[Jwt-reg-review] Request to register claim: sig_val_claims

Stefan Santesson <stefan@aaa-sec.com> Fri, 03 September 2021 15:32 UTC

Return-Path: <stefan@aaa-sec.com>
X-Original-To: jwt-reg-review@ietfa.amsl.com
Delivered-To: jwt-reg-review@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id BD1383A226F for <jwt-reg-review@ietfa.amsl.com>; Fri, 3 Sep 2021 08:32:41 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.898
X-Spam-Level:
X-Spam-Status: No, score=-1.898 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, RCVD_IN_MSPIKE_H2=-0.001, SPF_HELO_NONE=0.001, SPF_NONE=0.001, URIBL_BLOCKED=0.001] autolearn=ham autolearn_force=no
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id 3EuMgPphkZEt for <jwt-reg-review@ietfa.amsl.com>; Fri, 3 Sep 2021 08:32:37 -0700 (PDT)
Received: from smtp.outgoing.loopia.se (smtp.outgoing.loopia.se [93.188.3.37]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id E9D5A3A2270 for <jwt-reg-review@ietf.org>; Fri, 3 Sep 2021 08:32:36 -0700 (PDT)
Received: from s807.loopia.se (localhost [127.0.0.1]) by s807.loopia.se (Postfix) with ESMTP id 5C0EE2E97BE8 for <jwt-reg-review@ietf.org>; Fri, 3 Sep 2021 17:32:33 +0200 (CEST)
Received: from s899.loopia.se (unknown [172.22.191.6]) by s807.loopia.se (Postfix) with ESMTP id 4D70B2E28C05; Fri, 3 Sep 2021 17:32:33 +0200 (CEST)
Received: from s474.loopia.se (unknown [172.22.191.6]) by s899.loopia.se (Postfix) with ESMTP id 4B0002C8BA60; Fri, 3 Sep 2021 17:32:33 +0200 (CEST)
X-Virus-Scanned: amavisd-new at amavis.loopia.se
Received: from s645.loopia.se ([172.22.191.5]) by s474.loopia.se (s474.loopia.se [172.22.190.14]) (amavisd-new, port 10024) with LMTP id vZ_soHDHEEmz; Fri, 3 Sep 2021 17:32:32 +0200 (CEST)
X-Loopia-Auth: user
X-Loopia-User: mailstore2@aaa-sec.com
X-Loopia-Originating-IP: 85.235.7.89
Received: from [192.168.1.218] (gw.aaa-sec.ideon.se [85.235.7.89]) (Authenticated sender: mailstore2@aaa-sec.com) by s645.loopia.se (Postfix) with ESMTPSA id D8DEC157A09A; Fri, 3 Sep 2021 17:32:32 +0200 (CEST)
Message-ID: <44e53ac6-d54d-dd82-df21-c5ff12af88b2@aaa-sec.com>
Date: Fri, 03 Sep 2021 17:32:32 +0200
MIME-Version: 1.0
User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10.15; rv:92.0) Gecko/20100101 Thunderbird/92.0
Content-Language: en-US
To: jwt-reg-review@ietf.org
From: Stefan Santesson <stefan@aaa-sec.com>
Organization: 3xA Security AB
Cc: Russ Housley <housley@vigilsec.com>
Content-Type: text/plain; charset="UTF-8"
Content-Transfer-Encoding: 8bit
Archived-At: <https://mailarchive.ietf.org/arch/msg/jwt-reg-review/JEuYGV1pD6Xo2mevTtNUWsQxf3s>
Subject: [Jwt-reg-review] Request to register claim: sig_val_claims
X-BeenThere: jwt-reg-review@ietf.org
X-Mailman-Version: 2.1.29
Precedence: list
List-Id: "Expert review of proposed IANA registrations for JSON Web Token \(JWT\) claims." <jwt-reg-review.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/jwt-reg-review>, <mailto:jwt-reg-review-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/jwt-reg-review/>
List-Post: <mailto:jwt-reg-review@ietf.org>
List-Help: <mailto:jwt-reg-review-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/jwt-reg-review>, <mailto:jwt-reg-review-request@ietf.org?subject=subscribe>
X-List-Received-Date: Fri, 03 Sep 2021 15:32:42 -0000

Hi,

The draft https://datatracker.ietf.org/doc/draft-santesson-svt/ is being
requested for publication as individual submission

This draft includes the request to register the claim name
"sig_val_claims" as follows:

6.1.  Claim Names Registration


   This section registers the "sig_val_claims" claim name in the IANA
   "JSON Web Token Claims" registry established by Section 10.1 in
   [RFC7519].

6.1.1.  Registry Contents

   *  Claim Name: "sig_val_claims"
   *  Claim Description: Signature Validation Token Claims
   *  Change Controller: IESG
   *  Specification Document(s): Section 3.2.3 of {this document}


The draft specifies a Token having the form of a JWT which includes this
defined claim.

The rationale for this claim is described in the referenced document.

The solution is deployed is real services and it is considered for
national government usage which is the main reason to publish the
specification as an informational RFC.



/Stefan Santesson