Re: [OAUTH-WG] Fwd: New Version Notification for draft-lodderstedt-oauth-jwt-introspection-response-00.txt

LARMIGNAT Louis <Louis.LARMIGNAT@wavestone.com> Mon, 19 March 2018 08:26 UTC

Return-Path: <Louis.LARMIGNAT@wavestone.com>
X-Original-To: oauth@ietfa.amsl.com
Delivered-To: oauth@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 07B4C124319 for <oauth@ietfa.amsl.com>; Mon, 19 Mar 2018 01:26:03 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.919
X-Spam-Level:
X-Spam-Status: No, score=-1.919 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, HTML_MESSAGE=0.001, RCVD_IN_DNSWL_NONE=-0.0001, RCVD_IN_MSPIKE_H3=-0.01, RCVD_IN_MSPIKE_WL=-0.01, SPF_PASS=-0.001, URIBL_BLOCKED=0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (1024-bit key) header.d=solucomonline.onmicrosoft.com
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id vbhb5mKRlA9H for <oauth@ietfa.amsl.com>; Mon, 19 Mar 2018 01:26:00 -0700 (PDT)
Received: from EUR02-HE1-obe.outbound.protection.outlook.com (mail-eopbgr10057.outbound.protection.outlook.com [40.107.1.57]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id F1130120721 for <oauth@ietf.org>; Mon, 19 Mar 2018 01:25:59 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=solucomonline.onmicrosoft.com; s=selector1-solucomonline-onmicrosoft-com; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version; bh=e0Cm8WgAg7vt/khxmVsaigPYDeUCBKonYZundNfZl0o=; b=Dcg1Ol0+IXo1pRIR/PkqjsihaQsSNQ1ZfsgAjdHdLWwcbrI62hCF47EAcDrA17MuHQIPXsT0Dj2rbH+AmUHfvirFpI58aiJ5CWt3F+qBuJpicTYUWovk5GXRjXTrvUU7pLbFgYfaOSvSeiKJV3GQ4Z7pD4zCopISAt4puYbMSVA=
Received: from DB5PR03MB1191.eurprd03.prod.outlook.com (10.162.220.17) by DB5PR03MB1685.eurprd03.prod.outlook.com (10.165.5.11) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_CBC_SHA384_P256) id 15.20.588.14; Mon, 19 Mar 2018 08:25:55 +0000
Received: from DB5PR03MB1191.eurprd03.prod.outlook.com ([fe80::51ef:cae3:1728:bd41]) by DB5PR03MB1191.eurprd03.prod.outlook.com ([fe80::51ef:cae3:1728:bd41%13]) with mapi id 15.20.0588.016; Mon, 19 Mar 2018 08:25:55 +0000
From: LARMIGNAT Louis <Louis.LARMIGNAT@wavestone.com>
To: Brock Allen <brockallen@gmail.com>, Torsten Lodderstedt <torsten@lodderstedt.net>, "oauth@ietf.org" <oauth@ietf.org>
Thread-Topic: [OAUTH-WG] Fwd: New Version Notification for draft-lodderstedt-oauth-jwt-introspection-response-00.txt
Thread-Index: AQHTvu/78FHbTSFVrU6aBnDH4DxpKKPWY/aAgADS8gA=
Date: Mon, 19 Mar 2018 08:25:55 +0000
Message-ID: <DB5PR03MB1191DFA3BACC2806E2C07899F6D40@DB5PR03MB1191.eurprd03.prod.outlook.com>
References: <152140077785.15835.11388192447917251931.idtracker@ietfa.amsl.com> <2A1E98B8-973E-44F0-96F0-E319FD6969A8@lodderstedt.net> <308c1c61-a2ba-4e45-9fe6-9d525e554fb7@getmailbird.com>
In-Reply-To: <308c1c61-a2ba-4e45-9fe6-9d525e554fb7@getmailbird.com>
Accept-Language: fr-FR, en-US
Content-Language: fr-FR
X-MS-Has-Attach:
X-MS-TNEF-Correlator:
authentication-results: spf=none (sender IP is ) smtp.mailfrom=Louis.LARMIGNAT@wavestone.com;
x-originating-ip: [212.99.112.100]
x-ms-publictraffictype: Email
x-microsoft-exchange-diagnostics: 1; DB5PR03MB1685; 7:N1mm9/s2q+/brcpDp/g38Wld+TyA0HYcfteVgBhLJegggpv3L4PfKrP8L64pWvmgepi0DBMEUXnWLwaegBE9YdAv4xcZJS9Wcb2gGEXtDPClCOmZZp+UQHmT1zGBVaqVyCndDJF8K5Q+VA4aqOPpgVvnql6IimZeu2LIXOM0tOuEiiziToaMd2muOahlYIISDdHcJ5nk2i57V6W78XmfuA0R5V1/XXombdX2WZk5HHvhNHHW2qKP9dWN0ZJeaZyU
x-ms-exchange-antispam-srfa-diagnostics: SSOS;
x-ms-office365-filtering-ht: Tenant
x-ms-office365-filtering-correlation-id: cfd3eef7-d6ad-4802-2b53-08d58d730915
x-microsoft-antispam: UriScan:; BCL:0; PCL:0; RULEID:(7020095)(4652020)(48565401081)(5600026)(4604075)(3008032)(4534165)(4627221)(201703031133081)(201702281549075)(2017052603328)(7153060)(7193020); SRVR:DB5PR03MB1685;
x-ms-traffictypediagnostic: DB5PR03MB1685:
x-microsoft-antispam-prvs: <DB5PR03MB168501F7761679459F8788F7F6D40@DB5PR03MB1685.eurprd03.prod.outlook.com>
x-exchange-antispam-report-test: UriScan:(28532068793085)(120809045254105)(21748063052155);
x-exchange-antispam-report-cfa-test: BCL:0; PCL:0; RULEID:(8211001083)(6040522)(2401047)(8121501046)(5005006)(3231221)(944501244)(52105095)(3002001)(93006095)(93001095)(10201501046)(6055026)(6041310)(20161123564045)(201703131423095)(201702281528075)(20161123555045)(201703061421075)(201703061406153)(20161123560045)(20161123562045)(20161123558120)(6072148)(201708071742011); SRVR:DB5PR03MB1685; BCL:0; PCL:0; RULEID:; SRVR:DB5PR03MB1685;
x-forefront-prvs: 06167FAD59
x-forefront-antispam-report: SFV:NSPM; SFS:(10009020)(346002)(39380400002)(39850400004)(396003)(376002)(366004)(53754006)(189003)(199004)(377424004)(26244003)(3280700002)(478600001)(8676002)(68736007)(8936002)(81156014)(81166006)(10710500007)(1680700002)(2900100001)(966005)(14454004)(5660300001)(74316002)(3660700001)(33656002)(72206003)(66066001)(39060400002)(7736002)(106356001)(25786009)(14971765001)(3846002)(7696005)(316002)(2501003)(2950100002)(53546011)(6506007)(76176011)(2420400007)(102836004)(59450400001)(6116002)(6246003)(606006)(53936002)(2906002)(15650500001)(55016002)(229853002)(105586002)(97736004)(790700001)(26005)(99286004)(5890100001)(5250100002)(186003)(110136005)(9686003)(54896002)(236005)(6306002)(86362001)(6436002)(7110500001)(53386004); DIR:OUT; SFP:1101; SCL:1; SRVR:DB5PR03MB1685; H:DB5PR03MB1191.eurprd03.prod.outlook.com; FPR:; SPF:None; PTR:InfoNoRecords; MX:1; A:1; LANG:en;
received-spf: None (protection.outlook.com: wavestone.com does not designate permitted sender hosts)
x-microsoft-antispam-message-info: ONY5Vv5L7SBmDVSqgmeClfk+KRvL+rH83M0dTz60lFm/UMUK7cc8UOkKnHaat6nmZchR2UTDN47kGbTrMTYJs/Y9wHBfkBAaquJj07cC8B9VqpsVE9PEHOaCYSMb5JqNgWkJ6cvPtE7o/OxqE3jFjeOixwZVAUqNw7bWICK30SSPUWbLm9phtg5oCcpuIh51YexJPuD3YH30ik6Iz8OMLhUgqiolNR54BZKnH9ItL9EbDqG4gROUGpdCb/KqkIfiDAKUkLapHzFJESNGVEgcl9Nxor8ZW092E50Av1n2crrFuKDiNM2kUIdXdBbDzPT0aE6fkByqLN+EPy6duHFsOQ==
spamdiagnosticoutput: 1:99
spamdiagnosticmetadata: NSPM
Content-Type: multipart/alternative; boundary="_000_DB5PR03MB1191DFA3BACC2806E2C07899F6D40DB5PR03MB1191eurp_"
MIME-Version: 1.0
X-OriginatorOrg: wavestone.com
X-MS-Exchange-CrossTenant-Network-Message-Id: cfd3eef7-d6ad-4802-2b53-08d58d730915
X-MS-Exchange-CrossTenant-originalarrivaltime: 19 Mar 2018 08:25:55.4524 (UTC)
X-MS-Exchange-CrossTenant-fromentityheader: Hosted
X-MS-Exchange-CrossTenant-id: 5de96c96-c87c-4dce-aad9-f5c557b52ac1
X-MS-Exchange-Transport-CrossTenantHeadersStamped: DB5PR03MB1685
Archived-At: <https://mailarchive.ietf.org/arch/msg/oauth/F4rY8jzX-kVxqfPuffxhAfn84EE>
Subject: Re: [OAUTH-WG] Fwd: New Version Notification for draft-lodderstedt-oauth-jwt-introspection-response-00.txt
X-BeenThere: oauth@ietf.org
X-Mailman-Version: 2.1.22
Precedence: list
List-Id: OAUTH WG <oauth.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/oauth>, <mailto:oauth-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/oauth/>
List-Post: <mailto:oauth@ietf.org>
List-Help: <mailto:oauth-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/oauth>, <mailto:oauth-request@ietf.org?subject=subscribe>
X-List-Received-Date: Mon, 19 Mar 2018 08:26:03 -0000

Hi,

The draft Signing HTTP Messages (https://tools.ietf.org/html/draft-cavage-http-signatures-09) could not meet this requirement in a more generic way ?

Regards,
Louis

De : OAuth <oauth-bounces@ietf.org> De la part de Brock Allen
Envoyé : dimanche 18 mars 2018 20:40
À : Torsten Lodderstedt <torsten@lodderstedt.net>; oauth@ietf.org
Objet : Re: [OAUTH-WG] Fwd: New Version Notification for draft-lodderstedt-oauth-jwt-introspection-response-00.txt

Why is TLS to the intospection endpoint not sufficient? Are you thinking there needs to be some multi-tenancy support of some kind?

-Brock


On 3/18/2018 3:33:16 PM, Torsten Lodderstedt <torsten@lodderstedt.net<mailto:torsten@lodderstedt.net>> wrote:
Hi all,

I just submitted a new draft that Vladimir Dzhuvinov and I have written. It proposes a JWT-based response type for Token Introspection. The objective is to provide resource servers with signed tokens in case they need cryptographic evidence that the AS created the token (e.g. for liability).

I will present the new draft in the session on Wednesday.

kind regards,
Torsten.


Anfang der weitergeleiteten Nachricht:

Von: internet-drafts@ietf.org<mailto:internet-drafts@ietf.org>
Betreff: New Version Notification for draft-lodderstedt-oauth-jwt-introspection-response-00.txt
Datum: 18. März 2018 um 20:19:37 MEZ
An: "Vladimir Dzhuvinov" <vladimir@connect2id.com<mailto:vladimir@connect2id.com>>, "Torsten Lodderstedt" <torsten@lodderstedt.net<mailto:torsten@lodderstedt.net>>


A new version of I-D, draft-lodderstedt-oauth-jwt-introspection-response-00.txt
has been successfully submitted by Torsten Lodderstedt and posted to the
IETF repository.

Name:           draft-lodderstedt-oauth-jwt-introspection-response
Revision: 00
Title:          JWT Response for OAuth Token Introspection
Document date:  2018-03-15
Group:          Individual Submission
Pages:          5
URL:            https://www.ietf.org/internet-drafts/draft-lodderstedt-oauth-jwt-introspection-response-00.txt
Status:         https://datatracker.ietf.org/doc/draft-lodderstedt-oauth-jwt-introspection-response/
Htmlized:       https://tools.ietf.org/html/draft-lodderstedt-oauth-jwt-introspection-response-00
Htmlized:       https://datatracker.ietf.org/doc/html/draft-lodderstedt-oauth-jwt-introspection-response<https://datatracker..ietf.org/doc/html/draft-lodderstedt-oauth-jwt-introspection-response>


Abstract:
  This draft proposes an additional JSON Web Token (JWT) based response
  for OAuth 2.0 Token Introspection.




Please note that it may take a couple of minutes from the time of submission
until the htmlized version and diff are available at tools.ietf.org<http://tools.ietf.org>.

The IETF Secretariat

The information transmitted in the present email including the attachment is intended only for the person to whom or entity to which it is addressed and may contain confidential and/or privileged material. Any review, retransmission, dissemination or other use of, or taking of any action in reliance upon this information by persons or entities other than the intended recipient is prohibited. If you received this in error, please contact the sender and delete all copies of the material.

Ce message et toutes les pièces qui y sont éventuellement jointes sont confidentiels et transmis à l'intention exclusive de son destinataire. Toute modification, édition, utilisation ou diffusion par toute personne ou entité autre que le destinataire est interdite. Si vous avez reçu ce message par erreur, nous vous remercions de nous en informer immédiatement et de le supprimer ainsi que les pièces qui y sont éventuellement jointes.