[art] Re: art-art review of draft-ietf-oauth-resource-metadata
Michael Jones <michael_b_jones@hotmail.com> Wed, 11 September 2024 23:06 UTC
Return-Path: <michael_b_jones@hotmail.com>
X-Original-To: art@ietfa.amsl.com
Delivered-To: art@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 485E2C180B66 for <art@ietfa.amsl.com>; Wed, 11 Sep 2024 16:06:42 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -6.233
X-Spam-Level:
X-Spam-Status: No, score=-6.233 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, FORGED_HOTMAIL_RCVD2=0.874, FREEMAIL_FROM=0.001, RCVD_IN_DNSWL_HI=-5, RCVD_IN_MSPIKE_H2=-0.001, RCVD_IN_ZEN_BLOCKED_OPENDNS=0.001, SPF_PASS=-0.001, T_SCC_BODY_TEXT_LINE=-0.01, URIBL_BLOCKED=0.001, URIBL_DBL_BLOCKED_OPENDNS=0.001, URIBL_ZEN_BLOCKED_OPENDNS=0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (2048-bit key) header.d=hotmail.com
Received: from mail.ietf.org ([50.223.129.194]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id kqmWeTTSUfZm for <art@ietfa.amsl.com>; Wed, 11 Sep 2024 16:06:38 -0700 (PDT)
Received: from NAM11-DM6-obe.outbound.protection.outlook.com (mail-dm6nam11olkn2104.outbound.protection.outlook.com [40.92.19.104]) (using TLSv1.2 with cipher ECDHE-ECDSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 6E1BBC180B63 for <art@ietf.org>; Wed, 11 Sep 2024 16:06:38 -0700 (PDT)
ARC-Seal: i=1; a=rsa-sha256; s=arcselector10001; d=microsoft.com; cv=none; b=bEhmeQVuXCPQbM8YRnicw9rFm0j+eaywh74zTRJ7JGByr1I6zw2290nm1+HSbC2Z1Wbrk5PRnU1TUOu3UvIeYOe6lygV8q5oKBgapvbAmECGIUqjskIr2F588uaIcw8GYC2mNLn127MQ4y9LboOzxmOmqvNCBsBaWlF7VY7i14jOjT9cbU5JMx0/5/BhXI+BHDMRlymte1xw2QvVi63YVFiwnp0BGxvVoc1KUFPuBTlnJJ7MfY89AtnAVa8P/SYubxr6ypz+W6NFxh7ZHjQJn+nyDyWV7NltTxH0tndVjoWkXg6K3r2DV9mHtjI+RbBWigPBFDwTLv992u9kqVMezw==
ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=microsoft.com; s=arcselector10001; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-AntiSpam-MessageData-ChunkCount:X-MS-Exchange-AntiSpam-MessageData-0:X-MS-Exchange-AntiSpam-MessageData-1; bh=uLuJQf4dr5+lC66a3pYh4a/Somvf9jJQHYUnuIxsnVs=; b=ykF246qI16wktSIwh0QYqMmJL+M0MIPvW2t9hvx3iMZZS4TqstOCGemkluYCcHRN6O9vBf2TYz0tW79rACDND4U5xRMZa6VIHrwxa61NKKdHXWAaHWygyAIJI27FwKduHpf0trLOYz+RBsPKR/FQiY7BcVUqOuJvFFpyhudif6WsPCfsvuGB5SZ948+G9Z/2ONv/51LyUO7Yvi8/RdeIX0tjJGMbo20hD3fyzQu15iz8MaBcg4qUJCC5zz1CVPDb7RwYMmXnP8/4OBiXCBXuu/CT6YzG7vaor6HMRBI3rLXJf7Xy3UrsY9GYWsajRK8jPhOfxYXLr2QTwyBCKbkaHw==
ARC-Authentication-Results: i=1; mx.microsoft.com 1; spf=none; dmarc=none; dkim=none; arc=none
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=hotmail.com; s=selector1; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-SenderADCheck; bh=uLuJQf4dr5+lC66a3pYh4a/Somvf9jJQHYUnuIxsnVs=; b=pdAegzK8xwWQCMqCsII1I4Ff+4hPdpaMgiKVSayI+tR/PlFOU+HGMsOmF/Ol4vbH5SGH96cwammdzhAY3ftxC7KmgFJ+11lxF0F5IMVl4mAMbaS8r5BJgVBdYTIsdkXJP7pa970TlG5ezbsDj2vvASl7hwxm7VIKRegoa+j0k4nE2Z/tJkrDRkRK8IGaWEtDc17mxJlOgDHTE/S2A61jirbNZmvbdv5/Zt8DOlrRavvt3M4bht6+msD9lC8UdAls7AVcFX0MsQtuuu2+WIoAlfyQJ4gX60jv6ddotAuoPLbeh4pXlK0A/8WyA0KtP7ZsddIaAmA+8sfiBxE5YSLugw==
Received: from SJ0PR02MB7439.namprd02.prod.outlook.com (2603:10b6:a03:295::14) by CY4PEPF0000EDF9.namprd02.prod.outlook.com (2603:10b6:92f::1:0:5) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.20.7918.20; Wed, 11 Sep 2024 23:06:36 +0000
Received: from SJ0PR02MB7439.namprd02.prod.outlook.com ([fe80::6394:e79c:c32a:4c6a]) by SJ0PR02MB7439.namprd02.prod.outlook.com ([fe80::6394:e79c:c32a:4c6a%3]) with mapi id 15.20.7939.022; Wed, 11 Sep 2024 23:06:35 +0000
From: Michael Jones <michael_b_jones@hotmail.com>
To: Arnt Gulbrandsen <arnt@gulbrandsen.priv.no>, "art@ietf.org" <art@ietf.org>
Thread-Topic: [art] Re: art-art review of draft-ietf-oauth-resource-metadata
Thread-Index: AQHbBJ8/n9aQYfIEGEu79N5NltBrbg==
Date: Wed, 11 Sep 2024 23:06:35 +0000
Message-ID: <SJ0PR02MB74395C133891142856B00149B79B2@SJ0PR02MB7439.namprd02.prod.outlook.com>
References: <172357514156.942063.8970388467871714335@dt-datatracker-6df4c9dcf5-t2x2k> <379cb52e-816b-4377-bfac-5ce5e6c9cd1c@gulbrandsen.priv.no> <SJ0PR02MB74394171BE56CD006648180DB79B2@SJ0PR02MB7439.namprd02.prod.outlook.com>
In-Reply-To: <SJ0PR02MB74394171BE56CD006648180DB79B2@SJ0PR02MB7439.namprd02.prod.outlook.com>
Accept-Language: en-US
Content-Language: en-US
X-MS-Has-Attach:
X-MS-TNEF-Correlator:
x-tmn: [3RUG/J1l4JByNJEdeHzPShvSDoyX9Kz8]
x-ms-publictraffictype: Email
x-ms-traffictypediagnostic: SJ0PR02MB7439:EE_|CY4PEPF0000EDF9:EE_
x-ms-office365-filtering-correlation-id: dd9abe34-335f-42fa-501c-08dcd2b66257
x-microsoft-antispam: BCL:0;ARA:14566002|15080799006|7092599003|19110799003|461199028|8060799006|56899033|1602099012|3412199025|4302099013|102099032|440099028;
x-microsoft-antispam-message-info: 6N/cuhNRc88/Ny1q+cB49MjrhNg0wBbq4khrbkEIlv/qi0+ZTjO5Vjd9wIAy/AnljGxnnh3W+ZaRHWRU3okF1VtSazwU/4foqYAcg5q6GKo/A8KqiVC6O9V68sgrIMhK1uEIUXWPrvCcjZkuBZ9eHp3iBebOrX/l7Zn8H8I2HqKxYxqcYZHrHmYmM+it6yXTabfc3AP6VuNEetshdXjtODBFk+TQmGmcRKhRTngHJFFCY+NOl0ZBmeTezoJDMDmYt1F2Gw/3/Ngu3mlbPEcVl849+MD6fV6W6Ymx+5RL5gZaFN2cKOoEGNGGJB+I6thIjYF4Fhb6uZGn9jpma718Og/6DLmTq125dKhjN35izaBv8L48/1kMAp/S4tZRf3LzS6c7q2PxWycOfmqsahovZx1Rq3jmVj5oKkogM5DatEykac4O6UvUbbEVBsxqlN6YUXOKwwhuXmTtn74fRYmBJav+azmKxtydo0bR0H+4kktUvHXJEmbJPzOicg7G6FZzbKRXasY/zc6c86OppPAA5FLI6HC4elaBqnVaBzvkD43rVc6ZdlUrTg3+VkMkPzdZaT1lv17Kl5DxZBxoDeF7vl7gFjw+tqKEqBoIPsmtuXhO3jF16mMPWDwbCqWSJdINJzfKHG6WzKIitulU8jO7CCBFtBwcCVqSWTRGBhR6FqvffRImfSqTmqdwCd1uNUKH/pyVYpSTE20eRHhKN33oZMd7fkVxpWxXnZR0z4nkpCBWzIkjaY5tbtZWtcXA0qBWpMUd01jaK0X0Vn/QewtAHF4esDBVWfGEvBq/RNZH19PYVYy25WthDamwyVSfo8NRNGT8p/UytPqYwZk3xcIYOw==
x-ms-exchange-antispam-messagedata-chunkcount: 1
x-ms-exchange-antispam-messagedata-0: Wc1Tzu7gfZFEDP03v9Jzbce/sDM7RVEXzZikfDO+aa5IY8amWQtPjoD+Y4mx/eULFK+iAP4yyn0W+lIDkWVTCB+uQU9xSpTAtLKSAnKaNGe6uKr41dgvIgjQ0jBKi5WTOE69x2p9lgOoipA8Glf83X+fnJBmTxEB3PJPLvbYEmF05JUkXIv0pfcSVxRlppE4eg0FjLEv0CVwj6FGF3uk8E8Acp2PswIyWkQM9qd3rG+8o+LiTETLKemEiivdTgreMn4Mqlqs7pF45JLhY/QU6kSZgeZazaD1ffBp6/bOrKLrX2nUWCm6lQprpVQMn0d11m7NAd5s+L7MUnLWG3nhodyDjNAjFElWZLryl0EaFAmu7+QoENItRA+PMJFWDFGnrr2X2N6is10qNXPbbH72wb/rD8XFd0KQq6tH0BKgXI/hTKAzwS1/KQLg0MEYEQOI3SsDuEj4XGfQOyWMhFOmA6Zqs1wbZosp2flHyJAlH6BLEos3R1ZEatw71vGKR/OvkFi5BtvvxliD6U9nOCyGvtuUOlK/y2LbE1WY3P1KYwoaaAYeMfESTLoiY1S6ANkc0tp0bGNI9EGmE232afcLSlENjZh2428nNylMQHRZs83PIDJ3bvbOyUbOTfoziAxSHQ6zmp7kXmxU3AG/EyjAnIwuEnMIhsLcETv/T0F2Z9GN/H6WWl+YQsNMootsPKU830PxtP8ThZBdleaeEWjeZa/8GI8nmmT0Wxw+lRTdSZA62jwtL90t1LZ9IMIgZVDKVeoYUDYpA/Q22eJISdoeFNRCFK1PqNehALPSOTcJ28RAFK7r2kZvWyJe9zRmnQ7PbS9hxo1ErP8Y+MgCwD5Alp0GQcTQ4CEUgpdDryEfc90ku6KoqWNJRwLbQEyvsRc7eZlCdOL4AP0XSMfNPe3iyrGyS+QLvbNIIUpbWeEcqLwOhe7weYjHBrO+zXB5BxZHOKzGTSkS7m/t2fFAmWBc7IgQ65LvLkFHvM09eszx0CYRvpAg0bdudf55wScJCBxjx+xWfLPqxoeIKXS/shMKHLaIE59jfBk7nQHBtJZV/Wp6ph+kZXG2K/J9ukansfmjIX6vLdbdrN6e0PxkCqWBSwVxQkHRwjMAFu5uGeC/8jInii6qxFJoYCi7Z74m2IMdrICs4f1G49HN36GUX53o2rcjvaVl8Ad0HljS0xO+JD1Zot9+BFHccYg6IItmYbFxoynUMuWO7o6T9ivKbrRYrU/Xok00tenLiKQhNATjN1Q=
Content-Type: text/plain; charset="us-ascii"
Content-Transfer-Encoding: quoted-printable
MIME-Version: 1.0
X-OriginatorOrg: sct-15-20-7719-20-msonline-outlook-0f88b.templateTenant
X-MS-Exchange-CrossTenant-AuthAs: Internal
X-MS-Exchange-CrossTenant-AuthSource: SJ0PR02MB7439.namprd02.prod.outlook.com
X-MS-Exchange-CrossTenant-RMS-PersistedConsumerOrg: 00000000-0000-0000-0000-000000000000
X-MS-Exchange-CrossTenant-Network-Message-Id: dd9abe34-335f-42fa-501c-08dcd2b66257
X-MS-Exchange-CrossTenant-rms-persistedconsumerorg: 00000000-0000-0000-0000-000000000000
X-MS-Exchange-CrossTenant-originalarrivaltime: 11 Sep 2024 23:06:35.5139 (UTC)
X-MS-Exchange-CrossTenant-fromentityheader: Hosted
X-MS-Exchange-CrossTenant-id: 84df9e7f-e9f6-40af-b435-aaaaaaaaaaaa
X-MS-Exchange-Transport-CrossTenantHeadersStamped: CY4PEPF0000EDF9
Message-ID-Hash: 76CCMM4I6BXFNOMLSUXCGZWWXLJU7PYQ
X-Message-ID-Hash: 76CCMM4I6BXFNOMLSUXCGZWWXLJU7PYQ
X-MailFrom: michael_b_jones@hotmail.com
X-Mailman-Rule-Misses: dmarc-mitigation; no-senders; approved; emergency; loop; banned-address; member-moderation; header-match-art.ietf.org-0; nonmember-moderation; administrivia; implicit-dest; max-recipients; max-size; news-moderation; no-subject; digests; suspicious-header
CC: Deb Cooley <debcooley1@gmail.com>
X-Mailman-Version: 3.3.9rc4
Precedence: list
Subject: [art] Re: art-art review of draft-ietf-oauth-resource-metadata
List-Id: Applications and Real-Time Area Discussion <art.ietf.org>
Archived-At: <https://mailarchive.ietf.org/arch/msg/art/qitEPlp_b0yIdcke36csw5py3pQ>
List-Archive: <https://mailarchive.ietf.org/arch/browse/art>
List-Help: <mailto:art-request@ietf.org?subject=help>
List-Owner: <mailto:art-owner@ietf.org>
List-Post: <mailto:art@ietf.org>
List-Subscribe: <mailto:art-join@ietf.org>
List-Unsubscribe: <mailto:art-leave@ietf.org>
Arnt, your review comments are addressed in https://github.com/oauth-wg/draft-ietf-oauth-resource-metadata/pull/51/commits/c3b7cc68eb4f223a89fc928690b1905a129b4be4, which is part of https://github.com/oauth-wg/draft-ietf-oauth-resource-metadata/pull/51. Thanks again, -- Mike -----Original Message----- From: Michael Jones <michael_b_jones@hotmail.com> Sent: Tuesday, September 10, 2024 7:22 PM To: Arnt Gulbrandsen <arnt@gulbrandsen.priv.no>; art@ietf.org Cc: Deb Cooley <debcooley1@gmail.com> Subject: [art] Re: art-art review of draft-ietf-oauth-resource-metadata Thanks for the review, Arnt. Replies are inline below, prefixed by "Mike>". -----Original Message----- From: Arnt Gulbrandsen <arnt@gulbrandsen.priv.no> Sent: Wednesday, August 14, 2024 8:18 AM To: art@ietf.org Subject: [art] art-art review of draft-ietf-oauth-resource-metadata Hi, I'm the assigned art-art reviewer. The document is ready with nits, I think. As a reviewer, I have worked on software that used oauth, have worked on software that used JWT, have implemented dozens of other RFCs, but don't know oauth well. Introduction, third paragraph: the phrase self-asserted confuses me. Self is the metadata resource, right? Maybe phrasing along the lines of "can either be included directly in the metadata resources". Mike> Yes, the metadata resource is vouching for its own metadata when it is self-asserted. I'm reluctant change the "self-asserted" phrasing, because it's the same wording used for the same thing in the introduction to the other two OAuth metadata specs. You can find it at https://www.rfc-editor.org/rfc/rfc7591.html#section-1 and https://www.rfc-editor.org/rfc/rfc8414.html#section-1. Is it OK with you to leave it as-is for consistency sake? As an implementer I missed information about default/absent values: bearer_meethods_supported and resource_signing_alt_values_supported might explain what omission means. Mike> resource_signing_alg_values_supported includes this text about there being no default: "No default algorithms are implied if this entry is omitted.", so I think that one's already covered. Mike> For bearer_methods_supported, given we now have DPoP in which no bearer token methods are used, defaults (other than possibly none) don't make sense. However, you comment caused me to think about it and I plan to add this text: "The empty array [] can be used to indicate that no Bearer methods are supported. If this entry is omitted, no default Bearer methods supported are implied, nor does absence indicate that they are not supported." I'm curious about why one might want to not mention some scopes. I liked the example for authorization_server, perhaps you could add one here too. Mike> The "MAY choose not to advertise some scope values supported" language is also found in both RFC 7591 and RFC 8414. One reason for not listing all scopes is that some OAuth implementations use "structured scopes with parameters", where part of the scope name is a parameter value. For instance, such a scope name might be "you-can-use!https://example.com/use-this-thing". There may also be privacy reasons not to list them. The resource_policy_uri and the tos are human-readable, right? The one above explicitly says it is. Mike> In both cases, I'll borrow the applicable "human-readable" language from the corresponding entries in RFC 7591 and apply it here. Section 3.1 says one MUST query using GET. I couldn't help wondering about caching. As a client, is is okay to just cache as given by Cache-Control/Expires? As a server, can I stumble into a security problem if I serve this with too long/short lifetime? The security consideration don't say, I can't think of anything, but the security considerations also don't say there's nothing. Mike> Again, I looked at the parallel specs and https://www.rfc-editor.org/rfc/rfc8414.html#section-1 uses GET in the same way. I'd be glad to add a Security Considerations section on this is we can come up with something meaningful to say. Probably something about being aware of HTTP caching lifetimes? I really liked section 7.5. Mike> Thanks! When we wrote this at https://www.rfc-editor.org/rfc/rfc8414.html#section-6.3, there really were people making the security-by-obscurity argument that publishing the information in an easily accessible manner was bad! That's why this section is there. Section 7.6 says "fixed and enumerable". Don't see why it has to be fixed. Mike> Good point. I'll delete "fixed". In general I feel that I could implement this easily and well, which is really the key to any RFC. Good job. I do wonder what missing values of bearer_meethods_supported and resource_signing_alt_values_supported mean, though. Arnt Thanks for the useful review and positive feedback! -- Mike _______________________________________________ art mailing list -- art@ietf.org To unsubscribe send an email to art-leave@ietf.org _______________________________________________ art mailing list -- art@ietf.org To unsubscribe send an email to art-leave@ietf.org
- [art] art-art review of draft-ietf-oauth-resource… Arnt Gulbrandsen
- [art] Re: art-art review of draft-ietf-oauth-reso… Michael Jones
- [art] Re: art-art review of draft-ietf-oauth-reso… Michael Jones
- [art] Re: art-art review of draft-ietf-oauth-reso… Michael Jones