Re: [http-auth] [httpauth] Mutual authentication proposal
Yutaka OIWA <y.oiwa@aist.go.jp> Tue, 05 June 2012 05:28 UTC
Return-Path: <y.oiwa@aist.go.jp>
X-Original-To: http-auth@ietfa.amsl.com
Delivered-To: http-auth@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 19DBC21F875D for <http-auth@ietfa.amsl.com>; Mon, 4 Jun 2012 22:28:19 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -7.31
X-Spam-Level:
X-Spam-Status: No, score=-7.31 tagged_above=-999 required=5 tests=[AWL=-1.333, BAYES_00=-2.599, FM_FORGED_GMAIL=0.622, RCVD_IN_DNSWL_MED=-4]
Received: from mail.ietf.org ([12.22.58.30]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id 3falNwYlPqEa for <http-auth@ietfa.amsl.com>; Mon, 4 Jun 2012 22:28:17 -0700 (PDT)
Received: from na3sys010aog112.obsmtp.com (na3sys010aog112.obsmtp.com [74.125.245.92]) by ietfa.amsl.com (Postfix) with ESMTP id 4572C21F8757 for <http-auth@ietf.org>; Mon, 4 Jun 2012 22:28:17 -0700 (PDT)
Received: from mail-gg0-f172.google.com ([209.85.161.172]) (using TLSv1) by na3sys010aob112.postini.com ([74.125.244.12]) with SMTP ID DSNKT82Y8CGXiIRvtbX6kcV1gDLIg+pto/HT@postini.com; Mon, 04 Jun 2012 22:28:17 PDT
Received: by ggnc4 with SMTP id c4so3791946ggn.3 for <http-auth@ietf.org>; Mon, 04 Jun 2012 22:28:16 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=aist.go.jp; s=google; h=mime-version:in-reply-to:references:from:date:message-id:subject:to :content-type:content-transfer-encoding; bh=iaRgV4UWr/X4+Lfqn22TQpxFf9kZWPnIBWmG5N7nD6E=; b=Gbyu0j+fP1JbwSmiWdKV5pUjH1qe5rlrzmzEs3+RTDvxNxzoIrPcH2IdnOSSgSHEVP vf+czlgnE8L+4WvVghtroqDpgqSjiIvE8YQokJm7xg8CbZEY/pwmHo/0djEFO5fOevMt 00tTdXak0ffJuKBpmuyR8DLNG3J8RDhTh4JZY=
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=20120113; h=mime-version:in-reply-to:references:from:date:message-id:subject:to :content-type:content-transfer-encoding:x-gm-message-state; bh=iaRgV4UWr/X4+Lfqn22TQpxFf9kZWPnIBWmG5N7nD6E=; b=knrvXvICTn0QRmoS7XZGw/RAVa5uNrNY2i6gg33uYoYG+4DVsrhHNtzWYxcLySRiO+ MELdGdmRL2bRWfjbuLNjmPM5vwZYK/rIpbVR1tXICugD00nwFhCUzaD5enh21Smu8hGl TKV34aWWRTPMiBCeuvRfxN1l7XrTTu0QWiyBazV3C8L65tSHQJoomLF9MjhcS5Bt9qO/ lseJ2p6gMXGwuBuxmZ3B6wCXxqrm6e7lC6PlJWcwysQ2p7FSlxb2c5tcJ3l5tI2I7XOA m6iX8huH4WjrIVCddN3Rw8hNw0qCdIem7ziWIQAE8hux6iQOvT7OysqpkQHC5q3lkpRe xFgA==
Received: by 10.50.169.33 with SMTP id ab1mr716510igc.73.1338874096127; Mon, 04 Jun 2012 22:28:16 -0700 (PDT)
MIME-Version: 1.0
Received: by 10.50.7.98 with HTTP; Mon, 4 Jun 2012 22:27:56 -0700 (PDT)
In-Reply-To: <CAMeZVwuGYZqoZOH1hvc=-YWFKUizjMJmj+=c3ZkgswdYYP3pxw@mail.gmail.com>
References: <CAMeZVwuGYZqoZOH1hvc=-YWFKUizjMJmj+=c3ZkgswdYYP3pxw@mail.gmail.com>
From: Yutaka OIWA <y.oiwa@aist.go.jp>
Date: Tue, 05 Jun 2012 14:27:56 +0900
Message-ID: <CAMeZVwvgsMdY_EMyODzTAbZrWxp=GQpj_y=mLOZoyOx24-XevQ@mail.gmail.com>
To: HTTP Working Group <ietf-http-wg@w3.org>, "http-auth@ietf.org" <http-auth@ietf.org>
Content-Type: text/plain; charset="ISO-8859-1"
Content-Transfer-Encoding: quoted-printable
X-Gm-Message-State: ALoCoQnHrnk37cfm+PqvRtnyZ9t7xTc9syvnJmi/dlIPOgGN87kuaQHrSDNlEtaXxnNNhNk5LNIC
Subject: Re: [http-auth] [httpauth] Mutual authentication proposal
X-BeenThere: http-auth@ietf.org
X-Mailman-Version: 2.1.12
Precedence: list
List-Id: HTTP authentication methods <http-auth.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/http-auth>, <mailto:http-auth-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/http-auth>
List-Post: <mailto:http-auth@ietf.org>
List-Help: <mailto:http-auth-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/http-auth>, <mailto:http-auth-request@ietf.org?subject=subscribe>
X-List-Received-Date: Tue, 05 Jun 2012 05:28:19 -0000
Dear all, I created Wiki pages for my proposals: http://trac.tools.ietf.org/wg/httpbis/trac/wiki/HttpAuthProposals/MutualAuth http://trac.tools.ietf.org/wg/httpbis/trac/wiki/HttpAuthProposals/AuthExtension I hope you will feel the information helpful. Cheers, Yutaka 2012/6/4 Yutaka OIWA <y.oiwa@aist.go.jp>: > Dear all, > > with a few corrections from the May-21st draft, > I submitted the HTTP Mutual authentication draft as an httpbis proposal. > > The proposal consists of two parts: > > <http://www.ietf.org/id/draft-oiwa-httpbis-mutualauth-00.txt> > is the core proposal for HTTP Mutual authentication, > using RFC 2617 architecture. > > <http://www.ietf.org/id/draft-oiwa-httpbis-auth-extension-00.txt> > is the important companion draft for generic extensions > which makes HTTP authentication useful again with > many Web applications. > > The proposal is (both documents are) HTTP/1.1 compatible, and > as far as core HTTP request/response semantics are kept, > it should work with future HTTP/2.0, too. > > I will set up wiki pages for these around tomorrow or so. > It will include information on available reference implementations, > some more introductions and so on. > I hope you will enjoy the proposed solution. > > Following previous suggestions on http-auth, crypto primitive choices > are kept for future discussions. One of primitive candidates, > which is now for an "example" or "reference" purpose, > is available as an "individual" draft at > <http://tools.ietf.org/html/draft-oiwa-http-mutualauth-algo-02>. > To implement the core proposal now, please refer this, too. > > > P. S. > I also incremented the individual draft revisions for book-keeping purpose. > (One of these depends on the revision numbers embedded to the protocol). > Contents of these are exactly the same as httpbis-proposed versions. > > -- > Yutaka OIWA, Ph.D. Leader, Software Reliability Research Group > Research Institute for Secure Systems (RISEC) > National Institute of Advanced Industrial Science and Technology (AIST) > Mail addresses: <y.oiwa@aist.go.jp>, <yutaka@oiwa.jp> > OpenPGP: id[440546B5] fp[7C9F 723A 7559 3246 229D 3139 8677 9BD2 4405 46B5] -- Yutaka OIWA, Ph.D. Leader, Software Reliability Research Group Research Institute for Secure Systems (RISEC) National Institute of Advanced Industrial Science and Technology (AIST) Mail addresses: <y.oiwa@aist.go.jp>, <yutaka@oiwa.jp> OpenPGP: id[440546B5] fp[7C9F 723A 7559 3246 229D 3139 8677 9BD2 4405 46B5]
- [http-auth] [httpauth] Mutual authentication prop… Yutaka OIWA
- Re: [http-auth] [httpauth] Mutual authentication … Yutaka OIWA
- Re: [http-auth] [httpauth] Mutual authentication … Yutaka OIWA