Re: Call for adoption: draft-reschke-httpauth-auth-info-00

Rifaat Shekh-Yusef <rifaat.ietf@gmail.com> Mon, 02 February 2015 14:14 UTC

Return-Path: <ietf-http-wg-request+bounce-httpbisa-archive-bis2juki=lists.ietf.org@listhub.w3.org>
X-Original-To: ietfarch-httpbisa-archive-bis2Juki@ietfa.amsl.com
Delivered-To: ietfarch-httpbisa-archive-bis2Juki@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id B2B3A1A6FEF for <ietfarch-httpbisa-archive-bis2Juki@ietfa.amsl.com>; Mon, 2 Feb 2015 06:14:03 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -7.011
X-Spam-Level:
X-Spam-Status: No, score=-7.011 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, HTML_MESSAGE=0.001, RCVD_IN_DNSWL_HI=-5, SPF_HELO_PASS=-0.001, SPF_PASS=-0.001, T_RP_MATCHES_RCVD=-0.01] autolearn=ham
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id BQ0FXgLt_4CJ for <ietfarch-httpbisa-archive-bis2Juki@ietfa.amsl.com>; Mon, 2 Feb 2015 06:14:02 -0800 (PST)
Received: from frink.w3.org (frink.w3.org [128.30.52.56]) (using TLSv1.2 with cipher DHE-RSA-AES128-SHA (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 72D6A1A1AF1 for <httpbisa-archive-bis2Juki@lists.ietf.org>; Mon, 2 Feb 2015 06:11:55 -0800 (PST)
Received: from lists by frink.w3.org with local (Exim 4.80) (envelope-from <ietf-http-wg-request@listhub.w3.org>) id 1YIHgm-0002Fc-PW for ietf-http-wg-dist@listhub.w3.org; Mon, 02 Feb 2015 14:09:20 +0000
Resent-Date: Mon, 02 Feb 2015 14:09:20 +0000
Resent-Message-Id: <E1YIHgm-0002Fc-PW@frink.w3.org>
Received: from lisa.w3.org ([128.30.52.41]) by frink.w3.org with esmtp (Exim 4.80) (envelope-from <rifaat.ietf@gmail.com>) id 1YIHge-0002D6-5b for ietf-http-wg@listhub.w3.org; Mon, 02 Feb 2015 14:09:12 +0000
Received: from mail-la0-f44.google.com ([209.85.215.44]) by lisa.w3.org with esmtps (TLS1.0:RSA_ARCFOUR_SHA1:16) (Exim 4.72) (envelope-from <rifaat.ietf@gmail.com>) id 1YIHgd-0004CH-3W for ietf-http-wg@w3.org; Mon, 02 Feb 2015 14:09:12 +0000
Received: by mail-la0-f44.google.com with SMTP id s18so41214064lam.3 for <ietf-http-wg@w3.org>; Mon, 02 Feb 2015 06:08:44 -0800 (PST)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20120113; h=mime-version:in-reply-to:references:date:message-id:subject:from:to :cc:content-type; bh=Sx8liXMUWA6uYk6jIqHE4sACW5nKxRBAM/KkJZ5Xe2g=; b=ZdvmkhAmFPbvCmeTPvwayQxlWSQGao1LZQkA7sL4JMjsmQabXvQQwNoyTuL7Zc0onF VpuJi5PlRJxaIJd6suMgkrmJahN+QIQQEnd9iUV3Wj2DaTuPKPOVlSe7VzGRXLrKAuI3 j0e1IxFMMgiJtIXIx/VcATUmuGQdy+MDJsx+aZgtFVTjpAOq5OwbaP5XBcx4zPPxgy5z 3EY1KhMN2tuJjVM4TrOaMg2UulUmcdExADLM49jUUpQe0KaL8zy675367jGWPRm81BVu lfT2MaM1ADARDRrIbHFNc6NMmDoskmKIgFHY3N+QTHsbYAMS0heVmkJX4Ay0c7vh+8gz Z09g==
MIME-Version: 1.0
X-Received: by 10.152.204.40 with SMTP id kv8mr19897820lac.42.1422886124474; Mon, 02 Feb 2015 06:08:44 -0800 (PST)
Received: by 10.114.27.162 with HTTP; Mon, 2 Feb 2015 06:08:44 -0800 (PST)
In-Reply-To: <54CF7E9B.2060700@gmx.de>
References: <1BA93C83-91E9-4E7D-88CE-ADC8C39091C6@mnot.net> <CABkgnnXhg55e5N2O8yZJpTbz4qSm0-KpVApyDha_snetrFqvMw@mail.gmail.com> <54C9E419.1070407@greenbytes.de> <54CB7A4F.7090402@crf.canon.fr> <54CB7F48.4060800@gmx.de> <CAGL6epLUkFi6amhExWASqjS5Mvs1MVTJ1hDmhBTncznQV1GK1A@mail.gmail.com> <54CBFB6E.9070800@treenet.co.nz> <54CF7E9B.2060700@gmx.de>
Date: Mon, 02 Feb 2015 09:08:44 -0500
Message-ID: <CAGL6epL_XLY+ZeLPi3XVJsdaoSYFwhJuuy7zDeLspJ0tMfKvKw@mail.gmail.com>
From: Rifaat Shekh-Yusef <rifaat.ietf@gmail.com>
To: Julian Reschke <julian.reschke@gmx.de>
Cc: Amos Jeffries <squid3@treenet.co.nz>, ietf-http-wg@w3.org
Content-Type: multipart/alternative; boundary="001a11347da60157a5050e1b7e8f"
Received-SPF: pass client-ip=209.85.215.44; envelope-from=rifaat.ietf@gmail.com; helo=mail-la0-f44.google.com
X-W3C-Hub-Spam-Status: No, score=-2.2
X-W3C-Hub-Spam-Report: AWL=-1.418, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, FREEMAIL_FROM=0.001, HTML_MESSAGE=0.001, RCVD_IN_DNSWL_LOW=-0.7, SPF_PASS=-0.001, URIBL_BLOCKED=0.001
X-W3C-Scan-Sig: lisa.w3.org 1YIHgd-0004CH-3W 63bf9e89198490444a3e756c1addfa1f
X-Original-To: ietf-http-wg@w3.org
Subject: Re: Call for adoption: draft-reschke-httpauth-auth-info-00
Archived-At: <http://www.w3.org/mid/CAGL6epL_XLY+ZeLPi3XVJsdaoSYFwhJuuy7zDeLspJ0tMfKvKw@mail.gmail.com>
Resent-From: ietf-http-wg@w3.org
X-Mailing-List: <ietf-http-wg@w3.org> archive/latest/28742
X-Loop: ietf-http-wg@w3.org
Resent-Sender: ietf-http-wg-request@w3.org
Precedence: list
List-Id: <ietf-http-wg.w3.org>
List-Help: <http://www.w3.org/Mail/>
List-Post: <mailto:ietf-http-wg@w3.org>
List-Unsubscribe: <mailto:ietf-http-wg-request@w3.org?subject=unsubscribe>

This document does not define any semantics associated with these header,
which means that the document that uses these header will be the one that
must address the information leak issue.
I do not see why we would restrict a future use of these headers based on
the Digest usage; this seems odd to me.

Regards,
 Rifaat



On Mon, Feb 2, 2015 at 8:41 AM, Julian Reschke <julian.reschke@gmx.de>
wrote:

> On 2015-01-30 22:45, Amos Jeffries wrote:
>
>> On 31/01/2015 3:11 a.m., Rifaat Shekh-Yusef wrote:
>>
>>> Why would we restrict the use of this header in future protocols based on
>>> the Digest usage of this header?
>>> What would be the harm in allowing the new protocol that uses the header
>>> to
>>> restrict it usage?
>>>
>>>
>> Information leaks. User credentials and secure token are potentially
>> stored in here, as are details specific to the internal operation of the
>> security algorithm selected/negotiated.
>> ...
>>
>
> The intent of the draft was to separate out what was defined in RFC 2617;
> thus I agree that we shouldn't relax the use unless there's broad consensus
> that that would be a good idea.
>
> Best regards, Julian
>
>