with mapi id 15.20.3977.029; Thu, 25 Mar 2021 12:58:42 +0000
From: "Eric Vyncke (evyncke)" <evyncke@cisco.com>
To: Seitz Ludwig <ludwig.seitz@combitech.se>, The IESG <iesg@ietf.org>
CC: "draft-ietf-ace-oauth-authz@ietf.org" <draft-ietf-ace-oauth-authz@ietf.org>, "ace-chairs@ietf.org" <ace-chairs@ietf.org>, "ace@ietf.org" <ace@ietf.org>
Thread-Topic: [EXTERNAL] Éric Vyncke's No Objection on draft-ietf-ace-oauth-authz-38: (with COMMENT)
Thread-Index: AQHXHyuZU/A3KOOoPkeRpDWfQb0fYKqUYRwggABeeYA=
Date: Thu, 25 Mar 2021 12:58:42 +0000
Message-ID: <9F2C0EC3-797C-4719-BD85-0E8DD4FD0878@cisco.com>
References: <161642497935.28459.6337296577160925255@ietfa.amsl.com> <133ef81b68af4ee0ae5d573b51b9aa48@combitech.se>
In-Reply-To: <133ef81b68af4ee0ae5d573b51b9aa48@combitech.se>
Accept-Language: fr-BE, en-US
Content-Language: en-US
X-MS-Has-Attach:
X-MS-TNEF-Correlator:
user-agent: Microsoft-MacOutlook/16.47.21031401
authentication-results: combitech.se; dkim=none (message not signed) header.d=none;combitech.se; dmarc=none action=none header.from=cisco.com;
x-originating-ip: [2001:420:c0c1:36:3470:a7a9:9db:4371]
x-ms-publictraffictype: Email
x-ms-office365-filtering-correlation-id: 8f0a39b7-0415-4940-e292-08d8ef8db7a3
x-ms-traffictypediagnostic: PH0PR11MB4886:
x-microsoft-antispam-prvs: <PH0PR11MB4886391378A1D5B089FEF28DA9629@PH0PR11MB4886.namprd11.prod.outlook.com>
x-ms-oob-tlc-oobclassifiers: OLM:3044;
x-ms-exchange-senderadcheck: 1
x-microsoft-antispam: BCL:0;
x-microsoft-antispam-message-info: bQBdUszU8TPMfckVE3JBerMJWlr0yQ9HwF9romeOYgLTtrfuzx8gTdQPJaOachZPt2ItufjdQb36qkSMiD1escsahGOnSs0+lWSOtu4+OxEpkcmI9BNwHOadRkGp8wDHmV9rCqYPTbS0dXucEPnl3kTxOvjUszHqsYyBss/itkiwRA+H1llOkoYxQXLdIIpTwW4cSddEXtvhfSwfF8CGF0yh0YVpiZM4dZixkKvYfQ4vbzRW7ChEF3yG0EnZw0XJm3rnM21jDNWlmOGfrkcSdnbYIywkYSDwNhWuLcRXDXjmwOXQx5oVAZlU1R0frqaoIiFHJZFST9oBiDqJUO/xfYNFqGluYXhM/Kd6UVFbrk2uPQTo0s+WeBej2DN8XCG8BP1qupVstQU1ra/umF9WDh5qE0tMVqUZcZVKA3oq3UI+IWiRcbbuxOKyY6E2sTdXevz+y2r1AnerBZsGtmCLX/e1Pg5ktrlIRnbO6yTExfZ+UqU2oOK0Mme29jEeiNeBSb6Z9U5A4Gs6TpOxlnJUDE3Ods04lOiSKN0C9YCAMqhHvE9n6t7HzVyWp5KzKpogcEQIQmiw/g0K+m9lc4n5V4iG4siyMMvy7QOERcryApUtv4egHZ/v3iBgrnw9PbH/I6w7+85A01b/UVBmVl6Wkae95OgJjVS0mow09YFIgQEX9igUNTxk/ens2I7ZO7fP
x-forefront-antispam-report: CIP:255.255.255.255; CTRY:; LANG:en; SCL:1; SRV:; IPV:NLI; SFV:NSPM; H:PH0PR11MB4966.namprd11.prod.outlook.com; PTR:; CAT:NONE; SFS:(346002)(39860400002)(396003)(136003)(366004)(376002)(76116006)(2616005)(38100700001)(53546011)(4326008)(91956017)(6512007)(6506007)(8936002)(66574015)(66946007)(71200400001)(5660300002)(36756003)(86362001)(66446008)(478600001)(64756008)(66556008)(6486002)(83380400001)(66476007)(33656002)(2906002)(110136005)(54906003)(316002)(224303003)(186003)(45980500001); DIR:OUT; SFP:1101;
x-ms-exchange-antispam-messagedata: TPiWI6MBZuTeqXTNHVfowXRWRblbjbkID6eMwDrLXzN/ImoaxfN6cJluEf2P42CZxr4wDQLQKOEGwObIiD7Bzvi2xM+2368TdP4HbRhnwvlap1yTIWsAPwn4kiT3WeS8Lo+BzL8wfGVX2+l4Dcs9u4x98iYtq46uafaY34hTV5ifaKfALUsCLWV/6+X4pvL0njvKtlbmP1gDk1Tm5qfRv7I7GqW/vs6fZBRvicAUy2pXKFF7dlj2/kzQWB6pAvPpJ8x0x8XGsekJTOGeUh8Yrmr+vcFmJJe2vc9DwrloUIljjqiseCZzed5sz06hmWFtiBi/9v1L3YskS8YRnnhHVVaoDP7f9ldtDeosjBu7k1+n8woCjkUO7TNPj4f1mqcfWnX0sYAsvhBPQ8uLqMce1yqJdPYnzooe74wGGQ3q4yX3H8a+7pJdpD7kIW3f4zw9RED03gnqPjJRgPLic2SlEiSGze/UyJ/Xi2KJt5AXv8cSARpyV0SZxD9yYA7Djsw8D9Pw6RhSk+s1eIp0WJOmELwPMXolh3l3JaBMA2t5ArUbECQu26e2MczPKl6qE1U+CE8H1Tzh+H3eC4KAqCfL9jcEH5cW0hdtYgQNGjHbZyaYQY3oTiQuzp5MUTOskjQq6TS6bRLFI1MsQwA1974FPuixP3a886hI5RzcSaRrO2WI/swhy+NLy3qRxlIcPBqC3kCnxinVVmtq58cKamKX9wQUqIOkLVbtFZgpO/fc1xJyTHPUKDiMryEuiRJZR1FY3Ba/9Z7xJvnuXvRlzV95oSDg/rVnXSow6xcnkwdJSM3eLstgf4YBJMiftuM2hAnu4YVCfJJDl5uSBrCU2FDrqpzXGHooY7bFBFxJqjBLsx1jPeqww1WLrRP0FjdqP34NYFU/E1Qnxr46yai6DosCnwqdFRjhZUqcAOl+MJO5QR0qsAsK0awVi2BvG+/QzY3ZelHpdrtn9WXu0rKpy8+11lCYuRjWIEwMQ9/JZylPcm22I2JLDkFgMREp3C0NVPzdbqdXDEm/8EWIbrtJ9OtokC5cbvWmQh8WW2zfQhvCar7iG0M2lBHJ0biYqIs4Qe4m4wrqbeX6aVkuTfm05yG/PSqNbsjyKMfY+SsehKLdRv5zMJJZ0sadfZCzLqK/kG8JOcP7nUzkXsFGUbObMl/Uempaf+S48JeZH/cvk0LwFH1yG3b9VSiHlE0s8UfKXT8PfjlDzZ/aFfOnWjz31lUn7Efr1WTnsHpx107ohkGJI+ZQUUozR95kAyrnJmfs3WBFC96sJE0FfaVJH5mq/71pn4HdIQWYnVPn0Hyuum4ckvCr6D3uCV6lQnw4nH8AiFXE8+n+TCH5MEec+2aliLIMmcAYEPHh5S7tPoJnarXo+IA9jCDRP/bLtLVRnK/vyk54
x-ms-exchange-transport-forked: True
Content-Type: text/plain; charset="utf-8"
Content-ID: <D1FFFC0E7A875E46BBA9705AB91CEE68@namprd11.prod.outlook.com>
Content-Transfer-Encoding: base64
MIME-Version: 1.0
X-MS-Exchange-CrossTenant-AuthAs: Internal
X-MS-Exchange-CrossTenant-AuthSource: PH0PR11MB4966.namprd11.prod.outlook.com
X-MS-Exchange-CrossTenant-Network-Message-Id: 8f0a39b7-0415-4940-e292-08d8ef8db7a3
X-MS-Exchange-CrossTenant-originalarrivaltime: 25 Mar 2021 12:58:42.2088 (UTC)
X-MS-Exchange-CrossTenant-fromentityheader: Hosted
X-MS-Exchange-CrossTenant-id: 5ae1af62-9505-4097-a69a-c1553ef7840e
X-MS-Exchange-CrossTenant-mailboxtype: HOSTED
X-MS-Exchange-CrossTenant-userprincipalname: 8wz8tdNu5eOzdByxnOKdDXkPP1S5E0lCAx0sdXYL4ECueLAYUneELaoQ6qJsk2rWYV9JU+8508d+hZnLxGYF1g==
X-MS-Exchange-Transport-CrossTenantHeadersStamped: PH0PR11MB4886
X-OriginatorOrg: cisco.com
X-Outbound-SMTP-Client: 173.36.7.22, xbe-aln-007.cisco.com
X-Outbound-Node: rcdn-core-12.cisco.com
Archived-At: <https://mailarchive.ietf.org/arch/msg/ace/UyOh674by7DoR5GyqW6FjAdexwk>
Subject: Re: [Ace] [EXTERNAL] Éric Vyncke's No Objection on draft-ietf-ace-oauth-authz-38: (with COMMENT)
X-BeenThere: ace@ietf.org
X-Mailman-Version: 2.1.29
Precedence: list
List-Id: "Authentication and Authorization for Constrained Environments \(ace\)" <ace.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/ace>, <mailto:ace-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/ace/>
List-Post: <mailto:ace@ietf.org>
List-Help: <mailto:ace-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/ace>, <mailto:ace-request@ietf.org?subject=subscribe>
X-List-Received-Date: Thu, 25 Mar 2021 12:58:52 -0000

Thank you Seitz for your detailed and quick reply.

I agree with your replies (and thank you for the added information) and actions.

Regards

-éric


-----Original Message-----
From: Seitz Ludwig <ludwig.seitz@combitech.se>
Date: Thursday, 25 March 2021 at 10:42
To: Eric Vyncke <evyncke@cisco.com>, The IESG <iesg@ietf.org>
Cc: "draft-ietf-ace-oauth-authz@ietf.org" <draft-ietf-ace-oauth-authz@ietf.org>, "ace-chairs@ietf.org" <ace-chairs@ietf.org>, "ace@ietf.org" <ace@ietf.org>
Subject: RE: [EXTERNAL] Éric Vyncke's No Objection on draft-ietf-ace-oauth-authz-38: (with COMMENT)

    Hello Éric,

    Thank you for your review. I plan to submit an update of the draft to address your comments (and others') by the end of the week.
    I have some comments inline.

    /Ludwig

    > -----Original Message-----
    > == COMMENTS ==
    > 
    > -- Section 3 --
    > Should references/expansions be added for "HTTP/2, MQTT, BLE and QUIC"
    > ?
    Fixed

    > 
    > -- Section 3.1 --
    > Suggest to review the order of the definitions, notably popping up
    > "introspection" as it is used by most of the other terms.
    >
    Done


    > -- Section 4 --
    > Mostly cosmetic, any reason why figure 1 is so far away from its mention in
    > §1 ?
    > 
    I moved the figure and its explanations up in the section. The figure does not have a strong dependency on the text blocks that were moved down in the process.


    > In "ensure that its content cannot be modified, and if needed, that the
    > content is confidentiality protected", I wonder why the confidentiality is only
    > optional ? As far as I understand it, the possession of an access token grants
    > access to a ressource, so, it should be protected against sniffing. What did I
    > miss ?
    > 
    Actually you also need the proof-of-possession key. If that is only referenced in the token, or if the token only contains the public key part of an asymmetric key pair you could get away with only integrity protecting an access token.


    > In "If the AS successfully processes the request from the client" may look
    > ambiguous because processing correctly (per protocol) an invalid credential is
    > also "successfully processed". Suggest to mention something about "positive
    > authentication" ;)
    > 
    Fixed

    > -- Section 5 --
    > As a non-English native speaker, I cannot see the verb in the second
    > proposition in "For IoT, it cannot be assumed that the client and RS are part
    > of a common key infrastructure, so the AS provisions credentials or
    > associated information to allow mutual authentication.". While I obviously
    > understand the meaning, could it be rephrased ?
    > 
    Rephrased


    > -- Section 5.1.1 --
    > Could the word "unprotected" be better defined in "received on an
    > unprotected channel" ? E.g., is it only about TLS ? Else, I like the implicit lack
    > of trust.
    > 
    I'd like to avoid restricting the scope to protected/unprotected channels here, since we have profiles that use object security on the individual messages (oscore).

    > -- Section 5.1.2 --
    > I must admit that I have failed to understand the semantic of "audience"...
    > Can you either explain its meaning or provide a reference ?
    > 
    Added a reference

    > -- Section 5.5 --
    > In "Since it requires the use of a user agent (i.e., browser)" is it "i.e." or "e.g."
    > ?
    This comment seems to refer to an older version of the draft. 

    > 
    > -- Section 5.6 --
    > s/the semantics described below MUST be/the semantics described in this
    > section MUST be/ ?
    Fixed
    > 
    > In "The default name of this endpoint in an url-path is '/token'" should
    > "SHOULD" normative language be used ?
    > 
    This is inherited from OAuth 2.0, where I was given to understand that this is not even a SHOULD requirement.

    > -- Section 5.6.4.1 --
    > In figure 11, would you mind adding the section ID in addition to RFC 6749 ? I
    > failed to spot them in RFC 6749.
    > 
    Done (they are really well hidden in 6749)

    > -- Section 5.7.2 --
    > It is a little unclear to me which profile must be used as 'profile' is optionnial?
    > Should a default or any profile be used ?
    Added some guidance

    > 
    > -- Section 5.8.1 --
    > Suggest to use the BCP14 "SHOULD" in the text "The default name of this
    > endpoint in an url-path is '/authz-info'"
    I would like to maintain the alignment here with OAuth 2.0 were default endpoint names are not even a SHOULD.

    > 
    > -- Section 10.2 --
    > Is RFC 7049 really an informative reference as CBOR appears as the default
    > encoding ?
    This was updated to RFC 8949, which now is a normative reference. 

    > 
    > == NITS ==
    > 
    > s/application layer protocol/application-layer protocol/ ?
    FIXED
    > 
    > Should multi-words message names (e.g.,  AS Request Creation Hints) be
    > enclosed by quotes ?
    > 


    > -- Section 2 --
    > Please introduce "authz-info" before first use.
    > 
    There is a reference to the section where authz-info is defined in -38. Are you suggesting some other approach?

    > -- Section 3.1 --
    > "PoP" is expanded twice in this section ;-)
    Fixed

    > 
    > "CBOR encoding (CWT) " the "CWT" acronym does not match the expansion
    > :-)
    Rephrased this.
    > 
    > -- Section 4 --
    > 
    > Sometimes "Client" is used and sometimes "client" is used...
    > 
    Fixed

    > s/reference to a specific credential/reference to a specific access credential/
    > ?
    This actually refers to the proof-of-possession credential. I'll add some clarification.

    > 
    > -- Section 5.1.2 --
    > Can you introduce to "kid" acronym ? It too me a while to understand that it
    > is
    > (probably) key-id... :-)
    In -38 this section now says: "A "kid" element containing the key identifier ...". Does that address your issue?

    > 
    > Unsure whether "nonce: h'e0a156bb3f'," is the usual IETF way to introduce
    > an hexadecimal number.
    It is CBOR diagnostic notation as indicated in the reference to the figure.

    > 
    > typo in "5.8.4.  Key Expriation" :-)
    Fixed.