Re: [Id-event] Subject Identifiers - Working Group Last Call

Dave Tonge <dave.tonge@momentumft.co.uk> Thu, 03 June 2021 08:15 UTC

Return-Path: <dave.tonge@moneyhub.com>
X-Original-To: id-event@ietfa.amsl.com
Delivered-To: id-event@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 1D4183A2F53 for <id-event@ietfa.amsl.com>; Thu, 3 Jun 2021 01:15:44 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -0.738
X-Spam-Level:
X-Spam-Status: No, score=-0.738 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, HEADER_FROM_DIFFERENT_DOMAINS=0.249, HTML_FONT_LOW_CONTRAST=0.001, HTML_MESSAGE=0.001, RCVD_IN_DNSWL_NONE=-0.0001, SPF_HELO_NONE=0.001, SPF_PASS=-0.001, T_KAM_HTML_FONT_INVALID=0.01, URIBL_BLOCKED=0.001, WORD_INVIS=1] autolearn=no autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (1024-bit key) header.d=momentumft.co.uk
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id KxawGy1bEUz5 for <id-event@ietfa.amsl.com>; Thu, 3 Jun 2021 01:15:39 -0700 (PDT)
Received: from mail-ej1-x62b.google.com (mail-ej1-x62b.google.com [IPv6:2a00:1450:4864:20::62b]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id B74A73A2F55 for <id-event@ietf.org>; Thu, 3 Jun 2021 01:15:38 -0700 (PDT)
Received: by mail-ej1-x62b.google.com with SMTP id ce15so7940360ejb.4 for <id-event@ietf.org>; Thu, 03 Jun 2021 01:15:38 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=momentumft.co.uk; s=google; h=mime-version:references:in-reply-to:from:date:message-id:subject:to :cc; bh=4TMLSPT0gJmI+4jjW91x8BRv4IxAa3aJ9cwHfskta4k=; b=gbykdYU+2Q3OJq1wJvCJI+ACPfUbfTI0hG3WlW2bLopzz2+XGa/yOtkgwhuoBbBD1A Q76hql2gzabPsGqecsiwBuXEO1HoUVxEUcI+VZ3KK8LsNLEXmg06v0WM82bMV+lbHDKN lxOyeOxSP+vh1HzU1lzLxsw5+CbH2MXno/gXQ=
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20161025; h=x-gm-message-state:mime-version:references:in-reply-to:from:date :message-id:subject:to:cc; bh=4TMLSPT0gJmI+4jjW91x8BRv4IxAa3aJ9cwHfskta4k=; b=DbYtbdP00x+r1vNn8uAxiCk9foyfLzeyug47LvUlR5q1553bJl/dupzplidL91xzaM Cfsel//tI9+rKF/a1kJAsJme2mtBGxI6VfVgpNlPySl+BrnvC87wnwomWw+xKEknlOvu edQj6DlaTD+2/+C91PxAlF4tkxnRcnKk7zNvsSLoio8AsxzsDYQ3/DQAlHBj/kr+iTT+ Vs37DfC2QrhX+txUZXFdwOfU4R0eUp/laQOiTZpHMyux4Eeb3AOMtIIY7su8fg5MpEtr SigUcsMB0GAf20N7GdpxYbcKZPvlH5VP+sbqJL+ytr0v4ZDg5e7H/3Jr3HFV421NkSIj /R3Q==
X-Gm-Message-State: AOAM532yUgpTo+TBx7zwGxMbTSGprcR61DcU4otFvTEKo5j7AfWiacfp mrc/uQb/J+JOGCUk75qzkNXWSfq+/MD7GAdxb96/MwyTk1AKjZQWZe1Obu8beYnVmgFWbQk8WdO UTKLqPqjFy5/6qY+L9g==
X-Google-Smtp-Source: ABdhPJw7zv9+uFKa53xWJNLOmh8nH81Oo77T8NNJjggRXbPiLXxMZwzLX1cIj0auVGjFP4e9vcSShpi1H2h78K6kmsg=
X-Received: by 2002:a17:907:7b9e:: with SMTP id ne30mr23654374ejc.389.1622708135333; Thu, 03 Jun 2021 01:15:35 -0700 (PDT)
MIME-Version: 1.0
References: <CAD9ie-uSbNHq=Mt3ohA=URf5rv2hz7YUdUMhOf80C_f=XBrGLA@mail.gmail.com> <36D66A89-D178-6047-B270-73AD540E7FAD@hxcore.ol>
In-Reply-To: <36D66A89-D178-6047-B270-73AD540E7FAD@hxcore.ol>
From: Dave Tonge <dave.tonge@momentumft.co.uk>
Date: Thu, 03 Jun 2021 10:15:24 +0200
Message-ID: <CAP-T6TQZ0J-GNLRZ2Zt5jDnQNNPssLmmCEmuN6EXnCfigfsaQQ@mail.gmail.com>
To: Yaron Sheffer <yaronf.ietf@gmail.com>
Cc: Dick Hardt <dick.hardt@gmail.com>, SecEvent <id-event@ietf.org>, Roman Danyliw <rdd@cert.org>, Marius Scurtescu <marius.scurtescu@coinbase.com>, "Richard Backman, Annabelle" <richanna=40amazon.com@dmarc.ietf.org>
Content-Type: multipart/alternative; boundary="000000000000fb2a1305c3d82d78"
Archived-At: <https://mailarchive.ietf.org/arch/msg/id-event/6FwhADFXKSUYU779O1XHy2tNRj0>
Subject: Re: [Id-event] Subject Identifiers - Working Group Last Call
X-BeenThere: id-event@ietf.org
X-Mailman-Version: 2.1.29
Precedence: list
List-Id: "A mailing list to discuss the potential solution for a common identity event messaging format and distribution system." <id-event.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/id-event>, <mailto:id-event-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/id-event/>
List-Post: <mailto:id-event@ietf.org>
List-Help: <mailto:id-event-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/id-event>, <mailto:id-event-request@ietf.org?subject=subscribe>
X-List-Received-Date: Thu, 03 Jun 2021 08:15:44 -0000

I support progressing this document forward.

On Thu, 27 May 2021 at 14:46, Yaron Sheffer <yaronf.ietf@gmail.com> wrote:

> Thank you Dick and the authors.
>
>
>
> With my co-chair hat off, I support progressing this document. I also have
> a couple comments:
>
>
>
> 3.2.2: The text refers twice to "alias" subject IDs, but the format is now
> named "aliases".
>
>
>
> Fig. 14 seems to be in conflict with the requirement to have a single
> subject for the JWT ("a JWT has one and only one JWT Subject"). Yes, maybe
> Elizabeth has a second email address, but we cannot assume that
> applications have this kind of logic. Similarly, the subject-related
> discussion in Sec. 4.2 (which is arguably a bit vague) as well as Fig. 18
> seems to allow two different subjects within the JWT.
>
>
>
> Thanks,
>
>                 Yaron
>
>
>
> *From: *Dick Hardt <dick.hardt@gmail.com>
> *Date: *Wednesday, May 26, 2021 at 23:22
> *To: *SecEvent <id-event@ietf.org>
> *Cc: *Yaron Sheffer <yaronf.ietf@gmail.com>, Richard Backman, Annabelle
> <richanna=40amazon.com@dmarc.ietf.org>, Roman Danyliw <rdd@cert.org>,
> Marius Scurtescu <marius.scurtescu@coinbase.com>
> *Subject: *Subject Identifiers - Working Group Last Call
>
> Hello WG
>
>
>
> Thanks to Annabelle (and Marius) for the latest update:
>
>
>
>
> https://datatracker.ietf.org/doc/html/draft-ietf-secevent-subject-identifiers-08
>
>
>
> Yaron and I would like to make another working group last call on this
> draft. We are hopeful there will be enough feedback on this draft from
> people that have reviewed it for us to recommend the draft progressing to
> the next step.
>
>
>
> Please review and respond if you are supportive of this draft, and if you
> are not supportive, please clarify your concerns.
>
>
>
> Dick and Yaron
>
>
>
> [image: Image removed by sender.]ᐧ
> _______________________________________________
> Id-event mailing list
> Id-event@ietf.org
> https://www.ietf.org/mailman/listinfo/id-event
>


-- 
Dave Tonge
CTO
[image: Moneyhub Enterprise]
<http://www.google.com/url?q=http%3A%2F%2Fmoneyhubenterprise.com%2F&sa=D&sntz=1&usg=AFQjCNGUnR5opJv5S1uZOVg8aISwPKAv3A>
t: +44 (0)117 280 5120

Moneyhub Enterprise is a trading style of Moneyhub Financial Technology
Limited which is authorised and regulated by the Financial Conduct
Authority ("FCA"). Moneyhub Financial Technology is entered on the
Financial Services Register (FRN 809360) at fca.org.uk/register.
Moneyhub Financial
Technology is registered in England & Wales, company registration number
06909772 .
Moneyhub Financial Technology Limited 2018 ©

DISCLAIMER: This email (including any attachments) is subject to copyright,
and the information in it is confidential. Use of this email or of any
information in it other than by the addressee is unauthorised and unlawful.
Whilst reasonable efforts are made to ensure that any attachments are
virus-free, it is the recipient's sole responsibility to scan all
attachments for viruses. All calls and emails to and from this company may
be monitored and recorded for legitimate purposes relating to this
company's business. Any opinions expressed in this email (or in any
attachments) are those of the author and do not necessarily represent the
opinions of Moneyhub Financial Technology Limited or of any other group
company.

-- 


Moneyhub Enterprise is a trading style of Moneyhub Financial Technology 
Limited which is authorised and regulated by the Financial Conduct 
Authority ("FCA"). Moneyhub Financial Technology is entered on the 
Financial Services Register (FRN 809360) at https://register.fca.org.uk/ 
<https://register.fca.org.uk/>. Moneyhub Financial Technology is registered 
in England & Wales, company registration number 06909772. Moneyhub 
Financial Technology Limited 2020 © Moneyhub Enterprise, Regus Building, 
Temple Quay, 1 Friary, Bristol, BS1 6EA. 

DISCLAIMER: This email 
(including any attachments) is subject to copyright, and the information in 
it is confidential. Use of this email or of any information in it other 
than by the addressee is unauthorised and unlawful. Whilst reasonable 
efforts are made to ensure that any attachments are virus-free, it is the 
recipient's sole responsibility to scan all attachments for viruses. All 
calls and emails to and from this company may be monitored and recorded for 
legitimate purposes relating to this company's business. Any opinions 
expressed in this email (or in any attachments) are those of the author and 
do not necessarily represent the opinions of Moneyhub Financial Technology 
Limited or of any other group company.