Re: [OAUTH-WG] mistake in draft-ietf-oauth-v2-http-mac-01

prateek mishra <prateek.mishra@oracle.com> Thu, 09 August 2012 18:29 UTC

Return-Path: <prateek.mishra@oracle.com>
X-Original-To: oauth@ietfa.amsl.com
Delivered-To: oauth@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 73D7721F86B5 for <oauth@ietfa.amsl.com>; Thu, 9 Aug 2012 11:29:44 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -10.598
X-Spam-Level:
X-Spam-Status: No, score=-10.598 tagged_above=-999 required=5 tests=[AWL=-0.000, BAYES_00=-2.599, HTML_MESSAGE=0.001, RCVD_IN_DNSWL_HI=-8]
Received: from mail.ietf.org ([12.22.58.30]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id U575KkbUGAg5 for <oauth@ietfa.amsl.com>; Thu, 9 Aug 2012 11:29:43 -0700 (PDT)
Received: from acsinet15.oracle.com (acsinet15.oracle.com [141.146.126.227]) by ietfa.amsl.com (Postfix) with ESMTP id 9217221F871E for <oauth@ietf.org>; Thu, 9 Aug 2012 11:29:43 -0700 (PDT)
Received: from acsinet22.oracle.com (acsinet22.oracle.com [141.146.126.238]) by acsinet15.oracle.com (Sentrion-MTA-4.2.2/Sentrion-MTA-4.2.2) with ESMTP id q79ITfXW021602 (version=TLSv1/SSLv3 cipher=DHE-RSA-AES256-SHA bits=256 verify=OK) for <oauth@ietf.org>; Thu, 9 Aug 2012 18:29:42 GMT
Received: from acsmt358.oracle.com (acsmt358.oracle.com [141.146.40.158]) by acsinet22.oracle.com (8.14.4+Sun/8.14.4) with ESMTP id q79ITft8014428 (version=TLSv1/SSLv3 cipher=DHE-RSA-AES256-SHA bits=256 verify=NO) for <oauth@ietf.org>; Thu, 9 Aug 2012 18:29:41 GMT
Received: from abhmt101.oracle.com (abhmt101.oracle.com [141.146.116.53]) by acsmt358.oracle.com (8.12.11.20060308/8.12.11) with ESMTP id q79ITeMk003169 for <oauth@ietf.org>; Thu, 9 Aug 2012 13:29:40 -0500
Received: from [10.152.55.167] (/10.152.55.167) by default (Oracle Beehive Gateway v4.0) with ESMTP ; Thu, 09 Aug 2012 11:29:40 -0700
Message-ID: <5024018B.2040907@oracle.com>
Date: Thu, 09 Aug 2012 14:29:31 -0400
From: prateek mishra <prateek.mishra@oracle.com>
Organization: Oracle Corporation
User-Agent: Mozilla/5.0 (Windows NT 5.1; rv:14.0) Gecko/20120713 Thunderbird/14.0
MIME-Version: 1.0
To: oauth@ietf.org
References: <CAOKdZ1dzVcKBDt6CSLuHwc4NzUVd_hUMWdpJVS6=ncdJo05=UQ@mail.gmail.com> <502280D8.40708@mitre.org> <9AD4EEF7-6187-4A4F-A855-32819BCB8321@gmx.net> <5022D344.40600@mitre.org> <EEBC9705-16C0-4697-8F38-28660C3CB553@ve7jtb.com> <5023CC18.9090809@mitre.org> <1344531175.4871.YahooMailNeo@web31812.mail.mud.yahoo.com> <3940317E-948C-4909-9B8F-2689A6B8D4EB@gmail.com> <1344534823.39489.YahooMailNeo@web31801.mail.mud.yahoo.com> <5B59B739-F8E7-4F5A-A39C-8C46055D0E98@ve7jtb.com>
In-Reply-To: <5B59B739-F8E7-4F5A-A39C-8C46055D0E98@ve7jtb.com>
Content-Type: multipart/alternative; boundary="------------060809020500000202060507"
X-Source-IP: acsinet22.oracle.com [141.146.126.238]
Subject: Re: [OAUTH-WG] mistake in draft-ietf-oauth-v2-http-mac-01
X-BeenThere: oauth@ietf.org
X-Mailman-Version: 2.1.12
Precedence: list
List-Id: OAUTH WG <oauth.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/oauth>, <mailto:oauth-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/oauth>
List-Post: <mailto:oauth@ietf.org>
List-Help: <mailto:oauth-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/oauth>, <mailto:oauth-request@ietf.org?subject=subscribe>
X-List-Received-Date: Thu, 09 Aug 2012 18:29:44 -0000

+1

finishing a draft for historical reasons without the full context of HoK 
use-cases and identified threats concerns me

> In Vancouver the question was asked about the future of the MAC spec 
> due to it no linger having a editor.
>
> The Chair and AD indicated a desire to have a document on the 
> use-cases we are trying to address before deciding on progressing MAC 
> or starting a new document.
>
> Phil Hunt is going to put together a summery of the Vancouver 
> discussion and we are going to work on the use-case/problem 
> description document ASAP.
>
> People are welcome to contribute to the use-case document.
>
> Part of the problem with MAC has been that people could never agree on 
> what it was protecting against.
>
> I think there is general agreement that one or more proof mechanisms 
> are required for access tokens.
> Security for the token endpoint also cannot be ignored.
>
>
> John B.
>
> On 2012-08-09, at 1:53 PM, William Mills wrote:
>
>> MAC fixes the signing problems encountered in OAuth 1.0a, yes there 
>> are libraries out there for OAuth 1.0a.  MAC fits in to the OAuth 2 
>> auth model and will provide for a single codepath for sites that want 
>> to use both Bearer and MAC.
>>
>> ------------------------------------------------------------------------
>> *From:* Dick Hardt <dick.hardt@gmail.com <mailto:dick.hardt@gmail.com>>
>> *To:* William Mills <wmills_92105@yahoo.com 
>> <mailto:wmills_92105@yahoo.com>>
>> *Cc:* "oauth@ietf.org <mailto:oauth@ietf.org>" <oauth@ietf.org 
>> <mailto:oauth@ietf.org>>
>> *Sent:* Thursday, August 9, 2012 10:27 AM
>> *Subject:* Re: [OAUTH-WG] mistake in draft-ietf-oauth-v2-http-mac-01
>>
>>
>> On Aug 9, 2012, at 9:52 AM, William Mills wrote:
>>
>>> I find the idea of starting from scratch frustrating.  MAC solves a 
>>> set of specific problems and has a well defined use case.  It's 
>>> symmetric key based which doesn't work for some folks, and the 
>>> question is do we try to develop something that supports both PK and 
>>> SK, or finish the SK use case and then work on a PK based draft.
>>>
>>> I think it's better to leave them separate and finish out MAC which 
>>> is *VERY CLOSE* to being done.
>>
>> Who is interested in MAC? People can use OAuth 1.0 if they prefer 
>> that model.
>>
>> For my projects, I prefer the flexibility of a signed or encrypted 
>> JWT if I need holder of key.
>>
>> Just my $.02
>>
>> -- Dick
>>
>>
>>
>> _______________________________________________
>> OAuth mailing list
>> OAuth@ietf.org <mailto:OAuth@ietf.org>
>> https://www.ietf.org/mailman/listinfo/oauth
>
>
>
> _______________________________________________
> OAuth mailing list
> OAuth@ietf.org
> https://www.ietf.org/mailman/listinfo/oauth