Re: [OAUTH-WG] New Version Notification for draft-hunt-oauth-pop-architecture-00.txt

Anthony Nadalin <> Mon, 07 April 2014 01:46 UTC

Return-Path: <>
Received: from localhost ( []) by (Postfix) with ESMTP id 752D01A063B for <>; Sun, 6 Apr 2014 18:46:07 -0700 (PDT)
X-Virus-Scanned: amavisd-new at
X-Spam-Flag: NO
X-Spam-Score: -1.901
X-Spam-Status: No, score=-1.901 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, HTML_MESSAGE=0.001, RCVD_IN_DNSWL_NONE=-0.0001, SPF_HELO_PASS=-0.001, SPF_PASS=-0.001] autolearn=ham
Received: from ([]) by localhost ( []) (amavisd-new, port 10024) with ESMTP id 2JR_Vf2pvecS for <>; Sun, 6 Apr 2014 18:46:03 -0700 (PDT)
Received: from ( []) by (Postfix) with ESMTP id D004A1A01F0 for <>; Sun, 6 Apr 2014 18:46:02 -0700 (PDT)
Received: from ( by ( with Microsoft SMTP Server (TLS) id 15.0.918.8; Mon, 7 Apr 2014 01:45:55 +0000
Received: from ([]) by ([]) with mapi id 15.00.0918.000; Mon, 7 Apr 2014 01:45:55 +0000
From: Anthony Nadalin <>
To: Mike Jones <>, John Bradley <>, Phil Hunt <>
Thread-Topic: [OAUTH-WG] New Version Notification for draft-hunt-oauth-pop-architecture-00.txt
Date: Mon, 7 Apr 2014 01:45:54 +0000
Message-ID: <>
References: <> <> <> <> <> <> <>
In-Reply-To: <>
Accept-Language: en-US
Content-Language: en-US
x-originating-ip: [2404:1a0:1001:16:f0c2:abde:79ae:5539]
x-forefront-prvs: 0174BD4BDA
x-forefront-antispam-report: =?us-ascii?Q?SFV:NSPM; SFS:(10009001)(428001)(479174003)(24454002)(3774540?= =?us-ascii?Q?03)(189002)(199002)(377424004)(74662001)(90146001)(74502001)?= =?us-ascii?Q?(47446002)(15395725003)(16236675002)(81342001)(31966008)(818?= =?us-ascii?Q?16001)(93136001)(81686001)(92566001)(93516002)(81542001)(743?= =?us-ascii?Q?66001)(74706001)(85852003)(83072002)(74876001)(76576001)(863?= =?us-ascii?Q?62001)(76796001)(76786001)(69226001)(14971765001)(56816005)(?= =?us-ascii?Q?94316002)(97186001)(80976001)(97336001)(94946001)(74316001)(?= =?us-ascii?Q?59766001)(19609705001)(77982001)(19580395003)(83322001)(1958?= =?us-ascii?Q?0405001)(33646001)(16799955002)(87266001)(87936001)(2656002)?= =?us-ascii?Q?(20776003)(19300405004)(63696002)(15188155005)(80022001)(658?= =?us-ascii?Q?16001)(79102001)(15975445006)(95416001)(53806001)(54356001)(?= =?us-ascii?Q?46102001)(1511001)(99396002)(85306002)(56776001)(54316002)(5?= =?us-ascii?Q?0986001)(47976001)(49866001)(47736001)(76482001)(98676001)(1?= =?us-ascii?Q?5202345003)(4396001)(95666003)(42262001)(24736002)(3826001)(?= =?us-ascii?Q?19623215001); DIR:OUT; SFP:1101; SCL:1; SRVR:BLUPR03MB310; H:BLUP?= =?us-ascii?Q?; FPR:A84FFD3D.ACF677CC.B7C?= =?us-ascii?Q?37F49.52E4C9B1.204AA; MLV:sfv; PTR:InfoNoRecords; MX:1; A:1; LANG?= =?us-ascii?Q?:en; ?=
received-spf: None (: does not designate permitted sender hosts)
Content-Type: multipart/alternative; boundary="_000_5eb59ad6654c4e38adb85afba06bbc8bBLUPR03MB309namprd03pro_"
MIME-Version: 1.0
Cc: "" <>
Subject: Re: [OAUTH-WG] New Version Notification for draft-hunt-oauth-pop-architecture-00.txt
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: OAUTH WG <>
List-Unsubscribe: <>, <>
List-Archive: <>
List-Post: <>
List-Help: <>
List-Subscribe: <>, <>
X-List-Received-Date: Mon, 07 Apr 2014 01:46:07 -0000

I have to agree with Phil on this as there are already spec out there that use HoK and PoP , either of these work but prefer HoK as folks get confused with PoP as we have seen this within our company already

From: OAuth [] On Behalf Of Mike Jones
Sent: Thursday, April 3, 2014 11:32 AM
To: John Bradley; Phil Hunt
Subject: Re: [OAUTH-WG] New Version Notification for draft-hunt-oauth-pop-architecture-00.txt

I agree with what John wrote below.  Besides, PoP is more natural to say than HoK and certainly more natural to say than HOTK.  I'd like us to stay with the term Proof-of-Possession (PoP).

                                                            -- Mike

From: OAuth [] On Behalf Of John Bradley
Sent: Thursday, April 03, 2014 11:10 AM
To: Phil Hunt
Subject: Re: [OAUTH-WG] New Version Notification for draft-hunt-oauth-pop-architecture-00.txt

Some people and specs associate holder of key with asymmetric keys.  Proof of possession is thought to be a broader category including symmetric and key agreement eg

NIST defines the term PoP Protocol

In SAML the saml:SubjectConfirmation method  is called urn:oasis:names:tc:SAML:2.0:cm:holder-of-key

In WS* the term proof of possession is more common.

So I think for this document as an overview "Proof of Possession (PoP) Architecture" is fine.

John B.

On Apr 3, 2014, at 12:41 PM, Phil Hunt <<>> wrote:

What was wrong with HOK?

Aside: Why was "the" so important in HOTK?



On Apr 3, 2014, at 9:37 AM, Anil Saldhana <<>> wrote:

  why not just use "proof"?


Is that allowed by IETF?


On 04/03/2014 11:30 AM, Prateek Mishra wrote:
"key confirmed" or "key confirmation" is another term that is widely used for these use-cases
I really *like* the name "proof of possession", but I think the acronym PoP is going to be confused with POP.  HOTK has the advantage of not being a homonym for aything else.  What about "Possession Proof"?

William J. Mills
"Paranoid" MUX Yahoo!

On Thursday, April 3, 2014 1:38 AM, ""<> <><> wrote:

A new version of I-D, draft-hunt-oauth-pop-architecture-00.txt
has been successfully submitted by Hannes Tschofenig and posted to the
IETF repository.

Name:        draft-hunt-oauth-pop-architecture
Revision:    00
Title:        OAuth 2.0 Proof-of-Possession (PoP) Security Architecture
Document date:    2014-04-03
Group:        Individual Submission
Pages:        21

  The OAuth 2.0 bearer token specification, as defined in RFC 6750,
  allows any party in possession of a bearer token (a "bearer") to get
  access to the associated resources (without demonstrating possession
  of a cryptographic key).  To prevent misuse, bearer tokens must to be
  protected from disclosure in transit and at rest.

  Some scenarios demand additional security protection whereby a client
  needs to demonstrate possession of cryptographic keying material when
  accessing a protected resource.  This document motivates the
  development of the OAuth 2.0 proof-of-possession security mechanism.

Please note that it may take a couple of minutes from the time of submission
until the htmlized version and diff are available at<>g/>.

The IETF Secretariat

OAuth mailing list<>

OAuth mailing list<>