Re: [Ace] I-D Action: draft-ietf-ace-oauth-params-12.txt

Ludwig Seitz <ludwig_seitz@gmx.de> Sat, 01 February 2020 11:06 UTC

Return-Path: <ludwig_seitz@gmx.de>
X-Original-To: ace@ietfa.amsl.com
Delivered-To: ace@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id D23961200EB for <ace@ietfa.amsl.com>; Sat, 1 Feb 2020 03:06:24 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.599
X-Spam-Level:
X-Spam-Status: No, score=-2.599 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, FREEMAIL_FROM=0.001, RCVD_IN_DNSWL_LOW=-0.7, SPF_HELO_NONE=0.001, SPF_PASS=-0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (1024-bit key) header.d=gmx.net
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id uPV-iNgBZd0r for <ace@ietfa.amsl.com>; Sat, 1 Feb 2020 03:06:23 -0800 (PST)
Received: from mout.gmx.net (mout.gmx.net [212.227.15.15]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id A05D11200E6 for <ace@ietf.org>; Sat, 1 Feb 2020 03:06:22 -0800 (PST)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=gmx.net; s=badeba3b8450; t=1580555179; bh=cB8VhyZVn4D34q8Q5yJ8SwthPe0YRHYB8Q+61NGOtpo=; h=X-UI-Sender-Class:Subject:To:References:From:Date:In-Reply-To; b=ZAjt7j24oo+gERIgBaEf5PxQ769Zjv3lc9hk7k3yq60T1EU4UBCKzyIIRdbi1R5HO CsRXwSd7RhWVYkAdfoId5QOPnl+w5QtrM6ghAqPSZ0nB5sjuvhI17lgph8EhXD6Hjn ZMxBjQGyKo1L6wZIscqqHvAmFPtMaYlwAkGfoTsU=
X-UI-Sender-Class: 01bb95c1-4bf8-414a-932a-4f6e2808ef9c
Received: from [192.168.1.220] ([84.217.44.37]) by mail.gmx.com (mrgmx004 [212.227.17.190]) with ESMTPSA (Nemesis) id 1N1wq3-1jhrXO0QlV-012JbU for <ace@ietf.org>; Sat, 01 Feb 2020 12:06:19 +0100
To: ace@ietf.org
References: <158055488317.11743.17493600560023993363@ietfa.amsl.com>
From: Ludwig Seitz <ludwig_seitz@gmx.de>
Message-ID: <d1a481c5-f5e3-f733-5d14-422c6cf7fb0f@gmx.de>
Date: Sat, 01 Feb 2020 12:06:17 +0100
User-Agent: Mozilla/5.0 (X11; Linux x86_64; rv:68.0) Gecko/20100101 Thunderbird/68.4.1
MIME-Version: 1.0
In-Reply-To: <158055488317.11743.17493600560023993363@ietfa.amsl.com>
Content-Type: text/plain; charset="utf-8"; format="flowed"
Content-Language: en-US
Content-Transfer-Encoding: quoted-printable
X-Provags-ID: V03:K1:LwCScB4qSA268Y10SKlua3sVQSMa7i8tCYjkfinEJ2V9X9hm6Nh +9GM18POVad9WS9j6okLPIf8m1ZbT5JFpxrvxJGlb9/JitHYOg/aBoUOT8O3N/fyJwvFKLD 6vJnw4kjz565gRYkz7U1kKd5aD6VrNIBSxcuXn5GOFBPS5qUkwqtIKPDI+eVbW+z89y9p9T 4pRzokKvrR8QLBPGcuZFg==
X-UI-Out-Filterresults: notjunk:1;V03:K0:A8LRqQDVK7w=:iXd0XmhjA3MOJQWuDbVMAb WGdn7onBx5G5gjOx7Z+lx0OMW6WlGvLA3kGQWJAMRyk+vaiWe4GxqPy11uyrzrf9GvFipLTNa GCOobdCDkGQwxoHgn0UkiExxj6gxkgQSp71bKyPq4yxBBY3femF81JXrSv0043HueG9W/hrTT PgOAmixeqyWt+DQ2Y3k7uYQJgQSkk7aD9ITZdglQTsaLICXycrPRO524KjUcTEg3lh96MKTmn iLSGoZUaqZyTK6AWEYUv74/4lA6j4Cn798G4zy/FErPVEbTKDenqWimBev/19roetiJc6Lggt uTz1AFetjaVnBeLwFcEFMxx/famRnYBIo8p4hqa+2iG+g6Vzx7y9a081fEx1bt9VtCvZo9VI1 ReWr222tfbivUyM4eppJnoK3iQ8XPnh+qm02hl8Lm4Z6emacvyY0X51/OyClVx5YJ0QeluzUC Iu0Vl79juCvavmBtTa8Ah8NFGXjLalkYjb7Tir6d7DbobjHuGPZjxRN3I7f7geGjx3jFgBrCt uver52K5CM8T9unkOPmdpnxqmGbm08tJhrUdlss4+UFWX9l6CMAy+QKolnccMC/vSs2ZTCkM8 TNn+70dhglbUu/DeLgr5HsZ0ABSpiVL3qQX4sABPbLxNtDHoaJFWnIM3FyD2+qDKEemLyxlZm I4LhI8EtPSSvriHHvw9nK80OK4jRMwyBJBgl3U1ZlHJk3DZ5KAOQWW1mfJTiI924cvh15KXxj le3dn858mY+J+nMmsL/QvEdoh729Sw1y7E/TP4opiyxvaHbhdbd2nvNl3koxDNO6TMDY/khA6 7GKQVrHQpyEMOZs1ISnHsmrBni3HezxJLxnFNFuaFoqHX45Ur3vaNFcZiz3Q9nOe0pCBOaMbK 57im3bJ83RGSsZL92O1BKeiQ0gq34KL2phm0CHW7hOqT1FAYq3YERXpUJe5VFokRVZjDHHcCc 49DPOMFtLWMQIbUZ5dmGnJ4gHuXeSBxynTSqhXydEk2CIozmc79CdRzn76jcQSNeVgKlk6J2r QJYJwT/bLLYw5g7gqEoe37UTnqJ9ofwwkb9Vbh799RUZ2+RJbiMCt5KpP5mdP4+c8OhfyIKzs ozjJ/1M+cyYaL54ZrSARQxBQuV2HaBjGG+NFfjSusaKGF0pj4ZUL6mR9fqHbwwoJ+Gxn9G558 C7729S0ZKJQ+ln+nGH7U2BCFvzLKm8ySK80oTMUUzslJ7pTuz/kgdyZWDIvE2XWFHmZx0iL2N NRkZr3GJ+EohTeCUX
Archived-At: <https://mailarchive.ietf.org/arch/msg/ace/YFOSA7j6f_YuN2HOwK-3XKS2Ts0>
Subject: Re: [Ace] I-D Action: draft-ietf-ace-oauth-params-12.txt
X-BeenThere: ace@ietf.org
X-Mailman-Version: 2.1.29
Precedence: list
List-Id: "Authentication and Authorization for Constrained Environments \(ace\)" <ace.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/ace>, <mailto:ace-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/ace/>
List-Post: <mailto:ace@ietf.org>
List-Help: <mailto:ace-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/ace>, <mailto:ace-request@ietf.org?subject=subscribe>
X-List-Received-Date: Sat, 01 Feb 2020 11:06:25 -0000

Hello ACE,

this update (together with an upcoming update of
draft-ietf-ace-oauth-authz) fixes the issues raised by Brian Campbell.

Please review the new section 7. (Requirements when using asymmetric
keys) to see if you agree with the reasoning proposed therein.

Regards,

Ludwig


On 2020-02-01 12:01, internet-drafts@ietf.org wrote:
>
> A New Internet-Draft is available from the on-line Internet-Drafts directories.
> This draft is a work item of the Authentication and Authorization for Constrained Environments WG of the IETF.
>
>          Title           : Additional OAuth Parameters for Authorization in Constrained Environments (ACE)
>          Author          : Ludwig Seitz
> 	Filename        : draft-ietf-ace-oauth-params-12.txt
> 	Pages           : 11
> 	Date            : 2020-02-01
>
> Abstract:
>     This specification defines new parameters and encodings for the OAuth
>     2.0 token and introspection endpoints when used with the framework
>     for authentication and authorization for constrained environments
>     (ACE).  These are used to express the proof-of-possession key the
>     client wishes to use, the proof-of-possession key that the
>     Authorization Server has selected, and the key the Resource Server
>     uses to authenticate to the client.
>
>
> The IETF datatracker status page for this draft is:
> https://datatracker.ietf.org/doc/draft-ietf-ace-oauth-params/
>
> There are also htmlized versions available at:
> https://tools.ietf.org/html/draft-ietf-ace-oauth-params-12
> https://datatracker.ietf.org/doc/html/draft-ietf-ace-oauth-params-12
>
> A diff from the previous version is available at:
> https://www.ietf.org/rfcdiff?url2=draft-ietf-ace-oauth-params-12
>
>
> Please note that it may take a couple of minutes from the time of submission
> until the htmlized version and diff are available at tools.ietf.org.
>
> Internet-Drafts are also available by anonymous FTP at:
> ftp://ftp.ietf.org/internet-drafts/
>
> _______________________________________________
> Ace mailing list
> Ace@ietf.org
> https://www.ietf.org/mailman/listinfo/ace
>