Re: [Id-event] [UNVERIFIED SENDER] Re: AD review of draft-ietf-secevent-http-push-07

"Richard Backman, Annabelle" <richanna@amazon.com> Mon, 27 April 2020 23:31 UTC

Return-Path: <prvs=379e0d8e7=richanna@amazon.com>
X-Original-To: id-event@ietfa.amsl.com
Delivered-To: id-event@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 5B2563A0DEF; Mon, 27 Apr 2020 16:31:15 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -9.6
X-Spam-Level:
X-Spam-Status: No, score=-9.6 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIMWL_WL_HIGH=-0.001, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, SPF_HELO_NONE=0.001, SPF_PASS=-0.001, URIBL_BLOCKED=0.001, USER_IN_DEF_SPF_WL=-7.5] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (1024-bit key) header.d=amazon.com
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id zAOZnyYwRH2H; Mon, 27 Apr 2020 16:31:13 -0700 (PDT)
Received: from smtp-fw-6002.amazon.com (smtp-fw-6002.amazon.com [52.95.49.90]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 64CDD3A0DE7; Mon, 27 Apr 2020 16:31:13 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=amazon.com; i=@amazon.com; q=dns/txt; s=amazon201209; t=1588030274; x=1619566274; h=from:to:cc:date:message-id:references:in-reply-to: content-id:content-transfer-encoding:mime-version:subject; bh=t4JmFHJ1pRitp1Eljvpo4QkSRcR51fGWK3Us1LyDjCo=; b=siN3+mySyOczeX2cw6RTTmDZHyT4zZAlszo5ovil8yxLjvKtfaUZFibY JnSl6aOZXrTmp/Unn3GuIZRJmkaGi6/8xYhXfiNI/Eb3ASIljPcEkqRd1 OABWycF8LqR8sdN8u4hw7Bgtv87Chho/Y1S/IjGVyCT9JsnZ2d2u7ZNc/ Y=;
IronPort-SDR: 3Yw+JnFS5Y2xcYTOtzvLRMZ5dIS42WFvJaNIwDqn4mQ0ky48ztdElb7/MgoWEOxGLkiYXTyqIk TiOnREvTPAtg==
X-IronPort-AV: E=Sophos;i="5.73,325,1583193600"; d="scan'208";a="27539081"
Thread-Topic: [UNVERIFIED SENDER] Re: [Id-event] AD review of draft-ietf-secevent-http-push-07
Received: from iad12-co-svc-p1-lb1-vlan3.amazon.com (HELO email-inbound-relay-2b-a7fdc47a.us-west-2.amazon.com) ([10.43.8.6]) by smtp-border-fw-out-6002.iad6.amazon.com with ESMTP; 27 Apr 2020 23:30:58 +0000
Received: from EX13MTAUWC001.ant.amazon.com (pdx4-ws-svc-p6-lb7-vlan2.pdx.amazon.com [10.170.41.162]) by email-inbound-relay-2b-a7fdc47a.us-west-2.amazon.com (Postfix) with ESMTPS id 863F7C5C07; Mon, 27 Apr 2020 23:30:57 +0000 (UTC)
Received: from EX13D11UWC004.ant.amazon.com (10.43.162.101) by EX13MTAUWC001.ant.amazon.com (10.43.162.135) with Microsoft SMTP Server (TLS) id 15.0.1497.2; Mon, 27 Apr 2020 23:30:56 +0000
Received: from EX13D11UWC004.ant.amazon.com (10.43.162.101) by EX13D11UWC004.ant.amazon.com (10.43.162.101) with Microsoft SMTP Server (TLS) id 15.0.1497.2; Mon, 27 Apr 2020 23:30:56 +0000
Received: from EX13D11UWC004.ant.amazon.com ([10.43.162.101]) by EX13D11UWC004.ant.amazon.com ([10.43.162.101]) with mapi id 15.00.1497.006; Mon, 27 Apr 2020 23:30:56 +0000
From: "Richard Backman, Annabelle" <richanna@amazon.com>
To: Mike Jones <Michael.Jones@microsoft.com>, Benjamin Kaduk <kaduk@mit.edu>
CC: "draft-ietf-secevent-http-push.all@ietf.org" <draft-ietf-secevent-http-push.all@ietf.org>, "id-event@ietf.org" <id-event@ietf.org>
Thread-Index: AdYapvFcpkAs4jP3S4SfG8JyuYpI/QB9F6IAABFCfgD//47/gIAAdvYA//+RlQCAAAo2AA==
Date: Mon, 27 Apr 2020 23:30:56 +0000
Message-ID: <FF80E759-B7CC-4E19-8000-1DD63A0AB8D2@amazon.com>
References: <CH2PR00MB0678090216D0DC995E0AAD64F5D10@CH2PR00MB0678.namprd00.prod.outlook.com> <06FCE524-D221-475A-998B-24E3CE85635E@amazon.com> <20200427220816.GE27494@kduck.mit.edu> <5237A696-05A8-483D-BB7E-D10D372B8247@amazon.com> <MN2PR00MB0688AC0CCE37A185BF607179F5AF0@MN2PR00MB0688.namprd00.prod.outlook.com> <90E0D5D6-6741-403A-9E6B-8489CE0D0158@amazon.com>
In-Reply-To: <90E0D5D6-6741-403A-9E6B-8489CE0D0158@amazon.com>
Accept-Language: en-US
Content-Language: en-US
X-MS-Has-Attach:
X-MS-TNEF-Correlator:
user-agent: Microsoft-MacOutlook/10.21.0.200113
x-ms-exchange-messagesentrepresentingtype: 1
x-ms-exchange-transport-fromentityheader: Hosted
x-originating-ip: [10.43.160.8]
Content-Type: text/plain; charset="utf-8"
Content-ID: <3EC6709367FC3249817785FC16F5E06C@amazon.com>
Content-Transfer-Encoding: base64
MIME-Version: 1.0
Archived-At: <https://mailarchive.ietf.org/arch/msg/id-event/PHfjCIYCdP-ahjyz91lnm4PXeoM>
Subject: Re: [Id-event] [UNVERIFIED SENDER] Re: AD review of draft-ietf-secevent-http-push-07
X-BeenThere: id-event@ietf.org
X-Mailman-Version: 2.1.29
Precedence: list
List-Id: "A mailing list to discuss the potential solution for a common identity event messaging format and distribution system." <id-event.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/id-event>, <mailto:id-event-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/id-event/>
List-Post: <mailto:id-event@ietf.org>
List-Help: <mailto:id-event-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/id-event>, <mailto:id-event-request@ietf.org?subject=subscribe>
X-List-Received-Date: Mon, 27 Apr 2020 23:31:16 -0000

Pull request submitted: https://github.com/independentid/Identity-Events/pull/32

–
Annabelle Backman (she/her)
AWS Identity
https://aws.amazon.com/identity/
 

On 4/27/20, 3:54 PM, "Richard Backman, Annabelle" <richanna@amazon.com> wrote:

My impression was the changes were only in -push. If there some of these changes need to be made to -poll I can do that as well. Or is there a separate set of changes for -poll?

I will at least drop in on the virtual IIW. I am not sure how much of a presence I will be there, but happy to set aside some time to discuss either there or 1:1 via <video conference platform du jour as long as it isn't Zoom>.

–
Annabelle Backman (she/her)
AWS Identity
https://aws.amazon.com/identity/
 

On 4/27/20, 3:30 PM, "Mike Jones" <Michael.Jones@microsoft.com> wrote:

CAUTION: This email originated from outside of the organization. Do not click links or open attachments unless you can confirm the sender and know the content is safe.



Thanks Annabelle.  So you'll do Pull and I'll do Poll, right?  Let's check both of our changes into GitHub and review them for each other, and then publish together.

                                -- Mike

P.S.  Will you be at the virtual IIW this week, Annabelle?  Maybe we could virtually talk about the changes there, if doing so would be useful.

-----Original Message-----
From: Richard Backman, Annabelle <richanna@amazon.com>
Sent: Monday, April 27, 2020 3:24 PM
To: Benjamin Kaduk <kaduk@mit.edu>
Cc: Mike Jones <Michael.Jones@microsoft.com>; draft-ietf-secevent-http-push.all@ietf.org; id-event@ietf.org
Subject: [EXTERNAL] Re: [UNVERIFIED SENDER] Re: [Id-event] AD review of draft-ietf-secevent-http-push-07

Okay, I'll make the changes and get out an update.

Note that since all configuration of the transmitter/receiver relationship is out of scope per Section 1, saying that the expected identity for DNS-ID is "out of scope" is just rephrasing your suggestion of "the expected name will be configured" with language consistent with the rest of the text. __

–
Annabelle Backman (she/her)
AWS Identity
https://aws.amazon.com/identity/


On 4/27/20, 3:08 PM, "Benjamin Kaduk" <kaduk@mit.edu> wrote:

CAUTION: This email originated from outside of the organization. Do not click links or open attachments unless you can confirm the sender and know the content is safe.



On Mon, Apr 27, 2020 at 08:54:05PM +0000, Richard Backman, Annabelle wrote:
> I can put out an update, but I think I'm missing part of the conversation here.
>
> Here is what I understand the changes to be, all within -push:

I think that's right, as much as putting (3) out of scope pains me.

Thanks,

Ben

> 1. Section 1 should get the sentence "How SETs are defined and the process by which security events are identified for SET Recipients are specified in [RFC8417]."
>
> 2. In Section 5.3, replace "e.g., subject claims" with "PII" as was already done in -poll.
>
> 3. In Section 5.3, add text explaining that determining the expected service identity to match against using DNS-ID is out of scope.
>
> 4. In Privacy Considerations, add "SET Transmistters SHOULD attempt to deliver sets that are targeted to the specific business and protocol needs of subscribers", as already exists within -poll.
>
> –
> Annabelle Backman (she/her)
> AWS Identity
> https://aws.amazon.com/identity/
>
>
> On 4/24/20, 7:12 PM, "Mike Jones" <Michael.Jones@microsoft.com> wrote:
>
> CAUTION: This email originated from outside of the organization. Do not click links or open attachments unless you can confirm the sender and know the content is safe.
>
>
>
> These suggestions make sense to me.  Do you want to do these Annabelle, or would you like me to?  If I do it, it will probably be early next week.
>
>                                 Thanks all,
>                                 -- Mike
>
> -----Original Message-----
> From: Benjamin Kaduk <kaduk@mit.edu>
> Sent: Friday, April 24, 2020 5:44 PM
> To: Mike Jones <Michael.Jones@microsoft.com>
> Cc: draft-ietf-secevent-http-push.all@ietf.org; id-event@ietf.org
> Subject: Re: [Id-event] AD review of draft-ietf-secevent-http-push-07
>
> Hi Mike,
>
> My apologies for yet another long delay.  I'll trim the bits that are in good shape (nearly all of them!).
>
> I also took another look at the "diff" (manually, that is) between push and poll, and found a few things in poll that should probably be here as well.
>
> Section 1 should get the sentence "How SETs are defined and the process by which security events are identified for SET Recipients are specified in [RFC8417]."
>
> In the thread for -poll we said that Section 5.3 of this document would get a s/e.g., subject claims/PII/ to match, but that doesn't seem to have happened yet.
>
> The poll Privacy Considerations have a note at the start of the section about "SET Transmistters SHOULD attempt to deliver sets that are targeted to the specific business and protocol needs of subscribers"; would a similar note make sense for us?
>
> On Fri, Feb 07, 2020 at 05:17:12PM +0000, Mike Jones wrote:
> > draft-ietf-secevent-http-push-08<https://tools.ietf.org/html/draft-ietf-secevent-http-push-08> was published to address these review comments.  (-09<https://tools.ietf.org/html/draft-ietf-secevent-http-push-09> addressed additional editorial nits.)  Descriptions of the changes made for these comments are inline, prefixed by "Mike>".
> >
> >
> >
> > -----Original Message-----
> > From: Id-event <id-event-bounces@ietf.org> On Behalf Of Benjamin Kaduk
> > Sent: Tuesday, December 10, 2019 4:36 PM
> > To: draft-ietf-secevent-http-push.all@ietf.org
> > Cc: id-event@ietf.org
> > Subject: [Id-event] AD review of draft-ietf-secevent-http-push-07
> >
> >
> > Section 5
> >
> >
> >
> > I want to see how the discussion goes on poll's "Access Token Considerations" first, but we may want something like that as well.
> >
> >
> >
> > Mike> Yes, it makes sense to do that
>
> Since we no longer explicitly mention WWW-Authenticate in this document I won't insist on copying the Access Token Considerations over, but it could still be useful to do so.
>
> > Section 5.2
> >
> >
> >
> > RFC 6125 is great and I'm glad we're referencing it, but it does leave a couple of gaps to be specified for a full picture of application usage.
> >
> > Specifically, we should say what name from the certificate we validate (and, ideally, how the application knows what name it is expecting to see in that name field in the certificate).  Most applications these days will be using the DNS-ID, and perhaps something about wildcards and/or revocation info.  The last time I was making this comment on a document I pointed to RFC 8461 as a potential example to crib from, at least in terms of the types of things to talk about.
> >
> >
> >
> > Mike> I added DNS-ID.
>
> The DNS-ID is the part of the certificate that we compare a name against, but a comparison requires having two things -- since recipients are already configured, can't we say that the expected name will be configured as well?
>
> Thanks for all the updates!
>
> -Ben
>