Re: [OAUTH-WG] Fwd: I-D Action: draft-ietf-oauth-token-binding-02.txt
Mike Jones <Michael.Jones@microsoft.com> Tue, 14 March 2017 00:43 UTC
Return-Path: <Michael.Jones@microsoft.com>
X-Original-To: oauth@ietfa.amsl.com
Delivered-To: oauth@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 2078C129462; Mon, 13 Mar 2017 17:43:38 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.001
X-Spam-Level:
X-Spam-Status: No, score=-2.001 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, HTML_MESSAGE=0.001, RCVD_IN_DNSWL_NONE=-0.0001, SPF_HELO_PASS=-0.001, SPF_PASS=-0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (1024-bit key) header.d=microsoft.com
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id u4FShRdyDclu; Mon, 13 Mar 2017 17:43:35 -0700 (PDT)
Received: from NAM01-BY2-obe.outbound.protection.outlook.com (mail-by2nam01on0090.outbound.protection.outlook.com [104.47.34.90]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 42A72129410; Mon, 13 Mar 2017 17:43:35 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=microsoft.com; s=selector1; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version; bh=vI0p+9O3oFAkdpKWaz1Mx0sfDXse/H0+AD2hpj/5iuA=; b=ZjAvrRLR56Pn+IHVaRTCyGbtkztm/NRS1hrA8SvEn7fm1oxOy+XUxSBTczBS0wYhkd4WioPuSQ+Dv4X3z9XnLSqPMva1rEo9qfRZx5qm/yQ/JbRiIwwJpVWgnmbdIrbLB0BbHUbZQELaBpILk6vLQ2dY+ECdX3AZyn9ILcc4lno=
Received: from CY4PR21MB0504.namprd21.prod.outlook.com (10.172.122.14) by CY4PR21MB0504.namprd21.prod.outlook.com (10.172.122.14) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_128_CBC_SHA256_P256) id 15.1.991.0; Tue, 14 Mar 2017 00:43:34 +0000
Received: from CY4PR21MB0504.namprd21.prod.outlook.com ([10.172.122.14]) by CY4PR21MB0504.namprd21.prod.outlook.com ([10.172.122.14]) with mapi id 15.01.0991.000; Tue, 14 Mar 2017 00:43:34 +0000
From: Mike Jones <Michael.Jones@microsoft.com>
To: Brian Campbell <bcampbell@pingidentity.com>, oauth <oauth@ietf.org>, IETF Tokbind WG <unbearable@ietf.org>
Thread-Topic: [OAUTH-WG] Fwd: I-D Action: draft-ietf-oauth-token-binding-02.txt
Thread-Index: AQHSnEFNkgAXqWGVdUiR3jYbkJVSzqGTfxTw
Date: Tue, 14 Mar 2017 00:43:33 +0000
Message-ID: <CY4PR21MB05049486BD14F62A70E64653F5240@CY4PR21MB0504.namprd21.prod.outlook.com>
References: <148943968790.20370.17735775296781507437@ietfa.amsl.com> <CA+k3eCS5tgF0zpGhTbvasJry1XJTqi9_1HeJ+nCKWLHcmjOQMw@mail.gmail.com>
In-Reply-To: <CA+k3eCS5tgF0zpGhTbvasJry1XJTqi9_1HeJ+nCKWLHcmjOQMw@mail.gmail.com>
Accept-Language: en-US
Content-Language: en-US
X-MS-Has-Attach:
X-MS-TNEF-Correlator:
authentication-results: pingidentity.com; dkim=none (message not signed) header.d=none;pingidentity.com; dmarc=none action=none header.from=microsoft.com;
x-originating-ip: [2001:4898:80e8:4::36]
x-microsoft-exchange-diagnostics: 1; CY4PR21MB0504; 7:k4CjOcRQzhvsIEWQNMjKNcsTW+MIyXphL+keGI6x6jznECs5GioodBQZwMH4RsArmF4qVEgUG/T3EuhWTfYvEL1xNLpoJSCNporiY6DFJq332jH6GwpvKAwFXH6bpgl0CNugqAEh7SZOOPTD3LCRxT8JJ00umEwrcgJzxpTsNzaUCqvEIP6wbKEGZ4hxB2pCFvqBK75Hwba/ZpSPVRRbUleJUOw3irWfjXyorr7b4131IELRzZTlb3Q+TSroEFOSqha1aBkYdr1GHCWPAXZZUtHzNoryPwkxZzNZsu+Kdc/FPpXzl12S8YAQXmnO3rinhwwueL6fwwit4v0A/uHA2UI/6+UoTyrKb17NVo7M0G0=
x-ms-office365-filtering-correlation-id: ba0f373c-db8a-4739-50f9-08d46a732519
x-ms-office365-filtering-ht: Tenant
x-microsoft-antispam: UriScan:; BCL:0; PCL:0; RULEID:(22001)(2017030254011)(48565401081); SRVR:CY4PR21MB0504;
x-microsoft-antispam-prvs: <CY4PR21MB05048D200819C40C26F8CB40F5240@CY4PR21MB0504.namprd21.prod.outlook.com>
x-exchange-antispam-report-test: UriScan:(158342451672863)(120809045254105)(31418570063057)(21748063052155);
x-exchange-antispam-report-cfa-test: BCL:0; PCL:0; RULEID:(61425038)(6040375)(601004)(2401047)(8121501046)(5005006)(10201501046)(3002001)(6055026)(61426038)(61427038)(6041248)(20161123558025)(20161123560025)(20161123562025)(20161123564025)(20161123555025)(6072148); SRVR:CY4PR21MB0504; BCL:0; PCL:0; RULEID:; SRVR:CY4PR21MB0504;
x-forefront-prvs: 02462830BE
x-forefront-antispam-report: SFV:NSPM; SFS:(10019020)(39410400002)(39860400002)(39850400002)(39840400002)(39450400003)(209900001)(69234005)(377454003)(22974007)(377424004)(8676002)(122556002)(81166006)(99286003)(6306002)(2950100002)(7696004)(6436002)(55016002)(25786008)(606005)(3660700001)(5660300001)(3280700002)(2906002)(9686003)(14971765001)(53546007)(236005)(54896002)(7906003)(74316002)(8936002)(7736002)(2900100001)(33656002)(86362001)(86612001)(8990500004)(106116001)(189998001)(10090500001)(50986999)(230783001)(5005710100001)(10290500002)(53936002)(77096006)(966004)(229853002)(53376002)(6246003)(38730400002)(53386004)(102836003)(76176999)(54356999)(790700001)(6506006)(6116002)(6606295002); DIR:OUT; SFP:1102; SCL:1; SRVR:CY4PR21MB0504; H:CY4PR21MB0504.namprd21.prod.outlook.com; FPR:; SPF:None; MLV:sfv; LANG:en;
spamdiagnosticoutput: 1:99
spamdiagnosticmetadata: NSPM
Content-Type: multipart/alternative; boundary="_000_CY4PR21MB05049486BD14F62A70E64653F5240CY4PR21MB0504namp_"
MIME-Version: 1.0
X-OriginatorOrg: microsoft.com
X-MS-Exchange-CrossTenant-originalarrivaltime: 14 Mar 2017 00:43:34.0010 (UTC)
X-MS-Exchange-CrossTenant-fromentityheader: Hosted
X-MS-Exchange-CrossTenant-id: 72f988bf-86f1-41af-91ab-2d7cd011db47
X-MS-Exchange-Transport-CrossTenantHeadersStamped: CY4PR21MB0504
Archived-At: <https://mailarchive.ietf.org/arch/msg/oauth/9uvHWbjUAJXLI2uwM1vMLjR3i4k>
Subject: Re: [OAUTH-WG] Fwd: I-D Action: draft-ietf-oauth-token-binding-02.txt
X-BeenThere: oauth@ietf.org
X-Mailman-Version: 2.1.17
Precedence: list
List-Id: OAUTH WG <oauth.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/oauth>, <mailto:oauth-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/oauth/>
List-Post: <mailto:oauth@ietf.org>
List-Help: <mailto:oauth-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/oauth>, <mailto:oauth-request@ietf.org?subject=subscribe>
X-List-Received-Date: Tue, 14 Mar 2017 00:43:38 -0000
FYI, I blogged about this at http://self-issued.info/?p=1660 and as @selfissued<https://twitter.com/selfissued>. -- Mike From: OAuth [mailto:oauth-bounces@ietf.org] On Behalf Of Brian Campbell Sent: Monday, March 13, 2017 2:32 PM To: oauth <oauth@ietf.org>; IETF Tokbind WG <unbearable@ietf.org> Subject: [OAUTH-WG] Fwd: I-D Action: draft-ietf-oauth-token-binding-02.txt I'm pleased to announce that (with the diligent help of my distinguished co-authors) draft -02 of "OAuth 2.0 Token Binding"<https://tools.ietf.org/html/draft-ietf-oauth-token-binding-02> has been published. The changes from the prior draft are listed below with support for Token Binding of authorization codes and lots of new examples being the largest changes. o Added a section on Token Binding for authorization codes with one variation for native clients and one for web server clients. o Updated language to reflect that the binding is to the token binding key pair and that proof-of-possession of that key is done on the TLS connection. o Added a bunch of examples. o Added a few Open Issues so they are tracked in the document. o Updated the Token Binding and OAuth Metadata references. o Added William Denniss as an author. ---------- Forwarded message ---------- From: <internet-drafts@ietf.org<mailto:internet-drafts@ietf.org>> Date: Mon, Mar 13, 2017 at 3:14 PM Subject: [OAUTH-WG] I-D Action: draft-ietf-oauth-token-binding-02.txt To: i-d-announce@ietf.org<mailto:i-d-announce@ietf.org> Cc: oauth@ietf.org<mailto:oauth@ietf.org> A New Internet-Draft is available from the on-line Internet-Drafts directories. This draft is a work item of the Web Authorization Protocol of the IETF. Title : OAuth 2.0 Token Binding Authors : Michael B. Jones John Bradley Brian Campbell William Denniss Filename : draft-ietf-oauth-token-binding-02.txt Pages : 26 Date : 2017-03-13 Abstract: This specification enables OAuth 2.0 implementations to apply Token Binding to Access Tokens, Authorization Codes, and Refresh Tokens. This cryptographically binds these tokens to a client's Token Binding key pair, possession of which is proven on the TLS connections over which the tokens are intended to be used. This use of Token Binding protects these tokens from man-in-the-middle and token export and replay attacks. The IETF datatracker status page for this draft is: https://datatracker.ietf.org/doc/draft-ietf-oauth-token-binding/ There's also a htmlized version available at: https://tools.ietf.org/html/draft-ietf-oauth-token-binding-02 A diff from the previous version is available at: https://www.ietf.org/rfcdiff?url2=draft-ietf-oauth-token-binding-02 Please note that it may take a couple of minutes from the time of submission until the htmlized version and diff are available at tools.ietf.org<http://tools.ietf.org>. Internet-Drafts are also available by anonymous FTP at: ftp://ftp.ietf.org/internet-drafts/ _______________________________________________ OAuth mailing list OAuth@ietf.org<mailto:OAuth@ietf.org> https://www.ietf.org/mailman/listinfo/oauth
- [OAUTH-WG] I-D Action: draft-ietf-oauth-token-bin… internet-drafts
- [OAUTH-WG] Fwd: I-D Action: draft-ietf-oauth-toke… Brian Campbell
- Re: [OAUTH-WG] Fwd: I-D Action: draft-ietf-oauth-… Mike Jones