I-D Action: draft-ietf-httpbis-unprompted-auth-06.txt
internet-drafts@ietf.org Wed, 24 January 2024 00:47 UTC
Return-Path: <ietf-http-wg-request+bounce-httpbisa-archive-bis2juki=ietf.org@listhub.w3.org>
X-Original-To: ietfarch-httpbisa-archive-bis2Juki@ietfa.amsl.com
Delivered-To: ietfarch-httpbisa-archive-bis2Juki@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id BA5B9C14F748 for <ietfarch-httpbisa-archive-bis2Juki@ietfa.amsl.com>; Tue, 23 Jan 2024 16:47:37 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -7.656
X-Spam-Level:
X-Spam-Status: No, score=-7.656 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, HEADER_FROM_DIFFERENT_DOMAINS=0.249, MAILING_LIST_MULTI=-1, RCVD_IN_DNSWL_HI=-5, RCVD_IN_MSPIKE_H5=0.001, RCVD_IN_MSPIKE_WL=0.001, RCVD_IN_ZEN_BLOCKED_OPENDNS=0.001, SPF_PASS=-0.001, T_SCC_BODY_TEXT_LINE=-0.01, URIBL_BLOCKED=0.001, URIBL_DBL_BLOCKED_OPENDNS=0.001, URIBL_ZEN_BLOCKED_OPENDNS=0.001] autolearn=ham autolearn_force=no
Received: from mail.ietf.org ([50.223.129.194]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id Tw5p6tWIaldP for <ietfarch-httpbisa-archive-bis2Juki@ietfa.amsl.com>; Tue, 23 Jan 2024 16:47:34 -0800 (PST)
Received: from lyra.w3.org (lyra.w3.org [128.30.52.18]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange ECDHE (P-256) server-signature RSA-PSS (2048 bits) server-digest SHA256) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 0F306C14F6FC for <httpbisa-archive-bis2Juki@ietf.org>; Tue, 23 Jan 2024 16:47:34 -0800 (PST)
Received: from lists by lyra.w3.org with local (Exim 4.94.2) (envelope-from <ietf-http-wg-request@listhub.w3.org>) id 1rSROq-005PDE-OG for ietf-http-wg-dist@listhub.w3.org; Wed, 24 Jan 2024 00:45:52 +0000
Resent-Date: Wed, 24 Jan 2024 00:45:52 +0000
Resent-Message-Id: <E1rSROq-005PDE-OG@lyra.w3.org>
Received: from titan.w3.org ([128.30.52.76]) by lyra.w3.org with esmtps (TLS1.3) tls TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384 (Exim 4.94.2) (envelope-from <internet-drafts@ietf.org>) id 1rSROo-005PC8-SB for ietf-http-wg@listhub.w3.org; Wed, 24 Jan 2024 00:45:50 +0000
Received: from mail.ietf.org ([50.223.129.194]) by titan.w3.org with esmtps (TLS1.3) tls TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384 (Exim 4.94.2) (envelope-from <internet-drafts@ietf.org>) id 1rSROm-008IUj-J3 for ietf-http-wg@w3.org; Wed, 24 Jan 2024 00:45:50 +0000
Received: from ietfa.amsl.com (localhost [IPv6:::1]) by ietfa.amsl.com (Postfix) with ESMTP id ADE8DC14F6B4; Tue, 23 Jan 2024 16:45:44 -0800 (PST)
MIME-Version: 1.0
Content-Type: text/plain; charset="utf-8"
Content-Transfer-Encoding: 7bit
From: internet-drafts@ietf.org
To: i-d-announce@ietf.org
Cc: ietf-http-wg@w3.org
X-Test-IDTracker: no
X-IETF-IDTracker: 12.3.0
Auto-Submitted: auto-generated
Reply-To: ietf-http-wg@w3.org
Message-ID: <170605714469.28239.6411911885409941678@ietfa.amsl.com>
Date: Tue, 23 Jan 2024 16:45:44 -0800
Received-SPF: pass client-ip=50.223.129.194; envelope-from=internet-drafts@ietf.org; helo=mail.ietf.org
X-W3C-Hub-Spam-Status: No, score=-3.2
X-W3C-Hub-Spam-Report: BAYES_00=-1.9, RCVD_IN_DNSWL_MED=-2.3, RCVD_IN_MSPIKE_H4=0.001, RCVD_IN_MSPIKE_WL=0.001, SPF_HELO_NONE=0.001, SPF_PASS=-0.001, T_SCC_BODY_TEXT_LINE=-0.01, W3C_NW=1
X-W3C-Scan-Sig: titan.w3.org 1rSROm-008IUj-J3 eb5b257f01656244cb0bf4c738b46b5c
X-Original-To: ietf-http-wg@w3.org
Subject: I-D Action: draft-ietf-httpbis-unprompted-auth-06.txt
Archived-At: <https://www.w3.org/mid/170605714469.28239.6411911885409941678@ietfa.amsl.com>
Resent-From: ietf-http-wg@w3.org
X-Mailing-List: <ietf-http-wg@w3.org> archive/latest/51729
X-Loop: ietf-http-wg@w3.org
Resent-Sender: ietf-http-wg-request@w3.org
Precedence: list
List-Id: <ietf-http-wg.w3.org>
List-Help: <https://www.w3.org/email/>
List-Post: <mailto:ietf-http-wg@w3.org>
List-Unsubscribe: <mailto:ietf-http-wg-request@w3.org?subject=unsubscribe>
Internet-Draft draft-ietf-httpbis-unprompted-auth-06.txt is now available. It
is a work item of the HTTP (HTTPBIS) WG of the IETF.
Title: The Signature HTTP Authentication Scheme
Authors: David Schinazi
David M. Oliver
Jonathan Hoyland
Name: draft-ietf-httpbis-unprompted-auth-06.txt
Pages: 15
Dates: 2024-01-23
Abstract:
Existing HTTP authentication schemes are probeable in the sense that
it is possible for an unauthenticated client to probe whether an
origin serves resources that require authentication. It is possible
for an origin to hide the fact that it requires authentication by not
generating Unauthorized status codes, however that only works with
non-cryptographic authentication schemes: cryptographic signatures
require a fresh nonce to be signed, and there is no existing way for
the origin to share such a nonce without exposing the fact that it
serves resources that require authentication. This document proposes
a new non-probeable cryptographic authentication scheme.
The IETF datatracker status page for this Internet-Draft is:
https://datatracker.ietf.org/doc/draft-ietf-httpbis-unprompted-auth/
There is also an HTML version available at:
https://www.ietf.org/archive/id/draft-ietf-httpbis-unprompted-auth-06.html
A diff from the previous version is available at:
https://author-tools.ietf.org/iddiff?url2=draft-ietf-httpbis-unprompted-auth-06
Internet-Drafts are also available by rsync at:
rsync.ietf.org::internet-drafts
- I-D Action: draft-ietf-httpbis-unprompted-auth-06… internet-drafts