Origin-signed responses

Jeffrey Yasskin <jyasskin@google.com> Fri, 01 September 2017 16:39 UTC

Return-Path: <ietf-http-wg-request+bounce-httpbisa-archive-bis2juki=lists.ie@listhub.w3.org>
X-Original-To: ietfarch-httpbisa-archive-bis2Juki@ietfa.amsl.com
Delivered-To: ietfarch-httpbisa-archive-bis2Juki@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id E71AC133046 for <ietfarch-httpbisa-archive-bis2Juki@ietfa.amsl.com>; Fri, 1 Sep 2017 09:39:17 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -4.6
X-Spam-Level:
X-Spam-Status: No, score=-4.6 tagged_above=-999 required=5 tests=[DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, HEADER_FROM_DIFFERENT_DOMAINS=0.001, RCVD_IN_DNSWL_HI=-5, RCVD_IN_SORBS_SPAM=0.5, SPF_PASS=-0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (2048-bit key) header.d=google.com
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id am9OzPgu8meY for <ietfarch-httpbisa-archive-bis2Juki@ietfa.amsl.com>; Fri, 1 Sep 2017 09:39:16 -0700 (PDT)
Received: from frink.w3.org (frink.w3.org [128.30.52.56]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 6EB57132DF6 for <httpbisa-archive-bis2Juki@lists.ietf.org>; Fri, 1 Sep 2017 09:39:16 -0700 (PDT)
Received: from lists by frink.w3.org with local (Exim 4.89) (envelope-from <ietf-http-wg-request@listhub.w3.org>) id 1dnovq-0006an-HJ for ietf-http-wg-dist@listhub.w3.org; Fri, 01 Sep 2017 16:36:34 +0000
Resent-Date: Fri, 01 Sep 2017 16:36:34 +0000
Resent-Message-Id: <E1dnovq-0006an-HJ@frink.w3.org>
Received: from mimas.w3.org ([128.30.52.79]) by frink.w3.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.89) (envelope-from <jyasskin@google.com>) id 1dnovZ-0006Zx-51 for ietf-http-wg@listhub.w3.org; Fri, 01 Sep 2017 16:36:17 +0000
Received: from mail-wm0-f46.google.com ([74.125.82.46]) by mimas.w3.org with esmtps (TLS1.2:ECDHE_RSA_AES_128_GCM_SHA256:128) (Exim 4.89) (envelope-from <jyasskin@google.com>) id 1dnovT-0004uQ-7z for ietf-http-wg@w3.org; Fri, 01 Sep 2017 16:36:16 +0000
Received: by mail-wm0-f46.google.com with SMTP id 187so4581289wmn.1 for <ietf-http-wg@w3.org>; Fri, 01 Sep 2017 09:35:50 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=20161025; h=mime-version:from:date:message-id:subject:to; bh=woI5guWFqvftKc8ImUbD6E0w3Hv5FX/fo8vSsouxCZQ=; b=qltbGn5HsGi/FHkXvgAkiGdmVMKSIwn43QSAKJbpZ52hUSQ4Z7iIM5cCejVW/Gy+dN 85POfBj6IgUNvtYtZ1A2qStpYldDuBSIjFQxF7pXeKTAosmNUYr39YC4quFR7b0Ipke0 tDdrj/GkT++ld4pdE537lszOyNkJYdKq6rnUMrSzYcbDW39MZufw4mPAwmdTVqbXs8tY stQdD6Is0tKN7hPERjI2YzBg+ru8qdHuhjFwFYdbqEZJ8QAJIPxk0ProN9yurtf9sQr8 Skx1aFxROrF+VWcqgmcU76NwyvwutnHE4TiuLPyylFVzjkvLv2clzb2emsyhQjGZk8+U OUZw==
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20161025; h=x-gm-message-state:mime-version:from:date:message-id:subject:to; bh=woI5guWFqvftKc8ImUbD6E0w3Hv5FX/fo8vSsouxCZQ=; b=fPtyf4x0Oa1aQZwCRFaYctoiAgonwkIVfitaiD/NQDg7W3weR3ab8QH+8MpEZaJRi7 QZAfHSpmQ92o6WDymlGu616ZrSwC7B53TvPIauRhwUUNxYMg1eb313x/LAdi0xZiM841 K91SHAB7Yslkysusj4reKB0WeH730m7Tj9XkBwB5fdwLuUHxnwTu6KeYOk8aq3b5QCy0 a6wfubZDmHxbbS1+dcP5PdX01Bj3PhE0X/71z5e4T5A8nwvzA0xi5dv4Xvn2nbl/j7kR YKyUQa2CME1n4gQ+QKo+b29mBLFMG206ShISVjiN1969ruWzcJk/hJQ90JLpr7VDM8+u ePTA==
X-Gm-Message-State: AHPjjUgkGbAeNtNZGNm07DNYWI5DH4meq1oYtriJpdk04BvSFbJIqQzW w0HK1Azry4wMsIq7dC+k48jB6JhpBAqCJqK0FA==
X-Google-Smtp-Source: ADKCNb6X9lXezVW6ld2ztv/zhtdGXG1TQr8C8NqddpBeocYjn/EBCWu3QVra8UEIBNwDaO3/CJWJYePTSt9DyPIbkJg=
X-Received: by 10.28.156.198 with SMTP id f189mr783726wme.28.1504283748622; Fri, 01 Sep 2017 09:35:48 -0700 (PDT)
MIME-Version: 1.0
Received: by 10.28.27.72 with HTTP; Fri, 1 Sep 2017 09:35:27 -0700 (PDT)
From: Jeffrey Yasskin <jyasskin@google.com>
Date: Fri, 01 Sep 2017 09:35:27 -0700
Message-ID: <CANh-dXkbqBpGUrr-dXceQ5HzDjC6mSrrudTKjWwaBQcSO584ug@mail.gmail.com>
To: HTTP Working Group <ietf-http-wg@w3.org>
Content-Type: text/plain; charset="UTF-8"
Received-SPF: pass client-ip=74.125.82.46; envelope-from=jyasskin@google.com; helo=mail-wm0-f46.google.com
X-W3C-Hub-Spam-Status: No, score=-4.9
X-W3C-Hub-Spam-Report: AWL=3.637, BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, RCVD_IN_DNSWL_NONE=-0.0001, RCVD_IN_MSPIKE_H3=-0.01, RCVD_IN_MSPIKE_WL=-0.01, RCVD_IN_SORBS_SPAM=0.5, RP_MATCHES_RCVD=-0.001, SPF_PASS=-0.001, W3C_AA=-1, W3C_DB=-1, W3C_IRA=-1, W3C_IRR=-3, W3C_WL=-1
X-W3C-Scan-Sig: mimas.w3.org 1dnovT-0004uQ-7z 44dbd68e173103055abf7bb5841bd4ca
X-Original-To: ietf-http-wg@w3.org
Subject: Origin-signed responses
Archived-At: <http://www.w3.org/mid/CANh-dXkbqBpGUrr-dXceQ5HzDjC6mSrrudTKjWwaBQcSO584ug@mail.gmail.com>
Resent-From: ietf-http-wg@w3.org
X-Mailing-List: <ietf-http-wg@w3.org> archive/latest/34423
X-Loop: ietf-http-wg@w3.org
Resent-Sender: ietf-http-wg-request@w3.org
Precedence: list
List-Id: <ietf-http-wg.w3.org>
List-Help: <http://www.w3.org/Mail/>
List-Post: <mailto:ietf-http-wg@w3.org>
List-Unsubscribe: <mailto:ietf-http-wg-request@w3.org?subject=unsubscribe>

Hi all,

When I brought web packaging to IETF99 DISPATCH
(https://datatracker.ietf.org/doc/minutes-99-dispatch/), several
people said they wanted to see what it would look like split into
layers. https://tools.ietf.org/id/draft-yasskin-http-origin-signed-responses-00.html
discusses use cases and an outline of what the signing layer needs to
look like, but doesn't include an actual proposal for signatures yet.

What do you think? Is splitting the packaging proposal still the right approach?

I've also started a thread in art@ to talk about the packaging use
cases overall: https://mailarchive.ietf.org/arch/msg/art/gaS8EHxsdzcyPCaSqSyWSh-WbMY

Thanks,
Jeffrey