Re: [OAUTH-WG] Alexey Melnikov's Discuss on draft-ietf-oauth-amr-values-05: (with DISCUSS and COMMENT)

Mike Jones <Michael.Jones@microsoft.com> Wed, 01 March 2017 02:17 UTC

Return-Path: <Michael.Jones@microsoft.com>
X-Original-To: oauth@ietfa.amsl.com
Delivered-To: oauth@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 2AD6D129470; Tue, 28 Feb 2017 18:17:33 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -3.011
X-Spam-Level:
X-Spam-Status: No, score=-3.011 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, RCVD_IN_DNSWL_NONE=-0.0001, RCVD_IN_MSPIKE_H5=-1, RCVD_IN_MSPIKE_WL=-0.01, SPF_HELO_PASS=-0.001, SPF_PASS=-0.001, URIBL_BLOCKED=0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (1024-bit key) header.d=microsoft.com
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id 3PsM2d7CB1lF; Tue, 28 Feb 2017 18:17:18 -0800 (PST)
Received: from NAM01-SN1-obe.outbound.protection.outlook.com (mail-sn1nam01on0101.outbound.protection.outlook.com [104.47.32.101]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 4483D12978C; Tue, 28 Feb 2017 18:17:13 -0800 (PST)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=microsoft.com; s=selector1; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version; bh=cT/HoYjmyaDO98r8qlk2y2wtSu+/Yzhgo5XpN2QAXek=; b=S3MpII6ZmdnP8Mt6fQz5fMFmGcZd2QKYYqKg05y/wlVByQZnyHq91LCa1+ceWQnQ1gmV60rZeEDPDyVxFA803AyK8ju37ZpDCrYNTf9IGzjvbVI5O2eN/4y8MpL2jPTet8cqou+YsC50e9Vtp/rLuEArzHhVUgL2zT1nJAZ7+wc=
Received: from CY4PR21MB0504.namprd21.prod.outlook.com (10.172.122.14) by CY4PR21MB0504.namprd21.prod.outlook.com (10.172.122.14) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_CBC_SHA384_P384) id 15.1.947.0; Wed, 1 Mar 2017 02:17:08 +0000
Received: from CY4PR21MB0504.namprd21.prod.outlook.com ([10.172.122.14]) by CY4PR21MB0504.namprd21.prod.outlook.com ([10.172.122.14]) with mapi id 15.01.0947.007; Wed, 1 Mar 2017 02:17:08 +0000
From: Mike Jones <Michael.Jones@microsoft.com>
To: Alexey Melnikov <aamelnikov@fastmail.fm>, The IESG <iesg@ietf.org>
Thread-Topic: Alexey Melnikov's Discuss on draft-ietf-oauth-amr-values-05: (with DISCUSS and COMMENT)
Thread-Index: AQHSfSstZ8gA/avhoUyAuPTivWAUwqFV0P+QgAAArYCAADBacIABELoAgChOIqA=
Date: Wed, 01 Mar 2017 02:17:07 +0000
Message-ID: <CY4PR21MB050470C357582CFEA40DEE17F5290@CY4PR21MB0504.namprd21.prod.outlook.com>
References: <148602274618.28299.16863291767893795433.idtracker@ietfa.amsl.com> <BN3PR03MB2355DFDFA5F06F9479A2FE66F54C0@BN3PR03MB2355.namprd03.prod.outlook.com> <1486048021.331167.868093568.44D5380B@webmail.messagingengine.com> <BN3PR03MB235525F67155805900076665F54C0@BN3PR03MB2355.namprd03.prod.outlook.com> <1486116972.569299.869047696.03427CD3@webmail.messagingengine.com>
In-Reply-To: <1486116972.569299.869047696.03427CD3@webmail.messagingengine.com>
Accept-Language: en-US
Content-Language: en-US
X-MS-Has-Attach:
X-MS-TNEF-Correlator:
authentication-results: spf=none (sender IP is ) smtp.mailfrom=Michael.Jones@microsoft.com;
x-originating-ip: [50.47.83.32]
x-ms-office365-filtering-correlation-id: 36c28147-e168-4e9c-f970-08d460490fcf
x-ms-office365-filtering-ht: Tenant
x-microsoft-antispam: UriScan:; BCL:0; PCL:0; RULEID:(22001)(48565401081); SRVR:CY4PR21MB0504;
x-microsoft-exchange-diagnostics: 1; CY4PR21MB0504; 7:1Tt+jHQfZAwLfEwR1qhocLOTo3PvxAfCi/D4GNz9I7Qp0I9HsoIaNlVFAx7DQneexCzJ90+swdoSIOtZgcqcznZY6YSJO4sn8Us9WI26+/ueEHM+qbLTtteyrBG/VHDWLMyLOGp4XejUpw9XAuPPKjxw2ZgERUm8FhzhoE5SUHV7YvTj22nKg62T7gbI7rPlYvgoTrz3oflGZW4GcTinPJtj++rhFNKw7UU5iC7kHR1LxXAEh/m9H29Q95xYrAGZXczS3CbBvxyGRld9NzX6bqabq4dlV3UJladCRnhEM5T9nvfTrT19WlUm6gZEE8SZ9ucZTDVL2J4QHGIGOsxLs7xw5DPfptv+yBymUecSZSI=
x-microsoft-antispam-prvs: <CY4PR21MB05044571F99D4644B3F2FFC5F5290@CY4PR21MB0504.namprd21.prod.outlook.com>
x-exchange-antispam-report-test: UriScan:(120809045254105)(131327999870524)(248736688235697);
x-exchange-antispam-report-cfa-test: BCL:0; PCL:0; RULEID:(61425038)(6040375)(601004)(2401047)(8121501046)(5005006)(10201501046)(3002001)(6055026)(61426038)(61427038)(6041248)(20161123555025)(20161123558025)(20161123562025)(20161123564025)(20161123560025)(6072148); SRVR:CY4PR21MB0504; BCL:0; PCL:0; RULEID:; SRVR:CY4PR21MB0504;
x-forefront-prvs: 0233768B38
x-forefront-antispam-report: SFV:NSPM; SFS:(10019020)(6009001)(7916002)(39840400002)(39860400002)(39850400002)(39410400002)(39450400003)(13464003)(24454002)(377454003)(199003)(43784003)(51444003)(189002)(122556002)(53936002)(101416001)(38730400002)(6246003)(50986999)(76176999)(54356999)(53546006)(230783001)(93886004)(2950100002)(99286003)(54906002)(25786008)(68736007)(4326008)(229853002)(55016002)(92566002)(6506006)(6306002)(8666007)(66066001)(77096006)(9686003)(5660300001)(6436002)(7696004)(2906002)(10090500001)(5005710100001)(86612001)(3660700001)(2900100001)(6116002)(102836003)(3846002)(86362001)(3280700002)(8676002)(81156014)(81166006)(33656002)(7736002)(74316002)(189998001)(97736004)(10290500002)(8990500004)(106116001)(8936002)(305945005)(106356001)(105586002); DIR:OUT; SFP:1102; SCL:1; SRVR:CY4PR21MB0504; H:CY4PR21MB0504.namprd21.prod.outlook.com; FPR:; SPF:None; PTR:InfoNoRecords; A:1; MX:1; LANG:en;
received-spf: None (protection.outlook.com: microsoft.com does not designate permitted sender hosts)
spamdiagnosticoutput: 1:99
spamdiagnosticmetadata: NSPM
Content-Type: text/plain; charset="utf-8"
Content-Transfer-Encoding: base64
MIME-Version: 1.0
X-OriginatorOrg: microsoft.com
X-MS-Exchange-CrossTenant-originalarrivaltime: 01 Mar 2017 02:17:07.7797 (UTC)
X-MS-Exchange-CrossTenant-fromentityheader: Hosted
X-MS-Exchange-CrossTenant-id: 72f988bf-86f1-41af-91ab-2d7cd011db47
X-MS-Exchange-Transport-CrossTenantHeadersStamped: CY4PR21MB0504
Archived-At: <https://mailarchive.ietf.org/arch/msg/oauth/1tw7geg0IQdmLMXT2CGziJ6dvnM>
Cc: "oauth-chairs@ietf.org" <oauth-chairs@ietf.org>, "draft-ietf-oauth-amr-values@ietf.org" <draft-ietf-oauth-amr-values@ietf.org>, "oauth@ietf.org" <oauth@ietf.org>
Subject: Re: [OAUTH-WG] Alexey Melnikov's Discuss on draft-ietf-oauth-amr-values-05: (with DISCUSS and COMMENT)
X-BeenThere: oauth@ietf.org
X-Mailman-Version: 2.1.17
Precedence: list
List-Id: OAUTH WG <oauth.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/oauth>, <mailto:oauth-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/oauth/>
List-Post: <mailto:oauth@ietf.org>
List-Help: <mailto:oauth-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/oauth>, <mailto:oauth-request@ietf.org?subject=subscribe>
X-List-Received-Date: Wed, 01 Mar 2017 02:17:33 -0000

Hi Alexey,

Draft -06 https://tools.ietf.org/html/draft-ietf-oauth-amr-values-06 restricts the character set to the printed subset of ASCII previously discussed.  It also addresses the readability concern you raised.  Finally, it adds references to address Stephen's point.

Thanks again for taking the time to produce your useful review.

				-- Mike

-----Original Message-----
From: Alexey Melnikov [mailto:aamelnikov@fastmail.fm] 
Sent: Friday, February 3, 2017 2:16 AM
To: Mike Jones <Michael.Jones@microsoft.com>; The IESG <iesg@ietf.org>
Cc: draft-ietf-oauth-amr-values@ietf.org; Hannes Tschofenig <Hannes.Tschofenig@gmx.net>; oauth-chairs@ietf.org; oauth@ietf.org
Subject: Re: Alexey Melnikov's Discuss on draft-ietf-oauth-amr-values-05: (with DISCUSS and COMMENT)

On Thu, Feb 2, 2017, at 06:05 PM, Mike Jones wrote:
> I was planning to stay with the characters specified in 6.1 (a)
> https://tools.ietf.org/html/draft-ietf-oauth-amr-values-05#section-6.1:
> 
>    a.  require that Authentication Method Reference values being
>        registered use only printable ASCII characters excluding double
>        quote ('"') and backslash ('\') (the Unicode characters with code
>        points U+0021, U+0023 through U+005B, and U+005D through 
> U+007E),
> 
> That excludes space.  That's the set taken from RFC 7638, Section 6 
> https://tools.ietf.org/html/rfc7638#section-6, which is a very related 
> usage.
> 
> Space is excluded because sometimes in OAuth messages, values are 
> represented as space-separated strings.

I am sorry I misread this earlier: you already exclude space, so the text as specified is fine.

> 				-- Mike
> 
> -----Original Message-----
> From: Alexey Melnikov [mailto:aamelnikov@fastmail.fm]
> Sent: Thursday, February 2, 2017 7:07 AM
> To: Mike Jones <Michael.Jones@microsoft.com>; The IESG <iesg@ietf.org>
> Cc: draft-ietf-oauth-amr-values@ietf.org; Hannes Tschofenig 
> <Hannes.Tschofenig@gmx.net>; oauth-chairs@ietf.org; oauth@ietf.org
> Subject: Re: Alexey Melnikov's Discuss on draft-ietf-oauth-amr-values-05:
> (with DISCUSS and COMMENT)
> 
> Hi Mike,
> 
> On Thu, Feb 2, 2017, at 03:05 PM, Mike Jones wrote:
> > I'd be OK limiting the protocol elements to using ASCII characters, 
> > if that would be the IESG's preference.
> 
> I think that would be much simpler for everybody.
> 
> I still want to confirm that spaces are allowed in names. Can you 
> confirm?
> 
> > 
> > -----Original Message-----
> > From: Alexey Melnikov [mailto:aamelnikov@fastmail.fm]
> > Sent: Thursday, February 2, 2017 12:06 AM
> > To: The IESG <iesg@ietf.org>
> > Cc: draft-ietf-oauth-amr-values@ietf.org; Hannes Tschofenig 
> > <Hannes.Tschofenig@gmx.net>; oauth-chairs@ietf.org; 
> > Hannes.Tschofenig@gmx.net; oauth@ietf.org
> > Subject: Alexey Melnikov's Discuss on draft-ietf-oauth-amr-values-05:
> > (with DISCUSS and COMMENT)
> > 
> > Alexey Melnikov has entered the following ballot position for
> > draft-ietf-oauth-amr-values-05: Discuss
> > 
> > When responding, please keep the subject line intact and reply to 
> > all email addresses included in the To and CC lines. (Feel free to 
> > cut this introductory paragraph, however.)
> > 
> > 
> > Please refer to
> > https://www.ietf.org/iesg/statement/discuss-criteria.html
> > for more information about IESG DISCUSS and COMMENT positions.
> > 
> > 
> > The document, along with other ballot positions, can be found here:
> > https://datatracker.ietf.org/doc/draft-ietf-oauth-amr-values/
> > 
> > 
> > 
> > --------------------------------------------------------------------
> > --
> > DISCUSS:
> > --------------------------------------------------------------------
> > --
> > 
> > This is a fine document and I support its publication. However I 
> > have a small set of issues that I would like to discuss first.
> > 
> > Are non ASCII names needed? (This is a protocol element, not a human 
> > readable string, so non ASCII is not needed). Are ASCII spaces 
> > allowed in names? More generally: what do you call printable character?
> > 
> > 
> > --------------------------------------------------------------------
> > --
> > COMMENT:
> > --------------------------------------------------------------------
> > --
> > 
> > In Section 6.1: suggestion to first describe IANA registration 
> > policy, then describe restrictions on registered names. Otherwise 
> > the current text doesn't flow well.
> > 
> > I am also agreeing with Stephen's DISCUSS.
> > 
> >