Re: I-D Action: draft-ietf-httpbis-message-signatures-00.txt

Mark Nottingham <mnot@mnot.net> Wed, 15 April 2020 02:21 UTC

Return-Path: <ietf-http-wg-request+bounce-httpbisa-archive-bis2juki=lists.ie@listhub.w3.org>
X-Original-To: ietfarch-httpbisa-archive-bis2Juki@ietfa.amsl.com
Delivered-To: ietfarch-httpbisa-archive-bis2Juki@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 58FD93A153B for <ietfarch-httpbisa-archive-bis2Juki@ietfa.amsl.com>; Tue, 14 Apr 2020 19:21:27 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.752
X-Spam-Level:
X-Spam-Status: No, score=-2.752 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, HEADER_FROM_DIFFERENT_DOMAINS=0.248, MAILING_LIST_MULTI=-1, SPF_PASS=-0.001, URIBL_BLOCKED=0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (2048-bit key) header.d=mnot.net header.b=HBpTXlzl; dkim=pass (2048-bit key) header.d=messagingengine.com header.b=oGpVDu6h
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id ParaJvfpUaCh for <ietfarch-httpbisa-archive-bis2Juki@ietfa.amsl.com>; Tue, 14 Apr 2020 19:21:25 -0700 (PDT)
Received: from lyra.w3.org (lyra.w3.org [128.30.52.18]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 4F3593A153C for <httpbisa-archive-bis2Juki@lists.ietf.org>; Tue, 14 Apr 2020 19:21:24 -0700 (PDT)
Received: from lists by lyra.w3.org with local (Exim 4.92) (envelope-from <ietf-http-wg-request@listhub.w3.org>) id 1jOXd7-0000Po-1K for ietf-http-wg-dist@listhub.w3.org; Wed, 15 Apr 2020 02:18:21 +0000
Resent-Date: Wed, 15 Apr 2020 02:18:21 +0000
Resent-Message-Id: <E1jOXd7-0000Po-1K@lyra.w3.org>
Received: from mimas.w3.org ([128.30.52.79]) by lyra.w3.org with esmtps (TLS1.3:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.92) (envelope-from <mnot@mnot.net>) id 1jOXd5-0000P2-Tl for ietf-http-wg@listhub.w3.org; Wed, 15 Apr 2020 02:18:19 +0000
Received: from out1-smtp.messagingengine.com ([66.111.4.25]) by mimas.w3.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.92) (envelope-from <mnot@mnot.net>) id 1jOXd3-00064g-B2 for ietf-http-wg@w3.org; Wed, 15 Apr 2020 02:18:19 +0000
Received: from compute4.internal (compute4.nyi.internal [10.202.2.44]) by mailout.nyi.internal (Postfix) with ESMTP id 2919B5C019E; Tue, 14 Apr 2020 22:18:04 -0400 (EDT)
Received: from mailfrontend2 ([10.202.2.163]) by compute4.internal (MEProxy); Tue, 14 Apr 2020 22:18:04 -0400
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=mnot.net; h= content-type:mime-version:subject:from:in-reply-to:date:cc :content-transfer-encoding:message-id:references:to; s=fm2; bh=j gbjvMriPpKBQdGU3tazE2mGWAfvfflOpb8cvI2xC1g=; b=HBpTXlzl37Q+Q3CFV buYR0Rc+g7m/s6jprU4SCoCPKKfe9UxAXaYFFmQ4nHHCHAcW6TIEfjbki3Jx3CPj a9oBYe9WWk0v4E37Zsb+Ne3eWLg9g+5q/VWPlvs3yb3NTmYDZvfOty/pU+HZ0l19 2BisKkMsrAAqybYUjOdZxZLj/W5JIiogNeRf1bjdaTYVwrCUlBYwhNVt5el2neoS BtTRCLYbymbffpf5HAjunAxRC5G4hP4uWxyOUfb7ILKsaw1qNxI383czsdzIWoG/ LfFvgeonHyfthEmBsyWa5JFbFFKc8MVVex1iTKHeUuaPJw70ir3nDQZxfSgrhW2s DzW7g==
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d= messagingengine.com; h=cc:content-transfer-encoding:content-type :date:from:in-reply-to:message-id:mime-version:references :subject:to:x-me-proxy:x-me-proxy:x-me-sender:x-me-sender :x-sasl-enc; s=fm2; bh=jgbjvMriPpKBQdGU3tazE2mGWAfvfflOpb8cvI2xC 1g=; b=oGpVDu6hAirUg1fvkGmMF+tBeeEK/BwlojS/ScWh9gDQzdrQzsMV4i9Rt sCEZx/kyfgvkAvKLr/Xdh/UjqYM0JaUd1Egwdm4cFnQi9WszkCNeWMhjFCxid+9y QeiFfyM+uC7LqIAGYbOtP2nTn6I6YxDpKO081wIa1ig+fatf55bJeSnakiL9/Pqr 9KO1BUbFTE62jF6IE7wnQcfvoFB0D8BO0VItyo7M8JqOA4JnlMWrQw5AB7R2uNd5 WBSm/i6YoRfE0Q2JluNEL+JKSwS9O9kj1Uur7P8ZdhXmvXfLLfIW4SjI5u5MZBqn 9EWJALRzSPAhMTUXMskDYhhZpx7mw==
X-ME-Sender: <xms:2m6WXqrA-arLzPZHR9upnF9fZnJJr4aTTcjYndjX8OTa9dCo-Rq9IQ>
X-ME-Proxy-Cause: gggruggvucftvghtrhhoucdtuddrgeduhedrfedvgdehhecutefuodetggdotefrodftvf curfhrohhfihhlvgemucfhrghsthforghilhdpqfgfvfdpuffrtefokffrpgfnqfghnecu uegrihhlohhuthemuceftddtnecusecvtfgvtghiphhivghnthhsucdlqddutddtmdenuc fjughrpegtggfuhfgjfffgkfhfvffosehtqhhmtdhhtdejnecuhfhrohhmpeforghrkhcu pfhothhtihhnghhhrghmuceomhhnohhtsehmnhhothdrnhgvtheqnecuffhomhgrihhnpe hgihhthhhusgdrtghomhdpihgvthhfrdhorhhgpdhmnhhothdrnhgvthenucfkphepuddu ledrudejrdduheekrddvhedunecuvehluhhsthgvrhfuihiivgeptdenucfrrghrrghmpe hmrghilhhfrhhomhepmhhnohhtsehmnhhothdrnhgvth
X-ME-Proxy: <xmx:2m6WXkmDbIEKwoJy2EwHbRWxbvj5FR1GtpvxWvDZ9nQZW71-EIANpA> <xmx:2m6WXlUYVbHQu3P1vu64H1F3Tv4ay2atZZs6J7O2sbiy81PZ1ydxBg> <xmx:2m6WXgSTGTyzFyLM_MeqS1HaPXMrrUOgQAUD1u9106nCT5zYdPIYAg> <xmx:3G6WXti0Cv_GakdDltSN0415Qc1gco1lfXcLoYMVUztbS8z4H894Lw>
Received: from macbook-air.mnot.net (119-17-158-251.77119e.mel.static.aussiebb.net [119.17.158.251]) by mail.messagingengine.com (Postfix) with ESMTPA id 25AD33060066; Tue, 14 Apr 2020 22:18:01 -0400 (EDT)
Content-Type: text/plain; charset="utf-8"
Mime-Version: 1.0 (Mac OS X Mail 13.4 \(3608.80.23.2.2\))
From: Mark Nottingham <mnot@mnot.net>
In-Reply-To: <178BA71D-57D4-4DF1-8F69-ED886E933102@mit.edu>
Date: Wed, 15 Apr 2020 12:17:58 +1000
Cc: HTTP Working Group <ietf-http-wg@w3.org>
Content-Transfer-Encoding: quoted-printable
Message-Id: <40E23F35-84DA-489C-8BCA-E45605C604BD@mnot.net>
References: <158656012348.3496.5576237503432849190@ietfa.amsl.com> <178BA71D-57D4-4DF1-8F69-ED886E933102@mit.edu>
To: Justin Richer <jricher@mit.edu>
X-Mailer: Apple Mail (2.3608.80.23.2.2)
Received-SPF: pass client-ip=66.111.4.25; envelope-from=mnot@mnot.net; helo=out1-smtp.messagingengine.com
X-W3C-Hub-Spam-Status: No, score=-9.8
X-W3C-Hub-Spam-Report: BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, RCVD_IN_DNSWL_LOW=-0.7, RCVD_IN_MSPIKE_H3=0.001, RCVD_IN_MSPIKE_WL=0.001, SPF_HELO_PASS=-0.001, SPF_PASS=-0.001, W3C_AA=-1, W3C_DB=-1, W3C_IRA=-1, W3C_IRR=-3, W3C_WL=-1
X-W3C-Scan-Sig: mimas.w3.org 1jOXd3-00064g-B2 175769d2c36fa64aaecd1853eb8a9922
X-Original-To: ietf-http-wg@w3.org
Subject: Re: I-D Action: draft-ietf-httpbis-message-signatures-00.txt
Archived-At: <https://www.w3.org/mid/40E23F35-84DA-489C-8BCA-E45605C604BD@mnot.net>
Resent-From: ietf-http-wg@w3.org
X-Mailing-List: <ietf-http-wg@w3.org> archive/latest/37509
X-Loop: ietf-http-wg@w3.org
Resent-Sender: ietf-http-wg-request@w3.org
Precedence: list
List-Id: <ietf-http-wg.w3.org>
List-Help: <https://www.w3.org/Mail/>
List-Post: <mailto:ietf-http-wg@w3.org>
List-Unsubscribe: <mailto:ietf-http-wg-request@w3.org?subject=unsubscribe>

Great, thanks Justin. Look forward to seeing the draft in the repo (like Julian says, it doesn't have to be Markdown, although many find it easier).

In the meantime, I've created the 'signatures' label for issues: <https://github.com/httpwg/http-extensions/issues?q=is%3Aopen+is%3Aissue+label%3Asignatures>

Cheers,


> On 15 Apr 2020, at 1:21 am, Justin Richer <jricher@mit.edu> wrote:
> 
> A note to the WG: This draft is a copy of the ID that Annabelle had previously put together for the consensus call. We are now working on translating it into the the Markdown format and starting on the changes discussed within the document. 
> 
> Thanks to everyone who’s commented so far, we’ll be starting to work on actual issues once we have things in the right format and moved to the right repository within the HTTP WG. 
> 
> — Justin
> 
>> On Apr 10, 2020, at 7:08 PM, internet-drafts@ietf.org wrote:
>> 
>> 
>> A New Internet-Draft is available from the on-line Internet-Drafts directories.
>> This draft is a work item of the HTTP WG of the IETF.
>> 
>>       Title           : Signing HTTP Messages
>>       Authors         : Annabelle Backman
>>                         Justin Richer
>>                         Manu Sporny
>> 	Filename        : draft-ietf-httpbis-message-signatures-00.txt
>> 	Pages           : 38
>> 	Date            : 2020-04-10
>> 
>> Abstract:
>>  This document describes a mechanism for creating, encoding, and
>>  verifying digital signatures or message authentication codes over
>>  content within an HTTP message.  This mechanism supports use cases
>>  where the full HTTP message may not be known to the signer, and where
>>  the message may be transformed (e.g., by intermediaries) before
>>  reaching the verifier.
>> 
>> 
>> The IETF datatracker status page for this draft is:
>> https://datatracker.ietf.org/doc/draft-ietf-httpbis-message-signatures/
>> 
>> There are also htmlized versions available at:
>> https://tools.ietf.org/html/draft-ietf-httpbis-message-signatures-00
>> https://datatracker.ietf.org/doc/html/draft-ietf-httpbis-message-signatures-00
>> 
>> 
>> Please note that it may take a couple of minutes from the time of submission
>> until the htmlized version and diff are available at tools.ietf.org.
>> 
>> Internet-Drafts are also available by anonymous FTP at:
>> ftp://ftp.ietf.org/internet-drafts/
>> 
>> 
>> 
> 
> 

--
Mark Nottingham   https://www.mnot.net/