Re: [OAUTH-WG] Call for adoption - SD-JWT

Kristina Yasuda <Kristina.Yasuda@microsoft.com> Sat, 13 August 2022 00:09 UTC

Return-Path: <Kristina.Yasuda@microsoft.com>
X-Original-To: oauth@ietfa.amsl.com
Delivered-To: oauth@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 9A131C157B56 for <oauth@ietfa.amsl.com>; Fri, 12 Aug 2022 17:09:48 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.589
X-Spam-Level:
X-Spam-Status: No, score=-2.589 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIMWL_WL_HIGH=-0.582, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, HTML_MESSAGE=0.001, HTTPS_HTTP_MISMATCH=0.1, SPF_PASS=-0.001, T_SCC_BODY_TEXT_LINE=-0.01, URIBL_BLOCKED=0.001, URIBL_DBL_BLOCKED_OPENDNS=0.001, URIBL_ZEN_BLOCKED_OPENDNS=0.001] autolearn=unavailable autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (1024-bit key) header.d=microsoft.com
Received: from mail.ietf.org ([50.223.129.194]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id Toqnv1bTyeFT for <oauth@ietfa.amsl.com>; Fri, 12 Aug 2022 17:09:43 -0700 (PDT)
Received: from na01-obe.outbound.protection.outlook.com (mail-eastus2azlp170110002.outbound.protection.outlook.com [IPv6:2a01:111:f403:c110::2]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 7504AC14F737 for <oauth@ietf.org>; Fri, 12 Aug 2022 17:09:43 -0700 (PDT)
ARC-Seal: i=1; a=rsa-sha256; s=arcselector9901; d=microsoft.com; cv=none; b=N9Qp43DU0vtfJ/BBOdV4/AaHmpCy+B1yU2m6mi2/3bgTq4eMBfrMpBHlo4LnO4uGgPBxi5ELdygBEdag/dWzNBbSJTNo0goJ6x87O1F/L1h5yeoNAAwfVO7PmI3SDK3UQ7oBtIbJ2xsYE7u/tnGhJBnVG27etkHeyvneltvQkb+R0q+uDyJJc0t98cy3f/TBIRVsL/L76DVOX+hKLKCa5MIb5erSqBlXP7/wKiDRTDDMSxVEkyejRWv1M0wjnH9l9NghN/7jRa50QNxIfdTWC4pjnMyMxqTP+m4rqBYQSC7e0AOz+8N3H7YNAcZoTNjpgMDza/2BF1LTgRass970Tg==
ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=microsoft.com; s=arcselector9901; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-AntiSpam-MessageData-ChunkCount:X-MS-Exchange-AntiSpam-MessageData-0:X-MS-Exchange-AntiSpam-MessageData-1; bh=xeAIkcRVM1XFnOqhvYAES38BXyxE1Ym+LDOJ7fyyj7g=; b=e6JvaQkyI4yrzoqL5DclE9RjBzStUwmtH5pUK+MO6jnHuC+VFycUMwX/gBGTeKjmH3+KYZhddHyhvA9t0K932/Mmvydejm60l/rU/gE/TijVqeR1x0ONfe2Vaid23kXcBm6LvAgpe/1Reict4EI0X+Yv1dJgzvsQdFOnYuqT+WPSxpQVZjtfHK8BnezDzrUbJB12AzrJW5BBJ/5lMag1pkh3hY9xelOPFYK2TnXx///49jrSvU0NLwfzRVjVyobhOFoIc6Me82n5CNrVISComlCGTraKPl0vbaBSC9VS22r6xJlZnittOBD99Ci3xo/GHQMuqZFbFqI5XiSJvQGP+Q==
ARC-Authentication-Results: i=1; mx.microsoft.com 1; spf=pass smtp.mailfrom=microsoft.com; dmarc=pass action=none header.from=microsoft.com; dkim=pass header.d=microsoft.com; arc=none
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=microsoft.com; s=selector2; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-SenderADCheck; bh=xeAIkcRVM1XFnOqhvYAES38BXyxE1Ym+LDOJ7fyyj7g=; b=dbDAKg/0mqBvVQVfADeH30nh/b2krEt1fh8g2IrNA+0kRMbbKbIcX18rU2nNt03ndCOzVpDzuDxlvwv6HQy9PkkY7hfQInySeNUlspv+itsTEn2K2bBMlYVkiTfmm7j2rwjfJ/LvR7w7gytJVL7ZKYDj6GTYbzSW5N7CLFvBefM=
Received: from BYAPR00MB0885.namprd00.prod.outlook.com (2603:10b6:a03:104::32) by CO1PR00MB0994.namprd00.prod.outlook.com (2603:10b6:303:9c::19) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.20.5565.0; Sat, 13 Aug 2022 00:09:30 +0000
Received: from BYAPR00MB0885.namprd00.prod.outlook.com ([fe80::a72c:c1b1:f5e0:c826]) by BYAPR00MB0885.namprd00.prod.outlook.com ([fe80::a72c:c1b1:f5e0:c826%5]) with mapi id 15.20.5569.000; Sat, 13 Aug 2022 00:09:23 +0000
From: Kristina Yasuda <Kristina.Yasuda@microsoft.com>
To: Jaimandeep Singh <jaimandeep.phdcs21=40nfsu.ac.in@dmarc.ietf.org>, Rifaat Shekh-Yusef <rifaat.s.ietf@gmail.com>
CC: oauth <oauth@ietf.org>
Thread-Topic: [OAUTH-WG] Call for adoption - SD-JWT
Thread-Index: AQHYouCSYdQ/0/bazkK0Blh3C8f3dq2jlO0AgAUCcICAAq7pAIAABnOAgAC+n9A=
Date: Sat, 13 Aug 2022 00:09:23 +0000
Message-ID: <BYAPR00MB0885C2A34A57DF9340EE4221E5669@BYAPR00MB0885.namprd00.prod.outlook.com>
References: <CADNypP9xSXWKV=0nj803fW9xdqgguLWLOpMMQd0Uw3P16LQpfQ@mail.gmail.com> <CABzCy2C_o48+tyqpatFu73bXEZ193pvsVuvurV8q821kN8jT0A@mail.gmail.com> <CA+k3eCSx6Oonq-9EPdwjpCYSiVehbYMj+ds9fAM2gE7Pbw72xw@mail.gmail.com> <CADNypP9LxZrB=sLDMT2bxJMnr4otN9nE1Qg7nzNR+32ojmv4pg@mail.gmail.com> <CAODMz5Eqxhog=3wUUp70dcYkU091OCNP6559fMU1WenpAWJfsw@mail.gmail.com>
In-Reply-To: <CAODMz5Eqxhog=3wUUp70dcYkU091OCNP6559fMU1WenpAWJfsw@mail.gmail.com>
Accept-Language: en-US, ja-JP
Content-Language: en-US
X-MS-Has-Attach:
X-MS-TNEF-Correlator:
authentication-results: dkim=none (message not signed) header.d=none;dmarc=none action=none header.from=microsoft.com;
x-ms-publictraffictype: Email
x-ms-office365-filtering-correlation-id: 13b835e1-4d3b-4708-7375-08da7cc013dc
x-ms-traffictypediagnostic: CO1PR00MB0994:EE_
x-ms-exchange-senderadcheck: 1
x-ms-exchange-antispam-relay: 0
x-microsoft-antispam: BCL:0;
x-microsoft-antispam-message-info: XPxYZT0qYgC7mNbvmjR7Ueimh7rBH3oTHfzOkjzOtB26fal9W2ZdRPIj/MNpKWTL9CaIHI+wzBfQXWE8OCVFqCAkTm01yfYX1znaHQOLdwij/gI2xfWOousDF069kDKLdHp+4AawRxm7IibXwJ0GE4jbunoQ2Rle/D6fNnTShYxztFpULv2dyokhOC6/f8SzJnmdq4cD1myx/lRA+v6n2s8g3NRMPj2nqVewy5U7xvp0S1aOiCNDbq7Ms8X/bSRUyhwGLzgsfiByV5I8YCX/gH7rJc8pB0VV7coxo+0FdajYehIxaSIuktc8Nw+kupCF/ZTSB2v9VNCaJvsUT4owz/2AJIU3XROy0r71H5RQnRCo12PUQ1rVYt6uuHCoBdZgKj4vQgPQOPWDcUVWv+O9OyJBeRPas9mkqD1zawbUbbtSnaw3ydxUynsc8dAo3n7m3Agh2B0S2XCJTZhtGB8ZhcdRFxS6fN2jMFKY2xqMQrVTFVElWz1rY1xygcbo2Gr2eWOlE4bWZDJ3nEU5PIo7dEjTdqev9hVnhi2YWsBJ02rpJ59zwdhMS9yLQoSfYbW1QZGULpiz8tHkzV/ysaYCMRZ5plqzKV2dv5Z1eUTvRdx9K9tFBFibmu1rKDzHDEb0/EJ3XfGynS4zT/fJP8LdUWgyY0JGBRAPBNQ5lrxCETqa/PQMc8+pF11hMIhqb7c4xRzrv5hzK4+95JVqs1X/EMY/b7ZFwGzz2XsHC8CsNRgz4o/GJdLAu2DSY933KJanPHtOPQ22XZvGm9bgACrFBD80PPzIU6ZhY78TPX2ZZIh2UNQ2oWb7nW/q3W5/kUrZj5SzZkN3tD0JgkS8P5u5y8lHViJ3xuUaaTzojEg6yFZgEzv7vp7YobqGudGH8Z/t
x-forefront-antispam-report: CIP:255.255.255.255; CTRY:; LANG:en; SCL:1; SRV:; IPV:NLI; SFV:NSPM; H:BYAPR00MB0885.namprd00.prod.outlook.com; PTR:; CAT:NONE; SFS:(13230016)(4636009)(136003)(376002)(396003)(39860400002)(366004)(346002)(451199009)(122000001)(33656002)(2906002)(83380400001)(82960400001)(53546011)(316002)(82950400001)(38100700002)(10290500003)(110136005)(8990500004)(8936002)(5660300002)(66476007)(66946007)(76116006)(64756008)(66446008)(186003)(55016003)(52536014)(66556008)(478600001)(7696005)(9686003)(6506007)(41300700001)(966005)(86362001)(166002)(8676002)(4326008)(71200400001)(38070700005); DIR:OUT; SFP:1102;
x-ms-exchange-antispam-messagedata-chunkcount: 1
x-ms-exchange-antispam-messagedata-0: QqUwy8c6/PiRj2dSr2JKwdaRRTul1pNYK9Zb3k4GCIGaXYFLwqpl//xc7KLSh177xRQy/koOPhryNvOUQ06X+15EIv3c4hjik7HWj93DzYkpcMVXcpHM0Wkulg1q+FAj3XN3NzStJdaY3qETZTQH3xaFX0ZGSwZ0G9hImjalzGpvxbtZUO5jZF6Ev5xgPzULU9zE+SqKCf8KDZ+Fs0ryzWiK2l72eKrS6dX3fR/47gJMxwnI603Mv5lg4vXLzEN9H20w6Pm01VH6XBK3x0lCQ9b9RPLR+OvQQonzCWfAEI1fdgbG+MUQaXASojJS6wRHmB7fg3ScttoiW1y3p45s/09ijAexhwkIVr9q4JSkzP7ArAqWviIliRmt995Spr5idshoipV2BmNhM2cFQ9UAydUn66P7ZI4JZxRKf6fp37rdP78QORWyNTnvFc6V1R5XkM8hblizX5/ji8ahVqnDNue3gkjA4DfHIC+G50ALFbqfZIIDHsH+xKSIfAjiBRBuRztrvzhdznnj2TbcsTgj2HDanUUmYmzcBQCm8qWnmYlMnn2eMc1v5zuQrhYgIvozgHFCatjBnkdCgLii35GSbmJtUMb6zaX3J43VbZ32CAmnjp97rnDw4BoVeo501CUPMx9f1JSihzlM3nml25H2HQ3uYgio4Wv+aeL2onn/HLRqUuQr9O12BeMrWJ9oD+WvKNJ8xX5E/VNd3dO0vZFpo75OYOOlYY/7pzEQc6we35lXWcRMgZn//jmw4O4OE4rCBAoA3XVWSZ+1L1QneH2CagS67sxB3PfJ1rB+Z3QcgT8czObjfyc/5DbPaAI8tUAgOlN8yJEK2pXEYNB1g9pvZX0n2PoBzAQkaRKXvbk6cP3+j8vuBJpYWIy4pG6eyDEv5S31PexgUDdcaid43q0Njv/+Fa9b0LsExWyO9xxeN73SD7hMBuzVdkh9w2aftLiJl/rB2CvCfOUKEmcLXI4UY2c+gyCAKVjHCB1V3ayub25ZEZCNqwyDzNc+HlYvZ/blusIOCgfsllNpDx90CnNjYfsAImFvEA1d77asvb5CnoAjSpEkhQWjMQfeSBu4PmtN0DoTEZJhmmsv2KQaZBYKh1/Lnht+h95hWyPW/UjkkuMcida74otRsRVsFOGmLfOFRrlYBJL7hZyL3FV1Gg+UviiRPrlELeDu7w35pM/hO2kvhrJIPD/PMsXGzkeLfMFDbCgvs1d8VtWJafXbNB2pN01/6wbZe/l1q+7mMUc9diIvtxPXdAzW8H2p/t8xr8LCRgzbCDNnuAVnDf25jfHTECz8HigfcoAK+0Ml0h6xFCprb1F7U8badA9yM9VoayYaNbi03oitsoUN6yVN4CpMMzwh4jMptVCAJktTRPo6diX0QSstksptBShF87uqh9fK+5TIWXBbBZTul3ezHBQCtw00P/ysjhi/MgLte1LngoFfJF4TQKrkkhLecpF+bvRzGlHPCFIU0LOZcYaVrJfw5H+DBuYAQ4l9OLt07zSibwJ8ORorDUYxVkvqsldx9SXNu1Ti4703PR29snCrMFFc9+4SW/YZWGhdYiGURK3YbDjWKNo8m0Tdi0e7uf1oNoG7eXLnky9+pACdLh89LTmCvBxFYUJaHW5h6dkbKIdx69nCJH+I6xckZ4/SUUFoybT1
Content-Type: multipart/alternative; boundary="_000_BYAPR00MB0885C2A34A57DF9340EE4221E5669BYAPR00MB0885namp_"
MIME-Version: 1.0
X-OriginatorOrg: microsoft.com
X-MS-Exchange-Transport-CrossTenantHeadersStamped: CO1PR00MB0994
Archived-At: <https://mailarchive.ietf.org/arch/msg/oauth/rhs6fKjVzpK-d7L0mX8dFHoqxZg>
Subject: Re: [OAUTH-WG] Call for adoption - SD-JWT
X-BeenThere: oauth@ietf.org
X-Mailman-Version: 2.1.39
Precedence: list
List-Id: OAUTH WG <oauth.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/oauth>, <mailto:oauth-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/oauth/>
List-Post: <mailto:oauth@ietf.org>
List-Help: <mailto:oauth-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/oauth>, <mailto:oauth-request@ietf.org?subject=subscribe>
X-List-Received-Date: Sat, 13 Aug 2022 00:09:48 -0000

Thank you very much, everyone, for the feedback!
Really looking forward to keep working on the document.
Kindest Regards,
Kristina & Daniel

From: OAuth <oauth-bounces@ietf.org> On Behalf Of Jaimandeep Singh
Sent: Friday, August 12, 2022 5:44 AM
To: Rifaat Shekh-Yusef <rifaat.s.ietf@gmail.com>
Cc: oauth <oauth@ietf.org>
Subject: Re: [OAUTH-WG] Call for adoption - SD-JWT

Congratulations to the SD-JWT team and all the members for the hard work and patiently addressing all the concerns.

Regards and Best Wishes
Jaimandeep Singh

On Fri, 12 Aug, 2022, 5:51 pm Rifaat Shekh-Yusef, <rifaat.s.ietf@gmail.com<mailto:rifaat.s.ietf@gmail.com>> wrote:
Based on the feedback during the IETF meeting in Philadelphia and based on the feedback on the mailing list, the WG has decided to adopt the SD-JWT document as a WG document.


Authors,

Please, feel free to submit a WG -00 version for this document at your convenience.

Regards,
 Rifaat & Hannes





On Wed, Aug 10, 2022 at 3:23 PM Brian Campbell <bcampbell@pingidentity.com<mailto:bcampbell@pingidentity.com>> wrote:
As Nat and others have mentioned, JWT itself<https://nam06.safelinks.protection.outlook.com/?url=https%3A%2F%2Fdatatracker.ietf.org%2Fdoc%2Frfc7519%2F&data=05%7C01%7CKristina.Yasuda%40microsoft.com%7Cf12ab0c57bc140fc0ec308da7c60718e%7C72f988bf86f141af91ab2d7cd011db47%7C1%7C0%7C637959050933016540%7CUnknown%7CTWFpbGZsb3d8eyJWIjoiMC4wLjAwMDAiLCJQIjoiV2luMzIiLCJBTiI6Ik1haWwiLCJXVCI6Mn0%3D%7C3000%7C%7C%7C&sdata=CYrlvZdui%2FxM1tdXe7aGP2zny5kjyn2u9pkr4FHp3KA%3D&reserved=0> is a product of this WG. While JWT had applications in OAuth, it was developed as a more general purpose token format and has seen widespread usage. Working on a general purpose selective disclosure mechanism for JWT in this WG seems appropriate considering that history.

On Sun, Aug 7, 2022 at 8:53 AM Nat Sakimura <sakimura@gmail.com<mailto:sakimura@gmail.com>> wrote:
I support the adoption of SD-JWT. This is a natural and important extension to JWT which is a product of this WG and meets some of the use-cases that we left out years ago with relatively simple cryptographic techniques.

On Fri, Jul 29, 2022 at 9:17 AM Rifaat Shekh-Yusef <rifaat.s.ietf@gmail.com<mailto:rifaat.s.ietf@gmail.com>> wrote:
All,

This is a call for adoption for the SD-JWT document
https://datatracker.ietf.org/doc/draft-fett-oauth-selective-disclosure-jwt/<https://nam06.safelinks.protection.outlook.com/?url=https%3A%2F%2Fdatatracker.ietf.org%2Fdoc%2Fdraft-fett-oauth-selective-disclosure-jwt%2F&data=05%7C01%7CKristina.Yasuda%40microsoft.com%7Cf12ab0c57bc140fc0ec308da7c60718e%7C72f988bf86f141af91ab2d7cd011db47%7C1%7C0%7C637959050933016540%7CUnknown%7CTWFpbGZsb3d8eyJWIjoiMC4wLjAwMDAiLCJQIjoiV2luMzIiLCJBTiI6Ik1haWwiLCJXVCI6Mn0%3D%7C3000%7C%7C%7C&sdata=uULZOlK8LDGrc0YDR7m0%2B7uqYKcBlnf%2B4q14DHdf%2Fds%3D&reserved=0>

Please, provide your feedback on the mailing list by August 12th.

Regards,
 Rifaat & Hannes

_______________________________________________
OAuth mailing list
OAuth@ietf.org<mailto:OAuth@ietf.org>
https://www.ietf.org/mailman/listinfo/oauth<https://nam06.safelinks.protection.outlook.com/?url=https%3A%2F%2Fwww.ietf.org%2Fmailman%2Flistinfo%2Foauth&data=05%7C01%7CKristina.Yasuda%40microsoft.com%7Cf12ab0c57bc140fc0ec308da7c60718e%7C72f988bf86f141af91ab2d7cd011db47%7C1%7C0%7C637959050933016540%7CUnknown%7CTWFpbGZsb3d8eyJWIjoiMC4wLjAwMDAiLCJQIjoiV2luMzIiLCJBTiI6Ik1haWwiLCJXVCI6Mn0%3D%7C3000%7C%7C%7C&sdata=jPWUkrt5%2FfP7dyKZPyuevzPBcrAQrqU1zN6EZ22%2B4QI%3D&reserved=0>


--
Nat Sakimura (=nat)
Chairman, OpenID Foundation
http://nat.sakimura.org/<https://nam06.safelinks.protection.outlook.com/?url=http%3A%2F%2Fnat.sakimura.org%2F&data=05%7C01%7CKristina.Yasuda%40microsoft.com%7Cf12ab0c57bc140fc0ec308da7c60718e%7C72f988bf86f141af91ab2d7cd011db47%7C1%7C0%7C637959050933016540%7CUnknown%7CTWFpbGZsb3d8eyJWIjoiMC4wLjAwMDAiLCJQIjoiV2luMzIiLCJBTiI6Ik1haWwiLCJXVCI6Mn0%3D%7C3000%7C%7C%7C&sdata=rVdwsKDpTvDsl4v7gFeaJWF095HM6FtI2FX6EvAW7fg%3D&reserved=0>
@_nat_en
_______________________________________________
OAuth mailing list
OAuth@ietf.org<mailto:OAuth@ietf.org>
https://www.ietf.org/mailman/listinfo/oauth<https://nam06.safelinks.protection.outlook.com/?url=https%3A%2F%2Fwww.ietf.org%2Fmailman%2Flistinfo%2Foauth&data=05%7C01%7CKristina.Yasuda%40microsoft.com%7Cf12ab0c57bc140fc0ec308da7c60718e%7C72f988bf86f141af91ab2d7cd011db47%7C1%7C0%7C637959050933016540%7CUnknown%7CTWFpbGZsb3d8eyJWIjoiMC4wLjAwMDAiLCJQIjoiV2luMzIiLCJBTiI6Ik1haWwiLCJXVCI6Mn0%3D%7C3000%7C%7C%7C&sdata=jPWUkrt5%2FfP7dyKZPyuevzPBcrAQrqU1zN6EZ22%2B4QI%3D&reserved=0>

CONFIDENTIALITY NOTICE: This email may contain confidential and privileged material for the sole use of the intended recipient(s). Any review, use, distribution or disclosure by others is strictly prohibited.  If you have received this communication in error, please notify the sender immediately by e-mail and delete the message and any file attachments from your computer. Thank you.
_______________________________________________
OAuth mailing list
OAuth@ietf.org<mailto:OAuth@ietf.org>
https://www.ietf.org/mailman/listinfo/oauth<https://nam06.safelinks.protection.outlook.com/?url=https%3A%2F%2Fwww.ietf.org%2Fmailman%2Flistinfo%2Foauth&data=05%7C01%7CKristina.Yasuda%40microsoft.com%7Cf12ab0c57bc140fc0ec308da7c60718e%7C72f988bf86f141af91ab2d7cd011db47%7C1%7C0%7C637959050933172766%7CUnknown%7CTWFpbGZsb3d8eyJWIjoiMC4wLjAwMDAiLCJQIjoiV2luMzIiLCJBTiI6Ik1haWwiLCJXVCI6Mn0%3D%7C3000%7C%7C%7C&sdata=VGzGx%2BHG%2BmF6zWnB%2FXfStc6Z49M1RbuWQ0cdY7qHW1w%3D&reserved=0>