Re: [Ace] [COSE] Call for adoption for draft-wahlstroem-ace-cbor-web-token-00

Erik Wahlström <erik@wahlstromstekniska.se> Tue, 10 May 2016 08:43 UTC

Return-Path: <erik@wahlstromstekniska.se>
X-Original-To: ace@ietfa.amsl.com
Delivered-To: ace@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 8BBE012D1E0 for <ace@ietfa.amsl.com>; Tue, 10 May 2016 01:43:56 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.599
X-Spam-Level:
X-Spam-Status: No, score=-2.599 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, HTML_MESSAGE=0.001, RCVD_IN_DNSWL_LOW=-0.7] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (2048-bit key) header.d=wahlstromstekniska-se.20150623.gappssmtp.com
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id ygz4J-5eBt7V for <ace@ietfa.amsl.com>; Tue, 10 May 2016 01:43:54 -0700 (PDT)
Received: from mail-lf0-x22a.google.com (mail-lf0-x22a.google.com [IPv6:2a00:1450:4010:c07::22a]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 44BEC12D0C6 for <ace@ietf.org>; Tue, 10 May 2016 01:43:52 -0700 (PDT)
Received: by mail-lf0-x22a.google.com with SMTP id j8so6727908lfd.2 for <ace@ietf.org>; Tue, 10 May 2016 01:43:51 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=wahlstromstekniska-se.20150623.gappssmtp.com; s=20150623; h=mime-version:in-reply-to:references:date:message-id:subject:from:to :cc; bh=tSby/1R0Lu9eXQstX/YJ8XL0DFyOGbnRpVwShspzJqQ=; b=bPn/lEO5kS4Z++5m6QFNKEByjjHK3+PrBS3KwJF4F9RCPcxHGXrC7qiP4WyqvWN+xf Azla7jnU189E87xVsV8HZLfktl+MgPT7OlFha5k3HVGmlYbJpM3m08zgJqWtXxIfTDgj UZJxCGyCOstbRyQUM64xvs9o873H3c9e1vjacV185/20phKH8Psy7xljbdxGx0YBnO8X ePh/uSubc0Yxqmy75jQZY1XSEZMpElGQIRQovERTXvDWrrKU4SmK/LSx4JXabbjudqho 6BdE4vK2SCyQZKMcIRnL75XUXlvoF5R/EmeGbd1Wf0Y8LXqolvt5cCVUuTN1wh8W1HGL qmVw==
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20130820; h=x-gm-message-state:mime-version:in-reply-to:references:date :message-id:subject:from:to:cc; bh=tSby/1R0Lu9eXQstX/YJ8XL0DFyOGbnRpVwShspzJqQ=; b=gn/pL4v2KlHmnDqecfJD3m0DAykOyi9q2HRo9VzfjaSevsj7HepKwueFg5k30O1eMj 3Qm7ZmL9z56Ku3eJOVhmAdgJ1HG0iyJSeJEn4/VY6Z1u+T0+rwLbdmm+JiIyyZIXL71T dUFS0rXCCrb4wkk5jEntQuhWSXOI8nxZqb7ewakefp3iPpUgmHBRMXPUWPnuJytA33jn JIo7r4JTNvD1D1FnHwZA1a0TsoNKi59bB8ODcymjI6KyFLxci3+8ecfHoHOdeyetiT5M 3k+s9p2u1aUaHP5BUel8fSeV3DsZ3paWMeboIYfIdV+o4xmWmbGjKVzUpAIX/4tODRE/ Ey+A==
X-Gm-Message-State: AOPr4FWJULkd6HVTGryh0gad/1etojDU0iTHD8lSYmQMTvOfSCtFpjkF1ROcw8+jzCFz62NmmMEIReeq76cNXg==
MIME-Version: 1.0
X-Received: by 10.25.22.19 with SMTP id m19mr17054764lfi.118.1462869830177; Tue, 10 May 2016 01:43:50 -0700 (PDT)
Received: by 10.25.136.5 with HTTP; Tue, 10 May 2016 01:43:50 -0700 (PDT)
X-Originating-IP: [37.247.26.197]
In-Reply-To: <89B6F196-D08F-4FBD-9F0D-5B250284048F@mit.edu>
References: <D356A330.34F31%kepeng.lkp@alibaba-inc.com> <57309F46.9040705@tzi.org> <89B6F196-D08F-4FBD-9F0D-5B250284048F@mit.edu>
Date: Tue, 10 May 2016 10:43:50 +0200
Message-ID: <CA+KYQAuF-AzXEBQFo0-2VoCSBnCAPTAvHRwwngDUQcFgk0Q4SQ@mail.gmail.com>
From: Erik Wahlström <erik@wahlstromstekniska.se>
To: Justin Richer <jricher@mit.edu>
Content-Type: multipart/alternative; boundary="001a11406a9c94ae0a053278ec62"
Archived-At: <http://mailarchive.ietf.org/arch/msg/ace/ZR-F33uDuXXJLtPw-SlkOneBAOw>
Cc: Kathleen Moriarty <kathleen.moriarty.ietf@gmail.com>, Kepeng Li <kepeng.lkp@alibaba-inc.com>, "ace@ietf.org" <ace@ietf.org>, Carsten Bormann <cabo@tzi.org>, Hannes Tschofenig <hannes.tschofenig@gmx.net>, "<oauth@ietf.org>" <oauth@ietf.org>, cose <cose@ietf.org>
Subject: Re: [Ace] [COSE] Call for adoption for draft-wahlstroem-ace-cbor-web-token-00
X-BeenThere: ace@ietf.org
X-Mailman-Version: 2.1.17
Precedence: list
List-Id: "Authentication and Authorization for Constrained Environments \(ace\)" <ace.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/ace>, <mailto:ace-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/ace/>
List-Post: <mailto:ace@ietf.org>
List-Help: <mailto:ace-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/ace>, <mailto:ace-request@ietf.org?subject=subscribe>
X-List-Received-Date: Tue, 10 May 2016 08:43:56 -0000

Or keep the CBOR Web Token (CWT) for two major reasons:
- To show the very close relationship to JWT. It relies heavily on JWT and
it's iana registry. It is essentially a JWT but in CBOR/COSE instead of
JSON/JOSE.
- I would not say that JWT is the only format that works for the web, and
it's even used in other, non-traditional, web protocols. That means I don't
have a problem with the W in CWT at all. Why would JSON be the only web
protocol?

Then we also have one smaller (a lot smaller) reason, it's the fact that it
can be called "cot" just like JWT is called a "jot" and I figured that our
"cozy chairs" would very much like that fact because then it's essentially
a "cozy cot" :)

/ Erik


On Tue, May 10, 2016 at 2:49 AM, Justin Richer <jricher@mit.edu> wrote:

> We can also call it the “COSE Token”. As a chair of the COSE working
> group, I’m fine with that amount of co-branding.
>
>  — Justin
>
> > On May 9, 2016, at 9:31 AM, Carsten Bormann <cabo@tzi.org> wrote:
> >
> >> draft-ietf-ace-cbor-token-00.txt;
> >
> > For the record, I do not think that ACE has a claim on the term "CBOR
> > Token".  While the term token is not used in RFC 7049, there are many
> > tokens that could be expressed in CBOR or be used in applying CBOR to a
> > problem.
> >
> > ACE CBOR Token is fine, though.
> > (Or, better, CBOR ACE Token, CAT.)
> >
> > Grüße, Carsten
> >
> > _______________________________________________
> > COSE mailing list
> > COSE@ietf.org
> > https://www.ietf.org/mailman/listinfo/cose
>
> _______________________________________________
> Ace mailing list
> Ace@ietf.org
> https://www.ietf.org/mailman/listinfo/ace
>