[OAUTH-WG] Re: Mike Bishop's No Objection on draft-ietf-oauth-rfc8725bis-07: (with COMMENT)

Yaron Sheffer <yaronf.ietf@gmail.com> Tue, 11 August 2026 09:50 UTC

Return-Path: <yaronf.ietf@gmail.com>
X-Original-To: oauth@mail2.ietf.org
Delivered-To: oauth@mail2.ietf.org
Received: from localhost (localhost [127.0.0.1]) by mail2.ietf.org (Postfix) with ESMTP id A9E20127AE3EC for <oauth@mail2.ietf.org>; Tue, 11 Aug 2026 02:50:27 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=ietf.org; s=ietf1; t=1786441827; bh=w7EG7G8xNGiOPB4ckvmvqlqXTMdj8rUGf5pAiU4mJ9k=; h=From:To:Subject:Cc:Date:In-Reply-To:References:Reply-To; b=PdzbJ++bse5eeIv3le0W71iFjbMxqMH4UNq/uelVkBbvFNCRo9qjSimzypvQdxshk VYbSktKNOSWi0aNvjyfrHUnzPA1RymNDQfA5iWDC9z+kBF/5okV5DoKX+gGAwN/hzn H261wmIhhGGvMvKSKWkjFVohuYxgsQJd1m7N7XSw=
X-Virus-Scanned: amavisd-new at ietf.org
X-Spam-Flag: NO
X-Spam-Score: -2.099
X-Spam-Level:
X-Spam-Status: No, score=-2.099 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, FREEMAIL_FROM=0.001, RCVD_IN_DNSWL_NONE=-0.0001, SPF_HELO_NONE=0.001, SPF_PASS=-0.001] autolearn=unavailable autolearn_force=no
Authentication-Results: mail2.ietf.org (amavisd-new); dkim=pass (2048-bit key) header.d=gmail.com
Received: from mail2.ietf.org ([166.84.6.31]) by localhost (mail2.ietf.org [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id impQR_thk8CD for <oauth@mail2.ietf.org>; Tue, 11 Aug 2026 02:50:25 -0700 (PDT)
Received: from mail-wr1-x430.google.com (mail-wr1-x430.google.com [IPv6:2a00:1450:4864:20::430]) (using TLSv1.3 with cipher TLS_AES_128_GCM_SHA256 (128/128 bits) key-exchange X25519 server-signature ECDSA (P-256) server-digest SHA256) (No client certificate requested) by mail2.ietf.org (Postfix) with ESMTPS id D1A41127AE3E1 for <oauth@ietf.org>; Tue, 11 Aug 2026 02:50:25 -0700 (PDT)
Received: by mail-wr1-x430.google.com with SMTP id ffacd0b85a97d-47f703a9e5dso305305f8f.0 for <oauth@ietf.org>; Tue, 11 Aug 2026 02:50:25 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20251104; t=1786441825; x=1787046625; darn=ietf.org; h=content-transfer-encoding:content-type:mime-version:user-agent :reply-to:references:in-reply-to:message-id:date:cc:subject:to:from :from:to:cc:subject:date:message-id:reply-to:content-type; bh=LsZ8Oe3MVS8cNDSAHF3ChkQOsNgPvBfOz+N/LL/nz3Y=; b=RMo3zk37OpkolJZCgpB21H3TCGDsu2QvbK5O58xYhUZ8tebvbUKGflv9smprbkQNHH 2c9hFOfUI0xACoFLt3FOSSePXoMP0JE0P7R829cSb9shCF9mRpdS/1qRQAxNCAiCu35q R50tXB1OxTJhxPu+Q8zVe1HSU2TAnDlVdlM1vAQ1PkKrfSK6FiC9KX+YXJNGkP0JgQOt 00kD1heirnGD1OmUgdpPz2zR1J4LpgR1+D8CeUfECYWJFgfIWv0Eus39cjyNJSIEfjGs lDDrz95dNskCltj5JZsis1zapIXX0IoCsNzeIysmiSAZ4/fMKdJ9YrwHiDbNG42YJer9 +AKQ==
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1786441825; x=1787046625; h=content-transfer-encoding:content-type:mime-version:user-agent :reply-to:references:in-reply-to:message-id:date:cc:subject:to:from :x-gm-gg:x-gm-message-state:from:to:cc:subject:date:message-id :reply-to:content-type; bh=LsZ8Oe3MVS8cNDSAHF3ChkQOsNgPvBfOz+N/LL/nz3Y=; b=s4KlHUIyLLwFtnm8b5lCPNyndptTWpQAOLw9UMTMBQkVrrM9LT4K2Ud4miIqs+FUMF d8YwgShnj9EyDSgO74+3ma6GxEg8N7jhMROnf4SfpWm7u5dE5fb5p8MjZcwAE8mkE83l t9lpqoD/a8zbEmTU04To5R8kDdZoBaD6eH3ffAYlGceByrnc4tsWyyzg/g/f2PUL1N+E 2z013riJiyISgcLMvNUnhnESqxHg0iSGWO62Q9MskK4cupNSutFFJObRVh7ngkNLVxYA 4BwBMFlXlwiKNs9ucx9Ei/Jht+XGR1xZ/FON29E9twR/dNgpsezS1wvnwfF/ILgq1HrX pZAQ==
X-Forwarded-Encrypted: i=1; AHgh+RofMouQsyD2tFH0bNWaXqLqr/2gl4p02Gg4NU+xuVlDOcbE8laZQJE6+BBjxKWVgfymsRsIiw==@ietf.org
X-Gm-Message-State: AOJu0Yx14i42T6u2yYqwue5je3gMHPBGjbQ+jRsqUqAMZczd6Aog6oHo EZs+8Va9kkDTNvOsz4KOacRm/zza98/3K9XsQcYgFErKOcq+X+Lh0yMf
X-Gm-Gg: AR+sD12xb94pLcFndbw2zqdPZCU6OTF6HLZvM1YmdXJPF7RgRtJ8VlEMn9CrM/NbJQJ ivkVkiwow0nRRCqiSP6u5p1e7VbiUXkERaxGtAKtX8/oaggg9/NUI2Ow/7QXaXLpiIHKlKUSbef MmH6S8KjpS2JyF3jNylpw/4vT61CbAy2+Kl0MdzogwuXnc/yvIQ0CislfuxqmqE5SXaZK/iIRwx C6f8YPyuqzwsIxbGjNUbMdetMaIjAfojMRdX7yqlOmUfFnEHH/zNzvARYXfB6DbvDRGwb994dcE c129pkRPTlZBhnr+D5mLcbW4sGsGG7Z3eVpffWyE4BWdBXrygbaAEgvL+meKh3NxFLKit+mLG12 0mCHrIflFMcnt+MPhzuqG4dFTN5UQ97sROqq7kEoAi0MQifuFOTimz5wj+uvcRLqNdxYkg77rUp dqmjLN24Bk15tkcKvE/6VKkdOq9fMkuw70LkWDo1texvfy6bCvJqPeYsEV+JIRedFFPOMo7AANM jmZD0nnJZWAQiJ7SZtJb4aJFnRRyxap8CGkMDKyXuP+mDK8fGgAvFkz2M525Ea8wI115sjzEPzN XQ==
X-Received: by 2002:a05:6000:2210:b0:47f:9404:5185 with SMTP id ffacd0b85a97d-4814adcb36amr3293991f8f.24.1786441824606; Tue, 11 Aug 2026 02:50:24 -0700 (PDT)
Received: from ?IPv6:::ffff:192.168.68.103? (IGLD-84-229-147-168.inter.net.il. [84.229.147.168]) by smtp.gmail.com with ESMTPSA id ffacd0b85a97d-4814a5be1b7sm2997898f8f.14.2026.08.11.02.50.23 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Tue, 11 Aug 2026 02:50:24 -0700 (PDT)
From: Yaron Sheffer <yaronf.ietf@gmail.com>
To: Mike Bishop <mbishop@evequefou.be>, The IESG <iesg@ietf.org>
Date: Tue, 11 Aug 2026 09:50:22 +0000
Message-Id: <emd8a00778-6034-4398-9e43-e36aac92903b@gmail.com>
In-Reply-To: <178639628530.447588.9841270895770742511@dt-datatracker-559c48c7fb-9llwz>
References: <178639628530.447588.9841270895770742511@dt-datatracker-559c48c7fb-9llwz>
User-Agent: eMClient/10.4.0.0
MIME-Version: 1.0
Content-Type: text/plain; charset="utf-8"; format="flowed"
Content-Transfer-Encoding: quoted-printable
Message-ID-Hash: ZM57TEOORVS2ENMBB2XRBVEASNYUH4ZX
X-Message-ID-Hash: ZM57TEOORVS2ENMBB2XRBVEASNYUH4ZX
X-MailFrom: yaronf.ietf@gmail.com
X-Mailman-Rule-Misses: dmarc-mitigation; no-senders; approved; emergency; loop; banned-address; member-moderation; header-match-oauth.ietf.org-0; nonmember-moderation; administrivia; implicit-dest; max-recipients; max-size; news-moderation; no-subject; digests; suspicious-header
CC: Hannes.Tschofenig@gmx.net, draft-ietf-oauth-rfc8725bis@ietf.org, oauth-chairs@ietf.org, oauth@ietf.org
X-Mailman-Version: 3.3.9rc6
Precedence: list
Reply-To: Yaron Sheffer <yaronf.ietf@gmail.com>
Subject: [OAUTH-WG] Re: Mike Bishop's No Objection on draft-ietf-oauth-rfc8725bis-07: (with COMMENT)
List-Id: OAUTH WG <oauth.ietf.org>
Archived-At: <https://mailarchive.ietf.org/arch/msg/oauth/FLZmYxSt2t3UsXHBdQWH5Fpkbe8>
List-Archive: <https://mailarchive.ietf.org/arch/browse/oauth>
List-Help: <mailto:oauth-request@ietf.org?subject=help>
List-Owner: <mailto:oauth-owner@ietf.org>
List-Post: <mailto:oauth@ietf.org>
List-Subscribe: <mailto:oauth-join@ietf.org>
List-Unsubscribe: <mailto:oauth-leave@ietf.org>

Thank you Mike for your comments!

Opened issues 60, 61 and 62 at 
https://github.com/oauth-wg/draft-ietf-oauth-rfc8725bis/issues

Best,
     Yaron


------ Original Message ------
>From "Mike Bishop via Datatracker" <noreply@ietf.org>
To "The IESG" <iesg@ietf.org>
Cc Hannes.Tschofenig@gmx.net; draft-ietf-oauth-rfc8725bis@ietf.org; 
oauth-chairs@ietf.org; oauth@ietf.org
Date 11/08/2026 0:11:25
Subject Mike Bishop's No Objection on draft-ietf-oauth-rfc8725bis-07: 
(with COMMENT)

>Mike Bishop has entered the following ballot position for
>draft-ietf-oauth-rfc8725bis-07: No Objection
>
>When responding, please keep the subject line intact and reply to all
>email addresses included in the To and CC lines. (Feel free to cut this
>introductory paragraph, however.)
>
>
>Please refer to https://www.ietf.org/about/groups/iesg/statements/handling-ballot-positions/
>for more information about how to handle DISCUSS and COMMENT positions.
>
>
>The document, along with other ballot positions, can be found here:
>https://datatracker.ietf.org/doc/draft-ietf-oauth-rfc8725bis/
>
>
>
>----------------------------------------------------------------------
>COMMENT:
>----------------------------------------------------------------------
>
># IESG review of draft-ietf-oauth-rfc8725bis-07
>
>CC @MikeBishop
>
>## Comments
>
>### Section 3.15, paragraph 1
>```
>      Implementations are RECOMMENDED to set a reasonable upper limit on
>      the decompressed size of a JWE such as 250 KB, because without such a
>      limit, decompression can impose an unreasonable memory or CPU burden
>      on recipients.
>```
>Where is the 250 KB value coming from? When would someone select a different
>value? I read this as RECOMMENDing a limit and providing an example value, but
>then I'm not sure the example value adds anything besides a risk people will
>infer it as part of the recommendation. (A similar recommendation in 3.13 points
>to OWASP guidance for a particular combination with a note that it's merely a
>time-of-publishing value.)
>
>### "Appendix A.", paragraph 3
>```
>      2.  Encryption-Signature Confusion: Added mitigation for attacks
>          where verifiers don't distinguish between successful decryption
>          and successful signature validation (Section 3.12).
>```
>Is 3.12 the intended reference? This seems more related to 3.3's "MUST ...
>distinguish between signed JWTs (JWSes) and encrypted JWTs (JWEs)."
>
>## Nits
>
>All comments below are about very minor potential issues that you may choose to
>address in some way - or ignore - as you see fit. Some were flagged by
>automated tools (via https://github.com/larseggert/ietf-reviewtool) so there
>will likely be some false positives. There is no need to let me know what you
>did with these suggestions.
>
>### Inclusive language
>
>Found terminology that should be reviewed for inclusivity; see
>https://www.rfc-editor.org/part2/#inclusive_language for background and more
>guidance:
>
>  * Term `blindly`; alternatives might be `without consideration`, `negligently`,
>    `uncritically`, `unthinkingly`, `hastily`, etc.
>
>### Grammar/style
>
>#### Section 2.1, paragraph 3
>```
>simple signed JWT as their token. However verifiers don't always check that
>                                   ^^^^^^^
>```
>A comma may be missing after the conjunctive/linking adverb "However".
>
>
>