Re: [OAUTH-WG] [Ace] [COSE] Call for adoption for draft-wahlstroem-ace-cbor-web-token-00

Erik Wahlström <erik@wahlstromstekniska.se> Tue, 10 May 2016 08:43 UTC

Return-Path: <erik@wahlstromstekniska.se>
X-Original-To: oauth@ietfa.amsl.com
Delivered-To: oauth@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 189E812D56E for <oauth@ietfa.amsl.com>; Tue, 10 May 2016 01:43:58 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.599
X-Spam-Level:
X-Spam-Status: No, score=-2.599 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, HTML_MESSAGE=0.001, RCVD_IN_DNSWL_LOW=-0.7] autolearn=unavailable autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (2048-bit key) header.d=wahlstromstekniska-se.20150623.gappssmtp.com
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id 9i2FoU9khbta for <oauth@ietfa.amsl.com>; Tue, 10 May 2016 01:43:56 -0700 (PDT)
Received: from mail-lf0-x230.google.com (mail-lf0-x230.google.com [IPv6:2a00:1450:4010:c07::230]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 44CA712D18E for <oauth@ietf.org>; Tue, 10 May 2016 01:43:52 -0700 (PDT)
Received: by mail-lf0-x230.google.com with SMTP id m64so6766088lfd.1 for <oauth@ietf.org>; Tue, 10 May 2016 01:43:51 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=wahlstromstekniska-se.20150623.gappssmtp.com; s=20150623; h=mime-version:in-reply-to:references:date:message-id:subject:from:to :cc; bh=tSby/1R0Lu9eXQstX/YJ8XL0DFyOGbnRpVwShspzJqQ=; b=bPn/lEO5kS4Z++5m6QFNKEByjjHK3+PrBS3KwJF4F9RCPcxHGXrC7qiP4WyqvWN+xf Azla7jnU189E87xVsV8HZLfktl+MgPT7OlFha5k3HVGmlYbJpM3m08zgJqWtXxIfTDgj UZJxCGyCOstbRyQUM64xvs9o873H3c9e1vjacV185/20phKH8Psy7xljbdxGx0YBnO8X ePh/uSubc0Yxqmy75jQZY1XSEZMpElGQIRQovERTXvDWrrKU4SmK/LSx4JXabbjudqho 6BdE4vK2SCyQZKMcIRnL75XUXlvoF5R/EmeGbd1Wf0Y8LXqolvt5cCVUuTN1wh8W1HGL qmVw==
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20130820; h=x-gm-message-state:mime-version:in-reply-to:references:date :message-id:subject:from:to:cc; bh=tSby/1R0Lu9eXQstX/YJ8XL0DFyOGbnRpVwShspzJqQ=; b=fveQt3Ae/aagsXDa3QX4nP4+VG4MNQacDAu9xJi3KEC6gv9atf5wCXA4HaQ98FHF0q h75LWiR8C85ZUIf6empjEklzzxvXReeIAP0+y8DTLcas7UOXuDcEMGFez3fBNIpFu8JO P9dtTYv4PCDoQSyu6UMoYq9kPw7VmL6M1GSjSaRXZQpwOP38VC1i5k7id6YUuXvufD4t +MEHQF2649mL1NTWD9FeJzPCxuVksj2OPCEZM5k9mGBCGXuC9bFcGn2N9wj/LqAkpI0A 7OOfsTgjvQUFPwvfadn3eH7n4ax4FiHGFG4xHlULP1VeIt9P9UILNCVUV18r40UOlK3Z wKwg==
X-Gm-Message-State: AOPr4FWpD8XiQWq23R0/oWn0byE/ODGwgxcPvnImWth/Spm7O22BtLiivsVGBlFJe4SnUYGV2MQIVVPHDurnqg==
MIME-Version: 1.0
X-Received: by 10.25.22.19 with SMTP id m19mr17054764lfi.118.1462869830177; Tue, 10 May 2016 01:43:50 -0700 (PDT)
Received: by 10.25.136.5 with HTTP; Tue, 10 May 2016 01:43:50 -0700 (PDT)
X-Originating-IP: [37.247.26.197]
In-Reply-To: <89B6F196-D08F-4FBD-9F0D-5B250284048F@mit.edu>
References: <D356A330.34F31%kepeng.lkp@alibaba-inc.com> <57309F46.9040705@tzi.org> <89B6F196-D08F-4FBD-9F0D-5B250284048F@mit.edu>
Date: Tue, 10 May 2016 10:43:50 +0200
Message-ID: <CA+KYQAuF-AzXEBQFo0-2VoCSBnCAPTAvHRwwngDUQcFgk0Q4SQ@mail.gmail.com>
From: Erik Wahlström <erik@wahlstromstekniska.se>
To: Justin Richer <jricher@mit.edu>
Content-Type: multipart/alternative; boundary="001a11406a9c94ae0a053278ec62"
Archived-At: <http://mailarchive.ietf.org/arch/msg/oauth/0nV3jWDjSl0vmjbF55_45ucdpHI>
Cc: "ace@ietf.org" <ace@ietf.org>, "<oauth@ietf.org>" <oauth@ietf.org>, cose <cose@ietf.org>
Subject: Re: [OAUTH-WG] [Ace] [COSE] Call for adoption for draft-wahlstroem-ace-cbor-web-token-00
X-BeenThere: oauth@ietf.org
X-Mailman-Version: 2.1.17
Precedence: list
List-Id: OAUTH WG <oauth.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/oauth>, <mailto:oauth-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/oauth/>
List-Post: <mailto:oauth@ietf.org>
List-Help: <mailto:oauth-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/oauth>, <mailto:oauth-request@ietf.org?subject=subscribe>
X-List-Received-Date: Tue, 10 May 2016 08:43:58 -0000

Or keep the CBOR Web Token (CWT) for two major reasons:
- To show the very close relationship to JWT. It relies heavily on JWT and
it's iana registry. It is essentially a JWT but in CBOR/COSE instead of
JSON/JOSE.
- I would not say that JWT is the only format that works for the web, and
it's even used in other, non-traditional, web protocols. That means I don't
have a problem with the W in CWT at all. Why would JSON be the only web
protocol?

Then we also have one smaller (a lot smaller) reason, it's the fact that it
can be called "cot" just like JWT is called a "jot" and I figured that our
"cozy chairs" would very much like that fact because then it's essentially
a "cozy cot" :)

/ Erik


On Tue, May 10, 2016 at 2:49 AM, Justin Richer <jricher@mit.edu> wrote:

> We can also call it the “COSE Token”. As a chair of the COSE working
> group, I’m fine with that amount of co-branding.
>
>  — Justin
>
> > On May 9, 2016, at 9:31 AM, Carsten Bormann <cabo@tzi.org> wrote:
> >
> >> draft-ietf-ace-cbor-token-00.txt;
> >
> > For the record, I do not think that ACE has a claim on the term "CBOR
> > Token".  While the term token is not used in RFC 7049, there are many
> > tokens that could be expressed in CBOR or be used in applying CBOR to a
> > problem.
> >
> > ACE CBOR Token is fine, though.
> > (Or, better, CBOR ACE Token, CAT.)
> >
> > Grüße, Carsten
> >
> > _______________________________________________
> > COSE mailing list
> > COSE@ietf.org
> > https://www.ietf.org/mailman/listinfo/cose
>
> _______________________________________________
> Ace mailing list
> Ace@ietf.org
> https://www.ietf.org/mailman/listinfo/ace
>