Re: [OAUTH-WG] Shepherd Writeup for draft-ietf-oauth-spop-06.txt
Brian Campbell <bcampbell@pingidentity.com> Thu, 19 February 2015 22:28 UTC
Return-Path: <bcampbell@pingidentity.com>
X-Original-To: oauth@ietfa.amsl.com
Delivered-To: oauth@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id F12791A0AF8 for <oauth@ietfa.amsl.com>; Thu, 19 Feb 2015 14:28:22 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -3.578
X-Spam-Level:
X-Spam-Status: No, score=-3.578 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, FM_FORGED_GMAIL=0.622, HTML_MESSAGE=0.001, RCVD_IN_DNSWL_MED=-2.3, SPF_PASS=-0.001] autolearn=ham
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id ZeVyAG3ca-Ko for <oauth@ietfa.amsl.com>; Thu, 19 Feb 2015 14:28:20 -0800 (PST)
Received: from na3sys009aog101.obsmtp.com (na3sys009aog101.obsmtp.com [74.125.149.67]) (using TLSv1 with cipher DHE-RSA-AES256-SHA (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id D2D2D1A0372 for <oauth@ietf.org>; Thu, 19 Feb 2015 14:28:17 -0800 (PST)
Received: from mail-ie0-f178.google.com ([209.85.223.178]) (using TLSv1) by na3sys009aob101.postini.com ([74.125.148.12]) with SMTP ID DSNKVOZjgf+xXsrKvoxiC58lNI5dJH8L/K8K@postini.com; Thu, 19 Feb 2015 14:28:17 PST
Received: by iecat20 with SMTP id at20so3654985iec.12 for <oauth@ietf.org>; Thu, 19 Feb 2015 14:28:17 -0800 (PST)
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20130820; h=x-gm-message-state:mime-version:in-reply-to:references:from:date :message-id:subject:to:cc:content-type; bh=x/OTJ2X+LDXyBrLgBcZLUgQfrYm0KbnDypIM5Ghk7+o=; b=NIP4g8NyJRhOa6Wo4pOGQZMm2EnWe4Wsi4AhROC3c3xkEQA9Om6QahY1WtJpAU5EV+ z4VCWreKd6so3VwzD+LKG/EGB75+GcvlplZ5WOMhq2undXucpDRNx7I+mXb2pvZJMg8k w7ic90a7ajtoXyXuLBg9nbgw7Kxnt9wEUHRPIzfs3LpXdF8fO68DsHkEWSayuYV1Ege4 zIby4Php/pVgdJVY+9tdC0LLVl+phcChemFgXDcL8/SCBG8MLv2r6RbhpdbqhktcD25c 03IX99Ll7e+Zpf89ChV8+czu1uwiRhozw4JEGyJtPYG/mlg9NpL9n6EnyC5ohyBRgUQ+ KtBQ==
X-Gm-Message-State: ALoCoQmisPtfh8/uKOJHucE29z8F0YPUD+pUMr9sOpglt3xxw6l1TSeyDPor0gK00pP0E4MRu5piBKplwcEZ/aN1ESTiEegwcfVtN+7c5/3CKH306I6sO1X92OhM/MqvUeLGSgaW2/L7
X-Received: by 10.43.98.2 with SMTP id cm2mr8584496icc.75.1424384897061; Thu, 19 Feb 2015 14:28:17 -0800 (PST)
X-Received: by 10.43.98.2 with SMTP id cm2mr8584487icc.75.1424384896963; Thu, 19 Feb 2015 14:28:16 -0800 (PST)
MIME-Version: 1.0
Received: by 10.64.107.105 with HTTP; Thu, 19 Feb 2015 14:27:46 -0800 (PST)
In-Reply-To: <54E4CCDD.6010709@gmx.net>
References: <54C7BBA4.4030702@gmx.net> <CA+k3eCQCPiAR0s1cX5mC=h2O-5ptVTVq6=cVKHFKu_Adq8bJTg@mail.gmail.com> <2E3D2EE7-8F5F-452D-880A-D62A513AC853@lodderstedt.net> <54E370F9.8060209@gmx.net> <17faabb6e724fb54f3cb8060a3d9cb08@lodderstedt.net> <54E4B0AD.10801@gmx.net> <CA+k3eCThg3TxRtCuEwGGWG07yWZD82i87fUQjDrKs3sMmd5frg@mail.gmail.com> <54E4CCDD.6010709@gmx.net>
From: Brian Campbell <bcampbell@pingidentity.com>
Date: Thu, 19 Feb 2015 15:27:46 -0700
Message-ID: <CA+k3eCTqAFK_yfn65YOV-Ba0buhw9+cT=4+uF1aLO++7dfikbg@mail.gmail.com>
To: Hannes Tschofenig <hannes.tschofenig@gmx.net>
Content-Type: multipart/alternative; boundary="bcaec517c890ceb158050f78731b"
Archived-At: <http://mailarchive.ietf.org/arch/msg/oauth/87YfkVABciUcbypHBdUvjAAqvmg>
Cc: oauth <oauth@ietf.org>, "naa@google.com >> Naveen Agarwal" <naa@google.com>
Subject: Re: [OAUTH-WG] Shepherd Writeup for draft-ietf-oauth-spop-06.txt
X-BeenThere: oauth@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: OAUTH WG <oauth.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/oauth>, <mailto:oauth-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/oauth/>
List-Post: <mailto:oauth@ietf.org>
List-Help: <mailto:oauth-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/oauth>, <mailto:oauth-request@ietf.org?subject=subscribe>
X-List-Received-Date: Thu, 19 Feb 2015 22:28:23 -0000
I can't comment with any authority on product road-map (that's above my pay-grade) but I can speculate that we probably would support "S256" eventually. On Wed, Feb 18, 2015 at 10:33 AM, Hannes Tschofenig < hannes.tschofenig@gmx.net> wrote: > Thanks Brian for pointing me to Section 4.4.1 and to the MTI for "S256". > While this is good from a security point of view I am wondering whether > anyone is actually compliant to the specification. Neither PingIdentity > nor DT implements the S256 transform, if I understood that correctly. > Are you guys going planning to update your implementations? > > Ciao > Hannes > > On 02/18/2015 05:45 PM, Brian Campbell wrote: > > There's a bit of MTI talk tucked into > > https://tools.ietf.org/html/draft-ietf-oauth-spop-10#section-4.4.1 that > > perhaps needs to be expanded and/or placed somewhere else. > > > > On Wed, Feb 18, 2015 at 8:33 AM, Hannes Tschofenig > > <hannes.tschofenig@gmx.net <mailto:hannes.tschofenig@gmx.net>> wrote: > > > > Thanks for the info, Torsten. > > > > Your feedback raises an interesting question, namely what > functionality > > the parties have to implement to claim conformance to the > specification. > > > > Quickly scanning through the specification didn't tell me whether it > is > > OK to just implement the plain mode or whether both modes are > > mandatory-to-implement. We have to say something about this. > > > > Ciao > > Hannes > > > > > > On 02/18/2015 02:16 PM, torsten@lodderstedt.net > > <mailto:torsten@lodderstedt.net> wrote: > > > Hi Hannes, > > > > > > our implementation supports the "plain" mode only. We just verified > > > compliance of our implementation with the current spec. As the only > > > deviation, we do not enforce the minimum length of 43 characters > > of the > > > code verifier. > > > > > > kind regards, > > > Torsten. > > > > > > Am 17.02.2015 17:48, schrieb Hannes Tschofenig: > > >> Hi Torsten, > > >> > > >> does this mean that your implementation is not compliant with the > > >> current version anymore or that you haven't had time to verify > > whether > > >> there are differences to the earlier version? > > >> > > >> Ciao > > >> Hannes > > >> > > >> > > >> On 01/31/2015 05:34 PM, Torsten Lodderstedt wrote: > > >>> Deutsche Telekom also implemented an early version of the draft > last > > >>> year. > > >>> > > >>> > > >>> > > >>> Am 30.01.2015 um 18:50 schrieb Brian Campbell > > >>> <bcampbell@pingidentity.com <mailto:bcampbell@pingidentity.com> > > <mailto:bcampbell@pingidentity.com > > <mailto:bcampbell@pingidentity.com>>>: > > >>> > > >>>> > > >>>> On Tue, Jan 27, 2015 at 9:24 AM, Hannes Tschofenig > > >>>> <hannes.tschofenig@gmx.net <mailto:hannes.tschofenig@gmx.net> > > <mailto:hannes.tschofenig@gmx.net > > <mailto:hannes.tschofenig@gmx.net>>> wrote: > > >>>> > > >>>> > > >>>> 1) What implementations of the spec are you aware of? > > >>>> > > >>>> > > >>>> We have an AS side implementation of an earlier draft that was > > >>>> released in June of last year: > > >>>> > > > http://documentation.pingidentity.com/pages/viewpage.action?pageId=26706844 > > >>>> > > >>>> _______________________________________________ > > >>>> OAuth mailing list > > >>>> OAuth@ietf.org <mailto:OAuth@ietf.org> <mailto:OAuth@ietf.org > > <mailto:OAuth@ietf.org>> > > >>>> https://www.ietf.org/mailman/listinfo/oauth > > > > > >
- [OAUTH-WG] Shepherd Writeup for draft-ietf-oauth-… Hannes Tschofenig
- Re: [OAUTH-WG] Shepherd Writeup for draft-ietf-oa… Brian Campbell
- Re: [OAUTH-WG] Shepherd Writeup for draft-ietf-oa… Torsten Lodderstedt
- Re: [OAUTH-WG] Shepherd Writeup for draft-ietf-oa… Hannes Tschofenig
- Re: [OAUTH-WG] Shepherd Writeup for draft-ietf-oa… Hannes Tschofenig
- Re: [OAUTH-WG] Shepherd Writeup for draft-ietf-oa… Brian Campbell
- Re: [OAUTH-WG] Shepherd Writeup for draft-ietf-oa… torsten
- Re: [OAUTH-WG] Shepherd Writeup for draft-ietf-oa… Hannes Tschofenig
- Re: [OAUTH-WG] Shepherd Writeup for draft-ietf-oa… Brian Campbell
- Re: [OAUTH-WG] Shepherd Writeup for draft-ietf-oa… Hannes Tschofenig
- Re: [OAUTH-WG] Shepherd Writeup for draft-ietf-oa… Torsten Lodderstedt
- Re: [OAUTH-WG] Shepherd Writeup for draft-ietf-oa… John Bradley
- Re: [OAUTH-WG] Shepherd Writeup for draft-ietf-oa… Brian Campbell
- Re: [OAUTH-WG] Shepherd Writeup for draft-ietf-oa… Nat Sakimura