[Acme] Re: WG Last Call: draft-ietf-acme-authority-token-jwtclaimcon-03 (Ends 2026-07-25)

Russ Housley <housley@vigilsec.com> Thu, 23 July 2026 12:53 UTC

Return-Path: <housley@vigilsec.com>
X-Original-To: acme@mail2.ietf.org
Delivered-To: acme@mail2.ietf.org
Received: from localhost (localhost [127.0.0.1]) by mail2.ietf.org (Postfix) with ESMTP id 6F12C11D5F67A; Thu, 23 Jul 2026 05:53:05 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=ietf.org; s=ietf1; t=1784811185; bh=sjf/GvGg0jjEHILTOT4uuCkjuT15fFd/7V4pHJcMj0U=; h=Subject:From:In-Reply-To:Date:Cc:References:To; b=c8pkgi0IcY6/M2/HUdVg9XNpqLr9uFfdXmLWay1klwwWcD/1up/Fd9SxQbNe4YKiB 8LFnN7os573xGOCBHhbZ8HgYpDJZ+UneD1GdqdS2GUiTWShJm1tAr7SaApWU2tLqA+ noUjuFlUy4eEgMWIufBLkmOfo8vya+BSkJjweIrE=
X-Virus-Scanned: amavisd-new at ietf.org
X-Spam-Flag: NO
X-Spam-Score: -2.799
X-Spam-Level:
X-Spam-Status: No, score=-2.799 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, RCVD_IN_DNSWL_LOW=-0.7, RCVD_IN_VALIDITY_CERTIFIED_BLOCKED=0.001, RCVD_IN_VALIDITY_RPBL_BLOCKED=0.001, SPF_PASS=-0.001] autolearn=ham autolearn_force=no
Authentication-Results: mail2.ietf.org (amavisd-new); dkim=pass (2048-bit key) header.d=vigilsec.com
Received: from mail2.ietf.org ([166.84.6.31]) by localhost (mail2.ietf.org [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id 8pjBnpOq59Li; Thu, 23 Jul 2026 05:53:04 -0700 (PDT)
Received: from mail3.g24.pair.com (mail3.g24.pair.com [66.39.134.11]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature ECDSA (P-256) server-digest SHA256) (No client certificate requested) by mail2.ietf.org (Postfix) with ESMTPS id 5824311D5F675; Thu, 23 Jul 2026 05:53:04 -0700 (PDT)
Received: from mail3.g24.pair.com (localhost [127.0.0.1]) by mail3.g24.pair.com (Postfix) with ESMTP id 2F0301A1B82; Thu, 23 Jul 2026 08:53:04 -0400 (EDT)
Received: from smtpclient.apple (rtr-guestwired.meeting.ietf.org [31.133.144.1]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by mail3.g24.pair.com (Postfix) with ESMTPSA id 9EF841A1D49; Thu, 23 Jul 2026 08:53:03 -0400 (EDT)
Content-Type: text/plain; charset="utf-8"
Mime-Version: 1.0 (Mac OS X Mail 16.0 \(3864.600.51.1.1\))
From: Russ Housley <housley@vigilsec.com>
In-Reply-To: <178302982189.934.4382725200510676646@dt-datatracker-57b5d8f849-v5cht>
Date: Thu, 23 Jul 2026 08:52:52 -0400
Content-Transfer-Encoding: quoted-printable
Message-Id: <DA12DDD4-CFBA-4D3B-B7B2-D195A22AA2BA@vigilsec.com>
References: <178302982189.934.4382725200510676646@dt-datatracker-57b5d8f849-v5cht>
To: Mike Ounsworth <mike@ounsworth.ca>
X-Mailer: Apple Mail (2.3864.600.51.1.1)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=vigilsec.com; h=content-type:mime-version:subject:from:in-reply-to:date:cc:content-transfer-encoding:message-id:references:to; s=pair-202402141609; bh=7g0eXcMc7SriJGRUkjCh3DRBR7DgmguUr8/LTkI6XI0=; b=pCsX0A598kU5eiv5rhMCFIw9Y2qqdHYbWQhZN3khV3nTzZy7Yl5IUBYRpc59w1uGaNw22VECbt4L37wL8YfqgKt+Xqig+8UeMSOKahOwXY4EOdKll4nahiyuVgP5OUWceHsOmG1R7x9kPfHdDDkPCQ7BSyHGHp/JOvPMrpCx8w8e++NWcPgo4s/CcAGS6h4QjWiojDsRFZY9brjfQY/xl158xTpYDqmJ8E9jfJXPK4W47IYcuXn8RdScIYttno4Cs1RWF8VJl0NCOVQqiQ04mLYtd1sf4FAzRilyrn+1F8eTvZuz7kSfqxcZQSMlqF80ubAVJCTNhT1nCNwiwjBA9w==
X-Scanned-By: mailmunge 3.09
Message-ID-Hash: ARUDNA52WWRPHV4NGPQ7ILDSSY7XPLPU
X-Message-ID-Hash: ARUDNA52WWRPHV4NGPQ7ILDSSY7XPLPU
X-MailFrom: housley@vigilsec.com
X-Mailman-Rule-Misses: dmarc-mitigation; no-senders; approved; emergency; loop; banned-address; member-moderation; header-match-acme.ietf.org-0; nonmember-moderation; administrivia; implicit-dest; max-recipients; max-size; news-moderation; no-subject; digests; suspicious-header
CC: acme-chairs@ietf.org, IETF ACME <acme@ietf.org>, draft-ietf-acme-authority-token-jwtclaimcon@ietf.org
X-Mailman-Version: 3.3.9rc6
Precedence: list
Subject: [Acme] Re: WG Last Call: draft-ietf-acme-authority-token-jwtclaimcon-03 (Ends 2026-07-25)
List-Id: Automated Certificate Management Environment <acme.ietf.org>
Archived-At: <https://mailarchive.ietf.org/arch/msg/acme/prvQD5WJFLLDrVtbDA1MU0jPLMk>
List-Archive: <https://mailarchive.ietf.org/arch/browse/acme>
List-Help: <mailto:acme-request@ietf.org?subject=help>
List-Owner: <mailto:acme-owner@ietf.org>
List-Post: <mailto:acme@ietf.org>
List-Subscribe: <mailto:acme-join@ietf.org>
List-Unsubscribe: <mailto:acme-leave@ietf.org>

I have read the document, and I support publication, but I think a shortcoming needs to be addressed before it is passed to the IESG.

Section 5.4 says:

> Because this specification involves the JWTClaimConstraints and EnhancedJWTClaimConstraints extensions, the client MAY request an Authority Token with some subset of its own authority as the JWTClaimConstraints provided in the "tkvalue" element of the "atc" JSON object. JWTClaimConstraints can be constructed to define a limited scope of claims and claim values the client has authority over.

This is correct, but I think a few more details are needed.

JWTClaimConstraints specifies claim names that must be included (mustInclude) and it specifies values that are allowed in particular claims (permittedValues). All of the mustInclude need to be in the token.  Each value in the token need to be in the pmittedValues. In this way, the token satisfies the constraints, and a particular certificate can be issued that is a subset of those authorizations.

The structure for EnhancedJWTClaimConstraints is a bit more complex.  It also has claim names that MUST NOT appear (mustExclude). I would expect all of these to be in the token.

Russ

> On Jul 2, 2026, at 6:03 PM, Mike Ounsworth via Datatracker <noreply@ietf.org> wrote:
> 
> This message starts a WG Last Call for:
> draft-ietf-acme-authority-token-jwtclaimcon-03
> 
> This Working Group Last Call ends on 2026-07-25
> 
> Abstract:
>   This document defines an authority token profile for the validation
>   of JWTClaimConstraints and EnhancedJWTClaimConstraints certificate
>   extensions within the Automated Certificate Management Environment
>   (ACME) protocol.  This profile is based on the Authority Token
>   framework and establishes the specific ACME identifier type,
>   challenge mechanism, and token format necessary to authorize a client
>   to request a certificate containing these constraints.
> 
> File can be retrieved from:
> https://www.ietf.org/archive/id/draft-ietf-acme-authority-token-jwtclaimcon-03.txt
> 
> Please review and indicate your support or objection to proceed with the
> publication of this document by replying to this email keeping acme@ietf.org
> in copy. Objections should be explained and suggestions to resolve them are
> highly appreciated.
> 
> Authors, and WG participants in general, are reminded of the Intellectual
> Property Rights (IPR) disclosure obligations described in BCP 79 [1].
> Appropriate IPR disclosures required for full conformance with the provisions
> of BCP 78 [1] and BCP 79 [2] must be filed, if you are aware of any.
> Sanctions available for application to violators of IETF IPR Policy can be
> found at [3].
> 
> Thank you.
> 
> [1] https://datatracker.ietf.org/doc/bcp78/
> [2] https://datatracker.ietf.org/doc/bcp79/
> [3] https://datatracker.ietf.org/doc/rfc6701/
> 
> The IETF datatracker status page for this Internet-Draft is:
> https://datatracker.ietf.org/doc/draft-ietf-acme-authority-token-jwtclaimcon/
> 
> There is also an HTMLized version available at:
> https://datatracker.ietf.org/doc/html/draft-ietf-acme-authority-token-jwtclaimcon-03
> 
> A diff from the previous version is available at:
> https://author-tools.ietf.org/iddiff?url2=draft-ietf-acme-authority-token-jwtclaimcon-03
> 
> _______________________________________________
> Acme mailing list -- acme@ietf.org
> To unsubscribe send an email to acme-leave@ietf.org