Re: [Emu] New Version Notification for draft-janfred-eap-fido-02.txt

Alexander Clouter <alex+ietf@coremem.com> Mon, 04 March 2024 13:23 UTC

Return-Path: <alex+ietf@coremem.com>
X-Original-To: emu@ietfa.amsl.com
Delivered-To: emu@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 744C9C15198C for <emu@ietfa.amsl.com>; Mon, 4 Mar 2024 05:23:36 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.106
X-Spam-Level:
X-Spam-Status: No, score=-2.106 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, RCVD_IN_ZEN_BLOCKED_OPENDNS=0.001, SPF_HELO_NONE=0.001, SPF_PASS=-0.001, T_SCC_BODY_TEXT_LINE=-0.01, URIBL_BLOCKED=0.001, URIBL_DBL_BLOCKED_OPENDNS=0.001, URIBL_ZEN_BLOCKED_OPENDNS=0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (2048-bit key) header.d=coremem.com header.b="K0ayhC34"; dkim=pass (2048-bit key) header.d=messagingengine.com header.b="baLa67ut"
Received: from mail.ietf.org ([50.223.129.194]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id 4I5tEEe6r0wg for <emu@ietfa.amsl.com>; Mon, 4 Mar 2024 05:23:31 -0800 (PST)
Received: from wfout2-smtp.messagingengine.com (wfout2-smtp.messagingengine.com [64.147.123.145]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (2048 bits) server-digest SHA256) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 4E6A4C151986 for <emu@ietf.org>; Mon, 4 Mar 2024 05:23:31 -0800 (PST)
Received: from compute3.internal (compute3.nyi.internal [10.202.2.43]) by mailfout.west.internal (Postfix) with ESMTP id 29E5E1C0009A for <emu@ietf.org>; Mon, 4 Mar 2024 08:23:30 -0500 (EST)
Received: from imap46 ([10.202.2.96]) by compute3.internal (MEProxy); Mon, 04 Mar 2024 08:23:30 -0500
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=coremem.com; h= cc:content-type:content-type:date:date:from:from:in-reply-to :in-reply-to:message-id:mime-version:references:reply-to:subject :subject:to:to; s=fm3; t=1709558609; x=1709645009; bh=QmB6HhdwmG UKpM3fpP5dnLzVLQmUx/i37x8sWprTwfo=; b=K0ayhC34+by3ybYA5p5H0lZ+Qh VcLWhX7V9i+XpeRGxgMzzKQXWT8pzwYPgjWp6LYzX/awGZ8/ocrbw5l66KoYE9eE gmMeiR/06YEsO2QMc1BfUvaV7dN5JDcn1YtDzGhdJZzoZK+hvX1EwVRKSz2jBZLc upQGI4UCYzyHCuoNpnB+Co6qg2j/H/Xx9iCeEe1T2eVhF06suunm1qNMX13iT7vS OpXrxS69ESahVjAgSaJnHIJrvM2ZVNVWvhAR7s68nRx2iolnuGLXFqpa3eaEiPeL wPu7fzuGV5UUUZWEiubIySCnYm0IFKfOcxuL5Aw2bhG9VGE+dRgVk2hAjbiA==
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d= messagingengine.com; h=cc:content-type:content-type:date:date :feedback-id:feedback-id:from:from:in-reply-to:in-reply-to :message-id:mime-version:references:reply-to:subject:subject:to :to:x-me-proxy:x-me-proxy:x-me-sender:x-me-sender:x-sasl-enc; s= fm1; t=1709558609; x=1709645009; bh=QmB6HhdwmGUKpM3fpP5dnLzVLQmU x/i37x8sWprTwfo=; b=baLa67uthQgm7nd4lGnfKnpncwIBj7oIiw2Tr8uZboKG QYVVTzkZgdkdRykpW5nJGj7DwNW5LaCZSJj9bx5Xz6swvL7mz46fyQ2tbfPU+5z0 kPWi5G3BnGeAdiC3o7qHWWHACo2+sJnZX+sf/Zc+cWx14wLVAlGJxkXVjood0EDl HZ8K/xFzEqCHyIuJZw1+14c8RJKWoFXja4w2jnq8qXRXo+FP2NBQmlMVmwSnPxc/ 8igQ76f6dLSeiRX5StaIcUcGsXmxCpPJ7WBPwPsbWiD7hQz71MHY+EbgmlBGFsNu DH/nrr4uC+B/ldQn60BGJI0C9tiRytiAd8WtM/quVA==
X-ME-Sender: <xms:UcvlZZkjEu637QPY6jX77HddMNg2G2NG8nu3hyq94TRBe_wXZiUxeQ> <xme:UcvlZU26tnCnt-6bloc1hYxliO0Qelg_GAN1qDF0TXCNk8NnOx99Stzag3ACgdJIn ftc3auIXCMfayg70g>
X-ME-Proxy-Cause: gggruggvucftvghtrhhoucdtuddrgedvledrheejgdehtdcutefuodetggdotefrodftvf curfhrohhfihhlvgemucfhrghsthforghilhdpqfgfvfdpuffrtefokffrpgfnqfghnecu uegrihhlohhuthemuceftddtnecunecujfgurhepofgfggfkjghffffhvffutgesthdtre dtreertdenucfhrhhomhepfdetlhgvgigrnhguvghrucevlhhouhhtvghrfdcuoegrlhgv gidoihgvthhfsegtohhrvghmvghmrdgtohhmqeenucggtffrrghtthgvrhhnpeehleejve evvdelgfdtveegueeuueevfefhieeugeekleekjeeuhedvtdekuddtleenucffohhmrghi nhepfhhiughorghllhhirghntggvrdhorhhgnecuvehluhhsthgvrhfuihiivgeptdenuc frrghrrghmpehmrghilhhfrhhomheprghlvgigodhivghtfhestghorhgvmhgvmhdrtgho mh
X-ME-Proxy: <xmx:UcvlZfrYiqW0Usnjn8OyFImh9Lx6ZBfk4U1VH1TSe_vNftWzsre6zw> <xmx:UcvlZZlqalJyy8gGFNw5XoVSGqUs133gsedCgeAOkLYMsOMxUM_Ipg> <xmx:UcvlZX2dZOINVMwF1w2rC6cd16Ur2Zsq7Tv5uQRn_CXrGspYkdB3FA> <xmx:UcvlZU9bGF79QfokjJ4e8Wt8pC0ck683668kU-BIFXcRFeRFkaSuX46qJkE>
Feedback-ID: ie3614602:Fastmail
Received: by mailuser.nyi.internal (Postfix, from userid 501) id 5AB392A20090; Mon, 4 Mar 2024 08:23:29 -0500 (EST)
X-Mailer: MessagingEngine.com Webmail Interface
User-Agent: Cyrus-JMAP/3.11.0-alpha0-205-g4dbcac4545-fm-20240301.001-g4dbcac45
MIME-Version: 1.0
Message-Id: <15f77a31-d15c-47b7-8f4a-c8ff3bcee7e5@app.fastmail.com>
In-Reply-To: <19d725e9-586d-4f37-855a-dca2c5c04998@app.fastmail.com>
References: <170932527085.22824.18343512124707075119@ietfa.amsl.com> <66bca1b2-4b2d-429d-8f85-5c76d29005ad@dfn.de> <19d725e9-586d-4f37-855a-dca2c5c04998@app.fastmail.com>
Date: Mon, 04 Mar 2024 13:23:09 +0000
From: Alexander Clouter <alex+ietf@coremem.com>
To: EMU WG <emu@ietf.org>
Content-Type: text/plain
Archived-At: <https://mailarchive.ietf.org/arch/msg/emu/f18KWnl3jFjTo_gUse4nh-1MuOI>
Subject: Re: [Emu] New Version Notification for draft-janfred-eap-fido-02.txt
X-BeenThere: emu@ietf.org
X-Mailman-Version: 2.1.39
Precedence: list
List-Id: "EAP Methods Update \(EMU\)" <emu.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/emu>, <mailto:emu-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/emu/>
List-Post: <mailto:emu@ietf.org>
List-Help: <mailto:emu-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/emu>, <mailto:emu-request@ietf.org?subject=subscribe>
X-List-Received-Date: Mon, 04 Mar 2024 13:23:36 -0000

On Mon, 4 Mar 2024, at 10:06, Alexander Clouter wrote:
> On Fri, 1 Mar 2024, at 21:08, Jan-Frederik Rieckers wrote:
>> I just posted a new version of the EAP-FIDO draft.
>>
>> [snipped]
>>
>> Comments are welcome, as always.
>
> Trying to understand the need for 'Credentials IDs (PKIDs) in the 
> authentication request.

Oh, I should say, a perfectly good answer is "here is some bedtime reading materials"; the machinery here I am unfamiliar with beyond I have one of these passkeys in a draw.

I did search the CTAP doc[1], but maybe I missed it.

Cheers

[1] https://fidoalliance.org/specs/fido-v2.1-ps-20210615/fido-client-to-authenticator-protocol-v2.1-ps-errata-20220621.html