[OAUTH-WG] Re: Roman Danyliw's Discuss on draft-ietf-oauth-status-list-15: (with DISCUSS and COMMENT)

Brian Campbell <bcampbell@pingidentity.com> Wed, 08 April 2026 17:55 UTC

Return-Path: <bcampbell@pingidentity.com>
X-Original-To: oauth@mail2.ietf.org
Delivered-To: oauth@mail2.ietf.org
Received: from localhost (localhost [127.0.0.1]) by mail2.ietf.org (Postfix) with ESMTP id D579AD83600D for <oauth@mail2.ietf.org>; Wed, 8 Apr 2026 10:55:01 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=ietf.org; s=ietf1; t=1775670901; bh=W7JBUyJKhdZ/gu05u7SPzzhFVGDDHsAggUdYoxXep0s=; h=References:In-Reply-To:From:Date:Subject:To:Cc; b=c+nOGW4kcNZ+bmOSuh7YRbTIpRCKqLB+7el3AacgvtQmQFS/UTJK6Zo9+1GvnM6My 2TWX+A/nWEXEOxkKxDXFv2hds+lbwfW8rNYBJBR0cGL09L4ObJVnJ4CEQ8uBNBUTSg MnXmpnAJbuKFnPBxrjlyUsX2vuUmVXtZ4mAcVoIg=
X-Virus-Scanned: amavisd-new at ietf.org
X-Spam-Flag: NO
X-Spam-Score: -2.097
X-Spam-Level:
X-Spam-Status: No, score=-2.097 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, HTML_MESSAGE=0.001, RCVD_IN_DNSWL_NONE=-0.0001, SPF_HELO_NONE=0.001, SPF_NONE=0.001] autolearn=unavailable autolearn_force=no
Authentication-Results: mail2.ietf.org (amavisd-new); dkim=pass (2048-bit key) header.d=pingidentity.com
Received: from mail2.ietf.org ([166.84.6.31]) by localhost (mail2.ietf.org [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id Bt8NdqkjXVqA for <oauth@mail2.ietf.org>; Wed, 8 Apr 2026 10:55:01 -0700 (PDT)
Received: from mail-vk1-xa2c.google.com (mail-vk1-xa2c.google.com [IPv6:2607:f8b0:4864:20::a2c]) (using TLSv1.3 with cipher TLS_AES_128_GCM_SHA256 (128/128 bits) key-exchange X25519 server-signature ECDSA (P-256) server-digest SHA256) (No client certificate requested) by mail2.ietf.org (Postfix) with ESMTPS id BE840D835EC7 for <oauth@ietf.org>; Wed, 8 Apr 2026 10:53:42 -0700 (PDT)
Received: by mail-vk1-xa2c.google.com with SMTP id 71dfb90a1353d-56d89f35940so52052e0c.2 for <oauth@ietf.org>; Wed, 08 Apr 2026 10:53:42 -0700 (PDT)
ARC-Seal: i=1; a=rsa-sha256; t=1775670816; cv=none; d=google.com; s=arc-20240605; b=NL3R1Win50OWug2pgCxDqJdX5QSFjnesPvpM4jobF1F+JQ2kPHWFJv4vJ3dQZ1Bvra 7XM4+1VBwW5IHLsIYNDrbBH+TtkzTk3JtfBX0x6atEDLZ30eQdJSWhpSN3eKkKjfIteX tIDE0yXYESGsBwswTqnBMXwXJe33wmt6PcAnyWG3P0twgcQ+PtbtTff1twIb/FSuzkaR 9G1cGRU8n6mIQGyhRHgdPycYAMdSJrKlM8HguxAPxlbmJtnBdJCvpJBKJoqemaQAJNjJ 4tP2pn1T81F9mo0fTUur7ovWJ7NiabOMcIf1QEFIoxGZPSt61DVrcZRMn/B5UlUQAIZY VETQ==
ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=arc-20240605; h=cc:to:subject:message-id:date:from:in-reply-to:references :mime-version:dkim-signature; bh=mGd9gzk7Ictn1OHlHgEPYWxEPK57b+7UsDX9vhLNtqA=; fh=J+Bg+SwLryYDCbVoBS5KmCA7umZN4/ydq/bYyOIu9M4=; b=IE+TCDmsbQ83nOgXtwsBbjbRisM/P8/rBSLS/rINuM46JIGWiM0uh0SMCdOncOmd/2 dLofiHuKz1mH/Wmeo69R8JJf6MHi2/wXietL8zpQyrMewjpez/ARcWlLLFresC4xqNEv oXh57u8cSIbmvqvBhuXJzMa0Tqo7Kcjkcd60q7tbHzzTNd4YUPaQsPsrmuAKTFdTk12e vFPbpzblapgZpSFhZv+wPRoqLviEgWFRvwzeZDQ+vPGR2z1C27JgIAP1BRsEMy74PppH bzmuCKLpbkzWXt3BcawTH/6EJALmRrbaPE0u5hQN40ZqIpFxUnQlVr2+7jvQ9g9Y7q4P wqxw==; darn=ietf.org
ARC-Authentication-Results: i=1; mx.google.com; arc=none
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=pingidentity.com; s=google; t=1775670816; x=1776275616; darn=ietf.org; h=cc:to:subject:message-id:date:from:in-reply-to:references :mime-version:from:to:cc:subject:date:message-id:reply-to; bh=mGd9gzk7Ictn1OHlHgEPYWxEPK57b+7UsDX9vhLNtqA=; b=RD/OQrKpFG/tDpk+0fJG9EA2WPESgJeVZjqgbsth1cAw14iQ4S4LMKXgyrhNoKJA5E PhRh8pEX3aUlMCDzsmgPMObYabMj+yl60KE9gMNql9LxahKR1ndMoTAT0BVH4ngiXzIN cRj6B3sV6xOZPvnyrLxpslCeuXcftZ7qROsPQPsn7ZhVULw+5rT5fGR9seSKUJawLuGy 5Qd01rlEolc2HhFBHV8vAcqsE5TvTqEpzelqzw+JWsIyoriD9zXbkKBnNc/eTptiMErJ 14a2Bnt6BPP9j5Q7CNaZ2uFuoD151hFEFHisJbnaG3bjI9QcJQNSjSDW/m7HPpcUVNxL Cz5A==
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1775670816; x=1776275616; h=cc:to:subject:message-id:date:from:in-reply-to:references :mime-version:x-gm-gg:x-gm-message-state:from:to:cc:subject:date :message-id:reply-to; bh=mGd9gzk7Ictn1OHlHgEPYWxEPK57b+7UsDX9vhLNtqA=; b=olPzLNDXQxjPUvwMEL61chrH1a09N4gdT7FtO2cFfCHkdNG260Qutq1mMyTDAIJQcz 0VGKguErCKAgdNgJdY7/orLj5wrYuWqmqanmowzjY8G5cOAw0qQXzf/2Od5pwsyBROwP 2mscnlKrYsoihKaTUDr3rytqmM2pXmiOwT2GUSpcKt5br/mfHnunnT35MeaSF11hR+kq XuYnX/cMSWaK3GqVCWKVOWG9+B42GQq1qFDXDHWs/paKMD67nT/ouRAB3XoJL/Iw0Ivq Sa8+WHKErW5rom9Xqdd8aJGjLqRSzOKKs42mtRaPpgq/rFIl2yQubiE8Yhjm/dnay/A6 pATw==
X-Forwarded-Encrypted: i=1; AJvYcCWcQcnATRgLH0uiPBLR3Sru7fllvYKvJT5C7sJUyoWk6ASMhz6rfVa6oKSNeZkc+p6Nph/kjw==@ietf.org
X-Gm-Message-State: AOJu0YwyuJk2//vTul+uVP+L2cV9a7uKZXecXbJ6sYbHHlYnlbijwP7K wANghx0RnVf90MUw8kpsyw5ZdYUjMKjw5tA2LBGDchBob4TcAdO7F7DNjJHx2PBCH5dmx7ZuZEv GOBM183X0en+KbYB8l+Qp38OmaRylEat+mRy/Osb9Fhy2bh/kWg8JR59tbWzn0/D+HRPBRF82VS rlEQjms7qBIo29A+dX26xGnrI1wHvG3w==
X-Gm-Gg: AeBDiesKKvro9gizPeVqQ0ymXxrDZcq9Dj3fEng51Bxtmukwy9dmIjgQkAjrUh4mtwn 7cWfAbURcjWBkvL/ZcFEZ9dOV/CAms0VMjV+Fkv/wRfbYLUJcqE4+kHyzqfvIeMb8vrYBaCkLKe Pv8PRKnymF0z3JepdN6DL3cOQzfodeaWeMbVWj+Ggb6ZfdfQMDfEjD0Fdamv245yP2zmfFLe0Qr Hdc//Mlg9cvMnH3+gyRa/+2hcNmpCA4I2XUhBdlS6uvAJCFDyshwi8CO4L0UUS0N4oMkwOu5Ka8 KYGde+RAXf+ISJQHZ/L3nrBhMcV49GqjOXn7bhNd40/C/+cOF5A0KIAUW5/kSYgDkZ3B/g==
X-Received: by 2002:a05:6122:6283:b0:56e:e9cf:710e with SMTP id 71dfb90a1353d-56f27320ffamr757788e0c.3.1775670816009; Wed, 08 Apr 2026 10:53:36 -0700 (PDT)
MIME-Version: 1.0
References: <176773853290.3714955.7473131679988213225@dt-datatracker-5656579b89-p6k4r> <CA+k3eCR8A2WAPvAc4jz2g0UCyPugJs-r-PX8tuZ=3=nhonP7Lg@mail.gmail.com> <CAGgd1OfMELDFXkc9AGjUtu12LPg4Ym82iT9i2vQORU_S_Oo03A@mail.gmail.com> <CA+k3eCSjbFMTEdUjaj2K59HLGY6bmMBBj5JBAvCw64nuDM0-9A@mail.gmail.com> <CAGgd1Oc=KqQLAvM61h=xtEbSuumHBspQV6-JKekj7wn+jpaH0A@mail.gmail.com> <CA+k3eCSZBdFxqd+WCLhA5RCMacLjb2ymMBcsP=+4m0Q1urkKzw@mail.gmail.com> <CAGgd1Offh2EL7EdUXpTn8i_j8dS2JgipKExsuRZJeNgwsre4VA@mail.gmail.com> <CA+k3eCTU-p=Q_i6vUKBjJOpD1zmEez=XKbbknt3=VQ=5xcCsdw@mail.gmail.com> <CAGgd1OcMY-YCTuVjs+n1xE-Uy6b1QaOvHX5N5P6O++JB3H6hcQ@mail.gmail.com>
In-Reply-To: <CAGgd1OcMY-YCTuVjs+n1xE-Uy6b1QaOvHX5N5P6O++JB3H6hcQ@mail.gmail.com>
From: Brian Campbell <bcampbell@pingidentity.com>
Date: Wed, 08 Apr 2026 11:53:07 -0600
X-Gm-Features: AQROBzBuGbai6zgO4TxVPQuqwHG889BNhO3tsX55bWXWLhVVPyw0YMTY5K27Blc
Message-ID: <CA+k3eCS3qUKNTjTK4Q2K3HnLU_ObMotz1cbnuF_YXgnsN13bUw@mail.gmail.com>
To: Deb Cooley <debcooley1@gmail.com>
Content-Type: multipart/alternative; boundary="00000000000039fee9064ef69477"
Message-ID-Hash: 4LM7N6KJEHJBDZ6YUFFRWDD6YXYXQ5JD
X-Message-ID-Hash: 4LM7N6KJEHJBDZ6YUFFRWDD6YXYXQ5JD
X-MailFrom: bcampbell@pingidentity.com
X-Mailman-Rule-Misses: dmarc-mitigation; no-senders; approved; emergency; loop; banned-address; member-moderation; header-match-oauth.ietf.org-0; nonmember-moderation; administrivia; implicit-dest; max-recipients; max-size; news-moderation; no-subject; digests; suspicious-header
CC: Roman Danyliw <rdd@cert.org>, draft-ietf-oauth-status-list@ietf.org, The IESG <iesg@ietf.org>, "oauth-chairs@ietf.org" <oauth-chairs@ietf.org>, oauth <oauth@ietf.org>
X-Mailman-Version: 3.3.9rc6
Precedence: list
Subject: [OAUTH-WG] Re: Roman Danyliw's Discuss on draft-ietf-oauth-status-list-15: (with DISCUSS and COMMENT)
List-Id: OAUTH WG <oauth.ietf.org>
Archived-At: <https://mailarchive.ietf.org/arch/msg/oauth/2lxqQhTPyMsoD7-cYlbNMYurLCw>
List-Archive: <https://mailarchive.ietf.org/arch/browse/oauth>
List-Help: <mailto:oauth-request@ietf.org?subject=help>
List-Owner: <mailto:oauth-owner@ietf.org>
List-Post: <mailto:oauth@ietf.org>
List-Subscribe: <mailto:oauth-join@ietf.org>
List-Unsubscribe: <mailto:oauth-leave@ietf.org>

Apologies for the untimeliness of the reply here, life (mostly spring break
in this case) gets in the way sometimes. More inline w/ [BC] and some parts
snipped, which may or may not make this readable...

On Wed, Mar 25, 2026 at 4:12 PM Deb Cooley <debcooley1@gmail.com> wrote:

> inline w/ [DC]
>
> On Wed, Mar 25, 2026 at 3:45 PM Brian Campbell <bcampbell@pingidentity.com>
> wrote:
>
>>
>>
>>> I beg to differ.
>>>
>>
>> Reasonable people can disagree. Unreasonable people can disagree too.
>> Hopefully we're in the territory of the former here but one can never be
>> sure.
>>
>
> [DC]  most definitely the former, I'm just grumpy - fake jetlag mostly.
> Apologies, I try to not be grumpy most days.
>

[BC] I'm grumpy too and was definitely also including myself in that
uncertainty of possibly being unreasonable.

I'd like to blame real jetlag for the grumpiness but in this case I think
it mostly stems from feeling like I provided very reasonable and grounded
feedback/advice on this draft early on. And did so in service of helping
the draft find an appropriate WG and progress. At a point in time when
progress was very much uncertain. Then had that feedback/advice go
unheeded. Only to see the IETF Chair raise basically the same point of
concern in the final balloting as part of a blocking DISCUSS. It's
frustrating and grumpiness inducing (more than the usual grumpiness even).

Is it frustrating that things are held up at this stage? And
further frustrating to have a mere WG participant chime in about it? I'm
sure it is. It's also frustrating, from the perspective of that mere WG
participant, that the situation was entirely avoidable.



>>> Both spice and ace were contacted on their mailing lists asking for
>>> their concurrence (i.e. putting this together into one specification vice
>>> splintering the information into 2 specifications).  Those are the mailing
>>> list links in my message.
>>>
>>
>> I don't think getting permission (or really lack of objection) from
>> different WGs is at all equivalent to being in the charter. But maybe this
>> is another point on which reasonable people can disagree.
>>
>
> [DC]  my point here is: if there must be a status list draft, I'd rather
> see one which includes everything, vice multiple drafts, one for each
> technology.  If there is one place for a developer/integrator to go for
> information on how to do these status lists, that's better, no?  Because
> once the draft is an RFC, the people implementing it won't have to care
> which working group it came from.  They will have one and only one place to
> look.
>

[BC] Colloquially, I'm really hoping this will come to be known
as Cooley's 'Matchy Matchy' Corollary. And I do follow the line of
reasoning.  But there are other ways to slice it too.

I'd posit that a charter (even while acknowledging they sometimes get
neglected) serves multiple functions. One function is about carving up
territory and bringing the right competence to bear on the work. I think
that's what your point here addresses. But another function is focusing the
output to be reasonably cohesive. Having two completely different
serialization and securing mechanisms in one document is a major disservice
to consumers of that document who don't need both. It significantly adds to
the length and cognitive overhead of the draft and can also create a
synthetic expectation that implementing it all is somehow necessary. To the
best of my knowledge, neither SPICE nor ACE is using this work or has
expressed any interest in it. The justification, as I understand it, for
the CBOR/COSE/CWT parts is so that prospective mdoc/mdl implementations
could consume status lists with the same technology stack they already
have. That's clearly outside the OAUTH WG charter (current and future) and
arguably outside even a reasonable conception of IETF's consensus. Is it
worth the charter scope shenanigans and the significantly expanded scope
and complexity of the document? I do think reasonable people can disagree
there but my opinion is obviously that it is not worth it.



>
>>
>>
>>>
>>> As for the mdoc in ISO, that was modified to be merely an example, i.e.
>>> non-normative.
>>>
>>> Of course, I'm assuming that you brought all this up while the draft was
>>> in the working group, right?
>>>
>>
>> Yes. Actually even before it was in the working group, when, as mentioned
>> and linked in a prior message here, I advocated for this draft's adoption
>> in the WG with a scope appropriate to the WG.
>>
>>
>>   Because after it is passed to me, seems.... um... late....
>>>
>>
>>> What am I missing?
>>>
>>> Deb
>>>
>>> p.s.  Note:  you should really want an oauth recharter to ensure that
>>> the SD-JWT VC draft is squarely in charter, no?
>>>
>>
>> That feels a little bit like the old trope of the mobster saying, "that's
>> a nice little draft you got there, it'd be a shame if something happened to
>> it..."
>>
>> I acknowledge that work and RFC9901 are on the margins of the chartered
>> scope. That's also mentioned and linked in a prior message in this thread.
>> I also believe it is more defensible with respect to the current charter
>> and precedent than CBOR/COSE/CWT stuff.
>>
>
> [DC] yeah, I will just lean on the 'I'm grumpy' card here.  No one has
> ever said I was a mobster before.  Brutally honest, yes, Mean, sometimes,
> Mobster, no.... huh.... could be a new low. I do apologize for the veiled
> threat.
>

To be fair, "feels a little bit like the old trope of the mobster" is not
the same as mobster. But I'll apologize too for the veiled accusation.

-- 
_CONFIDENTIALITY NOTICE: This email may contain confidential and privileged 
material for the sole use of the intended recipient(s). Any review, use, 
distribution or disclosure by others is strictly prohibited.  If you have 
received this communication in error, please notify the sender immediately 
by e-mail and delete the message and any file attachments from your 
computer. Thank you._