Re: [http-auth] BoF in Atlanta

Lucy Lynch <llynch@civil-tongue.net> Fri, 12 October 2012 18:07 UTC

Return-Path: <llynch@civil-tongue.net>
X-Original-To: http-auth@ietfa.amsl.com
Delivered-To: http-auth@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id F21A521F8742 for <http-auth@ietfa.amsl.com>; Fri, 12 Oct 2012 11:07:25 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -102.599
X-Spam-Level:
X-Spam-Status: No, score=-102.599 tagged_above=-999 required=5 tests=[BAYES_00=-2.599, USER_IN_WHITELIST=-100]
Received: from mail.ietf.org ([64.170.98.30]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id odXkwmq9cogI for <http-auth@ietfa.amsl.com>; Fri, 12 Oct 2012 11:07:25 -0700 (PDT)
Received: from hiroshima.bogus.com (hiroshima.bogus.com [IPv6:2001:418:1::80]) by ietfa.amsl.com (Postfix) with ESMTP id 6B45621F852E for <http-auth@ietf.org>; Fri, 12 Oct 2012 11:07:25 -0700 (PDT)
Received: from hiroshima.bogus.com (localhost [127.0.0.1]) by hiroshima.bogus.com (8.14.3/8.14.3) with ESMTP id q9CI7CIk074398 (version=TLSv1/SSLv3 cipher=DHE-RSA-AES256-GCM-SHA384 bits=256 verify=NOT); Fri, 12 Oct 2012 11:07:12 -0700 (PDT) (envelope-from llynch@civil-tongue.net)
Received: from localhost (llynch@localhost) by hiroshima.bogus.com (8.14.3/8.14.3/Submit) with ESMTP id q9CI7Bkc074392; Fri, 12 Oct 2012 11:07:11 -0700 (PDT) (envelope-from llynch@civil-tongue.net)
Date: Fri, 12 Oct 2012 11:07:11 -0700
From: Lucy Lynch <llynch@civil-tongue.net>
X-X-Sender: llynch@hiroshima.bogus.com
To: Yoav Nir <ynir@checkpoint.com>
In-Reply-To: <8AEEA404-CC7C-4487-BE7D-99CBAA8BC48F@checkpoint.com>
Message-ID: <alpine.BSF.2.00.1210121102540.14872@hiroshima.bogus.com>
References: <8AEEA404-CC7C-4487-BE7D-99CBAA8BC48F@checkpoint.com>
User-Agent: Alpine 2.00 (BSF 1167 2008-08-23)
MIME-Version: 1.0
Content-Type: TEXT/PLAIN; charset="UTF-8"; format="flowed"
Content-Transfer-Encoding: 8bit
Cc: "http-auth@ietf.org" <http-auth@ietf.org>
Subject: Re: [http-auth] BoF in Atlanta
X-BeenThere: http-auth@ietf.org
X-Mailman-Version: 2.1.12
Precedence: list
List-Id: HTTP authentication methods <http-auth.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/http-auth>, <mailto:http-auth-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/http-auth>
List-Post: <mailto:http-auth@ietf.org>
List-Help: <mailto:http-auth-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/http-auth>, <mailto:http-auth-request@ietf.org?subject=subscribe>
X-List-Received-Date: Fri, 12 Oct 2012 18:07:26 -0000

On Fri, 5 Oct 2012, Yoav Nir wrote:

> Hi all
>
> The preliminary agenda is now posted at https://datatracker.ietf.org/meeting/85/agenda.txt , as well as at http://tools.ietf.org/agenda/85/
>
> Either way, we are currently scheduled to meet at 13:00 on Wednesday, 7-Nov, in Grand Ballroom D. We have 1.5 hours to go. Note that we cannot guarantee that the scheduling will not change, but it is not likely to, and we'll do our best to keep it on Wednesday.
>
> We propose the following agenda:
> - 13:00-13:05 Blue sheets, Note Well and agenda bashing
> - 13:05-13:20 Introduction and problem statement
> - 13:20-14:00 (Short!!!) presentations on the candidates
> - 14:00-14:30 Charter hack, and the usual BoF questions
>
> People with candidate documents, who wish to present at the session 
> should do the following:

just as an aide mémoire the following documents have been mentioned
on the BOF thread:

- draft-oiwa-*
- draft-farrell-httpbis-hoba
- draft-melnikov-httpbis-scram-auth
- draft-williams-httpbis-auth-classification
- draft-ahrens-httpbis-digest-auth-update (sean)

- Note: Actually, please include draft-williams-http-rest-auth
(RESTauth, successor to REST-GSS) and remove
draft-williams-httpbis-auth-classification. (nico)

- What about Negotiate? Its already an informational RFC but I have
a hunch that work has been done on it since it was published.
Somebody should ask (nudge-nudge) MSFT... (leif)

- http://www.w3.org/2012/webcrypto/WebCryptoAPI/ (harry)

- There is a proposal in HTML5 for enhancing form support of HTTP which
includes 'mapping' username\passwords into the same XHR.open()
functionality. Also included is a method for clearing the auth cache
on successful response which integrates with a HTTP request for server
notification and cookie clearing:
http://www.w3.org/wiki/User:Cjones/ISSUE-195 (cameron)

Also -

- active discussion on I18n but no documents listed

- Lucy

> - Notify the chairs sooner rather than later
> - Prepare a short presentation.
>  * You will only have a few minutes each and want to leave time for Q&A, so plan on no more than 5 minutes of presso.
>  * You don't each need to explain the problem. We'll do it in the introduction.
>  * You don't each need to explain what is the "HTTP authentication framework".
> - Send slides to the chairs (PDF or PPT format) early - no later than Monday the 5th.
> - If you would like to present, but will not be at the meeting, please contact us early so that we can arrange remote presentation or presentation by proxy.
>
> See you all there
>
> Derek & Yoav
>
> _______________________________________________
> http-auth mailing list
> http-auth@ietf.org
> https://www.ietf.org/mailman/listinfo/http-auth
>