Op-sec simplification

Martin Thomson <martin.thomson@gmail.com> Mon, 31 October 2016 01:09 UTC

Return-Path: <ietf-http-wg-request+bounce-httpbisa-archive-bis2juki=lists.ie@listhub.w3.org>
X-Original-To: ietfarch-httpbisa-archive-bis2Juki@ietfa.amsl.com
Delivered-To: ietfarch-httpbisa-archive-bis2Juki@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id D4CB2129448 for <ietfarch-httpbisa-archive-bis2Juki@ietfa.amsl.com>; Sun, 30 Oct 2016 18:09:24 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -8.498
X-Spam-Level:
X-Spam-Status: No, score=-8.498 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, HEADER_FROM_DIFFERENT_DOMAINS=0.001, RCVD_IN_DNSWL_HI=-5, RP_MATCHES_RCVD=-1.497, SPF_HELO_PASS=-0.001, SPF_PASS=-0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (2048-bit key) header.d=gmail.com
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id pA1nEq7LBF-5 for <ietfarch-httpbisa-archive-bis2Juki@ietfa.amsl.com>; Sun, 30 Oct 2016 18:09:23 -0700 (PDT)
Received: from frink.w3.org (frink.w3.org [128.30.52.56]) (using TLSv1.2 with cipher DHE-RSA-AES128-SHA (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 9765C129435 for <httpbisa-archive-bis2Juki@lists.ietf.org>; Sun, 30 Oct 2016 18:09:23 -0700 (PDT)
Received: from lists by frink.w3.org with local (Exim 4.80) (envelope-from <ietf-http-wg-request@listhub.w3.org>) id 1c1129-00023G-RM for ietf-http-wg-dist@listhub.w3.org; Mon, 31 Oct 2016 01:05:05 +0000
Resent-Date: Mon, 31 Oct 2016 01:05:05 +0000
Resent-Message-Id: <E1c1129-00023G-RM@frink.w3.org>
Received: from titan.w3.org ([128.30.52.76]) by frink.w3.org with esmtps (TLS1.2:RSA_AES_128_CBC_SHA1:128) (Exim 4.80) (envelope-from <martin.thomson@gmail.com>) id 1c1121-0000M7-SW for ietf-http-wg@listhub.w3.org; Mon, 31 Oct 2016 01:04:57 +0000
Received: from mail-qk0-f171.google.com ([209.85.220.171]) by titan.w3.org with esmtps (TLS1.2:ECDHE_RSA_AES_128_GCM_SHA256:128) (Exim 4.84_2) (envelope-from <martin.thomson@gmail.com>) id 1c111w-00040Q-0h for ietf-http-wg@w3.org; Mon, 31 Oct 2016 01:04:52 +0000
Received: by mail-qk0-f171.google.com with SMTP id o68so147121467qkf.3 for <ietf-http-wg@w3.org>; Sun, 30 Oct 2016 18:04:31 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20120113; h=mime-version:from:date:message-id:subject:to; bh=J0phPu38qC/v3qNO7+/FHa8DS1sDt+TBEWDGl2P6Aj8=; b=GG45DQRrdX104rTjo05Va5nfcRD43vuSG/Vu0crgxkFetcepTJRgRbAcB6gSR2x08H 5Jp/wXijQ5zndpWlzAdRHil9FlsljlsISrWUyIPUdyFgZ65+lr/K//5x0xVN5skpLbAN 34n51r7K7DDSoiSy8BDNHprMW02IXk6pX79Ovo+N5ig4AwZzbW9KzLMnjET1uc5xWBz8 Z6QvSnlxmBX9UrL+1EzHlhl4Azp2gRotlksB/b8XnYPGfx9hYvaLw7drII58TjOtnklm Al8wtsKa3zIWaUPL1R0yw2Pce5NXU6G6rgvIspT3AwWHqBCIPeO3shC37XKAo51LmIn6 LwaA==
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20130820; h=x-gm-message-state:mime-version:from:date:message-id:subject:to; bh=J0phPu38qC/v3qNO7+/FHa8DS1sDt+TBEWDGl2P6Aj8=; b=k3vww6iZaszmsvf+rT7fhbyuCIQ5R376k0s+htEIk1JAqvqz/+tLmJ2usdTXwjBnDr 33G1kqHdxVtkCxONB9tj0fNGPiG2xyX4zPuMFKfc6jv2B2q3wdGtbGBjp4vHIJpyoOqZ RDzumE4SBJPdN42QovkxgSc8j13mX5RPrRRjyeYgCavBBkoEbDBAIrPtNeZZqIKdwlkp 939YzH/ncmX5QoqI4uSq+4p5FDHB9k9a9818vdvWUZgj6bfpXkQWS7Jpyhk2zTgrcZuC /n95y3rKx8VPVO30X+DpxIoHlkN3yELF7QPqqkw3XMSFgupxYsh7Lq01rVIv4ZI9jAoR xc7w==
X-Gm-Message-State: ABUngve+CSScdNckqACrpCnv7VBzdYEYFAvwlUu9i5aq0z8b5EytWv3HcLMKErn2kH/faux9/JpD+RhBhm4D6Q==
X-Received: by 10.55.165.16 with SMTP id o16mr23340535qke.5.1477875866130; Sun, 30 Oct 2016 18:04:26 -0700 (PDT)
MIME-Version: 1.0
Received: by 10.140.85.7 with HTTP; Sun, 30 Oct 2016 18:04:25 -0700 (PDT)
From: Martin Thomson <martin.thomson@gmail.com>
Date: Mon, 31 Oct 2016 12:04:25 +1100
Message-ID: <CABkgnnX+Eu6hRnWLRU3D=vUpVmSo8zH4=8zk7d=Y7-CZcGa=nQ@mail.gmail.com>
To: HTTP Working Group <ietf-http-wg@w3.org>
Content-Type: text/plain; charset="UTF-8"
Received-SPF: pass client-ip=209.85.220.171; envelope-from=martin.thomson@gmail.com; helo=mail-qk0-f171.google.com
X-W3C-Hub-Spam-Status: No, score=-6.0
X-W3C-Hub-Spam-Report: AWL=-0.018, BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, FREEMAIL_FROM=0.001, RCVD_IN_DNSWL_NONE=-0.0001, RCVD_IN_MSPIKE_H2=-0.001, SPF_PASS=-0.001, W3C_AA=-1, W3C_DB=-1, W3C_IRA=-1, W3C_WL=-1
X-W3C-Scan-Sig: titan.w3.org 1c111w-00040Q-0h 2e4a512eadb2b0228ee53b2aa2d77a1e
X-Original-To: ietf-http-wg@w3.org
Subject: Op-sec simplification
Archived-At: <http://www.w3.org/mid/CABkgnnX+Eu6hRnWLRU3D=vUpVmSo8zH4=8zk7d=Y7-CZcGa=nQ@mail.gmail.com>
Resent-From: ietf-http-wg@w3.org
X-Mailing-List: <ietf-http-wg@w3.org> archive/latest/32742
X-Loop: ietf-http-wg@w3.org
Resent-Sender: ietf-http-wg-request@w3.org
Precedence: list
List-Id: <ietf-http-wg.w3.org>
List-Help: <http://www.w3.org/Mail/>
List-Post: <mailto:ietf-http-wg@w3.org>
List-Unsubscribe: <mailto:ietf-http-wg-request@w3.org?subject=unsubscribe>

In the spirit of continuing simplification, here's a PR on the
opportunistic security draft:

https://github.com/httpwg/http-extensions/pull/254

The main changes:

 - the .well-known resource is a flat list of origins
 - the client only needs to acquire a .wk from the secured server
 - the draft explicitly allows HTTP/1.1

As before, I apologize for short notice, but I plan to merge this
fairly soon and submit a draft revision.  Thanks to the magic of git,
any mistakes I've made - either in reading where consensus was headed,
or in editing - can be reverted easily.