[OAUTH-WG] Re: New Version Notification for draft-chen-oauth-agent-authz-use-cases-01.txt
"chenmeiling@chinamobile.com" <chenmeiling@chinamobile.com> Fri, 24 July 2026 14:32 UTC
Return-Path: <chenmeiling@chinamobile.com>
X-Original-To: oauth@mail2.ietf.org
Delivered-To: oauth@mail2.ietf.org
Received: from localhost (localhost [127.0.0.1]) by mail2.ietf.org (Postfix) with ESMTP id 825A311E3FCFE for <oauth@mail2.ietf.org>; Fri, 24 Jul 2026 07:32:42 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=ietf.org; s=ietf1; t=1784903562; bh=uhyu19RAamx8P0D+4gBKrckdg3co8ZWT3AesM9+u/dU=; h=Date:From:To:Cc:Subject:References; b=ShkPPGV/37dSlO8Wk17GSHDtLMqZwJSsz3RfWa03IPdxDxvaaR4hjZeQVDFIO8DaA Hv8VtxLjYzkWgR5PLND/ZtnD3k9FOlbX427CE66BYOhQZjHyydKAsMmWQZ3XqdoHCv VCmPDN+vJ8AgBtUCfowQnyt8xJ20SavsU9FZnyb8=
X-Virus-Scanned: amavisd-new at ietf.org
X-Spam-Flag: NO
X-Spam-Score: -2.387
X-Spam-Level:
X-Spam-Status: No, score=-2.387 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_INVALID=0.1, DKIM_SIGNED=0.1, HTML_MESSAGE=0.001, RCVD_IN_DNSWL_LOW=-0.7, RCVD_IN_VALIDITY_CERTIFIED_BLOCKED=0.001, RCVD_IN_VALIDITY_RPBL_BLOCKED=0.001, SPF_HELO_NONE=0.001, SPF_PASS=-0.001, T_KAM_HTML_FONT_INVALID=0.01] autolearn=ham autolearn_force=no
Authentication-Results: mail2.ietf.org (amavisd-new); dkim=fail (1024-bit key) reason="fail (body has been altered)" header.d=chinamobile.com
Received: from mail2.ietf.org ([166.84.6.31]) by localhost (mail2.ietf.org [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id wVnSSzLOJ2i4 for <oauth@mail2.ietf.org>; Fri, 24 Jul 2026 07:32:40 -0700 (PDT)
Received: from cmccmta6.chinamobile.com (cmccmta6.chinamobile.com [111.22.67.139]) by mail2.ietf.org (Postfix) with ESMTP id 3DFEF11E3FB36 for <oauth@ietf.org>; Fri, 24 Jul 2026 07:32:24 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=chinamobile.com; s=default; l=0; h=from:subject:message-id:to:cc:mime-version; bh=47DEQpj8HBSa+/TImW+5JCeuQeRkm5NMpJWZG3hSuFU=; b=vEyuzkLf+xCee/Pqe2BNGaWLfodNvJFejzyJeM0neb3sm0zFsHsOL+Xjy7vAMmwWrZ1dlRLcDldoG ptT5Lx+jUv55Yx1g3XIJL81JP3PIS2b3afegymndiBAJwlixr+CjbNVXCqmHVXzF60XTQ0HoB89kKI eXbvYbGMnyQwGEyw=
X-RM-TagInfo: emlType=0
X-RM-SPAM-FLAG: 00000000
Received: from mail.dlp.master (unknown[10.188.0.87]) by rmmx-syy-dmz-app05-12005 (RichMail) with SMTP id 2ee56a637767946-5b8c2; Fri, 24 Jul 2026 22:32:15 +0800 (CST)
X-RM-TRANSID: 2ee56a637767946-5b8c2
Received: from wxh.mailtest (localhost [127.0.0.1]) by mail.dlp.master (Postfix) with ESMTP id 6552C15A02DF for <oauth@ietf.org>; Fri, 24 Jul 2026 22:28:55 +0800 (CST)
Received: from spf.mail.chinamobile.com (unknown [10.230.70.214]) by mail.dlp.master (Postfix) with ESMTP id A1A8315A0214 for <oauth@ietf.org>; Fri, 24 Jul 2026 22:28:41 +0800 (CST)
X-RM-TagInfo: emlType=0
X-RM-SPAM-FLAG: 00000000
Received: from cmcc-PC (unknown[31.133.135.212]) by rmsmtp-syy-appsvr06-12006 (RichMail) with SMTP id 2ee66a63775a4e9-bb89d; Fri, 24 Jul 2026 22:32:01 +0800 (CST)
X-RM-TRANSID: 2ee66a63775a4e9-bb89d
Date: Fri, 24 Jul 2026 22:31:57 +0800
From: "chenmeiling@chinamobile.com" <chenmeiling@chinamobile.com>
To: morganLR <morganLR@proton.me>, "mohamad=40yuthent.com" <mohamad=40yuthent.com@dmarc.ietf.org>
References: <178326844691.267540.6806897697824010077@dt-datatracker-57b5d8f849-zrqfx>, <202607132157242002541@chinamobile.com>, <49E4C072-13E0-4A56-B6BA-2D1DF70F0C0C@yuthent.com>, <202607151957484157299@chinamobile.com>, <56ADA8DA-10DA-4899-A4B4-3907B5682808@yuthent.com>, <202607152116331707952@chinamobile.com>, <qKxC6Uj-5GJVJdb76e3zWpzPzN7pq4fE3Bm7SVyar8oU20vLNdf9UQ2eK9MtPCjZnc3_VP2C9Cjs3qZzienzFJCC1dRZzSHBdnDHtUC-kKc=@truealter.com>, <6173A0FE-5A07-4D85-B768-028241A019FD@yuthent.com>, <79C8FBE6-832B-4CDF-A04B-57369EC3971B@yuthent.com>, <zB0m8AyNdPnby_0TATSqlweeYCH6XbR4R-Vi23M6YW-EHOlHJGMa-85_nN4Dy9TUQ1dARmqEzJS1mrHUTzTHvCejFcHMv6hEHYGFU0jvX7g=@proton.me>
X-Priority: 3
X-GUID: 6F01A283-1F1D-4E73-ABC3-1A9A81AB361C
X-Has-Attach: no
X-Mailer: Foxmail 7.2.25.563[cn]
Mime-Version: 1.0
Message-ID: <202607242231550020395@chinamobile.com>
Content-Type: multipart/alternative; boundary="----=_001_NextPart145675248205_=----"
Message-ID-Hash: XXCJMCK3ZGNLC4TOCV4DJDC5YN3RCJF3
X-Message-ID-Hash: XXCJMCK3ZGNLC4TOCV4DJDC5YN3RCJF3
X-MailFrom: chenmeiling@chinamobile.com
X-Mailman-Rule-Misses: dmarc-mitigation; no-senders; approved; emergency; loop; banned-address; member-moderation; header-match-oauth.ietf.org-0; nonmember-moderation; administrivia; implicit-dest; max-recipients; max-size; news-moderation; no-subject; digests; suspicious-header
CC: blake <blake@truealter.com>, oauth <oauth@ietf.org>
X-Mailman-Version: 3.3.9rc6
Precedence: list
Subject: [OAUTH-WG] Re: New Version Notification for draft-chen-oauth-agent-authz-use-cases-01.txt
List-Id: OAUTH WG <oauth.ietf.org>
Archived-At: <https://mailarchive.ietf.org/arch/msg/oauth/0ajKy_eHdJVOR6Hsf5h4G8PBS0c>
List-Archive: <https://mailarchive.ietf.org/arch/browse/oauth>
List-Help: <mailto:oauth-request@ietf.org?subject=help>
List-Owner: <mailto:oauth-owner@ietf.org>
List-Post: <mailto:oauth@ietf.org>
List-Subscribe: <mailto:oauth-join@ietf.org>
List-Unsubscribe: <mailto:oauth-leave@ietf.org>
Hi Morgan, Thank you for your thorough review of the draft and for your very constructive feedback. We especially appreciate your generous offer to contribute the companion use case and the requirements mapping. To ensure we track this properly, I have opened two issues on our GitHub repository: Issue #17: Enhance UC5 with Cross-Draft Alignment Issue #18: Add New Use Case for Cross-Organizational Delegation Could you please take a look to confirm that these issues correctly capture the work you proposed? You can view all open issues at the following address: https://github.com/Maisy-ML/Agent-Authorization-Use-Cases/issues We look forward to your contribution and continuing the discussion on GitHub for this two issue. Best, Meiling chenmeiling@chinamobile.com From: morganLR Date: 2026-07-23 22:01 To: Mohamad Khalil Yossif CC: Blake; oauth; chenmeiling@chinamobile.com Subject: [OAUTH-WG] Re: New Version Notification for draft-chen-oauth-agent-authz-use-cases-01.txt Meiling, Thank you for the session presentation and for the -01 revision. The gap analysis is exactly the kind of foundation the group needs before mechanism selection, and I want to engage with two parts of it. First, on Use Case 5. During the session you referenced a prior list discussion of the cold-start scenario; in case it helps the record, that framing aligns with requirement R2 of draft-reece-wimse-cross-org-delegation-00 (cross-organizational verification without an interaction-specific prior arrangement), which I also applied in my July 20 note on the cross-domain transaction token thread. Your UC5 gap statement, no universal secure protocol for scoped, revocable access in a zero-trust, no-pre-channel initialization, is a very good articulation of it, and I would be glad to see it survive into whatever this document becomes. Second, an offer. UC5 as drafted covers the case where the service side lacks authorization infrastructure entirely. There is a companion case that I believe belongs alongside it: both sides have full trust infrastructure, the agent's organization and the service's organization each operate their own, and there is still no pre-authorization channel between them because they have never interacted. This is the ordinary condition of cross-organizational agent delegation, and its requirements are stricter in some dimensions (the service must be able to verify delegated, attenuated authority from another organization, potentially without a runtime callback to it) and looser in others. I would be happy to contribute that use case in your document's format, along with a mapping of the -01 gaps to the R1-R9 requirement set from the draft above, as review input rather than as competing structure. I also have a couple of small terminology notes, including one on the classical confused-deputy framing in UC3, that I will send separately so they do not clutter this thread. Thank you again for anchoring the discussion at the use-case level. Regards, Morgan Sent with Proton Mail secure email. On Wednesday, July 22nd, 2026 at 7:36 AM, Mohamad Khalil Yossif <mohamad=40yuthent.com@dmarc.ietf.org> wrote: > Following the axis you both settled on: the execution-time class in > that split is exactly where a delegation-constraint layer sits, and > the ex-ante piece is where the human-signed mandate lives before the > agent acts. > > I have posted a short problem statement on that upstream piece: > > draft-yossif-agent-mandate-problem-00 > https://datatracker.ietf.org/doc/draft-yossif-agent-mandate-problem/ > > No protocol, no mechanism. It states the gap between an authorized > agent and an authorized action, and the requirements any solution > would need to meet. draft-yossif-psea covers the execution-time > evidence; this new draft covers the ex-ante mandate the evidence is > verified against. > > For the catalogue: this may be worth citing as a problem reference > under the delegation class, alongside the existing entries. > > Feedback welcome on the framing. > > _______________________________________________ > OAuth mailing list -- oauth@ietf.org > To unsubscribe send an email to oauth-leave@ietf.org >
- [OAUTH-WG] Re: New Version Notification for draft… chenmeiling@chinamobile.com
- [OAUTH-WG] Re: New Version Notification for draft… Christopher Emerson
- [OAUTH-WG] Re: New Version Notification for draft… chenmeiling@chinamobile.com
- [OAUTH-WG] Re: New Version Notification for draft… Christopher Emerson
- [OAUTH-WG] Re: New Version Notification for draft… Mohamad Khalil Yossif
- [OAUTH-WG] Re: New Version Notification for draft… ~blake
- [OAUTH-WG] Re: New Version Notification for draft… Mohamad Khalil Yossif
- [OAUTH-WG] Re: New Version Notification for draft… chenmeiling@chinamobile.com
- [OAUTH-WG] Re: New Version Notification for draft… chenmeiling@chinamobile.com
- [OAUTH-WG] Re: New Version Notification for draft… Mohamad Khalil Yossif
- [OAUTH-WG] Re: New Version Notification for draft… chenmeiling@chinamobile.com
- [OAUTH-WG] Re: New Version Notification for draft… Christopher Emerson
- [OAUTH-WG] Re: New Version Notification for draft… Blake
- [OAUTH-WG] Re: New Version Notification for draft… chenmeiling@chinamobile.com
- [OAUTH-WG] Re: New Version Notification for draft… Lombardo, Jeff
- [OAUTH-WG] Re: New Version Notification for draft… chenmeiling@chinamobile.com
- [OAUTH-WG] Re: New Version Notification for draft… Mohamad Khalil Yossif
- [OAUTH-WG] Re: New Version Notification for draft… chenmeiling@chinamobile.com
- [OAUTH-WG] Re: New Version Notification for draft… Mohamad Khalil Yossif
- [OAUTH-WG] Re: New Version Notification for draft… Thi Nguyen-Huu
- [OAUTH-WG] Re: New Version Notification for draft… chenmeiling@chinamobile.com
- [OAUTH-WG] Re: New Version Notification for draft… Blake
- [OAUTH-WG] Re: New Version Notification for draft… Mohamad Khalil Yossif
- [OAUTH-WG] Re: New Version Notification for draft… Mohamad Khalil Yossif
- [OAUTH-WG] Re: New Version Notification for draft… morganLR
- [OAUTH-WG] Re: New Version Notification for draft… chenmeiling@chinamobile.com
- [OAUTH-WG] Re: New Version Notification for draft… morganLR
- [OAUTH-WG] Re: New Version Notification for draft… morganLR
- [OAUTH-WG] Re: New Version Notification for draft… Blake
- [OAUTH-WG] Re: New Version Notification for draft… jiangyuning (A)
- [OAUTH-WG] 回复: Re: New Version Notification for d… niyuan