[http-auth] [Mutual] (due Aug 28) Mutual auth issues (part 1)

Yutaka OIWA <y.oiwa@aist.go.jp> Thu, 13 August 2015 02:17 UTC

Return-Path: <y.oiwa@aist.go.jp>
X-Original-To: http-auth@ietfa.amsl.com
Delivered-To: http-auth@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id C3E1B1B2F3D for <http-auth@ietfa.amsl.com>; Wed, 12 Aug 2015 19:17:27 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.901
X-Spam-Level:
X-Spam-Status: No, score=-1.901 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, RCVD_IN_DNSWL_NONE=-0.0001, SPF_PASS=-0.001] autolearn=ham
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id Tb52pphJ6UON for <http-auth@ietfa.amsl.com>; Wed, 12 Aug 2015 19:17:26 -0700 (PDT)
Received: from APC01-PU1-obe.outbound.protection.outlook.com (mail-pu1apc01on0068.outbound.protection.outlook.com [104.47.126.68]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 8217C1B2F3C for <http-auth@ietf.org>; Wed, 12 Aug 2015 19:17:25 -0700 (PDT)
Received: from OS1PR01MB0200.jpnprd01.prod.outlook.com (10.161.230.139) by OS1PR01MB0200.jpnprd01.prod.outlook.com (10.161.230.139) with Microsoft SMTP Server (TLS) id 15.1.225.19; Thu, 13 Aug 2015 02:17:22 +0000
Received: from OS1PR01MB0200.jpnprd01.prod.outlook.com ([10.161.230.139]) by OS1PR01MB0200.jpnprd01.prod.outlook.com ([10.161.230.139]) with mapi id 15.01.0225.018; Thu, 13 Aug 2015 02:17:22 +0000
From: Yutaka OIWA <y.oiwa@aist.go.jp>
To: "http-auth@ietf.org" <http-auth@ietf.org>
Thread-Topic: [Mutual] (due Aug 28) Mutual auth issues (part 1)
Thread-Index: AdDVbU8S0YCBqDw+RAOYwINxg2v0vg==
Date: Thu, 13 Aug 2015 02:17:22 +0000
Message-ID: <OS1PR01MB0200719F947ACCD628FF3D7DA07D0@OS1PR01MB0200.jpnprd01.prod.outlook.com>
Accept-Language: ja-JP, en-US
Content-Language: ja-JP
X-MS-Has-Attach:
X-MS-TNEF-Correlator:
authentication-results: spf=none (sender IP is ) smtp.mailfrom=y.oiwa@aist.go.jp;
x-originating-ip: [150.29.157.99]
x-microsoft-exchange-diagnostics: 1; OS1PR01MB0200; 5:EOnCM73dQGFwyggxd1nRQbAorgInB19jzVT5K2JfmOrlEE2qLKdbY6KJaI4FTDLO2qe/ShwMkftfuEamMg7TVLWPwGClX4/VeYgbTJYqhu9NPHEo48LrQ1xA/NjDASlH2NP17LNgZEMiMZ2pFjS98w==; 24:0Lhx9jgOPhSrmJ0M/dBpe8MSDwX6XTBh7ACfxKzHwN7FKEZTF2Ak+PPAHgYHv0yWwH1jyHl9CX4JlCrZqi4mUwNMJ/Jh+MWInUCFtDn0j1U=; 20:VDAzullEao6nE0xgfFvW8BFRe8CjA6E0QLjbmYUPD2iW+dGYhH/ww30w0fFyvYSLsSTF0/UK7nWmpNz/Z7UZbw==
x-microsoft-antispam: UriScan:;BCL:0;PCL:0;RULEID:;SRVR:OS1PR01MB0200;
x-microsoft-antispam-prvs: <OS1PR01MB0200A381F9AA23D9BC42AFD5A07D0@OS1PR01MB0200.jpnprd01.prod.outlook.com>
x-exchange-antispam-report-test: UriScan:;
x-exchange-antispam-report-cfa-test: BCL:0; PCL:0; RULEID:(5005006)(3002001); SRVR:OS1PR01MB0200; BCL:0; PCL:0; RULEID:; SRVR:OS1PR01MB0200;
x-forefront-prvs: 0667289FF8
x-forefront-antispam-report: SFV:NSPM; SFS:(10009020)(6009001)(189002)(199003)(87936001)(105586002)(2656002)(106356001)(2351001)(2501003)(50986999)(64706001)(86362001)(229853001)(40100003)(66066001)(5003600100002)(10400500002)(110136002)(189998001)(76576001)(92566002)(5002640100001)(101416001)(107886002)(5001960100002)(54356999)(77156002)(46102003)(19580395003)(74482002)(5001830100001)(5001860100001)(4001540100001)(5001920100001)(81156007)(15975445007)(68736005)(97736004)(62966003)(450100001)(74316001)(19580405001)(33656002)(122556002)(77096005)(2900100001)(102836002)(4001430100001); DIR:OUT; SFP:1101; SCL:1; SRVR:OS1PR01MB0200; H:OS1PR01MB0200.jpnprd01.prod.outlook.com; FPR:; SPF:None; PTR:InfoNoRecords; MX:1; A:1; LANG:en;
received-spf: None (protection.outlook.com: aist.go.jp does not designate permitted sender hosts)
spamdiagnosticoutput: 1:23
spamdiagnosticmetadata: NSPM
Content-Type: text/plain; charset="us-ascii"
Content-Transfer-Encoding: quoted-printable
MIME-Version: 1.0
X-OriginatorOrg: aist.go.jp
X-MS-Exchange-CrossTenant-originalarrivaltime: 13 Aug 2015 02:17:22.7527 (UTC)
X-MS-Exchange-CrossTenant-fromentityheader: Hosted
X-MS-Exchange-CrossTenant-id: 18a7fec8-652f-409b-8369-272d9ce80620
X-MS-Exchange-Transport-CrossTenantHeadersStamped: OS1PR01MB0200
Archived-At: <http://mailarchive.ietf.org/arch/msg/http-auth/WNLMw3l4zEjKGH5HR6Y-F-7Krck>
Cc: Mutual auth contact <mutual-auth-contact-ml@aist.go.jp>
Subject: [http-auth] [Mutual] (due Aug 28) Mutual auth issues (part 1)
X-BeenThere: http-auth@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: HTTP authentication methods <http-auth.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/http-auth>, <mailto:http-auth-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/http-auth/>
List-Post: <mailto:http-auth@ietf.org>
List-Help: <mailto:http-auth-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/http-auth>, <mailto:http-auth-request@ietf.org?subject=subscribe>
X-List-Received-Date: Thu, 13 Aug 2015 02:17:28 -0000

Dear all HTTPAUTH WG members,

I'd like to have your comments on the following three issues.
Please make your initial response *before August 28*, or the
WG will consider these issues as successfully resolved
(as the WG Chair said in the Prague meeting.)

We appreciate your responses in any of the following form:
  * on the github issue tracking system (comments, pull-request etc.)
  * on this mailing list
  * on the private email
We'll summarize comments on the medium above, and send it to this
mailing list.  (Please be understood that your comments on the
private email may be included in the summary and published.)


==== draft-ietf-httpauth-mutual ====

= Section 3.1 =

[P1] Is adoption of RFC5987 OK?
https://github.com/yoiwa/httpauth-mutual/issues/1

[P2] The encoding is fixed to UTF-8, without any language.
     (justification: it is not an on-line negotiable parameter,
      and the new protocol does not need to consider older
      clients.)
https://github.com/yoiwa/httpauth-mutual/issues/2

= Section 4: Messages =

[P3] Are the reserved parameter names making sense?
https://github.com/yoiwa/httpauth-mutual/issues/3


Thank you for your cooperation.

-- 
Yutaka OIWA, Ph.D.               Cyber Physical Architecture Research Group
                                  Information Technology Research Institute
    National Institute of Advanced Industrial Science and Technology (AIST)
                      Mail addresses: <y.oiwa@aist.go.jp>, <yutaka@oiwa.jp>
OpenPGP: id[440546B5] fp[7C9F 723A 7559 3246 229D  3139 8677 9BD2 4405 46B5]