Re: [Ace] I-D Action: draft-ietf-ace-revoked-token-notification-06.txt

Marco Tiloca <marco.tiloca@ri.se> Fri, 02 June 2023 13:59 UTC

Return-Path: <marco.tiloca@ri.se>
X-Original-To: ace@ietfa.amsl.com
Delivered-To: ace@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 6C894C14CE38 for <ace@ietfa.amsl.com>; Fri, 2 Jun 2023 06:59:24 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.096
X-Spam-Level:
X-Spam-Status: No, score=-2.096 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, HTML_MESSAGE=0.001, NICE_REPLY_A=-0.001, RCVD_IN_ZEN_BLOCKED_OPENDNS=0.001, SPF_HELO_NONE=0.001, SPF_PASS=-0.001, URIBL_BLOCKED=0.001, URIBL_DBL_BLOCKED_OPENDNS=0.001, URIBL_ZEN_BLOCKED_OPENDNS=0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (1024-bit key) header.d=ri.se
Received: from mail.ietf.org ([50.223.129.194]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id b22RKiR02du5 for <ace@ietfa.amsl.com>; Fri, 2 Jun 2023 06:59:20 -0700 (PDT)
Received: from MM0P280CU005.outbound.protection.outlook.com (mail-swedensouthazlp170110001.outbound.protection.outlook.com [IPv6:2a01:111:f403:c203::1]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id ADED9C14CE33 for <ace@ietf.org>; Fri, 2 Jun 2023 06:59:19 -0700 (PDT)
ARC-Seal: i=1; a=rsa-sha256; s=arcselector9901; d=microsoft.com; cv=none; b=aCRDin6khFpY/nW1fuiQkL4wItLQwBNFPKy/l84CgMVWxyL+5BOYA0/ierhFAmgUqLLx+K1T5+M+Fipn0lV/+BbbCHs33XkGerKRNJTw35o6EtMM664aW6R9+QCzj2KIkiu7i+ecYLwdPv+IlO9euQofanqvIJ7ehsQjrzb5GEed4JAV9lHjYex3FIg7e22CuIrhbKCibuMJQeYu/cdx/tNWw25yEARY1a8eVXnd19a4cUx4zSdzFbRo9kNHKpkQHSJGvp1OK1ALyFtEi90+wqwwg7D8eLptR+bviwJ6HfjKa6Or7E6asbtTqKR1tZqlP7cBBGsz+qRX0OsyTGHpdQ==
ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=microsoft.com; s=arcselector9901; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-AntiSpam-MessageData-ChunkCount:X-MS-Exchange-AntiSpam-MessageData-0:X-MS-Exchange-AntiSpam-MessageData-1; bh=r12C7A2bfW1F/sJIlQhw7oyHRaOTqDYJk6id9igDrLg=; b=nWOzIy7sL2LQ+sqJn/YWcckDkM+ZyG9tGr+4mnHpe2/dDQExwjFwSopHN99taMPeTlL4Kmn/iaDF6/orQVkBVmbhGXebU/sl3AX2XJxVF2fy/lgoXSiazunQDVAEVKKDDmSxmsRxyXnEQAFBpIoIAwbHZJR1/Cxu/GTmzXKBaQ0fhpvoYe39/UFf3zFdW92rZlzE8wE65c8uD91FK9fDapurhJ/fPHYttcsflmiwrntgEWd1GWQfF5uqWQez2a/zdeFZ/0+4l6A2ZiOMZ7b1D1w0NP+7XLZoAVHeb1+0E15mMD7nBWTgekSmzKVGx7EFW8t67SPi/hAbxfsvVoUakQ==
ARC-Authentication-Results: i=1; mx.microsoft.com 1; spf=pass smtp.mailfrom=ri.se; dmarc=pass action=none header.from=ri.se; dkim=pass header.d=ri.se; arc=none
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=ri.se; s=selector1; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-SenderADCheck; bh=r12C7A2bfW1F/sJIlQhw7oyHRaOTqDYJk6id9igDrLg=; b=PR8R6qhDCr/Svh4G2a1H/kFTnvrxf1cRCtamDwwtL3N48/JU18GQS6EF9+H0brsRhCg5bD3eynH/fyvcL2e4Jf+NVCWwcDcV6eobe3k2DrpBnK4GQEUMK6b9Hfeb191vioYSwO5Tio7pme5c8AqrOzVadIBOlE4KedeRuSXZBEk=
Authentication-Results: dkim=none (message not signed) header.d=none;dmarc=none action=none header.from=ri.se;
Received: from GVYP280MB0464.SWEP280.PROD.OUTLOOK.COM (2603:10a6:150:37::17) by MM0P280MB0279.SWEP280.PROD.OUTLOOK.COM (2603:10a6:190:f::14) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.20.6455.26; Fri, 2 Jun 2023 13:59:12 +0000
Received: from GVYP280MB0464.SWEP280.PROD.OUTLOOK.COM ([fe80::c0b1:e5f:ef9b:2dde]) by GVYP280MB0464.SWEP280.PROD.OUTLOOK.COM ([fe80::c0b1:e5f:ef9b:2dde%5]) with mapi id 15.20.6455.026; Fri, 2 Jun 2023 13:59:12 +0000
Message-ID: <6ade8140-fb23-a0d6-508e-e3125801c917@ri.se>
Date: Fri, 02 Jun 2023 15:59:11 +0200
User-Agent: Mozilla/5.0 (X11; Linux x86_64; rv:102.0) Gecko/20100101 Thunderbird/102.11.0
Content-Language: en-US
To: ace@ietf.org
References: <168571378549.16758.9002597789734611185@ietfa.amsl.com>
From: Marco Tiloca <marco.tiloca@ri.se>
In-Reply-To: <168571378549.16758.9002597789734611185@ietfa.amsl.com>
Content-Type: multipart/signed; micalg="pgp-sha256"; protocol="application/pgp-signature"; boundary="------------yW0psGA11cLmEN1Aw8hKFLqN"
X-ClientProxiedBy: GV2PEPF000000FD.SWEP280.PROD.OUTLOOK.COM (2603:10a6:144:1:0:1:0:1a) To GVYP280MB0464.SWEP280.PROD.OUTLOOK.COM (2603:10a6:150:37::17)
MIME-Version: 1.0
X-MS-PublicTrafficType: Email
X-MS-TrafficTypeDiagnostic: GVYP280MB0464:EE_|MM0P280MB0279:EE_
X-MS-Office365-Filtering-Correlation-Id: e094e50d-2793-423f-3331-08db63718b99
X-MS-Exchange-SenderADCheck: 1
X-MS-Exchange-AntiSpam-Relay: 0
X-Microsoft-Antispam: BCL:0;
X-Microsoft-Antispam-Message-Info: s+Qg2pEqwoXbnbsDPgudqqjYenxGEb/FGgFJnMcHomTYXnoeK5KHEVFG4Plx/S6j6VWINuvWc7XhZg4AmwWalWmopJgJ8RClY4PTgxbNqP63DyhWCZh+WkdwoMe7e1SOWXta7oBfdnjHhWjBFH+Kuru6MNoZYN3dE/DlMUtEQMKwn/FmOX//K9QbVslSBvEpzTtblTCGm4lLLe7aA9Xt/ogfpUCuuZZ4XIf56cTWVraUZu1xE1fX3bDNZTBkgJ6Cw6TZ54wVYDkWtPTu2jPbQh5LtB9hossYNqF7KPnQhwlYVNzIiMT/l3VPJz1KbhGD3z3UQzveOA0g20z8W5A2OKJU5Q0cPdkWOkejUdAG/qi+le4S+jGGa2r6j1IWb9FEDnDnlPPJlS65JABvSrPrlneWt3aUkvjktlcH7Yzpk69nKncL1jMje566q6DZWJ6u3g6K0z2HSjJBXWovvJZhgYOZ8ZVptApFakqLZr4BxePdj3fLt1xiZwJgPt6ziA0vyirC32TFsh3EvG+HTJw65dYX+UlrdgGXk/Ez1+XnaOni6Z2sooPdgff4XBbfaoWTVk8pChfiQehACuUxcX7kZzoDASBiPi0ulmUbD9T9hKyBEUmhXq/z+KgZunPiAnXuwID/8KoCWpkAh4rhA53DBQ==
X-Forefront-Antispam-Report: CIP:255.255.255.255; CTRY:; LANG:en; SCL:1; SRV:; IPV:NLI; SFV:NSPM; H:GVYP280MB0464.SWEP280.PROD.OUTLOOK.COM; PTR:; CAT:NONE; SFS:(13230028)(4636009)(376002)(396003)(346002)(366004)(39860400002)(136003)(451199021)(966005)(6486002)(33964004)(478600001)(45080400002)(66574015)(83380400001)(53546011)(186003)(6512007)(6506007)(26005)(2616005)(36756003)(21480400003)(38100700002)(86362001)(31696002)(166002)(66556008)(6916009)(316002)(66946007)(8936002)(8676002)(5660300002)(235185007)(15650500001)(44832011)(31686004)(41300700001)(2906002)(66476007)(43740500002)(45980500001); DIR:OUT; SFP:1101;
X-MS-Exchange-AntiSpam-MessageData-ChunkCount: 1
X-MS-Exchange-AntiSpam-MessageData-0: rMqr3Ml7+U8tVvdSLqTB4OI/iTWkNcTpXREsTLgHhO5AEazU93DCjoTkCnkieoAE2MyH1+SnQfIYWjTnIXlcWMMr75P0JBuT9ySg9SRM36V9sAdoBBOSDGT9xNiRrw3OJ7ZmF47g2a8n9CvNp5b0WkdM1OwHz0ex+eO6q6mwvyMSept+OlT7H2RSRMbEimBQdDs3DehR8DhOsasWcNi5jKQoxVwBZg6SGfUNyDIFXSt9tcLub17eDAj9xmaizjl8P9OSQsBkmu46PHXGcvJezCvISouRFO3mGNSaHsRkJXN26/9SvIZTii/D2AqzklzhZ1LIf8xUbw96aeMtwRTGCOj3G/AJbjnrt058x0CXmHkUTVozMkUJsazmxN9yBTQRcSTKi7j/jLKheyRfoOudNnWbQJ65CgusNSHOE7EDICcYSxpy0RWSSfCYPK1Li34jx82BofCkgDDEurZzivuRZpGY2OnHWp2wMWfxtDy3LRJhpqpDAO9xWpgw7KleHcwX4m9dvXlSBH2CgAHtc1iHZk/r0i5Rkk7cm7g6Xsl1UqnJwWOvI4qaLAlmEK+lMFUB5ZOelp8CRl/u+IQhQmHUz+YSuXQcUAQvk4h4rRhzOSYpIKXCDLNLW81zc+Li9xUU10zCkAgP2w0KCmSGKJxRonBOj/p3WWKp3BjgnVr3fLQsZsmSrxsPWxDgWeHVSo8IT0uIIONEB3QH2lukd02jJ1kKJe08zfPkCuyvNvK5IjL0gwwSaYJl6Q0sl7GypBNXT0FKU2QUXbn3VSpJGf7++kfyA5nfnNW631/dgXuU1R9bGIiOlOJpj37M8TCmvEc6eWMZPePHa4VeoP/xMmghZk7YPivdxT2K830EtsaiEbL14HRbiOUOZhC7zvcKqQYT2ZyG8vkmWl5HdlGMuZWjHuRyxXgZc4kIJGyuuA9pY+6c9sWLGk0dIG3ahZdXsE5Jf2iVJgHhNp+BVE1/mnvu+vGjJC8qns8s3WMkmBfqLfTGAEPEqys9xHAyD+VxIiukeiIWI00/8NpMAy6RhqzJlEtbFb/ZPjHddNf6q9X2KdBatsRIuewRYnVnOYS37Ap6fInWO54gW4vHyWbZGAcBqeWkk9oNEKSgyZyC7nDY4aUpsh/b2+TWYONW6dmaQWmTOfjtK+Z/dO/EAoGXI629eskh06l22wi5nEPV+yEeEhdMIEd51MGzb+y+v4YjP5ws8tj2hTL+imMYC8h7bx4Jv/S3j4A16gYgjE/+i4d8mbK1G7Q7iZiJDsDYd5u/aLoClCg+FLSaNuSa1PoSau0qUQwVnXVg9JujF/whch4PuY3BRuk9Ta7t5Idvp4PFhXxTLhZkkNnu0kZPaCRaFHdU5HhjSrR/iicttPyFqV3fJq7bUHe4PEt5nY3dsVJeyNPG1CsiCQiZ7FqOKQl1GsyAIRLpe/G6OtjlGyeftCSYS70OFP0WEhgDHu5cueHuyaBI+NxeuXQo/W+k7mhhTzDZhggEFRzFOgR0du1pb0i++56ZSNtajZP839DokbwbgpFWtgvFgkQexPSLxUFinE20GxWMBuUsxcc+K4pzzruZXTFiXeFtSlniWvY7KODHGCB/
X-OriginatorOrg: ri.se
X-MS-Exchange-CrossTenant-Network-Message-Id: e094e50d-2793-423f-3331-08db63718b99
X-MS-Exchange-CrossTenant-AuthSource: GVYP280MB0464.SWEP280.PROD.OUTLOOK.COM
X-MS-Exchange-CrossTenant-AuthAs: Internal
X-MS-Exchange-CrossTenant-OriginalArrivalTime: 02 Jun 2023 13:59:12.8662 (UTC)
X-MS-Exchange-CrossTenant-FromEntityHeader: Hosted
X-MS-Exchange-CrossTenant-Id: 5a9809cf-0bcb-413a-838a-09ecc40cc9e8
X-MS-Exchange-CrossTenant-MailboxType: HOSTED
X-MS-Exchange-CrossTenant-UserPrincipalName: o9evnZ8DAYPNU9ifOfIORbAnqRQ2T5oniIWj7Vw35DK1KIwCnIvJ0ZGOZVOEzHjhaBzNNPGy7hN0EDCI6D/AjA==
X-MS-Exchange-Transport-CrossTenantHeadersStamped: MM0P280MB0279
Archived-At: <https://mailarchive.ietf.org/arch/msg/ace/fc7te5c7nQ4FTdtO1AkxUsU_GpI>
Subject: Re: [Ace] I-D Action: draft-ietf-ace-revoked-token-notification-06.txt
X-BeenThere: ace@ietf.org
X-Mailman-Version: 2.1.39
Precedence: list
List-Id: "Authentication and Authorization for Constrained Environments \(ace\)" <ace.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/ace>, <mailto:ace-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/ace/>
List-Post: <mailto:ace@ietf.org>
List-Help: <mailto:ace-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/ace>, <mailto:ace-request@ietf.org?subject=subscribe>
X-List-Received-Date: Fri, 02 Jun 2023 13:59:24 -0000

Hello ACE,

This revision addresses the comments from the Shepherd review [1] - 
thanks Göran! - about avoiding repetitions in the instructions for the 
Expert review in the IANA considerations.

Best,
/Marco

[1] https://mailarchive.ietf.org/arch/msg/ace/mHpTsE-lDvzfMSt0cd-j_B-VknM/

On 2023-06-02 15:49, internet-drafts@ietf.org wrote:
> A New Internet-Draft is available from the on-line Internet-Drafts
> directories. This Internet-Draft is a work item of the Authentication and
> Authorization for Constrained Environments (ACE) WG of the IETF.
>
>     Title           : Notification of Revoked Access Tokens in the Authentication and Authorization for Constrained Environments (ACE) Framework
>     Authors         : Marco Tiloca
>                       Francesca Palombini
>                       Sebastian Echeverria
>                       Grace Lewis
>     Filename        : draft-ietf-ace-revoked-token-notification-06.txt
>     Pages           : 59
>     Date            : 2023-06-02
>
> Abstract:
>     This document specifies a method of the Authentication and
>     Authorization for Constrained Environments (ACE) framework, which
>     allows an Authorization Server to notify Clients and Resource Servers
>     (i.e., registered devices) about revoked access tokens.  As specified
>     in this document, the method allows Clients and Resource Servers to
>     access a Token Revocation List on the Authorization Server by using
>     the Constrained Application Protocol (CoAP), with the possible
>     additional use of resource observation.  Resulting (unsolicited)
>     notifications of revoked access tokens complement alternative
>     approaches such as token introspection, while not requiring
>     additional endpoints on Clients and Resource Servers.
>
> The IETF datatracker status page for this Internet-Draft is:
> https://eur05.safelinks.protection.outlook.com/?url=https%3A%2F%2Fdatatracker.ietf.org%2Fdoc%2Fdraft-ietf-ace-revoked-token-notification%2F&data=05%7C01%7Cmarco.tiloca%40ri.se%7C95ea6b8b42ac43855c8908db6370555c%7C5a9809cf0bcb413a838a09ecc40cc9e8%7C0%7C0%7C638213106358422106%7CUnknown%7CTWFpbGZsb3d8eyJWIjoiMC4wLjAwMDAiLCJQIjoiV2luMzIiLCJBTiI6Ik1haWwiLCJXVCI6Mn0%3D%7C3000%7C%7C%7C&sdata=65fT4PBJh6n1lXP3Yc2%2FRMQGs3c2js7bRt4v8NHn31E%3D&reserved=0
>
> There is also an HTML version available at:
> https://eur05.safelinks.protection.outlook.com/?url=https%3A%2F%2Fwww.ietf.org%2Farchive%2Fid%2Fdraft-ietf-ace-revoked-token-notification-06.html&data=05%7C01%7Cmarco.tiloca%40ri.se%7C95ea6b8b42ac43855c8908db6370555c%7C5a9809cf0bcb413a838a09ecc40cc9e8%7C0%7C0%7C638213106358578341%7CUnknown%7CTWFpbGZsb3d8eyJWIjoiMC4wLjAwMDAiLCJQIjoiV2luMzIiLCJBTiI6Ik1haWwiLCJXVCI6Mn0%3D%7C3000%7C%7C%7C&sdata=s54dqeAzCX%2F%2B%2FQ%2BhglRsi6ZgxEh0B%2BNNcvfRuo98Iw4%3D&reserved=0
>
> A diff from the previous version is available at:
> https://eur05.safelinks.protection.outlook.com/?url=https%3A%2F%2Fauthor-tools.ietf.org%2Fiddiff%3Furl2%3Ddraft-ietf-ace-revoked-token-notification-06&data=05%7C01%7Cmarco.tiloca%40ri.se%7C95ea6b8b42ac43855c8908db6370555c%7C5a9809cf0bcb413a838a09ecc40cc9e8%7C0%7C0%7C638213106358578341%7CUnknown%7CTWFpbGZsb3d8eyJWIjoiMC4wLjAwMDAiLCJQIjoiV2luMzIiLCJBTiI6Ik1haWwiLCJXVCI6Mn0%3D%7C3000%7C%7C%7C&sdata=RdEg95mShkqw3iRYr1y1CacOvrOW7rCA1c1MEDJygAo%3D&reserved=0
>
> Internet-Drafts are also available by rsync at rsync.ietf.org::internet-drafts
>
>
> _______________________________________________
> Ace mailing list
> Ace@ietf.org
> https://eur05.safelinks.protection.outlook.com/?url=https%3A%2F%2Fwww.ietf.org%2Fmailman%2Flistinfo%2Face&data=05%7C01%7Cmarco.tiloca%40ri.se%7C95ea6b8b42ac43855c8908db6370555c%7C5a9809cf0bcb413a838a09ecc40cc9e8%7C0%7C0%7C638213106358578341%7CUnknown%7CTWFpbGZsb3d8eyJWIjoiMC4wLjAwMDAiLCJQIjoiV2luMzIiLCJBTiI6Ik1haWwiLCJXVCI6Mn0%3D%7C3000%7C%7C%7C&sdata=tjL6Crith90apAI6sEYRaNvbipo14yNrGnEMj0Eapgo%3D&reserved=0

-- 
Marco Tiloca
Ph.D., Senior Researcher

Phone: +46 (0)70 60 46 501

RISE Research Institutes of Sweden AB
Box 1263
164 29 Kista (Sweden)

Division: Digital Systems
Department: Computer Science
Unit: Cybersecurity

https://www.ri.se