Re: [apps-discuss] [websec] [saag] HTTP authentication: the next generation

Ben Laurie <benl@google.com> Mon, 13 December 2010 12:07 UTC

Return-Path: <benl@google.com>
X-Original-To: apps-discuss@core3.amsl.com
Delivered-To: apps-discuss@core3.amsl.com
Received: from localhost (localhost [127.0.0.1]) by core3.amsl.com (Postfix) with ESMTP id C56D23A6E8E for <apps-discuss@core3.amsl.com>; Mon, 13 Dec 2010 04:07:11 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -109.977
X-Spam-Level:
X-Spam-Status: No, score=-109.977 tagged_above=-999 required=5 tests=[BAYES_00=-2.599, FM_FORGED_GMAIL=0.622, RCVD_IN_DNSWL_HI=-8, USER_IN_WHITELIST=-100]
Received: from mail.ietf.org ([64.170.98.32]) by localhost (core3.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id PVFw5N9jl637 for <apps-discuss@core3.amsl.com>; Mon, 13 Dec 2010 04:07:11 -0800 (PST)
Received: from smtp-out.google.com (smtp-out.google.com [74.125.121.35]) by core3.amsl.com (Postfix) with ESMTP id E49673A6E8D for <apps-discuss@ietf.org>; Mon, 13 Dec 2010 04:07:08 -0800 (PST)
Received: from kpbe17.cbf.corp.google.com (kpbe17.cbf.corp.google.com [172.25.105.81]) by smtp-out.google.com with ESMTP id oBDC8jrK017216 for <apps-discuss@ietf.org>; Mon, 13 Dec 2010 04:08:45 -0800
DKIM-Signature: v=1; a=rsa-sha1; c=relaxed/relaxed; d=google.com; s=beta; t=1292242126; bh=IjyN8R0N33aGAIFAsPoKvVzfyyw=; h=MIME-Version:In-Reply-To:References:Date:Message-ID:Subject:From: To:Cc:Content-Type; b=Yb3kzYgDWRmY5mxDWtFvaHfcsHnwpFnk7d/XudI0GYrG1a01QcMwyKKbTQO+DQwjw xZY2rLIyubGVind62c8pw==
Received: from pzk9 (pzk9.prod.google.com [10.243.19.137]) by kpbe17.cbf.corp.google.com with ESMTP id oBDC8hBH010757 for <apps-discuss@ietf.org>; Mon, 13 Dec 2010 04:08:44 -0800
Received: by pzk9 with SMTP id 9so929869pzk.15 for <apps-discuss@ietf.org>; Mon, 13 Dec 2010 04:08:43 -0800 (PST)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=beta; h=domainkey-signature:mime-version:received:received:in-reply-to :references:date:message-id:subject:from:to:cc:content-type; bh=jnk/rIg1eD9tZ2qzrBPET1JpYPZwhSbJgLeKzkK3VjE=; b=xbhr0gmJzm0BSQVE4EXZPxPvzxwDbzk8RYeu/+ztSagtknC/eRAIHNvgO9f4wsz56P CYomMJegFuaBAnXh8Dng==
DomainKey-Signature: a=rsa-sha1; c=nofws; d=google.com; s=beta; h=mime-version:in-reply-to:references:date:message-id:subject:from:to :cc:content-type; b=Rw1xtelJDClcXIznUGgalnYuvnVjjorS/PQoclxpboKmnhAPy2zJmoWpritlHxlap0 Y59t0yFafY3Qv7+O0gBw==
MIME-Version: 1.0
Received: by 10.142.199.20 with SMTP id w20mr3107000wff.419.1292242123701; Mon, 13 Dec 2010 04:08:43 -0800 (PST)
Received: by 10.142.47.14 with HTTP; Mon, 13 Dec 2010 04:08:43 -0800 (PST)
In-Reply-To: <ADDEC353-8DE6-408C-BC75-A50B795E2F6C@checkpoint.com>
References: <4D02AF81.6000907@stpeter.im> <p06240809c928635499e8@10.20.30.150> <ADDEC353-8DE6-408C-BC75-A50B795E2F6C@checkpoint.com>
Date: Mon, 13 Dec 2010 12:08:43 +0000
Message-ID: <AANLkTikwzY7XWz8qKcAkUdvE6OiRmQ1KqsmQngE_F5PV@mail.gmail.com>
From: Ben Laurie <benl@google.com>
To: Yoav Nir <ynir@checkpoint.com>
Content-Type: text/plain; charset="ISO-8859-1"
X-System-Of-Record: true
X-Mailman-Approved-At: Mon, 13 Dec 2010 09:49:55 -0800
Cc: "apps-discuss@ietf.org" <apps-discuss@ietf.org>, "pgut001@cs.auckland.ac.nz" <pgut001@cs.auckland.ac.nz>, websec <websec@ietf.org>, Paul Hoffman <paul.hoffman@vpnc.org>, "kitten@ietf.org" <kitten@ietf.org>, Yaron Sheffer <yaronf.ietf@gmail.com>, "http-auth@ietf.org" <http-auth@ietf.org>, "saag@ietf.org" <saag@ietf.org>, Hannes Tschofenig <Hannes.Tschofenig@gmx.net>, "ietf-http-wg@w3.org Group" <ietf-http-wg@w3.org>
Subject: Re: [apps-discuss] [websec] [saag] HTTP authentication: the next generation
X-BeenThere: apps-discuss@ietf.org
X-Mailman-Version: 2.1.9
Precedence: list
List-Id: General discussion of application-layer protocols <apps-discuss.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/listinfo/apps-discuss>, <mailto:apps-discuss-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/apps-discuss>
List-Post: <mailto:apps-discuss@ietf.org>
List-Help: <mailto:apps-discuss-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/apps-discuss>, <mailto:apps-discuss-request@ietf.org?subject=subscribe>
X-List-Received-Date: Mon, 13 Dec 2010 12:07:11 -0000

On 11 December 2010 23:10, Yoav Nir <ynir@checkpoint.com> wrote:
> TLS client certificates work, but as we've learned both with the web and with IPsec clients, people would much rather not use them. A few IETFs ago (Chicago?), a bunch of us tried to push the idea of TLS with EAP authentication.

I think what we've learnt is that we need to provide good UI and
portability if we want people to use them.