Re: [Id-event] [Last-Call] Last Call: <draft-ietf-secevent-http-poll-09.txt> (Poll-Based Security Event Token (SET) Delivery Using HTTP) to Proposed Standard

Mike Jones <Michael.Jones@microsoft.com> Tue, 09 June 2020 00:20 UTC

Return-Path: <Michael.Jones@microsoft.com>
X-Original-To: id-event@ietfa.amsl.com
Delivered-To: id-event@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 97D1D3A0807; Mon, 8 Jun 2020 17:20:15 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.101
X-Spam-Level:
X-Spam-Status: No, score=-2.101 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIMWL_WL_HIGH=-0.001, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, SPF_PASS=-0.001, URIBL_BLOCKED=0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (1024-bit key) header.d=microsoft.com
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id uEakwmYvbhJo; Mon, 8 Jun 2020 17:20:14 -0700 (PDT)
Received: from NAM06-BL2-obe.outbound.protection.outlook.com (mail-eopbgr650105.outbound.protection.outlook.com [40.107.65.105]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 16DE63A07AF; Mon, 8 Jun 2020 17:20:13 -0700 (PDT)
ARC-Seal: i=1; a=rsa-sha256; s=arcselector9901; d=microsoft.com; cv=none; b=WsNcN5PVHKq8Awxi41QeQ5cHOTpyi2U9vhfaVIxhDp/CCUtr1mnpZjokn424EJFD1YeWMIX74lxoJJbtWFjlFTGlPSqGLHK85flgJztT/PFDxwdVaI29V6AfYsAN9SoX6USOFQ+Df3jWxjEWkokXl5bnR0zfSCyEpuB5vizgQCz01FPunPYl1PzGgbzG4S6pQfwGjvJx0Pa7DD81YApMnnrT3Bok8vs3XJnqfBh7VJapiSfwNOT5aqc0ch0qGHRizJVGC9KQEyW6rCcgz4cKZano9+HijdlE9JgjRHUubASTS3Y0eTuATLwDeV094hGB13+d6m9CEB5wMgqKy5WiRg==
ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=microsoft.com; s=arcselector9901; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-SenderADCheck; bh=RQ/7bm2ogcGTvpXXRwMBHWKN1jPWm84wOMmoIjIn1lc=; b=S9CEhiFGHS0lUIfY4Zv/KXefL+G7R24BSCeKKlgcdC1kfjyM6WH9QYgXzXBZ95eFdV3nVjXWlOPMYWJRMfq2NhKMWT9YNUTr/OIOh+NR5fDM9zTIIlHoGWIbK8DEIhPRQy83Ry6WE+71k3BXYZmD44pE/eUHKH63tXjw4ybrNCndFFjUcd6FKDNRo1HHZJ1QoApOi81hnLVPB+hTbGJd8gy2/XLCJ+w16dlfvIE+Cspiwf1KOPC+f3fybPJeE/ncoO9dU4piHqgSKUSDYu0BwUtDsGFhRkLy9VgcMPaQrPo2fGl2r5Pr3s+rvkBKWCWpd09vgq/aa9rmwYcA57Y+sA==
ARC-Authentication-Results: i=1; mx.microsoft.com 1; spf=pass smtp.mailfrom=microsoft.com; dmarc=pass action=none header.from=microsoft.com; dkim=pass header.d=microsoft.com; arc=none
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=microsoft.com; s=selector2; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-SenderADCheck; bh=RQ/7bm2ogcGTvpXXRwMBHWKN1jPWm84wOMmoIjIn1lc=; b=KJ5PNeVNthKq+aBpHbXVrqO2UstPAKgrvfUtJ+HSV7KRm4YsOTkQ1gNThiRTLHhdaLVKRASUg1qh2A9uGj/y9zBf/8aTVGGRe1iuzdXs4VdfojcuyvNawy8G5sL8Smh8B4/+pR7MOpsM2/UE+bvWJMGkXmmPRoIkt6ytG8LoNXw=
Received: from MN2PR00MB0686.namprd00.prod.outlook.com (2603:10b6:208:15f::13) by MN2PR00MB0558.namprd00.prod.outlook.com (2603:10b6:208:fd::19) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.20.3114.0; Tue, 9 Jun 2020 00:20:12 +0000
Received: from MN2PR00MB0686.namprd00.prod.outlook.com ([fe80::b816:9dfb:f80d:3b9f]) by MN2PR00MB0686.namprd00.prod.outlook.com ([fe80::b816:9dfb:f80d:3b9f%8]) with mapi id 15.20.3114.000; Tue, 9 Jun 2020 00:20:12 +0000
From: Mike Jones <Michael.Jones@microsoft.com>
To: Benjamin Kaduk <kaduk@mit.edu>, Mark Nottingham <mnot@mnot.net>
CC: "last-call@ietf.org" <last-call@ietf.org>, "secevent-chairs@ietf.org" <secevent-chairs@ietf.org>, "id-event@ietf.org" <id-event@ietf.org>, "draft-ietf-secevent-http-poll@ietf.org" <draft-ietf-secevent-http-poll@ietf.org>
Thread-Topic: [Last-Call] Last Call: <draft-ietf-secevent-http-poll-09.txt> (Poll-Based Security Event Token (SET) Delivery Using HTTP) to Proposed Standard
Thread-Index: AdY987ylEvCKvQCXQwiY/uvS1fG4Vg==
Date: Tue, 09 Jun 2020 00:20:12 +0000
Message-ID: <MN2PR00MB0686FB35104E6FA9F4EF6540F5820@MN2PR00MB0686.namprd00.prod.outlook.com>
Accept-Language: en-US
Content-Language: en-US
X-MS-Has-Attach:
X-MS-TNEF-Correlator:
msip_labels: MSIP_Label_f42aa342-8706-4288-bd11-ebb85995028c_ActionId=9f7b7952-4c6e-4402-84fc-000015df8287; MSIP_Label_f42aa342-8706-4288-bd11-ebb85995028c_ContentBits=0; MSIP_Label_f42aa342-8706-4288-bd11-ebb85995028c_Enabled=true; MSIP_Label_f42aa342-8706-4288-bd11-ebb85995028c_Method=Standard; MSIP_Label_f42aa342-8706-4288-bd11-ebb85995028c_Name=Internal; MSIP_Label_f42aa342-8706-4288-bd11-ebb85995028c_SetDate=2020-06-09T00:18:35Z; MSIP_Label_f42aa342-8706-4288-bd11-ebb85995028c_SiteId=72f988bf-86f1-41af-91ab-2d7cd011db47;
authentication-results: mit.edu; dkim=none (message not signed) header.d=none;mit.edu; dmarc=none action=none header.from=microsoft.com;
x-originating-ip: [50.47.87.252]
x-ms-publictraffictype: Email
x-ms-office365-filtering-ht: Tenant
x-ms-office365-filtering-correlation-id: 4950337d-bafc-42d7-f135-08d80c0ae024
x-ms-traffictypediagnostic: MN2PR00MB0558:
x-microsoft-antispam-prvs: <MN2PR00MB0558275831D492F19FD46A58F5820@MN2PR00MB0558.namprd00.prod.outlook.com>
x-ms-oob-tlc-oobclassifiers: OLM:9508;
x-forefront-prvs: 042957ACD7
x-ms-exchange-senderadcheck: 1
x-microsoft-antispam: BCL:0;
x-microsoft-antispam-message-info: 1UaDisK3I/oi866APIeM2NhpygUXG6dXmltQe+5z53Eh7iecC1HWVoVoDJeBj+w1pic6ac/cOVHGrXdzattY4kU3jT/8D3BoweX1k9h2Se3vq+r7X6gvCc0d+dS2oNTQ09PW8YVEQ1NLVvoJmhEJa7uYmoguPaPMGcGZbXGs+JzhjRjtOZT3lcrcdcdnpy4vZ7B41r9lHKVyPbwqfS08lDf7bDoFCOt+H43LO5SDBA4DgHdKTF5MROVzvm60H7kpuTuZXuS9yd4N69c4ntrsN2+L1RXNAn/YYzPvLCyzQ38qZC5yuKHVBGHvVdPLUBrYrHbJKn2tjfP5CmgcBSi3KMa6HQ+lU3UPGNDIarWuYlPzj+pSPu5NJkgiRlgpHgWD5baOujYed6S+j90wkiw6zQ==
x-forefront-antispam-report: CIP:255.255.255.255; CTRY:; LANG:en; SCL:1; SRV:; IPV:NLI; SFV:NSPM; H:MN2PR00MB0686.namprd00.prod.outlook.com; PTR:; CAT:NONE; SFTY:; SFS:(4636009)(346002)(136003)(366004)(376002)(396003)(39860400002)(4326008)(55016002)(26005)(186003)(86362001)(82960400001)(82950400001)(2906002)(9686003)(966005)(53546011)(8990500004)(7696005)(15650500001)(71200400001)(6506007)(66556008)(64756008)(10290500003)(66946007)(478600001)(110136005)(54906003)(5660300002)(316002)(33656002)(66446008)(52536014)(66476007)(76116006)(8676002)(83380400001)(8936002); DIR:OUT; SFP:1102;
x-ms-exchange-antispam-messagedata: IbgCcMLZJZZEKjDjabolMtrIil7iCTgXGjYQJzjHvP77LxsSk5rd4ZXqGIW8DTG0Rec43B3JRcYtKpPCvRUU5QtKOeTNYXTG7gZwiGSpJzQB69cFqLcj3vp/0jgR3o1RvPiXlbqUXzzVM1OvrHwsgMpU9AMImSCssxLQd1ay2skVr7jdA04xFofRD6pI/GNZ0w8anj41ewiX4SjNMH5eb6MwNfpUPaQp4BJ5wr72nsrDt1UzDzbr9mxWLWV1vtVjMLPLFLFfoZj+JzUYMy3pWSS1j4IGnCI72hc+Mbkz39AgHE+9NsxL8XWBmNmkF8dG2vCgE57rMkflN4BZ9W1QdcXd4VgyUdk6URiW4RdnbdhkTsEo3acfPgkHELDDDxrygxrgK6G5g03Nlt403gtpqDGxda8trXkqxjLN/mc1aPi7zrghUOSUPbH4xyoYbeYzRHxxa0vgDyC6RLHLBVlsJRd6uShW6nxLj8o1SE0Mv+s=
x-ms-exchange-transport-forked: True
Content-Type: text/plain; charset="us-ascii"
Content-Transfer-Encoding: quoted-printable
MIME-Version: 1.0
X-OriginatorOrg: microsoft.com
X-MS-Exchange-CrossTenant-Network-Message-Id: 4950337d-bafc-42d7-f135-08d80c0ae024
X-MS-Exchange-CrossTenant-originalarrivaltime: 09 Jun 2020 00:20:12.1454 (UTC)
X-MS-Exchange-CrossTenant-fromentityheader: Hosted
X-MS-Exchange-CrossTenant-id: 72f988bf-86f1-41af-91ab-2d7cd011db47
X-MS-Exchange-CrossTenant-mailboxtype: HOSTED
X-MS-Exchange-CrossTenant-userprincipalname: rWkyWljarjeSjWUOn66KoC4c/7OUbxzcSHhcAGmvqgtCccU7myk2uwYwSRckbiodgm6Rq1i8uhtXWrCVzdhKBQ==
X-MS-Exchange-Transport-CrossTenantHeadersStamped: MN2PR00MB0558
Archived-At: <https://mailarchive.ietf.org/arch/msg/id-event/_E3St6k_0XanCl22UnTNEKW0ewA>
Subject: Re: [Id-event] [Last-Call] Last Call: <draft-ietf-secevent-http-poll-09.txt> (Poll-Based Security Event Token (SET) Delivery Using HTTP) to Proposed Standard
X-BeenThere: id-event@ietf.org
X-Mailman-Version: 2.1.29
Precedence: list
List-Id: "A mailing list to discuss the potential solution for a common identity event messaging format and distribution system." <id-event.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/id-event>, <mailto:id-event-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/id-event/>
List-Post: <mailto:id-event@ietf.org>
List-Help: <mailto:id-event-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/id-event>, <mailto:id-event-request@ietf.org?subject=subscribe>
X-List-Received-Date: Tue, 09 Jun 2020 00:20:16 -0000

Thanks for your review, Mark.  I corrected (1) as you suggested in https://tools.ietf.org/html/draft-ietf-secevent-http-push-11.

				-- Mike

-----Original Message-----
From: Benjamin Kaduk <kaduk@mit.edu> 
Sent: Friday, May 8, 2020 5:04 PM
To: Mark Nottingham <mnot@mnot.net>
Cc: last-call@ietf.org; secevent-chairs@ietf.org; id-event@ietf.org; draft-ietf-secevent-http-poll@ietf.org
Subject: Re: [Last-Call] Last Call: <draft-ietf-secevent-http-poll-09.txt> (Poll-Based Security Event Token (SET) Delivery Using HTTP) to Proposed Standard

Hi Mark,

On Mon, May 04, 2020 at 04:52:10PM +1000, Mark Nottingham wrote:
> Just two comments, based upon a quick read:
> 
> 1. In section 2: POST is not specific to HTTP/1.1, and it's not good practice to specify a HTTP version. Just say "HTTP POST".

Thanks for noting that, it's a good point (and probably just an oversight, as "HTTP POST" is used sevarl times but "HTTP/1.1 POST" just the once).

> 2. I'm not intimately familiar with the use case, but using POST in this manner precludes caching as well as fan-out (i.e., "collapsed forwarding"). Have you considered just using Atom or a similar event feed structure?

There's a bit of discussion on this point at https://tools.ietf.org/html/draft-ietf-secevent-http-push-08#appendix-A,
though Atom itself is not listed there.

-Ben