Re: I-D Action: draft-ietf-httpbis-message-signatures-00.txt

Justin Richer <jricher@mit.edu> Tue, 14 April 2020 15:24 UTC

Return-Path: <ietf-http-wg-request+bounce-httpbisa-archive-bis2juki=lists.ie@listhub.w3.org>
X-Original-To: ietfarch-httpbisa-archive-bis2Juki@ietfa.amsl.com
Delivered-To: ietfarch-httpbisa-archive-bis2Juki@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 27BEC3A0908 for <ietfarch-httpbisa-archive-bis2Juki@ietfa.amsl.com>; Tue, 14 Apr 2020 08:24:37 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.652
X-Spam-Level:
X-Spam-Status: No, score=-2.652 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, HEADER_FROM_DIFFERENT_DOMAINS=0.248, MAILING_LIST_MULTI=-1, SPF_PASS=-0.001, URIBL_BLOCKED=0.001] autolearn=ham autolearn_force=no
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id CxtDtVoCO-n8 for <ietfarch-httpbisa-archive-bis2Juki@ietfa.amsl.com>; Tue, 14 Apr 2020 08:24:35 -0700 (PDT)
Received: from lyra.w3.org (lyra.w3.org [128.30.52.18]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 559B13A0A3D for <httpbisa-archive-bis2Juki@lists.ietf.org>; Tue, 14 Apr 2020 08:24:22 -0700 (PDT)
Received: from lists by lyra.w3.org with local (Exim 4.92) (envelope-from <ietf-http-wg-request@listhub.w3.org>) id 1jONNd-0004ct-Mb for ietf-http-wg-dist@listhub.w3.org; Tue, 14 Apr 2020 15:21:41 +0000
Resent-Date: Tue, 14 Apr 2020 15:21:41 +0000
Resent-Message-Id: <E1jONNd-0004ct-Mb@lyra.w3.org>
Received: from mimas.w3.org ([128.30.52.79]) by lyra.w3.org with esmtps (TLS1.3:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.92) (envelope-from <jricher@mit.edu>) id 1jONNd-0004cB-7g for ietf-http-wg@listhub.w3.org; Tue, 14 Apr 2020 15:21:41 +0000
Received: from outgoing-auth-1.mit.edu ([18.9.28.11] helo=outgoing.mit.edu) by mimas.w3.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.92) (envelope-from <jricher@mit.edu>) id 1jONNb-0001rx-3S for ietf-http-wg@w3.org; Tue, 14 Apr 2020 15:21:41 +0000
Received: from [192.168.1.13] (static-71-174-62-56.bstnma.fios.verizon.net [71.174.62.56]) (authenticated bits=0) (User authenticated as jricher@ATHENA.MIT.EDU) by outgoing.mit.edu (8.14.7/8.12.4) with ESMTP id 03EFLSPX024441 (version=TLSv1/SSLv3 cipher=DHE-RSA-AES256-GCM-SHA384 bits=256 verify=NOT) for <ietf-http-wg@w3.org>; Tue, 14 Apr 2020 11:21:28 -0400
From: Justin Richer <jricher@mit.edu>
Content-Type: text/plain; charset="utf-8"
Content-Transfer-Encoding: quoted-printable
Mime-Version: 1.0 (Mac OS X Mail 13.4 \(3608.80.23.2.2\))
Date: Tue, 14 Apr 2020 11:21:27 -0400
References: <158656012348.3496.5576237503432849190@ietfa.amsl.com>
To: HTTP Working Group <ietf-http-wg@w3.org>
In-Reply-To: <158656012348.3496.5576237503432849190@ietfa.amsl.com>
Message-Id: <178BA71D-57D4-4DF1-8F69-ED886E933102@mit.edu>
X-Mailer: Apple Mail (2.3608.80.23.2.2)
X-W3C-Hub-Spam-Status: No, score=-10.2
X-W3C-Hub-Spam-Report: BAYES_00=-1.9, RCVD_IN_DNSWL_MED=-2.3, SPF_HELO_NONE=0.001, SPF_PASS=-0.001, W3C_AA=-1, W3C_IRA=-1, W3C_IRR=-3, W3C_WL=-1
X-W3C-Scan-Sig: mimas.w3.org 1jONNb-0001rx-3S 771ce46b7a57c60066824dcd836026a4
X-Original-To: ietf-http-wg@w3.org
Subject: Re: I-D Action: draft-ietf-httpbis-message-signatures-00.txt
Archived-At: <https://www.w3.org/mid/178BA71D-57D4-4DF1-8F69-ED886E933102@mit.edu>
Resent-From: ietf-http-wg@w3.org
X-Mailing-List: <ietf-http-wg@w3.org> archive/latest/37502
X-Loop: ietf-http-wg@w3.org
Resent-Sender: ietf-http-wg-request@w3.org
Precedence: list
List-Id: <ietf-http-wg.w3.org>
List-Help: <https://www.w3.org/Mail/>
List-Post: <mailto:ietf-http-wg@w3.org>
List-Unsubscribe: <mailto:ietf-http-wg-request@w3.org?subject=unsubscribe>

A note to the WG: This draft is a copy of the ID that Annabelle had previously put together for the consensus call. We are now working on translating it into the the Markdown format and starting on the changes discussed within the document. 

Thanks to everyone who’s commented so far, we’ll be starting to work on actual issues once we have things in the right format and moved to the right repository within the HTTP WG. 

 — Justin

> On Apr 10, 2020, at 7:08 PM, internet-drafts@ietf.org wrote:
> 
> 
> A New Internet-Draft is available from the on-line Internet-Drafts directories.
> This draft is a work item of the HTTP WG of the IETF.
> 
>        Title           : Signing HTTP Messages
>        Authors         : Annabelle Backman
>                          Justin Richer
>                          Manu Sporny
> 	Filename        : draft-ietf-httpbis-message-signatures-00.txt
> 	Pages           : 38
> 	Date            : 2020-04-10
> 
> Abstract:
>   This document describes a mechanism for creating, encoding, and
>   verifying digital signatures or message authentication codes over
>   content within an HTTP message.  This mechanism supports use cases
>   where the full HTTP message may not be known to the signer, and where
>   the message may be transformed (e.g., by intermediaries) before
>   reaching the verifier.
> 
> 
> The IETF datatracker status page for this draft is:
> https://datatracker.ietf.org/doc/draft-ietf-httpbis-message-signatures/
> 
> There are also htmlized versions available at:
> https://tools.ietf.org/html/draft-ietf-httpbis-message-signatures-00
> https://datatracker.ietf.org/doc/html/draft-ietf-httpbis-message-signatures-00
> 
> 
> Please note that it may take a couple of minutes from the time of submission
> until the htmlized version and diff are available at tools.ietf.org.
> 
> Internet-Drafts are also available by anonymous FTP at:
> ftp://ftp.ietf.org/internet-drafts/
> 
> 
>