Re: Call for adoption: draft-reschke-httpauth-auth-info-00
Amos Jeffries <squid3@treenet.co.nz> Fri, 30 January 2015 21:50 UTC
Return-Path: <ietf-http-wg-request+bounce-httpbisa-archive-bis2juki=lists.ietf.org@listhub.w3.org>
X-Original-To: ietfarch-httpbisa-archive-bis2Juki@ietfa.amsl.com
Delivered-To: ietfarch-httpbisa-archive-bis2Juki@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 90C381A7026 for <ietfarch-httpbisa-archive-bis2Juki@ietfa.amsl.com>; Fri, 30 Jan 2015 13:50:31 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -6.912
X-Spam-Level:
X-Spam-Status: No, score=-6.912 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, RCVD_IN_DNSWL_HI=-5, SPF_HELO_PASS=-0.001, SPF_PASS=-0.001, T_RP_MATCHES_RCVD=-0.01] autolearn=ham
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id zIPsynKTIhPs for <ietfarch-httpbisa-archive-bis2Juki@ietfa.amsl.com>; Fri, 30 Jan 2015 13:50:27 -0800 (PST)
Received: from frink.w3.org (frink.w3.org [128.30.52.56]) (using TLSv1.2 with cipher DHE-RSA-AES128-SHA (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id DDE4C1A07BE for <httpbisa-archive-bis2Juki@lists.ietf.org>; Fri, 30 Jan 2015 13:50:27 -0800 (PST)
Received: from lists by frink.w3.org with local (Exim 4.80) (envelope-from <ietf-http-wg-request@listhub.w3.org>) id 1YHJOO-0003WD-16 for ietf-http-wg-dist@listhub.w3.org; Fri, 30 Jan 2015 21:46:20 +0000
Resent-Date: Fri, 30 Jan 2015 21:46:20 +0000
Resent-Message-Id: <E1YHJOO-0003WD-16@frink.w3.org>
Received: from maggie.w3.org ([128.30.52.39]) by frink.w3.org with esmtp (Exim 4.80) (envelope-from <squid3@treenet.co.nz>) id 1YHJOJ-0003VS-2i for ietf-http-wg@listhub.w3.org; Fri, 30 Jan 2015 21:46:15 +0000
Received: from 121-99-228-82.static.orcon.net.nz ([121.99.228.82] helo=treenet.co.nz) by maggie.w3.org with esmtp (Exim 4.72) (envelope-from <squid3@treenet.co.nz>) id 1YHJO7-0007TW-9i for ietf-http-wg@w3.org; Fri, 30 Jan 2015 21:46:15 +0000
Received: from [192.168.2.25] (121-98-154-105.bng1.mdr.orcon.net.nz [121.98.154.105]) by treenet.co.nz (Postfix) with ESMTP id 39EB3E6D9F for <ietf-http-wg@w3.org>; Sat, 31 Jan 2015 10:45:30 +1300 (NZDT)
Message-ID: <54CBFB6E.9070800@treenet.co.nz>
Date: Sat, 31 Jan 2015 10:45:18 +1300
From: Amos Jeffries <squid3@treenet.co.nz>
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; rv:31.0) Gecko/20100101 Thunderbird/31.4.0
MIME-Version: 1.0
To: ietf-http-wg@w3.org
References: <1BA93C83-91E9-4E7D-88CE-ADC8C39091C6@mnot.net> <CABkgnnXhg55e5N2O8yZJpTbz4qSm0-KpVApyDha_snetrFqvMw@mail.gmail.com> <54C9E419.1070407@greenbytes.de> <54CB7A4F.7090402@crf.canon.fr> <54CB7F48.4060800@gmx.de> <CAGL6epLUkFi6amhExWASqjS5Mvs1MVTJ1hDmhBTncznQV1GK1A@mail.gmail.com>
In-Reply-To: <CAGL6epLUkFi6amhExWASqjS5Mvs1MVTJ1hDmhBTncznQV1GK1A@mail.gmail.com>
Content-Type: text/plain; charset="windows-1252"
Content-Transfer-Encoding: 7bit
Received-SPF: pass client-ip=121.99.228.82; envelope-from=squid3@treenet.co.nz; helo=treenet.co.nz
X-W3C-Hub-Spam-Status: No, score=-3.4
X-W3C-Hub-Spam-Report: AWL=-1.544, BAYES_00=-1.9, SPF_HELO_PASS=-0.001, SPF_PASS=-0.001, TVD_RCVD_IP=0.001
X-W3C-Scan-Sig: maggie.w3.org 1YHJO7-0007TW-9i 4840384cf46601e419850d1fe14a4197
X-Original-To: ietf-http-wg@w3.org
Subject: Re: Call for adoption: draft-reschke-httpauth-auth-info-00
Archived-At: <http://www.w3.org/mid/54CBFB6E.9070800@treenet.co.nz>
Resent-From: ietf-http-wg@w3.org
X-Mailing-List: <ietf-http-wg@w3.org> archive/latest/28717
X-Loop: ietf-http-wg@w3.org
Resent-Sender: ietf-http-wg-request@w3.org
Precedence: list
List-Id: <ietf-http-wg.w3.org>
List-Help: <http://www.w3.org/Mail/>
List-Post: <mailto:ietf-http-wg@w3.org>
List-Unsubscribe: <mailto:ietf-http-wg-request@w3.org?subject=unsubscribe>
On 31/01/2015 3:11 a.m., Rifaat Shekh-Yusef wrote: > Why would we restrict the use of this header in future protocols based on > the Digest usage of this header? > What would be the harm in allowing the new protocol that uses the header to > restrict it usage? > Information leaks. User credentials and secure token are potentially stored in here, as are details specific to the internal operation of the security algorithm selected/negotiated. This header is clearly security related and very likely will be used to transmit confidential information at some point. At the very least the security, privacy, cacheability, and hop-by-hop re-usability behaviours of this header need to be explicitly bounded. i.e. recipients only implementing this spec need to be made aware of the *potential* for critical information to be contained in traffic from future schemes they do not implement already. I expect this header to be used as a way to indicate implicit non-cacheable authenticated response from out-of-band authentitication (HTML login, federated, session resumption, connection auth with no request credentials) - a direct way to kill^H^H contain auth Cookie data Also as a way to pass Kerberos or NTLM username/group and TTL for the credentials back to intermediaries without requiring them to participate in the auth. Each of these has different needs when it comes to security, but the one thing they have in common is that they are still sensitive and related to some previous possibly out-of-band, possibly incomplete authentication process the recipient has nothing to do with. I'm also fairly sure there are cases where no sensitive information at all is transmitted, but security protection is not to protect against best-case scenarios. Amos
- Re: Call for adoption: draft-reschke-httpauth-aut… Julian Reschke
- Re: Call for adoption: draft-reschke-httpauth-aut… Alexey Melnikov
- Call for adoption: draft-reschke-httpauth-auth-in… Mark Nottingham
- Re: Call for adoption: draft-reschke-httpauth-aut… Martin Thomson
- Re: Call for adoption: draft-reschke-httpauth-aut… Yutaka OIWA
- Re: Call for adoption: draft-reschke-httpauth-aut… Amos Jeffries
- Re: Call for adoption: draft-reschke-httpauth-aut… Mark Nottingham
- Re: Call for adoption: draft-reschke-httpauth-aut… Julian Reschke
- Re: Call for adoption: draft-reschke-httpauth-aut… Yutaka OIWA
- Re: Call for adoption: draft-reschke-httpauth-aut… Hervé Ruellan
- Re: Call for adoption: draft-reschke-httpauth-aut… Julian Reschke
- Re: Call for adoption: draft-reschke-httpauth-aut… Rifaat Shekh-Yusef
- Re: Call for adoption: draft-reschke-httpauth-aut… Amos Jeffries
- Re: Call for adoption: draft-reschke-httpauth-aut… Bjoern Hoehrmann
- Re: Call for adoption: draft-reschke-httpauth-aut… Julian Reschke
- Re: Call for adoption: draft-reschke-httpauth-aut… Bjoern Hoehrmann
- Re: Call for adoption: draft-reschke-httpauth-aut… Mark Nottingham
- Re: Call for adoption: draft-reschke-httpauth-aut… Julian Reschke
- Re: Call for adoption: draft-reschke-httpauth-aut… Rifaat Shekh-Yusef
- Re: Call for adoption: draft-reschke-httpauth-aut… Julian Reschke