Re: [Ace] Review Comments on -03

Jim Schaad <ietf@augustcellars.com> Mon, 16 July 2018 12:26 UTC

Return-Path: <ietf@augustcellars.com>
X-Original-To: ace@ietfa.amsl.com
Delivered-To: ace@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 8E8CE13103F; Mon, 16 Jul 2018 05:26:38 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.9
X-Spam-Level:
X-Spam-Status: No, score=-1.9 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, RCVD_IN_DNSWL_NONE=-0.0001, SPF_PASS=-0.001, URIBL_BLOCKED=0.001] autolearn=ham autolearn_force=no
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id hZecIqWtmMV4; Mon, 16 Jul 2018 05:26:33 -0700 (PDT)
Received: from mail2.augustcellars.com (augustcellars.com [50.45.239.150]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 5FB96131053; Mon, 16 Jul 2018 05:26:33 -0700 (PDT)
Received: from Jude (31.133.140.188) by mail2.augustcellars.com (192.168.0.56) with Microsoft SMTP Server (TLS) id 15.0.1347.2; Mon, 16 Jul 2018 05:22:38 -0700
From: Jim Schaad <ietf@augustcellars.com>
To: 'Carsten Bormann' <cabo@tzi.org>
CC: draft-ietf-ace-dtls-authorize@ietf.org, 'ace' <ace@ietf.org>
References: <00dc01d41c9e$af8ad9b0$0ea08d10$@augustcellars.com> <36CFDA3E-528E-4921-A433-850A99283FA2@tzi.org>
In-Reply-To: <36CFDA3E-528E-4921-A433-850A99283FA2@tzi.org>
Date: Mon, 16 Jul 2018 08:26:04 -0400
Message-ID: <011301d41d00$2bdc9970$8395cc50$@augustcellars.com>
MIME-Version: 1.0
Content-Type: text/plain; charset="utf-8"
Content-Transfer-Encoding: quoted-printable
X-Mailer: Microsoft Outlook 16.0
Content-Language: en-us
Thread-Index: AQISnfGbyY4/fVbcu1WJoEsmubpuZwFA2NvQpAq8vEA=
X-Originating-IP: [31.133.140.188]
Archived-At: <https://mailarchive.ietf.org/arch/msg/ace/Z54yP7vfVetqbGsWuR-NFVjeesA>
Subject: Re: [Ace] Review Comments on -03
X-BeenThere: ace@ietf.org
X-Mailman-Version: 2.1.27
Precedence: list
List-Id: "Authentication and Authorization for Constrained Environments \(ace\)" <ace.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/ace>, <mailto:ace-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/ace/>
List-Post: <mailto:ace@ietf.org>
List-Help: <mailto:ace-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/ace>, <mailto:ace-request@ietf.org?subject=subscribe>
X-List-Received-Date: Mon, 16 Jul 2018 12:26:39 -0000

In the event of an unauthorized, the RS has the ability to return a URL to the AS it knows about.  If it returns coaps://AS/token, then this might be thought of implying that one needs to use dtls to talk to the AS rather than using OSCORE.  The same might be true if you just returned coap://AS/token.  Once upon a time, I thought there was some work being done in the core group that would help clean this up.  It has not finished, nor have I seen much about it recently.

Jim
 

> -----Original Message-----
> From: Carsten Bormann <cabo@tzi.org>
> Sent: Monday, July 16, 2018 7:14 AM
> To: Jim Schaad <ietf@augustcellars.com>
> Cc: draft-ietf-ace-dtls-authorize@ietf.org; ace <ace@ietf.org>
> Subject: Re: Review Comments on -03
> 
> Hi Jim,
> 
> > On Jul 15, 2018, at 20:48, Jim Schaad <ietf@augustcellars.com> wrote:
> >
> > * It is too bad that we don't have the generic coap schemas defined
> > yet so that we can use that as part of the URL returned with an access
> > denied response.
> 
> Can you expand on that?  What should we have defined?
> 
> Grüße, Carsten