Re: [COSE] Consensus Call: Adoption of the COSE Token

Anthony Nadalin <tonynad@microsoft.com> Wed, 18 November 2015 00:38 UTC

Return-Path: <tonynad@microsoft.com>
X-Original-To: cose@ietfa.amsl.com
Delivered-To: cose@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 6943B1B365B for <cose@ietfa.amsl.com>; Tue, 17 Nov 2015 16:38:08 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.001
X-Spam-Level:
X-Spam-Status: No, score=-2.001 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, HTML_MESSAGE=0.001, RCVD_IN_DNSWL_NONE=-0.0001, SPF_HELO_PASS=-0.001, SPF_PASS=-0.001] autolearn=ham
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id k8MIFzrQsdfA for <cose@ietfa.amsl.com>; Tue, 17 Nov 2015 16:38:05 -0800 (PST)
Received: from na01-bl2-obe.outbound.protection.outlook.com (mail-bl2on0129.outbound.protection.outlook.com [65.55.169.129]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 2A78D1B3659 for <cose@ietf.org>; Tue, 17 Nov 2015 16:38:04 -0800 (PST)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=microsoft.com; s=selector1; h=From:To:Date:Subject:Message-ID:Content-Type:MIME-Version; bh=Pg0FSoVLeS7XEsMohcHqyu20E09fqCNwD8gxMNgn48Y=; b=Qh5E60N1/q/uIRRFEom/lF37sqAx3VWwbls5HeiNUC8pLYFBA+W0ZisXIXWLqmnbq6sPlXuXNmnxHxampD75dz8MLul0BD1+8cLlYTyvkiTFTnQxZLC5MUSSmAyGWFZFoI0qZmYFw2SR5kZ/S3lUVQBCAOEHuc2gJrq8liC2z1g=
Received: from BN3PR0301MB1234.namprd03.prod.outlook.com (10.161.207.22) by BN3PR0301MB1234.namprd03.prod.outlook.com (10.161.207.22) with Microsoft SMTP Server (TLS) id 15.1.331.20; Wed, 18 Nov 2015 00:38:02 +0000
Received: from BN3PR0301MB1234.namprd03.prod.outlook.com ([10.161.207.22]) by BN3PR0301MB1234.namprd03.prod.outlook.com ([10.161.207.22]) with mapi id 15.01.0331.019; Wed, 18 Nov 2015 00:38:02 +0000
From: Anthony Nadalin <tonynad@microsoft.com>
To: "cose@ietf.org" <cose@ietf.org>
Thread-Topic: Re: [COSE] Consensus Call: Adoption of the COSE Token
Thread-Index: AdEhmRloc+CDWNXAQUezKr7HUjMehg==
Date: Wed, 18 Nov 2015 00:38:02 +0000
Message-ID: <BN3PR0301MB1234FE6235C166D31C1FE42DA61C0@BN3PR0301MB1234.namprd03.prod.outlook.com>
Accept-Language: en-US
Content-Language: en-US
X-MS-Has-Attach:
X-MS-TNEF-Correlator:
authentication-results: spf=none (sender IP is ) smtp.mailfrom=tonynad@microsoft.com;
x-originating-ip: [2001:4898:80e8:e::240]
x-microsoft-exchange-diagnostics: 1; BN3PR0301MB1234; 5:9ymd2NI8ObOq/lc3ji5kfFYEjiF86/ENJM1fcnZixjWT4pXvxggrAzueEU8Wchj/CrzSBGxZTzmfkNF8AV60xy+Gj59IYKZ1RHf+z2Zv8frY+wFft+bovRzMPxl3xcdows6q5wpmP8LyFmod0WqZgQ==; 24:kZVG66uExsX+I2Ukn12MJZ6NgrL9jY/llZM+4r4wGjMqqP5BC4jAcEqUBY9fqKXsjOSeHg+bOd14cK2z3PyszsGkTZs9/tNlRmBY4002bgM=
x-microsoft-antispam: UriScan:;BCL:0;PCL:0;RULEID:;SRVR:BN3PR0301MB1234;
x-microsoft-antispam-prvs: <BN3PR0301MB12346EFB523666840CFFBEFBA61C0@BN3PR0301MB1234.namprd03.prod.outlook.com>
x-exchange-antispam-report-test: UriScan:(108003899814671);
x-exchange-antispam-report-cfa-test: BCL:0; PCL:0; RULEID:(61425024)(601004)(2401047)(8121501046)(5005006)(520078)(10201501046)(3002001)(61426024)(61427024); SRVR:BN3PR0301MB1234; BCL:0; PCL:0; RULEID:; SRVR:BN3PR0301MB1234;
x-forefront-prvs: 0764C4A8CD
x-forefront-antispam-report: SFV:NSPM; SFS:(10019020)(6009001)(189002)(24454002)(377454003)(199003)(16236675004)(10090500001)(86612001)(33656002)(10290500002)(10400500002)(5004730100002)(5002640100001)(450100001)(101416001)(5005710100001)(8990500004)(5001960100002)(5007970100001)(2351001)(107886002)(19625215002)(110136002)(76576001)(74316001)(105586002)(189998001)(97736004)(99286002)(19580405001)(5008740100001)(19580395003)(11100500001)(77096005)(2501003)(54356999)(15975445007)(102836002)(586003)(50986999)(92566002)(86362001)(87936001)(40100003)(5003600100002)(2900100001)(19300405004)(122556002)(106356001)(81156007)(3826002)(42262002); DIR:OUT; SFP:1102; SCL:1; SRVR:BN3PR0301MB1234; H:BN3PR0301MB1234.namprd03.prod.outlook.com; FPR:; SPF:None; PTR:InfoNoRecords; MX:1; A:1; LANG:en;
received-spf: None (protection.outlook.com: microsoft.com does not designate permitted sender hosts)
spamdiagnosticoutput: 1:23
spamdiagnosticmetadata: NSPM
Content-Type: multipart/alternative; boundary="_000_BN3PR0301MB1234FE6235C166D31C1FE42DA61C0BN3PR0301MB1234_"
MIME-Version: 1.0
X-OriginatorOrg: microsoft.com
X-MS-Exchange-CrossTenant-originalarrivaltime: 18 Nov 2015 00:38:02.3855 (UTC)
X-MS-Exchange-CrossTenant-fromentityheader: Hosted
X-MS-Exchange-CrossTenant-id: 72f988bf-86f1-41af-91ab-2d7cd011db47
X-MS-Exchange-Transport-CrossTenantHeadersStamped: BN3PR0301MB1234
Archived-At: <http://mailarchive.ietf.org/arch/msg/cose/wzTccuXXQwnxox9xWyDr_-Um1dM>
Subject: Re: [COSE] Consensus Call: Adoption of the COSE Token
X-BeenThere: cose@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: CBOR Object Signing and Encryption <cose.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/cose>, <mailto:cose-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/cose/>
List-Post: <mailto:cose@ietf.org>
List-Help: <mailto:cose-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/cose>, <mailto:cose-request@ietf.org?subject=subscribe>
X-List-Received-Date: Wed, 18 Nov 2015 00:38:08 -0000

My preference would be the same as John's



John Bradley <ve7jtb@ve7jtb.com> Sun, 15 November 2015 00:08 UTCS
My preference is B then A.

We are rechartering OAuth anyway.   We did not do JOSE in the OAuth WG but were responsible for the security token format.

The core of CWT should be in OAuth using the existing JWT registry and extensions done in ACE.

John B.
> On Nov 7, 2015, at 5:01 AM, Justin Richer <jricher@MIT.EDU> wrote:
>
> At the Yokohama meeting, the chairs agreed to do a consensus call regarding the adoption and placement of new work to define a COSE Token, analogous to the JWT from JOSE. In the room, there was a general sentiment of support for the work being done, with the wide adoption of JWT and its driving of JOSE being a common theme of precedent. What wasn't clear is where the work should be done and to what end it should drive. The six positions we are asking the working group to consider and voice their support for are:
>
> A) Define the COSE Token within the COSE working group along side the COSE Messages (and potentially COSE Auxiliary Algorithms) draft.
> B) Define the COSE Token inside the OAuth working group.
> C) Define the COSE Token inside the ACE working group.
> D) Don't define the COSE Token anywhere.
> E) You need more information to decide.
> F) You don't give a flying rat about the COSE Token.*
>
> The consensus call will remain open for two weeks from today, closing on November 21, 2015; at which time, hopefully we will have a clear answer and direction to point this work.
>
> Thank you,
> - Justin & Kepeng, your COSE chairs
>
> * I promised those in the room at Yokohama to offer a flying rat option, for which I am deeply sorry.
> _______________________________________________
> COSE mailing list
> COSE@ietf.org
> https://www.ietf.org/mailman/listinfo/cose