Re: [Id-event] Barry Leiba's No Objection on draft-ietf-secevent-http-push-12: (with COMMENT)

Mike Jones <Michael.Jones@microsoft.com> Thu, 25 June 2020 23:04 UTC

Return-Path: <Michael.Jones@microsoft.com>
X-Original-To: id-event@ietfa.amsl.com
Delivered-To: id-event@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 284413A1055; Thu, 25 Jun 2020 16:04:13 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.1
X-Spam-Level:
X-Spam-Status: No, score=-2.1 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIMWL_WL_HIGH=-0.001, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, RCVD_IN_DNSWL_BLOCKED=0.001, SPF_PASS=-0.001, URIBL_BLOCKED=0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (1024-bit key) header.d=microsoft.com
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id G9TsVvhqufy5; Thu, 25 Jun 2020 16:04:11 -0700 (PDT)
Received: from NAM06-BL2-obe.outbound.protection.outlook.com (mail-eopbgr650100.outbound.protection.outlook.com [40.107.65.100]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id E71B33A1056; Thu, 25 Jun 2020 16:04:10 -0700 (PDT)
ARC-Seal: i=1; a=rsa-sha256; s=arcselector9901; d=microsoft.com; cv=none; b=Lg0L7w9TAjBUuezZ9mgdan9cd7Acmbekdl/Ea32la6mmEwMepttBRcU+Sg3/Oju9S60WASCKVbnKTzBrrLtZG7KiJqLKUQX0ixAdPy/zJsEqYA2e2CZwC/9LUU6qztn1/qUn4l+ltyIHtrcun8wHYw7hOjWjuTBfn/P1UPo+tYmkzYNCDMd4Qbr6gWqbzfHIAopiUBTwm//lbyTg3ofpy4Z0y7ijOUDH7l/633jWgIG5aYj4uwpx/DpDweOvUk1EMMLvMJ2Tg7R75aM6+4IIbAcI5hb8ZPiKDfq0JqfiCrmlPkuWxJlocd1LvDdq5Y+rASIbYaBsEM628AuUeYAOOg==
ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=microsoft.com; s=arcselector9901; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-SenderADCheck; bh=+gsaDn/WhNoWvy9ruoTziPZBrco1mAU+S4u1ty9JDLA=; b=ZYQ6uu1F/a2HAPqtradk3PcDiz/YHgnA4HGVyT/Xlkvbay6mDu7FZi4uOJlR9F74hvFV6t8iUWYIKctVZELuzsjhTBpmDVTA3vVDLQS2XTV3djg9J+QFxT5I7smEQjiW8PKacACi8fxtZ6uZzjUATykjsfqNQfoYU47H/d8mECQzJVjiUvajs9Jc6w7RpgMNWQXN9g3z9TbRzVccjaISWJdqK2ZQk1juSuf4Vdz/iE/DqeCvNbRzC4B4iQlOccRX3Rr8dPec/W5qQd2G2lOn3n/Yzag4+JRnqzyUDI8GCFeADlVt1lLz9N646qQXamGGRXnYCi1Gwq7uU0rP67UdNA==
ARC-Authentication-Results: i=1; mx.microsoft.com 1; spf=pass smtp.mailfrom=microsoft.com; dmarc=pass action=none header.from=microsoft.com; dkim=pass header.d=microsoft.com; arc=none
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=microsoft.com; s=selector2; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-SenderADCheck; bh=+gsaDn/WhNoWvy9ruoTziPZBrco1mAU+S4u1ty9JDLA=; b=YdUAcfGxy0ut2xtmQeNNhzir88DcbEEnvvcQC85ehXEmMNK3l7ErY3JZ9wJh82fiQ+RdXO9trIXFLzarVrCjmW08hfHHWDj3ahB2zOOBjRpRwkp4L3wixXA2bf/eiL/Uv6nFIGijkIsT7NA74SjpH3ixmsoKj4uLlIXcUzWVVdw=
Received: from BY5PR00MB0676.namprd00.prod.outlook.com (2603:10b6:a03:20c::15) by BYAPR00MB0455.namprd00.prod.outlook.com (2603:10b6:a03:d5::28) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.20.3175.0; Thu, 25 Jun 2020 23:04:08 +0000
Received: from BY5PR00MB0676.namprd00.prod.outlook.com ([fe80::5574:af38:1a1e:f8c9]) by BY5PR00MB0676.namprd00.prod.outlook.com ([fe80::5574:af38:1a1e:f8c9%8]) with mapi id 15.20.3175.000; Thu, 25 Jun 2020 23:04:08 +0000
From: Mike Jones <Michael.Jones@microsoft.com>
To: Benjamin Kaduk <kaduk@mit.edu>
CC: Barry Leiba <barryleiba@computer.org>, The IESG <iesg@ietf.org>, "secevent-chairs@ietf.org" <secevent-chairs@ietf.org>, Yaron Sheffer <yaronf.ietf@gmail.com>, "draft-ietf-secevent-http-push@ietf.org" <draft-ietf-secevent-http-push@ietf.org>, "id-event@ietf.org" <id-event@ietf.org>
Thread-Topic: Barry Leiba's No Objection on draft-ietf-secevent-http-push-12: (with COMMENT)
Thread-Index: AdZLROw0jits7vbBQYO+L2G9505ftQ==
Date: Thu, 25 Jun 2020 23:04:08 +0000
Message-ID: <BY5PR00MB067685BDEC298104A769926CF5920@BY5PR00MB0676.namprd00.prod.outlook.com>
Accept-Language: en-US
Content-Language: en-US
X-MS-Has-Attach:
X-MS-TNEF-Correlator:
msip_labels: MSIP_Label_f42aa342-8706-4288-bd11-ebb85995028c_ActionId=4a40f627-0c3c-4994-9d88-0622f49759ff; MSIP_Label_f42aa342-8706-4288-bd11-ebb85995028c_ContentBits=0; MSIP_Label_f42aa342-8706-4288-bd11-ebb85995028c_Enabled=true; MSIP_Label_f42aa342-8706-4288-bd11-ebb85995028c_Method=Standard; MSIP_Label_f42aa342-8706-4288-bd11-ebb85995028c_Name=Internal; MSIP_Label_f42aa342-8706-4288-bd11-ebb85995028c_SetDate=2020-06-25T23:03:08Z; MSIP_Label_f42aa342-8706-4288-bd11-ebb85995028c_SiteId=72f988bf-86f1-41af-91ab-2d7cd011db47;
authentication-results: mit.edu; dkim=none (message not signed) header.d=none;mit.edu; dmarc=none action=none header.from=microsoft.com;
x-originating-ip: [50.47.87.252]
x-ms-publictraffictype: Email
x-ms-office365-filtering-ht: Tenant
x-ms-office365-filtering-correlation-id: cec3594b-98c2-4a59-2ee9-08d8195c1103
x-ms-traffictypediagnostic: BYAPR00MB0455:
x-microsoft-antispam-prvs: <BYAPR00MB04550100F7D6C71B20BCD09BF5920@BYAPR00MB0455.namprd00.prod.outlook.com>
x-ms-oob-tlc-oobclassifiers: OLM:7691;
x-ms-exchange-senderadcheck: 1
x-microsoft-antispam: BCL:0;
x-microsoft-antispam-message-info: 3o4aoxhzYAp9OCzFUJ1Hut9ztZp3LU61bD1ykfNxwd73hNlkq4n8V6GSs4OCgIEIEY4l7x/jRAS9LX6DWcxVOE8803Z3oxf+K7sexUXXEla10opjMhHWf412cMuxiVjrjIRpX4MXli0HyRcxNMQK2L7dp9hNRPJYJv86wOeb1uPNrlS9m1ZtD3eAFii5YhW8+oAow60WhERyg0weVqXtc9H/OfcGzMlcxMz3GavMq2cYsm3oe+Ze+8qNnYKrKIzQZctZs5WV5s8n1WBNT3gNDrNXXWoO1aitjXm+vk7RZgWQolntrg+lRGl3r14KTt2VFqHvROUstTuGssniNeg73HqAXrqLF63SAjYHoTsURkQXkRjVMvsaL2dYrHykcplfOqDB5cnk+axQJ02KkFIAMA==
x-forefront-antispam-report: CIP:255.255.255.255; CTRY:; LANG:en; SCL:1; SRV:; IPV:NLI; SFV:NSPM; H:BY5PR00MB0676.namprd00.prod.outlook.com; PTR:; CAT:NONE; SFTY:; SFS:(4636009)(396003)(136003)(346002)(366004)(376002)(39860400002)(6506007)(186003)(52536014)(478600001)(966005)(4326008)(26005)(71200400001)(64756008)(53546011)(66446008)(66476007)(5660300002)(66946007)(66556008)(76116006)(83380400001)(8990500004)(316002)(6916009)(8936002)(33656002)(10290500003)(55016002)(86362001)(82950400001)(7696005)(2906002)(54906003)(9686003)(8676002)(82960400001); DIR:OUT; SFP:1102;
x-ms-exchange-antispam-messagedata: 1Dbm8o6cSkaa7wsoiHGl4wsLdwnNyVpvLaW9Ku5YxdjrY10taNsNGBSFt0mM7UxCm6tcvSucgI270+ZmyU8y0mwGGYr7R0+rKCu1qS8ei/ifV96Rp4jwIk+Cb4kJcynlEGZkYUryYxAqI6ubQUMgv1Ae5vDtBxBL2qCRPS9W/BelQ9fEJWKe8r0Xg8vTCHP5h2KfgxQ8jJbNTQXGMJu6bD2vNnOn5LPXGZayW+Z7jyYM1IpEjj6BSyTtFstvEXUD8SqNQohRuUWQ0u3Q9ZlV0YU1wFGVpL8laKR2yN5HWFuZO3bGcgD2uayCpU4B6XiwTcDtzEA6nkn6c8p7HNV91Agx7/NvAGTnP7FoHbIwxTnecROEjPwqJEP9apHHkVsX+Pfv8NZvr6ueQGfxurIBN+DvhAY6JgmALAySwnXbZEThPytLqysa28csBjInlvkbg0fIKZh5OPSG8FrfhsdjKnlkMmJtddC+/xVBdk6JQSs=
x-ms-exchange-transport-forked: True
Content-Type: text/plain; charset="utf-8"
Content-Transfer-Encoding: base64
MIME-Version: 1.0
X-OriginatorOrg: microsoft.com
X-MS-Exchange-CrossTenant-AuthAs: Internal
X-MS-Exchange-CrossTenant-AuthSource: BY5PR00MB0676.namprd00.prod.outlook.com
X-MS-Exchange-CrossTenant-Network-Message-Id: cec3594b-98c2-4a59-2ee9-08d8195c1103
X-MS-Exchange-CrossTenant-originalarrivaltime: 25 Jun 2020 23:04:08.4449 (UTC)
X-MS-Exchange-CrossTenant-fromentityheader: Hosted
X-MS-Exchange-CrossTenant-id: 72f988bf-86f1-41af-91ab-2d7cd011db47
X-MS-Exchange-CrossTenant-mailboxtype: HOSTED
X-MS-Exchange-CrossTenant-userprincipalname: z539B9fDHh5fc76nMIL6Yawv10aPeKEZY6l/RNVOjDBMWo3z//PPlUtnNMtnWD3HRKEaWrM0P1KO/30YFAAq4A==
X-MS-Exchange-Transport-CrossTenantHeadersStamped: BYAPR00MB0455
Archived-At: <https://mailarchive.ietf.org/arch/msg/id-event/MtEmTcFXd6xszIJXtgUpT10D2ik>
Subject: Re: [Id-event] Barry Leiba's No Objection on draft-ietf-secevent-http-push-12: (with COMMENT)
X-BeenThere: id-event@ietf.org
X-Mailman-Version: 2.1.29
Precedence: list
List-Id: "A mailing list to discuss the potential solution for a common identity event messaging format and distribution system." <id-event.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/id-event>, <mailto:id-event-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/id-event/>
List-Post: <mailto:id-event@ietf.org>
List-Help: <mailto:id-event-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/id-event>, <mailto:id-event-request@ietf.org?subject=subscribe>
X-List-Received-Date: Thu, 25 Jun 2020 23:04:13 -0000

I've noted this and will think about ways to improve the guidance.

				Thanks,
				-- Mike

-----Original Message-----
From: Benjamin Kaduk <kaduk@mit.edu> 
Sent: Thursday, June 25, 2020 3:13 PM
To: Mike Jones <Michael.Jones=40microsoft.com@dmarc.ietf.org>
Cc: Barry Leiba <barryleiba@computer.org>; The IESG <iesg@ietf.org>; secevent-chairs@ietf.org; Yaron Sheffer <yaronf.ietf@gmail.com>; draft-ietf-secevent-http-push@ietf.org; id-event@ietf.org
Subject: Re: Barry Leiba's No Objection on draft-ietf-secevent-http-push-12: (with COMMENT)

Thanks for the updates, Mike.  Just one note...

On Thu, Jun 25, 2020 at 05:54:32AM +0000, Mike Jones wrote:
> Thanks for your review, Barry.  https://tools.ietf.org/html/draft-ietf-secevent-http-push-13 is intended to address your comments.  Detailed replies are inline, prefixed by "Mike>".
> 
> -----Original Message-----
> From: Barry Leiba via Datatracker <noreply@ietf.org>
> Sent: Wednesday, June 24, 2020 1:41 PM
> To: The IESG <iesg@ietf.org>
> Cc: draft-ietf-secevent-http-push@ietf.org; secevent-chairs@ietf.org; 
> id-event@ietf.org; Yaron Sheffer <yaronf.ietf@gmail.com>; 
> yaronf.ietf@gmail.com
> Subject: Barry Leiba's No Objection on 
> draft-ietf-secevent-http-push-12: (with COMMENT)
> 
[...]
> — Section 7.1 —
> 
>    Future assignments are to be made
>    through the Specification Required registration policy
> 
> Please provide some brief guidance to the designated experts.  Thanks.
> 
> Mike> Done - mostly copying applicable guidance from the JWT spec [RFC 
> Mike> 7519]

Unfortunately, the RFC 7519 guidance is perhaps a bit lacking, in that while it says the experts should consider several factors (duplication of existing functionality, general vs. specific applicability, etc.), it doesn't say very clearly which direction any given factor should move the experts in.  For example, while I expect near-universal agreement that duplicating existing functionality should receive pushback, the agreement may be less clear that proposals that are only useful by a single application should get pushback.

I think we've done a little better with our guidance to experts in more recent RFCs, but my spot-checking failed to find one that I liked.

-Ben