Return-Path: <amit.gupta@insideview.com>
X-Original-To: oauth@ietfa.amsl.com
Delivered-To: oauth@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1])
 by ietfa.amsl.com (Postfix) with ESMTP id E725B1A0194
 for <oauth@ietfa.amsl.com>; Fri, 16 Jan 2015 00:39:13 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: 0.1
X-Spam-Level: 
X-Spam-Status: No, score=0.1 tagged_above=-999 required=5 tests=[BAYES_50=0.8, 
 HTML_MESSAGE=0.001, RCVD_IN_DNSWL_LOW=-0.7, SPF_PASS=-0.001]
 autolearn=ham
Received: from mail.ietf.org ([4.31.198.44])
 by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024)
 with ESMTP id 7XzHUR8_F1Qn for <oauth@ietfa.amsl.com>;
 Fri, 16 Jan 2015 00:39:10 -0800 (PST)
Received: from server506.appriver.com (server506i.appriver.com [50.56.144.147])
 (using TLSv1 with cipher DES-CBC3-SHA (112/168 bits))
 (No client certificate requested)
 by ietfa.amsl.com (Postfix) with ESMTPS id 846501A6F2D
 for <oauth@ietf.org>; Fri, 16 Jan 2015 00:39:10 -0800 (PST)
X-Note-AR-ScanTimeLocal: 1/16/2015 2:39:08 AM
X-Policy: insideview.com - insideview.com
X-Policy: insideview.com - insideview.com
X-Policy: insideview.com - insideview.com
X-Policy: insideview.com - insideview.com
X-Primary: amit.gupta@insideview.com
X-Note: This Email was scanned by AppRiver SecureTide
X-Note: SecureTide Build: 11/21/2014 10:58:18 PM UTC
X-Virus-Scan: V-
X-Note-SnifferID: 0
X-Note: TCH-CT/SI:0-85/SG:5 1/16/2015 2:38:56 AM
X-GBUdb-Analysis: 1, 169.254.1.45, Ugly c=1 p=-0.9966 Source White
X-Signature-Violations: 0-0-0-22755-c
X-Note: Spam Tests Failed: 
X-Country-Path: UNKNOWN->PRIVATE->United States
X-Note-Sending-IP: 10.242.229.139
X-Note-Reverse-DNS: smtp.exg6.exghost.com
X-Note-Return-Path: amit.gupta@insideview.com
X-Note: User Rule Hits: 
X-Note: Global Rule Hits: G251 G252 G253 G254 G258 G259 G371 
X-Note: Encrypt Rule Hits: 
X-Note: Mail Class: VALID
X-Note: Headers Injected
Received: from [10.242.229.139] (HELO smtp.exg6.exghost.com)
 by server506.appriver.com (CommuniGate Pro SMTP 6.0.2)
 with ESMTPS id 139610586; Fri, 16 Jan 2015 02:39:08 -0600
Received: from DAGN10A-E6.exg6.exghost.com ([169.254.1.45]) by
 HT03-E6.exg6.exghost.com ([50.56.144.21]) with mapi id 14.03.0210.002; Fri,
 16 Jan 2015 02:39:08 -0600
From: Amit Gupta <amit.gupta@insideview.com>
To: "torsten@lodderstedt.net" <torsten@lodderstedt.net>,
 "mscurtescu@google.com" <mscurtescu@google.com>, "sdronia@gmx.de"
 <sdronia@gmx.de>
Thread-Topic: RFC 7009 OAuth 2.0 Token Revocation //proposed change wrt to
 "default" revocation of refresh tokens
Thread-Index: AdAxZRlLaRyw+19oS/CIjljjczH2vw==
Date: Fri, 16 Jan 2015 08:39:07 +0000
Message-ID: <EC5D50A28C853445B767C0962CAD45720F7F1E3C@DAGN10a-e6.exg6.exghost.com>
Accept-Language: en-US
Content-Language: en-US
X-MS-Has-Attach: 
X-MS-TNEF-Correlator: 
x-originating-ip: [209.61.191.156]
x-rerouted-by-exchange: 
Content-Type: multipart/alternative;
 boundary="_000_EC5D50A28C853445B767C0962CAD45720F7F1E3CDAGN10ae6exg6ex_"
MIME-Version: 1.0
Archived-At: <http://mailarchive.ietf.org/arch/msg/oauth/E60iF12UhSvaX6y3Zqa5mOaKyY8>
X-Mailman-Approved-At: Fri, 16 Jan 2015 05:31:18 -0800
Cc: "oauth@ietf.org" <oauth@ietf.org>
Subject: [OAUTH-WG] RFC 7009 OAuth 2.0 Token Revocation //proposed change
 wrt to "default" revocation of refresh tokens
X-BeenThere: oauth@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: OAUTH WG <oauth.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/oauth>,
 <mailto:oauth-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/oauth/>
List-Post: <mailto:oauth@ietf.org>
List-Help: <mailto:oauth-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/oauth>,
 <mailto:oauth-request@ietf.org?subject=subscribe>
X-List-Received-Date: Fri, 16 Jan 2015 08:40:59 -0000

--_000_EC5D50A28C853445B767C0962CAD45720F7F1E3CDAGN10ae6exg6ex_
Content-Type: text/plain; charset="us-ascii"
Content-Transfer-Encoding: quoted-printable

Hi Torsten, Stefanie, Marius



I wanted to suggest an addition to the token revocation rfc7009 to provide =
more clarity on how revocation of refresh tokens should be handled. I feel =
the rfc should,

1. Describe how the client/resource-owner can provide "standing instruction=
s" to the OAuth server to revoke refresh tokens.

2. Describe the default way to for the OAuth server to define constrains fo=
r revocation of refresh token if this constrains are not specified by the c=
lient/resource owner.



The way it could be handled is:

1. Store a Client level threshold (clt) of number of valid refresh tokens p=
er "user-client" combination (and OAuth server can store the default value =
for clt, if undefined by the client or resource owner).

2. Keep the "time to live" for the access token reasonably small (few minut=
es to couple of hours).

a. Revocation of active token removes the token ad the refresh token.

b. When new tokens are generated, up to "clt" number of Refresh tokens is m=
aintained by the OAuth server (the most recent refresh token over writes th=
e cltth  refresh token for user-client combination).

c. Revocation of inactive token removes the refresh token.



We have implemented such a scheme for our OAuth server, whereby "clt" is se=
t to five by default (if not specified in client the properties). Therefore=
,

1. Whenever a new token and refresh token is created, it overwrites the 5th=
 (clt=3D5) oldest refresh token (for clientId-userId combination).

2. Code grant tokens are only valid for 1 hour. When the token expires, ref=
resh token is not removed.

3. When an "active" token is revoked, Token and it's refresh token is also =
revoked.

4. When an "expired" token is revoked, only the corresponding refresh token=
 is revoked.



The above example explicitly specify how to handle revocation of refresh to=
kens when the client has not informed the OAuth server about how expiry of =
refresh tokens should be handled. This also allows clients to specify certa=
in constrains (like default time to live for tokens, and client level thres=
hold for number of refresh tokens to keep active for each client-user combi=
nation).



Are you planning to update the RFC on the scheme to handle revocation of re=
fresh token? If not, would you be willing to include the proposed changes t=
o RFC7009? Please let me know.

--

Thanks,

Amit


--_000_EC5D50A28C853445B767C0962CAD45720F7F1E3CDAGN10ae6exg6ex_
Content-Type: text/html; charset="us-ascii"
Content-Transfer-Encoding: quoted-printable

<html xmlns:v=3D"urn:schemas-microsoft-com:vml" xmlns:o=3D"urn:schemas-micr=
osoft-com:office:office" xmlns:w=3D"urn:schemas-microsoft-com:office:word" =
xmlns:m=3D"http://schemas.microsoft.com/office/2004/12/omml" xmlns=3D"http:=
//www.w3.org/TR/REC-html40">
<head>
<meta http-equiv=3D"Content-Type" content=3D"text/html; charset=3Dus-ascii"=
>
<meta name=3D"Generator" content=3D"Microsoft Word 15 (filtered medium)">
<style><!--
/* Font Definitions */
@font-face
	{font-family:"Cambria Math";
	panose-1:2 4 5 3 5 4 6 3 2 4;}
@font-face
	{font-family:Calibri;
	panose-1:2 15 5 2 2 2 4 3 2 4;}
/* Style Definitions */
p.MsoNormal, li.MsoNormal, div.MsoNormal
	{margin:0in;
	margin-bottom:.0001pt;
	font-size:11.0pt;
	font-family:"Calibri",sans-serif;}
a:link, span.MsoHyperlink
	{mso-style-priority:99;
	color:#0563C1;
	text-decoration:underline;}
a:visited, span.MsoHyperlinkFollowed
	{mso-style-priority:99;
	color:#954F72;
	text-decoration:underline;}
pre
	{mso-style-priority:99;
	mso-style-link:"HTML Preformatted Char";
	margin:0in;
	margin-bottom:.0001pt;
	font-size:10.0pt;
	font-family:"Courier New";}
span.EmailStyle17
	{mso-style-type:personal-compose;
	font-family:"Calibri",sans-serif;
	color:windowtext;}
span.HTMLPreformattedChar
	{mso-style-name:"HTML Preformatted Char";
	mso-style-priority:99;
	mso-style-link:"HTML Preformatted";
	font-family:"Courier New";}
.MsoChpDefault
	{mso-style-type:export-only;}
@page WordSection1
	{size:8.5in 11.0in;
	margin:1.0in 1.0in 1.0in 1.0in;}
div.WordSection1
	{page:WordSection1;}
/* List Definitions */
@list l0
	{mso-list-id:424615152;
	mso-list-type:hybrid;
	mso-list-template-ids:571390316 67698703 67698713 67698715 67698703 676987=
13 67698715 67698703 67698713 67698715;}
@list l0:level1
	{mso-level-tab-stop:none;
	mso-level-number-position:left;
	text-indent:-.25in;}
@list l0:level2
	{mso-level-number-format:alpha-lower;
	mso-level-tab-stop:none;
	mso-level-number-position:left;
	text-indent:-.25in;}
@list l0:level3
	{mso-level-number-format:roman-lower;
	mso-level-tab-stop:none;
	mso-level-number-position:right;
	text-indent:-9.0pt;}
@list l0:level4
	{mso-level-tab-stop:none;
	mso-level-number-position:left;
	text-indent:-.25in;}
@list l0:level5
	{mso-level-number-format:alpha-lower;
	mso-level-tab-stop:none;
	mso-level-number-position:left;
	text-indent:-.25in;}
@list l0:level6
	{mso-level-number-format:roman-lower;
	mso-level-tab-stop:none;
	mso-level-number-position:right;
	text-indent:-9.0pt;}
@list l0:level7
	{mso-level-tab-stop:none;
	mso-level-number-position:left;
	text-indent:-.25in;}
@list l0:level8
	{mso-level-number-format:alpha-lower;
	mso-level-tab-stop:none;
	mso-level-number-position:left;
	text-indent:-.25in;}
@list l0:level9
	{mso-level-number-format:roman-lower;
	mso-level-tab-stop:none;
	mso-level-number-position:right;
	text-indent:-9.0pt;}
@list l1
	{mso-list-id:666399037;
	mso-list-type:hybrid;
	mso-list-template-ids:359169978 67698703 67698713 67698715 67698703 676987=
13 67698715 67698703 67698713 67698715;}
@list l1:level1
	{mso-level-tab-stop:none;
	mso-level-number-position:left;
	text-indent:-.25in;}
@list l1:level2
	{mso-level-number-format:alpha-lower;
	mso-level-tab-stop:none;
	mso-level-number-position:left;
	text-indent:-.25in;}
@list l1:level3
	{mso-level-number-format:roman-lower;
	mso-level-tab-stop:none;
	mso-level-number-position:right;
	text-indent:-9.0pt;}
@list l1:level4
	{mso-level-tab-stop:none;
	mso-level-number-position:left;
	text-indent:-.25in;}
@list l1:level5
	{mso-level-number-format:alpha-lower;
	mso-level-tab-stop:none;
	mso-level-number-position:left;
	text-indent:-.25in;}
@list l1:level6
	{mso-level-number-format:roman-lower;
	mso-level-tab-stop:none;
	mso-level-number-position:right;
	text-indent:-9.0pt;}
@list l1:level7
	{mso-level-tab-stop:none;
	mso-level-number-position:left;
	text-indent:-.25in;}
@list l1:level8
	{mso-level-number-format:alpha-lower;
	mso-level-tab-stop:none;
	mso-level-number-position:left;
	text-indent:-.25in;}
@list l1:level9
	{mso-level-number-format:roman-lower;
	mso-level-tab-stop:none;
	mso-level-number-position:right;
	text-indent:-9.0pt;}
@list l2
	{mso-list-id:1450467994;
	mso-list-type:hybrid;
	mso-list-template-ids:25301300 67698703 67698713 67698715 67698703 6769871=
3 67698715 67698703 67698713 67698715;}
@list l2:level1
	{mso-level-tab-stop:none;
	mso-level-number-position:left;
	text-indent:-.25in;}
@list l2:level2
	{mso-level-number-format:alpha-lower;
	mso-level-tab-stop:none;
	mso-level-number-position:left;
	text-indent:-.25in;}
@list l2:level3
	{mso-level-number-format:roman-lower;
	mso-level-tab-stop:none;
	mso-level-number-position:right;
	text-indent:-9.0pt;}
@list l2:level4
	{mso-level-tab-stop:none;
	mso-level-number-position:left;
	text-indent:-.25in;}
@list l2:level5
	{mso-level-number-format:alpha-lower;
	mso-level-tab-stop:none;
	mso-level-number-position:left;
	text-indent:-.25in;}
@list l2:level6
	{mso-level-number-format:roman-lower;
	mso-level-tab-stop:none;
	mso-level-number-position:right;
	text-indent:-9.0pt;}
@list l2:level7
	{mso-level-tab-stop:none;
	mso-level-number-position:left;
	text-indent:-.25in;}
@list l2:level8
	{mso-level-number-format:alpha-lower;
	mso-level-tab-stop:none;
	mso-level-number-position:left;
	text-indent:-.25in;}
@list l2:level9
	{mso-level-number-format:roman-lower;
	mso-level-tab-stop:none;
	mso-level-number-position:right;
	text-indent:-9.0pt;}
ol
	{margin-bottom:0in;}
ul
	{margin-bottom:0in;}
--></style><!--[if gte mso 9]><xml>
<o:shapedefaults v:ext=3D"edit" spidmax=3D"1026" />
</xml><![endif]--><!--[if gte mso 9]><xml>
<o:shapelayout v:ext=3D"edit">
<o:idmap v:ext=3D"edit" data=3D"1" />
</o:shapelayout></xml><![endif]-->
</head>
<body lang=3D"EN-US" link=3D"#0563C1" vlink=3D"#954F72">
<div class=3D"WordSection1">
<pre style=3D"page-break-before:always"><span style=3D"font-size:12.0pt;col=
or:black">Hi Torsten, Stefanie, Marius <o:p></o:p></span></pre>
<pre style=3D"page-break-before:always"><span style=3D"font-size:12.0pt;col=
or:black"><o:p>&nbsp;</o:p></span></pre>
<pre style=3D"page-break-before:always"><span style=3D"font-size:12.0pt;col=
or:black">I wanted to suggest an addition to the token revocation rfc7009 t=
o provide more clarity on how revocation of refresh tokens should be handle=
d. I feel the rfc should,<o:p></o:p></span></pre>
<pre style=3D"margin-left:.5in;text-indent:-.25in;page-break-before:always;=
mso-list:l1 level1 lfo3"><![if !supportLists]><span style=3D"font-size:12.0=
pt;color:black"><span style=3D"mso-list:Ignore">1.<span style=3D"font:7.0pt=
 &quot;Times New Roman&quot;"> </span></span></span><![endif]><span style=
=3D"font-size:12.0pt;color:black">Describe how the client/resource-owner ca=
n provide &#8220;standing instructions&#8221; to the OAuth server to revoke=
 refresh tokens. <o:p></o:p></span></pre>
<pre style=3D"margin-left:.5in;text-indent:-.25in;page-break-before:always;=
mso-list:l1 level1 lfo3"><![if !supportLists]><span style=3D"font-size:12.0=
pt;color:black"><span style=3D"mso-list:Ignore">2.<span style=3D"font:7.0pt=
 &quot;Times New Roman&quot;"> </span></span></span><![endif]><span style=
=3D"font-size:12.0pt;color:black">Describe the default way to for the OAuth=
 server to define constrains for revocation of refresh token if this constr=
ains are not specified by the client/resource owner.<o:p></o:p></span></pre=
>
<pre style=3D"page-break-before:always"><span style=3D"font-size:12.0pt;col=
or:black"><o:p>&nbsp;</o:p></span></pre>
<pre style=3D"page-break-before:always"><span style=3D"font-size:12.0pt;col=
or:black">The way it could be handled is:<o:p></o:p></span></pre>
<pre style=3D"margin-left:.5in;text-indent:-.25in;page-break-before:always;=
mso-list:l0 level1 lfo1"><![if !supportLists]><span style=3D"font-size:12.0=
pt;color:black"><span style=3D"mso-list:Ignore">1.<span style=3D"font:7.0pt=
 &quot;Times New Roman&quot;"> </span></span></span><![endif]><span style=
=3D"font-size:12.0pt;color:black">Store a Client level threshold (<span sty=
le=3D"background:yellow;mso-highlight:yellow">clt</span>) of number of vali=
d refresh tokens per &#8220;user-client&#8221; combination (and OAuth serve=
r can store the default value for clt, if undefined by the client or resour=
ce owner). <o:p></o:p></span></pre>
<pre style=3D"margin-left:.5in;text-indent:-.25in;page-break-before:always;=
mso-list:l0 level1 lfo1"><![if !supportLists]><span style=3D"font-size:12.0=
pt;color:black"><span style=3D"mso-list:Ignore">2.<span style=3D"font:7.0pt=
 &quot;Times New Roman&quot;"> </span></span></span><![endif]><span style=
=3D"font-size:12.0pt;color:black">Keep the &#8220;time to live&#8221; for t=
he access token reasonably small (few minutes to couple of hours). <o:p></o=
:p></span></pre>
<pre style=3D"margin-left:1.0in;text-indent:-.25in;page-break-before:always=
;mso-list:l0 level2 lfo1"><![if !supportLists]><span style=3D"font-size:12.=
0pt;color:black"><span style=3D"mso-list:Ignore">a.<span style=3D"font:7.0p=
t &quot;Times New Roman&quot;"> </span></span></span><![endif]><span style=
=3D"font-size:12.0pt;color:black">Revocation of active token removes the to=
ken ad the refresh token.<o:p></o:p></span></pre>
<pre style=3D"margin-left:1.0in;text-indent:-.25in;page-break-before:always=
;mso-list:l0 level2 lfo1"><![if !supportLists]><span style=3D"font-size:12.=
0pt;color:black"><span style=3D"mso-list:Ignore">b.<span style=3D"font:7.0p=
t &quot;Times New Roman&quot;"> </span></span></span><![endif]><span style=
=3D"font-size:12.0pt;color:black">When new tokens are generated, up to &#82=
20;clt&#8221; number of Refresh tokens is maintained by the OAuth server (t=
he most recent refresh token over writes the clt<sup>th</sup> &nbsp;refresh=
 token for user-client combination).<o:p></o:p></span></pre>
<pre style=3D"margin-left:1.0in;text-indent:-.25in;page-break-before:always=
;mso-list:l0 level2 lfo1"><![if !supportLists]><span style=3D"font-size:12.=
0pt;color:black"><span style=3D"mso-list:Ignore">c.<span style=3D"font:7.0p=
t &quot;Times New Roman&quot;"> </span></span></span><![endif]><span style=
=3D"font-size:12.0pt;color:black">Revocation of inactive token removes the =
refresh token.<o:p></o:p></span></pre>
<pre style=3D"margin-left:.5in;page-break-before:always"><span style=3D"fon=
t-size:12.0pt;color:black"><o:p>&nbsp;</o:p></span></pre>
<pre style=3D"page-break-before:always"><span style=3D"font-size:12.0pt;col=
or:black">We have implemented such a scheme for our OAuth server, whereby &=
#8220;clt&#8221; is set to five by default (if not specified in client the =
properties). Therefore, <o:p></o:p></span></pre>
<pre style=3D"margin-left:.5in;text-indent:-.25in;page-break-before:always;=
mso-list:l2 level1 lfo2"><![if !supportLists]><span style=3D"font-size:12.0=
pt;color:black"><span style=3D"mso-list:Ignore">1.<span style=3D"font:7.0pt=
 &quot;Times New Roman&quot;"> </span></span></span><![endif]><span style=
=3D"font-size:12.0pt;color:black">Whenever a new token and refresh token is=
 created, it overwrites the 5<sup>th</sup> (clt=3D5) oldest refresh token (=
for clientId-userId combination). <o:p></o:p></span></pre>
<pre style=3D"margin-left:.5in;text-indent:-.25in;page-break-before:always;=
mso-list:l2 level1 lfo2"><![if !supportLists]><span style=3D"font-size:12.0=
pt;color:black"><span style=3D"mso-list:Ignore">2.<span style=3D"font:7.0pt=
 &quot;Times New Roman&quot;"> </span></span></span><![endif]><span style=
=3D"font-size:12.0pt;color:black">Code grant tokens are only valid for 1 ho=
ur. When the token expires, refresh token is not removed.<o:p></o:p></span>=
</pre>
<pre style=3D"margin-left:.5in;text-indent:-.25in;page-break-before:always;=
mso-list:l2 level1 lfo2"><![if !supportLists]><span style=3D"font-size:12.0=
pt;color:black"><span style=3D"mso-list:Ignore">3.<span style=3D"font:7.0pt=
 &quot;Times New Roman&quot;"> </span></span></span><![endif]><span style=
=3D"font-size:12.0pt;color:black">When an &#8220;active&#8221; token is rev=
oked, Token and it&#8217;s refresh token is also revoked. <o:p></o:p></span=
></pre>
<pre style=3D"margin-left:.5in;text-indent:-.25in;page-break-before:always;=
mso-list:l2 level1 lfo2"><![if !supportLists]><span style=3D"font-size:12.0=
pt;color:black"><span style=3D"mso-list:Ignore">4.<span style=3D"font:7.0pt=
 &quot;Times New Roman&quot;"> </span></span></span><![endif]><span style=
=3D"font-size:12.0pt;color:black">When an &#8220;expired&#8221; token is re=
voked, only the corresponding refresh token is revoked. <o:p></o:p></span><=
/pre>
<pre style=3D"page-break-before:always"><span style=3D"font-size:12.0pt;col=
or:black"><o:p>&nbsp;</o:p></span></pre>
<pre style=3D"page-break-before:always"><span style=3D"font-size:12.0pt;col=
or:black">The above example explicitly specify how to handle revocation of =
refresh tokens when the client has not informed the OAuth server about how =
expiry of refresh tokens should be handled. This also allows clients to spe=
cify certain constrains (like default time to live for tokens, and client l=
evel threshold for number of refresh tokens to keep active for each client-=
user combination). <o:p></o:p></span></pre>
<pre style=3D"page-break-before:always"><span style=3D"font-size:12.0pt;col=
or:black"><o:p>&nbsp;</o:p></span></pre>
<pre style=3D"page-break-before:always"><span style=3D"font-size:12.0pt;col=
or:black">Are you planning to update the RFC on the scheme to handle revoca=
tion of refresh token? If not, would you be willing to include the proposed=
 changes to RFC7009? Please let me know.<o:p></o:p></span></pre>
<pre style=3D"page-break-before:always"><span style=3D"font-size:12.0pt;col=
or:black">--<o:p></o:p></span></pre>
<pre style=3D"page-break-before:always"><span style=3D"font-size:12.0pt;col=
or:black">Thanks,<o:p></o:p></span></pre>
<pre style=3D"page-break-before:always"><span style=3D"font-size:12.0pt;col=
or:black">Amit<o:p></o:p></span></pre>
<p class=3D"MsoNormal"><o:p>&nbsp;</o:p></p>
</div>
</body>
</html>

--_000_EC5D50A28C853445B767C0962CAD45720F7F1E3CDAGN10ae6exg6ex_--

