Return-Path: <michael_b_jones@hotmail.com>
X-Original-To: art@ietfa.amsl.com
Delivered-To: art@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1])
	by ietfa.amsl.com (Postfix) with ESMTP id 63442C14F5F8
	for <art@ietfa.amsl.com>; Fri, 13 Sep 2024 17:22:02 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -6.234
X-Spam-Level: 
X-Spam-Status: No, score=-6.234 tagged_above=-999 required=5
	tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1,
	DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, FORGED_HOTMAIL_RCVD2=0.874,
	FREEMAIL_FROM=0.001, RCVD_IN_DNSWL_HI=-5, RCVD_IN_MSPIKE_H2=-0.001,
	RCVD_IN_ZEN_BLOCKED_OPENDNS=0.001, SPF_PASS=-0.001,
	T_SCC_BODY_TEXT_LINE=-0.01, URIBL_DBL_BLOCKED_OPENDNS=0.001,
	URIBL_ZEN_BLOCKED_OPENDNS=0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (2048-bit key)
	header.d=hotmail.com
Received: from mail.ietf.org ([50.223.129.194])
	by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024)
	with ESMTP id 2Hb871DVsQ_C for <art@ietfa.amsl.com>;
	Fri, 13 Sep 2024 17:21:58 -0700 (PDT)
Received: from NAM02-SN1-obe.outbound.protection.outlook.com
 (mail-sn1nam02olkn2079.outbound.protection.outlook.com [40.92.44.79])
	(using TLSv1.2 with cipher ECDHE-ECDSA-AES256-GCM-SHA384 (256/256 bits))
	(No client certificate requested)
	by ietfa.amsl.com (Postfix) with ESMTPS id A247AC14F5E3
	for <art@ietf.org>; Fri, 13 Sep 2024 17:21:58 -0700 (PDT)
ARC-Seal: i=1; a=rsa-sha256; s=arcselector10001; d=microsoft.com; cv=none;
 b=msoPoGjFO2L+7d1OogesaF8fCNFSi5oijpE6PaWgK8sjvmDFlWXawLbXhUYW1U1+obpQRJFHmEVhIYLFjUvEsJiccQT3un/MXSasX7jK5qMFoPWRDDMhEsh/RLsPAmcQYPklu/w0dYww3fogpHCGq0M6WUOontxkwJgPtpVI4AqkuzVq0x2hWvvy4idDMRh75qvCr8DP9T8oT2JTyiQ1XPk4LxFnZveiRRoJz4djr1sbNH+0tDYyg9IC8VrNrOt4knfXMRMUivw5bL11y4QEz1TJfhcOJ+PqP+8vBfEfMMVaLG9EsJ+5yZwRwAnLdZl/HY88EFD5YrGQB2RH6ix0Ng==
ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=microsoft.com;
 s=arcselector10001;
 h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-AntiSpam-MessageData-ChunkCount:X-MS-Exchange-AntiSpam-MessageData-0:X-MS-Exchange-AntiSpam-MessageData-1;
 bh=6zJ8NUMxfuIMed/vI2iR1Gi4i4cZzX1J3d6UJeqJaeA=;
 b=LAH07wSypOvYJxS9A69qUhMehnbTE85FrkC2DibU4Eact6UNgcKwRiWx/L4Na2zxtOSkQbkagG116Z0owZEzAyE5U2f8wzhKh9xwWhUkL8+sZAXGXHcTEnWWVBkxPuT4iW3k3AcOiXxcldPjk0zjgVJ4G+heO1R2J/teOpM/HKACAtzLNzrGMUVXWa4tSWyWAM5yvoyPSTT/NKltBc5IVbkaqpRmTPZbs/6rySmguwtkr+KqhH1t1unJFwcN9jLMdVUOOF5Ss3AQAntLcWwj3yUkk0ZhqGAdPC0h1V8alGkMGdlQmcSu9x65svEoPEzriqaKdUjJluhuBlirl0kbbw==
ARC-Authentication-Results: i=1; mx.microsoft.com 1; spf=none; dmarc=none;
 dkim=none; arc=none
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=hotmail.com;
 s=selector1;
 h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-SenderADCheck;
 bh=6zJ8NUMxfuIMed/vI2iR1Gi4i4cZzX1J3d6UJeqJaeA=;
 b=hLwl5R/mQiy6rX/+cqYlcpMndPD3Lj/b0nWqS+IXdKMpU2YpfhE8iqkfK35RzieB+GGGzHi2mesmSRY4pvi1aRxcbOealo8RAN1qGhmxCKeY6Xh8jq4Z5CutIQlEaDNBewR17nJ1AJOWRUcOpBj0v9c7w413Qp7DArubRBS+J6ap1dkCVHUfWPiRcA79WnjLEW7aunQvJntGW/qrsS4ZrkgMmPbnUh2TRMo10yOKGx1Ms4t5L+8n7hYqDafjnnS6lwhyR6PqqxjWQx0/RrrMsmJh4q2ahEFppccTN6ST5hamXghNymLy94utZs+sITVAxU9YWLyW4XVTgjLLZWX2UQ==
Received: from SJ0PR02MB7439.namprd02.prod.outlook.com (2603:10b6:a03:295::14)
 by PH0PR02MB7143.namprd02.prod.outlook.com (2603:10b6:510:1f::19) with
 Microsoft SMTP Server (version=TLS1_2,
 cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.20.7962.21; Sat, 14 Sep
 2024 00:21:56 +0000
Received: from SJ0PR02MB7439.namprd02.prod.outlook.com
 ([fe80::6394:e79c:c32a:4c6a]) by SJ0PR02MB7439.namprd02.prod.outlook.com
 ([fe80::6394:e79c:c32a:4c6a%3]) with mapi id 15.20.7962.018; Sat, 14 Sep 2024
 00:21:56 +0000
From: Michael Jones <michael_b_jones@hotmail.com>
To: Arnt Gulbrandsen <arnt@gulbrandsen.priv.no>, "art@ietf.org" <art@ietf.org>
Thread-Topic: [art] Re: art-art review of draft-ietf-oauth-resource-metadata
Thread-Index: AQHbBJ8/n9aQYfIEGEu79N5NltBrbrJWbrKw
Date: Sat, 14 Sep 2024 00:21:54 +0000
Message-ID: 
 <SJ0PR02MB7439411319EB0FEA7B44F805B7662@SJ0PR02MB7439.namprd02.prod.outlook.com>
References: 
 <172357514156.942063.8970388467871714335@dt-datatracker-6df4c9dcf5-t2x2k>
 <379cb52e-816b-4377-bfac-5ce5e6c9cd1c@gulbrandsen.priv.no>
 <SJ0PR02MB74394171BE56CD006648180DB79B2@SJ0PR02MB7439.namprd02.prod.outlook.com>
 <SJ0PR02MB74395C133891142856B00149B79B2@SJ0PR02MB7439.namprd02.prod.outlook.com>
In-Reply-To: 
 <SJ0PR02MB74395C133891142856B00149B79B2@SJ0PR02MB7439.namprd02.prod.outlook.com>
Accept-Language: en-US
Content-Language: en-US
X-MS-Has-Attach: 
X-MS-TNEF-Correlator: 
x-ms-publictraffictype: Email
x-ms-traffictypediagnostic: SJ0PR02MB7439:EE_|PH0PR02MB7143:EE_
x-ms-office365-filtering-correlation-id: 44bcd809-105f-499f-1bda-08dcd4533ceb
x-microsoft-antispam: 
 BCL:0;ARA:14566002|15080799006|461199028|8060799006|19110799003|7092599003|4302099013|440099028|102099032|3412199025|56899033|1602099012;
x-microsoft-antispam-message-info: 
 79el3/YLlBaYYuEuv0UXDFF+CvJkukyqlADVQaz0BrvGfI0PsjhMeuRXOPNiOg5mjZ1YYv2RWeHd0wrNwWzck3U/Zv5xjMWPaOJr57enTm0J7/bbG3U5l3pCbrtenrUlrFuWM6YJknbzdU5kQolX/weyZV1vjJXYU/MoSb20QWtZ9Jzup172R4x1kKpsk0qFyv0i1ncf5IPM6wTvCiSzPsEufPdcxCS+uR9kKFl6h/NaGza76DXSanAtaB0p658n2rhQvSCFzA9EXKDAlzGyzyRSh25g4zjiz/XjhQeMXIPd3YdMwGYYnXPutrKvX4EvniD1ciHj5Q0L+onMWHD+B9FK2muP7f08dcaEa02x+JFZuAqTtSAioQgyLQQblFHkUYXoTb4P835IfNRhSeBAu4ByhaaWt0/hsmB8PIY7Vddegg/QcBoysRrC8sdIV+6OmyByWdi6gjf7WBPIV3N+thJQZTK9Xj90E0xrmVRm3Stq+CpHnpWd6eiVMg1p+rbG/jPWvEjtQVRbG5X8vPv7I1VDBidijm/fT2z4FbFhzDgEWYu4fNHS4HMVo+JreX91wWeFsyHQYchahrVNA128nD/mvv9UcQcu8mD0fawOBCutgZvzEIfarUS5vYEMzTfqAeJPtU0O299qjIvkoyKUalvHxBSa9A8tY027ORoqzHV4ohOP/rbGnr7eU43oaihDPWcunUIBG3OquiBm7ZqbEX9wdlQxD7wLDpkAX3zbxYnEMNmyE5tvQOynJ89lQ6wD9Vzvc+ZcyqH7oSP9JnR2YAt3ZK3bG4MQ3NxyhH3sdn21qt0ZgXR0q2OdcAlEuvMmm7WtXLzLenaqdVhEOSXULA==
x-ms-exchange-antispam-messagedata-chunkcount: 1
x-ms-exchange-antispam-messagedata-0: 
 =?us-ascii?Q?mg1ZUjAkoIlFi2LqB/4Ij71hFKaMTmEHCD/o5c3CCZY3q6G61mw8pIet4zZR?=
 =?us-ascii?Q?0Zn20KxiFDb68haUff0J/7nFViDEw117YuAwbLrBr/TLBtuc0DfsDzAEm3v3?=
 =?us-ascii?Q?NSwJm/2U9JtxAB6RfZDb3/5CJp5yaAVk3/wJIo/QQgd50H8LjB4Pxe93FCrc?=
 =?us-ascii?Q?6V7KN4Lz6Z6gixUe3LliGz2+0L1XN7H8lgY4/Spe2NdY2diwqGyq9riPm9iC?=
 =?us-ascii?Q?QdGfiLTt5DKrpka6sYWovEtG+vN9PQhQZIpzQqYNx6Pcj716e3k3hNi5Xqjf?=
 =?us-ascii?Q?1jYVXi+E4sN3W4oa58x8mq10vcdJSTtR/5rnV7FI4Cw8xJsj9lexpL0rWTCF?=
 =?us-ascii?Q?+UdPyGGFQNDwrAOjBHqjeUhR6Wrv+zXLa1NKNZPI+AJyiAAbsUxVxRq2155/?=
 =?us-ascii?Q?HNxabpQJ9xJ/rcDdeJ8TJX38j0kzyAYYNSaTTzKiyprgym6Fy5eZT846CuJz?=
 =?us-ascii?Q?X1ufnhbtXFdizfijLwf/xSGhdijD0e52emR8eS8dLNsdQ7jluMq0YDVD5fee?=
 =?us-ascii?Q?xT6MXrqck0plVxIBVB9/UeGXjiHsonYnchB++q7CnRwQnH273tl7JY9WmwPa?=
 =?us-ascii?Q?SVSXY+r06WpQwPkZQtaO6ZVzBq1Klra8+aZa47FmoghHAaHFet6W0UigvqLm?=
 =?us-ascii?Q?HyYrNBN6IW6Nkd3brkapmLvwuCNMhUljYKsEVUPAp4Mjum51aicQcOcBQWJm?=
 =?us-ascii?Q?E9gTQEf/oZ19Qvc8HO9s3HfangEXdMAyihxgverenxDkBlLi1DzbuRsDpduL?=
 =?us-ascii?Q?ODuSGjdZGE/apD/KuHDlTRHNYaAyO85PQjHp6dC2SOKBYSYK6EnFc2gUKBI2?=
 =?us-ascii?Q?fA0Y/Wvkap4LwgH9t9hhaxDjX48pelBhBLBDPhL9Vi3E9jhxbfURoN3GfQ9o?=
 =?us-ascii?Q?1J1ggY/W2aVRp2qNF1LDX4jyjJrsrGAE2/tTEVbX2Y2l1njFDAO0Wyu6u63N?=
 =?us-ascii?Q?jSv8ngk6bLqy7uo/b+Swwm4aPZKuxDB4oinnhiKP8yCeIItCHrkbeZMOGYWC?=
 =?us-ascii?Q?RPEhZEOpUKNnXU94Pdqet4OkAUJ87FsxaV7PbkJHJ0TbycDo3Gdg1AuD1xah?=
 =?us-ascii?Q?xYy6chiHhuKXdElS77R0yCG2dNVFwUdfgy6oob0XG6QkxZuikHMwoChMqhu7?=
 =?us-ascii?Q?6P9HYrpFxAWWZvXOpfvgiQMLJ6/gZ3c+C/0ZIySwAtLWcKnzmbFXeGslDuyz?=
 =?us-ascii?Q?RvC7jjKPN7Km2ktEvzjrylDmsPmutLL88VUEsfGGh+r8bf452Ddw1Qgnf4s?=
 =?us-ascii?Q?=3D?=
Content-Type: text/plain; charset="us-ascii"
Content-Transfer-Encoding: quoted-printable
MIME-Version: 1.0
X-OriginatorOrg: sct-15-20-4755-11-msonline-outlook-3d941.templateTenant
X-MS-Exchange-CrossTenant-AuthAs: Internal
X-MS-Exchange-CrossTenant-AuthSource: SJ0PR02MB7439.namprd02.prod.outlook.com
X-MS-Exchange-CrossTenant-RMS-PersistedConsumerOrg: 
 00000000-0000-0000-0000-000000000000
X-MS-Exchange-CrossTenant-Network-Message-Id: 
 44bcd809-105f-499f-1bda-08dcd4533ceb
X-MS-Exchange-CrossTenant-rms-persistedconsumerorg: 
 00000000-0000-0000-0000-000000000000
X-MS-Exchange-CrossTenant-originalarrivaltime: 14 Sep 2024 00:21:54.8831
 (UTC)
X-MS-Exchange-CrossTenant-fromentityheader: Hosted
X-MS-Exchange-CrossTenant-id: 84df9e7f-e9f6-40af-b435-aaaaaaaaaaaa
X-MS-Exchange-Transport-CrossTenantHeadersStamped: PH0PR02MB7143
Message-ID-Hash: 2KCAZA7DU7DOPSTA2RPYXZEWU4JCMCWZ
X-Message-ID-Hash: 2KCAZA7DU7DOPSTA2RPYXZEWU4JCMCWZ
X-MailFrom: michael_b_jones@hotmail.com
X-Mailman-Rule-Misses: dmarc-mitigation; no-senders; approved; emergency;
 loop; banned-address; member-moderation; header-match-art.ietf.org-0;
 nonmember-moderation; administrivia; implicit-dest; max-recipients; max-size;
 news-moderation; no-subject; digests; suspicious-header
CC: Deb Cooley <debcooley1@gmail.com>
X-Mailman-Version: 3.3.9rc4
Precedence: list
Subject: =?utf-8?q?=5Bart=5D_Re=3A_art-art_review_of_draft-ietf-oauth-resource-metada?=
	=?utf-8?q?ta?=
List-Id: Applications and Real-Time Area Discussion <art.ietf.org>
Archived-At: 
 <https://mailarchive.ietf.org/arch/msg/art/dEo68Qtr6UFlIwF_NXuZ0dH87Bo>
List-Archive: <https://mailarchive.ietf.org/arch/browse/art>
List-Help: <mailto:art-request@ietf.org?subject=help>
List-Owner: <mailto:art-owner@ietf.org>
List-Post: <mailto:art@ietf.org>
List-Subscribe: <mailto:art-join@ietf.org>
List-Unsubscribe: <mailto:art-leave@ietf.org>

Arnt, the newly published version of https://datatracker.ietf.org/doc/draft=
-ietf-oauth-resource-metadata/ incorporates the changes to address your rev=
iew comments.

                                Thanks again!
                                -- Mike

-----Original Message-----
From: Michael Jones
Sent: Wednesday, September 11, 2024 4:07 PM
To: Arnt Gulbrandsen <arnt@gulbrandsen.priv.no>; art@ietf.org
Cc: Deb Cooley <debcooley1@gmail.com>
Subject: RE: [art] Re: art-art review of draft-ietf-oauth-resource-metadata

Arnt, your review comments are addressed in https://github.com/oauth-wg/dra=
ft-ietf-oauth-resource-metadata/pull/51/commits/c3b7cc68eb4f223a89fc928690b=
1905a129b4be4, which is part of https://github.com/oauth-wg/draft-ietf-oaut=
h-resource-metadata/pull/51.

                                Thanks again,
                                -- Mike

-----Original Message-----
From: Michael Jones <michael_b_jones@hotmail.com>
Sent: Tuesday, September 10, 2024 7:22 PM
To: Arnt Gulbrandsen <arnt@gulbrandsen.priv.no>; art@ietf.org
Cc: Deb Cooley <debcooley1@gmail.com>
Subject: [art] Re: art-art review of draft-ietf-oauth-resource-metadata

Thanks for the review, Arnt.  Replies are inline below, prefixed by "Mike>"=
.

-----Original Message-----
From: Arnt Gulbrandsen <arnt@gulbrandsen.priv.no>
Sent: Wednesday, August 14, 2024 8:18 AM
To: art@ietf.org
Subject: [art] art-art review of draft-ietf-oauth-resource-metadata

Hi,

I'm the assigned art-art reviewer. The document is ready with nits, I think=
.

As a reviewer, I have worked on software that used oauth, have worked on so=
ftware that used JWT, have implemented dozens of other RFCs, but don't know=
 oauth well.

Introduction, third paragraph: the phrase self-asserted confuses me. Self i=
s the metadata resource, right? Maybe phrasing along the lines of "can eith=
er be included directly in the metadata resources".

Mike> Yes, the metadata resource is vouching for its own metadata when it i=
s self-asserted.  I'm reluctant change the "self-asserted" phrasing, becaus=
e it's the same wording used for the same thing in the introduction to the =
other two OAuth metadata specs.  You can find it at https://www.rfc-editor.=
org/rfc/rfc7591.html#section-1 and https://www.rfc-editor.org/rfc/rfc8414.h=
tml#section-1.  Is it OK with you to leave it as-is for consistency sake?

As an implementer I missed information about default/absent values:
bearer_meethods_supported and resource_signing_alt_values_supported might e=
xplain what omission means.

Mike> resource_signing_alg_values_supported includes this text about there =
being no default: "No default algorithms are implied if this entry is omitt=
ed.", so I think that one's already covered.

Mike> For bearer_methods_supported, given we now have DPoP in which no bear=
er token methods are used, defaults (other than possibly none) don't make s=
ense.  However, you comment caused me to think about it and I plan to add t=
his text:  "The empty array [] can be used to indicate that no Bearer metho=
ds are supported.  If this entry is omitted, no default Bearer methods supp=
orted are implied, nor does absence indicate that they are not supported."

I'm curious about why one might want to not mention some scopes. I liked th=
e example for authorization_server, perhaps you could add one here too.

Mike> The "MAY choose not to advertise some scope values supported" languag=
e is also found in both RFC 7591 and RFC 8414.  One reason for not listing =
all scopes is that some OAuth implementations use "structured scopes with p=
arameters", where part of the scope name is a parameter value.  For instanc=
e, such a scope name might be "you-can-use!https://example.com/use-this-thi=
ng".  There may also be privacy reasons not to list them.

The resource_policy_uri and the tos are human-readable, right? The one abov=
e explicitly says it is.

Mike> In both cases, I'll borrow the applicable "human-readable" language f=
rom the corresponding entries in RFC 7591 and apply it here.

Section 3.1 says one MUST query using GET. I couldn't help wondering about =
caching. As a client, is is okay to just cache as given by Cache-Control/Ex=
pires? As a server, can I stumble into a security problem if I serve this w=
ith too long/short lifetime? The security consideration don't say, I can't =
think of anything, but the security considerations also don't say there's n=
othing.

Mike> Again, I looked at the parallel specs and https://www.rfc-editor.org/=
rfc/rfc8414.html#section-1 uses GET in the same way.  I'd be glad to add a =
Security Considerations section on this is we can come up with something me=
aningful to say.  Probably something about being aware of HTTP caching life=
times?

I really liked section 7.5.

Mike> Thanks!  When we wrote this at https://www.rfc-editor.org/rfc/rfc8414=
.html#section-6.3, there really were people making the security-by-obscurit=
y argument that publishing the information in an easily accessible manner w=
as bad!  That's why this section is there.

Section 7.6 says "fixed and enumerable". Don't see why it has to be fixed.

Mike> Good point.  I'll delete "fixed".

In general I feel that I could implement this easily and well, which is rea=
lly the key to any RFC. Good job. I do wonder what missing values of bearer=
_meethods_supported and resource_signing_alt_values_supported mean, though.

Arnt

Thanks for the useful review and positive feedback!

                                -- Mike
_______________________________________________
art mailing list -- art@ietf.org
To unsubscribe send an email to art-leave@ietf.org ________________________=
_______________________
art mailing list -- art@ietf.org
To unsubscribe send an email to art-leave@ietf.org

