Re: [Id-event] Push delivery - shepherd review

Marius Scurtescu <marius.scurtescu@coinbase.com> Sun, 14 April 2019 18:52 UTC

Return-Path: <marius.scurtescu@coinbase.com>
X-Original-To: id-event@ietfa.amsl.com
Delivered-To: id-event@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id A74F61201BE for <id-event@ietfa.amsl.com>; Sun, 14 Apr 2019 11:52:13 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2
X-Spam-Level:
X-Spam-Status: No, score=-2 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIMWL_WL_HIGH=-0.001, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, HTML_MESSAGE=0.001, RCVD_IN_DNSWL_NONE=-0.0001, SPF_PASS=-0.001, URIBL_BLOCKED=0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (1024-bit key) header.d=coinbase.com
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id ObuMkVIkohbP for <id-event@ietfa.amsl.com>; Sun, 14 Apr 2019 11:52:11 -0700 (PDT)
Received: from mail-pg1-x530.google.com (mail-pg1-x530.google.com [IPv6:2607:f8b0:4864:20::530]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 96A491201B8 for <id-event@ietf.org>; Sun, 14 Apr 2019 11:52:11 -0700 (PDT)
Received: by mail-pg1-x530.google.com with SMTP id 85so7507421pgc.3 for <id-event@ietf.org>; Sun, 14 Apr 2019 11:52:11 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=coinbase.com; s=google; h=mime-version:references:in-reply-to:from:date:message-id:subject:to :cc; bh=wyG213E6r6lRnshDZ3QCp6oPPxPXkOnFFwIkRYI+XTQ=; b=Oa8G830r4+jTehs5cBOva8OSEeV2CsuwZxMoVyfxMqu8drO6XkEYqe8v3wfluuaMgz 2qBKR6cdydNdWMgSJvWX7h9DHJFCPXJVU3BKgG1+6hL2SGiBSkmeL1EMVRZSIjP5CL8w L2nrZMsBmYa1tOtsEWV/Vo8/69hNwHkC22CNs=
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20161025; h=x-gm-message-state:mime-version:references:in-reply-to:from:date :message-id:subject:to:cc; bh=wyG213E6r6lRnshDZ3QCp6oPPxPXkOnFFwIkRYI+XTQ=; b=MTgXCxsnyIt00lJpULfvQSZRaUyj64Pw9RuU3/JGOZZFSFu1kiZKd/ww3KQlHqaIjo qmHiUARSSwWaGn1wBvksb8rxmxmUIjlKGQ0EC6fRXzoURsE+uQ2sZ5n9Pi6zC7Ypfxtp HTKxRnFEOz3shpjBhd6BjYe3GDjHqc0u6oYfeQlAFEkkehUhkj0H6XDzl1ERHjuwIi6e 4m8YgODyi5umhTWtmVtDDUYCzZywsen91TcltY4lyfgdju7FSH0+4vUL3jDXsPr6+iap z6dyE7DhgCuiMVSBujP249d3KpuUlBu0pvKmOjXNtgw9VrzTXWJXRdhxxq2lejGqjVpZ 03/g==
X-Gm-Message-State: APjAAAW+pEDrxYTE871JltCeC+IRSKtPkFQLnCUjdW+WUTi/ln7XN0nX nXarF+enGoQIHCSvSxcmkr9p9i67QUuz0SG1U5yJBA==
X-Google-Smtp-Source: APXvYqyfw21TAD8ZkRqUOvXsnaKgsIKyVK5L4vCNjwg7UtIJuE83XZctm+jpOQyslF/+xPId6DkN2edG2egoy5hunt4=
X-Received: by 2002:a62:26c1:: with SMTP id m184mr33518550pfm.102.1555267930797; Sun, 14 Apr 2019 11:52:10 -0700 (PDT)
MIME-Version: 1.0
References: <40c0d06d-2df5-e776-0ec3-142358d91086@gmail.com>
In-Reply-To: <40c0d06d-2df5-e776-0ec3-142358d91086@gmail.com>
From: Marius Scurtescu <marius.scurtescu@coinbase.com>
Date: Sun, 14 Apr 2019 11:51:58 -0700
Message-ID: <CABpvcNvutQGG7xTAmCfmFYiGMN_4xuCEkM5Y7mGkKK-LoP5k1A@mail.gmail.com>
To: Yaron Sheffer <yaronf.ietf@gmail.com>, "Richard Backman, Annabelle" <richanna@amazon.com>, Mike Jones <Michael.Jones@microsoft.com>, Mark Dobrinic <mark.dobrinic@curity.io>
Cc: SecEvent <id-event@ietf.org>
Content-Type: multipart/alternative; boundary="0000000000008be2d40586820860"
Archived-At: <https://mailarchive.ietf.org/arch/msg/id-event/kIBH1I4DKnply12kjUtCXclwMuk>
Subject: Re: [Id-event] Push delivery - shepherd review
X-BeenThere: id-event@ietf.org
X-Mailman-Version: 2.1.29
Precedence: list
List-Id: "A mailing list to discuss the potential solution for a common identity event messaging format and distribution system." <id-event.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/id-event>, <mailto:id-event-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/id-event/>
List-Post: <mailto:id-event@ietf.org>
List-Help: <mailto:id-event-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/id-event>, <mailto:id-event-request@ietf.org?subject=subscribe>
X-List-Received-Date: Sun, 14 Apr 2019 18:52:14 -0000

I captured all feedback here:
https://github.com/independentid/Identity-Events/pull/25

Please review and let me know if further edits are needed.

Thanks,
Marius


On Fri, Apr 12, 2019 at 5:45 AM Yaron Sheffer <yaronf.ietf@gmail.com> wrote:

> There's always one more nit...
>
>    - 1.1: this documents -> this document
>    - 2: i.e., return an "access_denied" error response -> i.e., return an
>    error response such as "access_denied" [because rejection can result in
>    other responses]
>    - 2.3: detects an error parsing or validating a SET transmitted in a
>    SET Transmission Request -> detects an error parsing, validating or
>    authenticating a SET transmitted in a SET Transmission Request [because all
>    later examples use status code 400 for this rather than 401, and this is an
>    important enough case to be stated  normatively].
>    - 5.2: PII: expand the acronym.
>    - 5.4: "then the SET Transmitter SHOULD sign the SET in accordance
>    with [RFC7515] and/or encrypt it using authenticated encryption in
>    accordance with [RFC7516]." The second half of this sentence is incorrect.
>    JWE with RSA (encrypted to the Recipient) and AES-GCM does NOT authenticate
>    the Transmitter. It ensures message integrity but not authenticity.
>    - 7.1.1: error_code: please review again the ASCII ranges, or better
>    yet, spell out the allowed characters. For example, 0x20 is "space" which
>    we probably don't want.
>
> Thanks,
>
>     Yaron
> _______________________________________________
> Id-event mailing list
> Id-event@ietf.org
> https://www.ietf.org/mailman/listinfo/id-event
>