Re: [Id-event] Last Call: <draft-ietf-secevent-http-poll-09.txt> (Poll-Based Security Event Token (SET) Delivery Using HTTP) to Proposed Standard

Mark Nottingham <mnot@mnot.net> Mon, 04 May 2020 06:52 UTC

Return-Path: <mnot@mnot.net>
X-Original-To: id-event@ietfa.amsl.com
Delivered-To: id-event@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 642F83A0CBE; Sun, 3 May 2020 23:52:19 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.1
X-Spam-Level:
X-Spam-Status: No, score=-2.1 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, SPF_PASS=-0.001, URIBL_BLOCKED=0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (2048-bit key) header.d=mnot.net header.b=T9UKRbUc; dkim=pass (2048-bit key) header.d=messagingengine.com header.b=DBDJC2OF
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id NGNo9JVphtxJ; Sun, 3 May 2020 23:52:18 -0700 (PDT)
Received: from wout4-smtp.messagingengine.com (wout4-smtp.messagingengine.com [64.147.123.20]) (using TLSv1.2 with cipher AECDH-AES256-SHA (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 006E13A0CB2; Sun, 3 May 2020 23:52:17 -0700 (PDT)
Received: from compute4.internal (compute4.nyi.internal [10.202.2.44]) by mailout.west.internal (Postfix) with ESMTP id 3FEE651E; Mon, 4 May 2020 02:52:17 -0400 (EDT)
Received: from mailfrontend2 ([10.202.2.163]) by compute4.internal (MEProxy); Mon, 04 May 2020 02:52:17 -0400
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=mnot.net; h= content-type:mime-version:subject:from:in-reply-to:date:cc :content-transfer-encoding:message-id:references:to; s=fm2; bh=Z Ny/EeQWspvjC3FssNLTj4XFMpUjq1W8NYUBVyDVr7o=; b=T9UKRbUc41IXe2BBc 6UUDEkEBKzhPUqKACA6S9NirbCfzsVaYPB86r3oQkUMePkr/v27v2FhjZEgc0jq7 YLAW2jAbSAqh5kjGmxceTz9O2YK2sdvwLRCEV7yYrVnmsjPNj2TZxhAnITrSHTw8 6XDmYLy21gga2ZP24XQM5rrl3FhHHlaF6OXDb1ASFVHrnt9p7kN0Z4go6TThhYdR 9rOmQzl9DDv8cy41GmQGlHYYaAb+82fxJ+l5JPGubf/sBVYkZj7AcLHxyrYOeFBa VMvnkgGJcPJAMkd+RMgQ2M0TClkDdEAz6V1fmTs2WBRQpzJQ7+uZ9u51z+F0EDTZ geLgw==
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d= messagingengine.com; h=cc:content-transfer-encoding:content-type :date:from:in-reply-to:message-id:mime-version:references :subject:to:x-me-proxy:x-me-proxy:x-me-sender:x-me-sender :x-sasl-enc; s=fm2; bh=ZNy/EeQWspvjC3FssNLTj4XFMpUjq1W8NYUBVyDVr 7o=; b=DBDJC2OFCmYQMhsPUk2UEClXd2UroFJeSRRTVsp6EQv5yOtWEDPcU/P/p u2OeS6AknM/PorXRnbgegZSWzty7w0OveInG+ielYM827SbSzwZ2tN+Av3naumsq S9YOOpO9WmIbmr5+XRPuokajgWOIpL9OBK2TKCRBCTJnEwA+iD8SMXbKQNZieE0s cPt1UfgvfpRwliwBXQ8s2V+JiVUM1WzijA6DBm5dRt2h22XTjUx1sGQAFuJObuav zEkeeE0hQqDnAJSy7HEPXdkq/CPnCi7oIbvigaOs4oYtSsULgMVc92Lr2ruo8IA3 S8CAurLZQCe/XEMf3y+a6ige5Lpxg==
X-ME-Sender: <xms:oLuvXqZ7mbklgGlwPYoT83NZRULs4wLRP-nJvKGDecq6VXEnoZpIQQ>
X-ME-Proxy-Cause: gggruggvucftvghtrhhoucdtuddrgeduhedrjeefgdduuddtucetufdoteggodetrfdotf fvucfrrhhofhhilhgvmecuhfgrshhtofgrihhlpdfqfgfvpdfurfetoffkrfgpnffqhgen uceurghilhhouhhtmecufedttdenucenucfjughrpegtggfuhfgjfffgkfhfvffosehtqh hmtdhhtddvnecuhfhrohhmpeforghrkhcupfhothhtihhnghhhrghmuceomhhnohhtsehm nhhothdrnhgvtheqnecuggftrfgrthhtvghrnhepvefffffhudetveevhfeuffeigedtue dtheffleetffeftddtgeegjeehieeuteetnecuffhomhgrihhnpehmnhhothdrnhgvthen ucfkphepudduledrudejrdduheekrddvhedunecuvehluhhsthgvrhfuihiivgeptdenuc frrghrrghmpehmrghilhhfrhhomhepmhhnohhtsehmnhhothdrnhgvth
X-ME-Proxy: <xmx:oLuvXuLS6x1vSmOM7ZWK8VEM8B8uVuxvldoeTqkcTtN9yge9Z2eIZA> <xmx:oLuvXt0F_S5TU8Da7CSABoc34Nib7Rgf7BomFTxwrJsAgiN5z9odcw> <xmx:oLuvXkijWqiV-dIopsrfmoud0njE-VzTzsMLZEAZhXXcl25c7wSspA> <xmx:oLuvXpU332WxAvUucv0w5enlKKu4HspjpSKzVTOyGl5N0XQJBGGiTA>
Received: from macbook-air.mnot.net (119-17-158-251.77119e.mel.static.aussiebb.net [119.17.158.251]) by mail.messagingengine.com (Postfix) with ESMTPA id 8BAFF3065FF7; Mon, 4 May 2020 02:52:14 -0400 (EDT)
Content-Type: text/plain; charset="us-ascii"
Mime-Version: 1.0 (Mac OS X Mail 13.4 \(3608.80.23.2.2\))
From: Mark Nottingham <mnot@mnot.net>
In-Reply-To: <158820314329.8065.5649161881109410292@ietfa.amsl.com>
Date: Mon, 04 May 2020 16:52:10 +1000
Cc: secevent-chairs@ietf.org, draft-ietf-secevent-http-poll@ietf.org, id-event@ietf.org
Content-Transfer-Encoding: quoted-printable
Message-Id: <28F85EC1-B149-48E2-827A-24BD551D7732@mnot.net>
References: <158820314329.8065.5649161881109410292@ietfa.amsl.com>
To: last-call@ietf.org
X-Mailer: Apple Mail (2.3608.80.23.2.2)
Archived-At: <https://mailarchive.ietf.org/arch/msg/id-event/eX6u-PUEK8QxvvpVE4miG5B4Vlo>
Subject: Re: [Id-event] Last Call: <draft-ietf-secevent-http-poll-09.txt> (Poll-Based Security Event Token (SET) Delivery Using HTTP) to Proposed Standard
X-BeenThere: id-event@ietf.org
X-Mailman-Version: 2.1.29
Precedence: list
List-Id: "A mailing list to discuss the potential solution for a common identity event messaging format and distribution system." <id-event.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/id-event>, <mailto:id-event-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/id-event/>
List-Post: <mailto:id-event@ietf.org>
List-Help: <mailto:id-event-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/id-event>, <mailto:id-event-request@ietf.org?subject=subscribe>
X-List-Received-Date: Mon, 04 May 2020 06:52:19 -0000

Just two comments, based upon a quick read:

1. In section 2: POST is not specific to HTTP/1.1, and it's not good practice to specify a HTTP version. Just say "HTTP POST".

2. I'm not intimately familiar with the use case, but using POST in this manner precludes caching as well as fan-out (i.e., "collapsed forwarding"). Have you considered just using Atom or a similar event feed structure?

Cheers,


> On 30 Apr 2020, at 9:32 am, The IESG <iesg-secretary@ietf.org> wrote:
> 
> 
> The IESG has received a request from the Security Events WG (secevent) to
> consider the following document: - 'Poll-Based Security Event Token (SET)
> Delivery Using HTTP'
>  <draft-ietf-secevent-http-poll-09.txt> as Proposed Standard
> 

--
Mark Nottingham   https://www.mnot.net/