Re: [Ace] Genart telechat review of draft-ietf-ace-cbor-web-token-12

Benjamin Kaduk <kaduk@mit.edu> Tue, 27 February 2018 03:40 UTC

Return-Path: <kaduk@mit.edu>
X-Original-To: ace@ietfa.amsl.com
Delivered-To: ace@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 0F2F112E056; Mon, 26 Feb 2018 19:40:23 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -4.21
X-Spam-Level:
X-Spam-Status: No, score=-4.21 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, RCVD_IN_DNSWL_MED=-2.3, SPF_PASS=-0.001, T_RP_MATCHES_RCVD=-0.01, URIBL_BLOCKED=0.001] autolearn=ham autolearn_force=no
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id U0OWTX2CHFgz; Mon, 26 Feb 2018 19:40:21 -0800 (PST)
Received: from dmz-mailsec-scanner-4.mit.edu (dmz-mailsec-scanner-4.mit.edu [18.9.25.15]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 0900812DDD0; Mon, 26 Feb 2018 19:40:20 -0800 (PST)
X-AuditID: 1209190f-1ddff7000000046a-1f-5a94d322ba0e
Received: from mailhub-auth-4.mit.edu ( [18.7.62.39]) (using TLS with cipher DHE-RSA-AES256-SHA (256/256 bits)) (Client did not present a certificate) by dmz-mailsec-scanner-4.mit.edu (Symantec Messaging Gateway) with SMTP id 28.FE.01130.323D49A5; Mon, 26 Feb 2018 22:40:19 -0500 (EST)
Received: from outgoing.mit.edu (OUTGOING-AUTH-1.MIT.EDU [18.9.28.11]) by mailhub-auth-4.mit.edu (8.13.8/8.9.2) with ESMTP id w1R3eExx014094; Mon, 26 Feb 2018 22:40:15 -0500
Received: from kduck.kaduk.org (24-107-191-124.dhcp.stls.mo.charter.com [24.107.191.124]) (authenticated bits=56) (User authenticated as kaduk@ATHENA.MIT.EDU) by outgoing.mit.edu (8.13.8/8.12.4) with ESMTP id w1R3e91N005123 (version=TLSv1/SSLv3 cipher=DHE-RSA-AES256-SHA bits=256 verify=NOT); Mon, 26 Feb 2018 22:40:12 -0500
Date: Mon, 26 Feb 2018 21:40:09 -0600
From: Benjamin Kaduk <kaduk@mit.edu>
To: Dan Romascanu <dromasca@gmail.com>
Cc: Jim Schaad <ietf@augustcellars.com>, gen-art <gen-art@ietf.org>, draft-ietf-ace-cbor-web-token.all@ietf.org, ietf <ietf@ietf.org>, ace@ietf.org
Message-ID: <20180227034009.GT50954@kduck.kaduk.org>
References: <151967178760.21771.14005895812023525211@ietfa.amsl.com> <021201d3af3e$1f204cc0$5d60e640$@augustcellars.com> <CAFgnS4USoaMrDSbvOZj4Pwg3DprMNNxrHoPn+DK-YjVNB-Jrog@mail.gmail.com>
MIME-Version: 1.0
Content-Type: text/plain; charset="us-ascii"
Content-Disposition: inline
In-Reply-To: <CAFgnS4USoaMrDSbvOZj4Pwg3DprMNNxrHoPn+DK-YjVNB-Jrog@mail.gmail.com>
User-Agent: Mutt/1.9.1 (2017-09-22)
X-Brightmail-Tracker: H4sIAAAAAAAAA+NgFprAKsWRmVeSWpSXmKPExsUixG6nrqt8eUqUweN71hbfv/UwW2zd/ZjV ovGxlsXVV59ZLFZP/85m8WzjfBYHNo+Nc6azeeycdZfdY8mSn0wBzFFcNimpOZllqUX6dglc GbN6r7IVzBCrmNZ8mrmBcYFgFyMnh4SAicTuE++Yuhi5OIQEFjNJzN60DMrZyChxa/JmVgjn KpPE3OUrWUBaWARUJe7sfsIGYrMJqEg0dF9mBrFFBNQktj1+DdbNLLCUUWLu3m1gCWEBX4mW Jf2sIDYv0L7jNxtZIKYeZJTYdQxkH0hCUOLkzCdgG5gFtCRu/HsJFOcAsqUllv/jADE5BQIl GvdIgFSICihL7O07xD6BUWAWkuZZSJpnITQvYGRexSibklulm5uYmVOcmqxbnJyYl5dapGui l5tZopeaUrqJERTYnJL8OxjnNHgfYhTgYFTi4Z0hNyVKiDWxrLgy9xCjJAeTkigv+xqgEF9S fkplRmJxRnxRaU5q8SFGCQ5mJRHelYsnRwnxpiRWVqUW5cOkpDlYlMR53U20o4QE0hNLUrNT UwtSi2CyMhwcShK8OpeAhgoWpaanVqRl5pQgpJk4OEGG8wANZwSp4S0uSMwtzkyHyJ9i1OW4 8eJ1G7MQS15+XqqUOK8SSJEASFFGaR7cHFBCksjeX/OKURzoLWFeZ5AqHmAyg5v0CmgJE9AS 9/8TQJaUJCKkpBoYHdKcTHfHL62dvvpal9YUXrszOav6SmbN3Fd34smU/WfKjwn4b7T6t/TK +66fn/x+mnnde1oz73ted+E0k1Ilwb0TX3h7OQremZFx+P2Dh7lHJMIPWZ53TzuZt1ozR922 ccrx3SY3prG7Trqm+k5627qIh0YF2wVcFc6v3n2zrXHrXe8sS8+WhUosxRmJhlrMRcWJAFq0 R4ojAwAA
Archived-At: <https://mailarchive.ietf.org/arch/msg/ace/YcEvArqJVjCAxOp9EG02O_2CbJs>
Subject: Re: [Ace] Genart telechat review of draft-ietf-ace-cbor-web-token-12
X-BeenThere: ace@ietf.org
X-Mailman-Version: 2.1.22
Precedence: list
List-Id: "Authentication and Authorization for Constrained Environments \(ace\)" <ace.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/ace>, <mailto:ace-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/ace/>
List-Post: <mailto:ace@ietf.org>
List-Help: <mailto:ace-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/ace>, <mailto:ace-request@ietf.org?subject=subscribe>
X-List-Received-Date: Tue, 27 Feb 2018 03:40:23 -0000

On Mon, Feb 26, 2018 at 11:19:04PM +0200, Dan Romascanu wrote:
> Hi Jim,
> 
> Thank you for your answer and for addressing my comments.
> 
> On item #2:
> 
> 
> 
> On Mon, Feb 26, 2018 at 10:12 PM, Jim Schaad <ietf@augustcellars.com> wrote:
> 
> >
> >
> > > -----Original Message-----
> > > From: Dan Romascanu [mailto:dromasca@gmail.com]
> > >
> >
> > ...
> 
> > >
> > > 2. I am a little confused by the definition of policies in Section 9.1:
> > >
> > >    Depending upon the values being requested, registration requests are
> > >    evaluated on a Standards Track Required, Specification Required,
> > >    Expert Review, or Private Use basis [RFC8126] after a three-week
> > >    review period on the cwt-reg-review@ietf.org mailing list, on the
> > >    advice of one or more Designated Experts.
> > >
> > > How does this work? The request is forwarded to the designated expert,
> > > he/she make a recommendation concerning the policy on the mail list, and
> > > depending on the feedback received a policy is selected? Who establishes
> > > consensus?
> > >
> > > Frankly, I wonder if this can work at all. Are there other examples of
> > four
> > > different policies for the same registry, applied on a case-to-case
> > basis?
> >
> > This is the same approach that is being used for the COSE registries.  As
> > an example, you can look at https://www.iana.org/
> > assignments/cose/cose.xhtml#algorithms.
> >
> > Part of the issue about this is that the JOSE/JWT registries do have the
> > same different policies, but that differences are hidden from the IANA
> > registry.  Since they allow for a URI to be used as the identifier of a
> > field, only the plain text versions are registered.  Thus I can use "
> > http://augustcellars.com/JWT/My_Tag" as an identifier.  Since for CBOR
> > the set of tag values is closed and does not have this escape (nor would
> > one want the length of the tag) it is necessary to have this break down of
> > tag fields.
> >
> >
> >
> >
> This does not seem to be exactly the same approach. The COSE RFC 8152
> defines the registry policy in a different manner. There is only one policy
> that is proposed 'Expert Review' and than the Expert Review Instructions
> are used to define the cases when a Standards Track specification is
> required. No such text exists in the current I-D. There is no separation of
> the values space in the registry according to the type of assignment here,
> as  in RFC 8152.

The template in section 9.1.1 has the different policies for the
different integer ranges, under the 'Claim Key' section.  Kathleen
(IIRC) already noted that this should probably be repeated in the
introductory part of section 9.1 as well, and that will be done
before the document is sent to the IESG.

-Benjamin