Re: [OAUTH-WG] JWK Thumbprint URI Specification
Mike Jones <Michael.Jones@microsoft.com> Wed, 24 November 2021 21:18 UTC
Return-Path: <Michael.Jones@microsoft.com>
X-Original-To: oauth@ietfa.amsl.com
Delivered-To: oauth@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 7B76E3A0C35 for <oauth@ietfa.amsl.com>; Wed, 24 Nov 2021 13:18:16 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.8
X-Spam-Level:
X-Spam-Status: No, score=-2.8 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIMWL_WL_HIGH=-0.701, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, HTML_MESSAGE=0.001, SPF_PASS=-0.001, URIBL_BLOCKED=0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (1024-bit key) header.d=microsoft.com
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id G0aqtSUy1b8h for <oauth@ietfa.amsl.com>; Wed, 24 Nov 2021 13:18:11 -0800 (PST)
Received: from na01-obe.outbound.protection.outlook.com (mail-cusazlp17011013.outbound.protection.outlook.com [40.93.13.13]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 1A0163A0C2D for <oauth@ietf.org>; Wed, 24 Nov 2021 13:18:11 -0800 (PST)
ARC-Seal: i=1; a=rsa-sha256; s=arcselector9901; d=microsoft.com; cv=none; b=Bhkx8zl4ClWt3EozkJlGceM8+3ak5trYAx7z5oGPxwnDrjKJPPbgrVg12+wielO8HSv5Rpks727fDeB58WzvgNX/kDy7BSCb9EruqnWF2lV9gnCJuxg+DAgER9LrnU1LYa/OigqHfD5okXgjfiXvXzPN/3Bv3CF9UZhTajAJ39kYpRrKKaLFpQ2Ei+VIVu1bE3q9GS5j+4UeD8pL47XZaDDpYVqqFpyntwaH7N9kVkm6R0ic9xLz8LzJdxls9ZeBP4wu22+y031mb4GJsoxv+onm688CKR/ei365iGbCgou8CDjN0OZsGSit1LaZvfJbOa+Hsg9X/F1DBaWEXxAlJQ==
ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=microsoft.com; s=arcselector9901; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-AntiSpam-MessageData-ChunkCount:X-MS-Exchange-AntiSpam-MessageData-0:X-MS-Exchange-AntiSpam-MessageData-1; bh=XUnFTOkVwvWOQjB0L8IKneU+xxiNa7aedMWn2gOG+pA=; b=oQbcpKJyz5s/4vDN2ROhi4zHDLN0kFCY3/8XxPwkY7K/iOGncSwuDhORe0/PLnen+bgwgxNZTTQNY7tXHtc+X1dZ/jBc9S3giDKJcGlU7RwNgkwhIh/KBB6NUQhDaJARm3Ei9hWX3+P9K6VohpKbM97efB55G954tu0Dc1SSgVvJgQJgk9qgYB6LRGRuZZ4ia5apUo4ZW3qESka8o4QZ21IxIfmqgP4EMxJIqT4GLwI4QyC6Ho2x/x47sSJApBI4vSjY2zqt1c/24GfTxQAcu9N5LD1vD2iFfVSgsdXHjXYWfbRxdz5VjpXLa5VPPaNIUSyO5j55k+FJYJjPwlyRog==
ARC-Authentication-Results: i=1; mx.microsoft.com 1; spf=pass smtp.mailfrom=microsoft.com; dmarc=pass action=none header.from=microsoft.com; dkim=pass header.d=microsoft.com; arc=none
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=microsoft.com; s=selector2; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-SenderADCheck; bh=XUnFTOkVwvWOQjB0L8IKneU+xxiNa7aedMWn2gOG+pA=; b=Bx1imFzlkBYrM0XdTRwTzf0ce0DqFt0MDVYK5AiXT4iNc5LW63FF2m0LPN0ZAwiwylgdHn4L7UwZj7du5yzu+bLkg6Ziu+5H3JTtBktjYJ6zSIALaMPue7LjSdd/2sNXvv9ZoB9A8EEk+QriJGOjRFdDHULDf+F5zYbAD3AKaRk=
Received: from CO1PR00MB0996.namprd00.prod.outlook.com (2603:10b6:303:97::16) by BYAPR00MB0567.namprd00.prod.outlook.com (2603:10b6:a03:102::25) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.20.4768.0; Wed, 24 Nov 2021 21:18:02 +0000
Received: from CO1PR00MB0996.namprd00.prod.outlook.com ([fe80::3023:f763:185d:d649]) by CO1PR00MB0996.namprd00.prod.outlook.com ([fe80::3023:f763:185d:d649%7]) with mapi id 15.20.4776.000; Wed, 24 Nov 2021 21:18:01 +0000
From: Mike Jones <Michael.Jones@microsoft.com>
To: David Chadwick <D.W.Chadwick@kent.ac.uk>, "oauth@ietf.org" <oauth@ietf.org>
Thread-Topic: [OAUTH-WG] JWK Thumbprint URI Specification
Thread-Index: AdfheMDRWyYbpy0SSVyO9E40rck/fw==
Date: Wed, 24 Nov 2021 21:18:01 +0000
Message-ID: <CO1PR00MB09964F02A8CD8231F94401C1F5619@CO1PR00MB0996.namprd00.prod.outlook.com>
Accept-Language: en-US
Content-Language: en-US
X-MS-Has-Attach:
X-MS-TNEF-Correlator:
authentication-results: dkim=none (message not signed) header.d=none;dmarc=none action=none header.from=microsoft.com;
x-ms-publictraffictype: Email
x-ms-office365-filtering-correlation-id: 548b968f-048d-4fdf-f5a0-08d9af8fe5a1
x-ms-traffictypediagnostic: BYAPR00MB0567:EE_
x-microsoft-antispam-prvs: <BYAPR00MB056713B8DD928D6CABE02D9FF5619@BYAPR00MB0567.namprd00.prod.outlook.com>
x-ms-oob-tlc-oobclassifiers: OLM:10000;
x-ms-exchange-senderadcheck: 1
x-ms-exchange-antispam-relay: 0
x-microsoft-antispam: BCL:0;
x-microsoft-antispam-message-info: raAtzNCkLYd/mF8EWsAZaDQsnHPZwPthJijeTGkah2ECpTLSBlKe9R2CWA4vfFwOzyeAI4T4F2IcI+TB2cMbkhpJGEQz0Ocg/uVAtWHXV4iqFWUzk4k4RbFWC/Q8DGFJLACphPe2f5J0KphPIzQHYvyMZFKJ8FRk8Nv0J0YnXkPWFjFg2cWd9LegxdqlcxtYURH6k451bHmQqq/P+a8zSEdj9oqqTT0vSJCGkq4JZ1luGWPEVsBLQUpDJXZqbK2lYn96vMSbwQQcy3fiNRy/d0FhnF0Z8X94qf+86j+iJQ8M72Deq7DOuhxR3sqTOlpEl7QkSJs6QckcApfjiTWKT7JeSRQ31WM7du5FaDFqyXCQq2/nl+D7MbK5ANpV7OJsYtV0QwGJoETWCI7W/HTvVghd0SqczkdTEtrEjzUHfuW2WvbkIOzSDx/1/O6fs+fEL1afEFG3XCLED7q5qpBSvIrofCptISj8HEhC2OlWV754Ap8/MK+aKOOjNkoKD0vEiJsW7dr0XZN1R+UCfdYdP2onAoMso17ADd6rP6v/hkLlSIlQkSIwIHjk5SflLkLQCQ4CUt0sVTuFXhItUfcp2G9cs0YB9mQHK0O3PcDq/8IQyHU1tvzwODBBHeCrAicG8WivTnLUN0+5LxpbBIDv4epZhm5w3c9s6oA9OqC4nE4QXsfa6WYq6t+pcenVJDI9KUvATBOdOYp9tP6emQcW2gS/XXsDG2DqvRMXcSmy/WIUTj692DhIF+rJJ9/2bUHIXZ13WdnU/deybhCH4bRC0bjkBG0+uPhNV7XaA+wBQaUzpH7sQZpOjhTymf4Str0DZ5Rq58ACiH2CkI30YUgBE0m9GEo3vaPljFpUBVY4sTCp4+umQHD4lQX1bHUs9lnj
x-forefront-antispam-report: CIP:255.255.255.255; CTRY:; LANG:en; SCL:1; SRV:; IPV:NLI; SFV:NSPM; H:CO1PR00MB0996.namprd00.prod.outlook.com; PTR:; CAT:NONE; SFS:(13230001)(4636009)(366004)(66446008)(9686003)(6506007)(86362001)(55016003)(52536014)(5660300002)(64756008)(38070700005)(8936002)(82950400001)(82960400001)(2906002)(110136005)(71200400001)(66476007)(7696005)(10290500003)(21615005)(76116006)(66556008)(33656002)(66946007)(8676002)(166002)(508600001)(38100700002)(8990500004)(966005)(53546011)(316002)(122000001)(186003)(20210929001); DIR:OUT; SFP:1102;
x-ms-exchange-antispam-messagedata-chunkcount: 1
x-ms-exchange-antispam-messagedata-0: ElgJ5lbnX1l4757vo2cbjaPScC5V9PFsEn48ogsmnKBhQhdUCESeR58ihPK9rIuHE1BPIFk8RpvyD2YAXgA+/o/tRlHLehwfFevnz7DPHHgXZs49oenhAzBXspHVM5Q8dmVFsvZrOnNvhofFk8XlUYdIsF2IEnEHcUdLk7vLYlXW+uXgnw1Z3uaJ6FVWAY7zeZAZCOyHms5/GGk3JkMQlYZAec3BPCuF5wpT5enF0NDUZWRvnDsG1kiMKpYqKzR3Y7LaCDY7ytaKo9DIGS8rmB3JTk9NK7xvfb5hdPP2u2tlHYxZXHrjdNGhYK/yWcBGo8nfxMwRtplGqZ5AYvasnnQ+ww+4QFCORbNp2lwUtIo/GLcTs9lVS5ou4GW/2i4bX+eDTNPJf6V86AhFWplr+wkiBQPbvGm6smxoGww1Roh7RebjUHGvcplDDp9of/oruXmLSRCKU1gclus27vuTDkn7FFrZsrVzwin3y2wpYRzG5jStvGJBbjdsPmvkpFadL0Pjh0sXzTcpk43Kb/cPDKCnFps3KJx55qHWFcVd6EikXP6TQC94ttKeQAHIPngPNaFz+KB07ipQ7gG2YoJTNH5pKXeS4PKPltoRv8S+5uzEwOQr4tqeQcRSvTGyqcdvujdAzx0zQBgbZQ4wWCx5X+5mOol6luozTt55iAXaSbfgHl7ddsvPSMzcuBEWjqD5LCNvDffiWy9ch2pCK17ouotuZTlaTWroI05gAOl3skUHFqhUpTO4rneSGIT6KZlXCORFhOg9mCGctYzOPCYLjf11l3Cfz7ZKkdOCx0nAirNBfuwFygGXBluKAsu60hkcqzBWjOr6tf+fU8VqZUoP2gEvTfX0jyw1xmZj0/sN7IpNH2tyqiB3tFxVApShiKgZQQ9QwEXtobYqD1/BqtBll2VxEmGEeUdt5ISw6aLLF4bP1Kr14FkC7w24mOzKj9KkJtRTOVHFVfeZVMGAjbMEWEZIo01lxnRmuJr6P07sbNmb4JHFtn1nIK9a2zKl3TCEA29FoVFVCfZJIg84jW2NVRUUGhJQWIRLdsgQ7JWhpA5YJX8LJ8GZtl8q7Cn/ZqTcPuZGF0V8Qn55emsKBvbOl5jzci7ayi6VEEg8UtaIyqdWUVdvy2FxkVLnseD/STG0D5bV7FTh/ZuUuN93frxUvVUzZQqau7adH1Jp8SSXPnEl7PzgFW1owim99GBoEDcUr553mIiw7HzqgyGskE4NZNcRS9DcmeN3QIH4KUNl6pAVjn1A7Hrk5PO720ylbVz+HuF+UqbgzGPBHz5Tgmtb50CLH/v1Zs8QtdmDBeJ2I5ltFR+CdzI2Pv5DNGLwe371CkZiDZmdwMPeo4izzQE0T5W8veuMMFSQux/QKaharrjOWE2UGT0Cs8dnEUtEv7hfFsPv9fi/FpelS3A09x5lZKWML//jxHMAymy3mi4gjgp05za+MHNIvBZj+wRmtnFod3jWd4+0g9O7afXe8KW6/aX/09lyBs2SUCPrr55BwYmNvyL7NZVs+51/+4n5FQo0DN8x1khkpXKmLIhczV5NxRLJ9v1SSY7Y+FNweZUqf3ESOrPhs4FvNTDtixZQlPtN6/PPIzGJne2cBLlCj6aJEiCxrtj2Sgu6XKOKVnsG1pkfanCxlwTFt067KXUsZUWdPCqen5k3U8o18N5sZ8lTmzn2X9kbXzygOe2Qy4Wt2IY=
Content-Type: multipart/alternative; boundary="_000_CO1PR00MB09964F02A8CD8231F94401C1F5619CO1PR00MB0996namp_"
MIME-Version: 1.0
X-OriginatorOrg: microsoft.com
X-MS-Exchange-CrossTenant-AuthAs: Internal
X-MS-Exchange-CrossTenant-AuthSource: CO1PR00MB0996.namprd00.prod.outlook.com
X-MS-Exchange-CrossTenant-Network-Message-Id: 548b968f-048d-4fdf-f5a0-08d9af8fe5a1
X-MS-Exchange-CrossTenant-originalarrivaltime: 24 Nov 2021 21:18:01.5816 (UTC)
X-MS-Exchange-CrossTenant-fromentityheader: Hosted
X-MS-Exchange-CrossTenant-id: 72f988bf-86f1-41af-91ab-2d7cd011db47
X-MS-Exchange-CrossTenant-mailboxtype: HOSTED
X-MS-Exchange-CrossTenant-userprincipalname: ihxf38p9PpCxajfNjC6ST+HRGdFmffZ3Wol3TNI2RRYqLb8v5wQQgRftwMp1XM4tv1bzHyBnnKWxhiIoq35YXw==
X-MS-Exchange-Transport-CrossTenantHeadersStamped: BYAPR00MB0567
Archived-At: <https://mailarchive.ietf.org/arch/msg/oauth/J9yjZE5IZQQlRaUNJqfEYWztAlU>
Subject: Re: [OAUTH-WG] JWK Thumbprint URI Specification
X-BeenThere: oauth@ietf.org
X-Mailman-Version: 2.1.29
Precedence: list
List-Id: OAUTH WG <oauth.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/oauth>, <mailto:oauth-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/oauth/>
List-Post: <mailto:oauth@ietf.org>
List-Help: <mailto:oauth-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/oauth>, <mailto:oauth-request@ietf.org?subject=subscribe>
X-List-Received-Date: Wed, 24 Nov 2021 21:18:17 -0000
The JWK Thumbprint is typically used as a key identifier. Yes, the key needs to be known by other means if you’re going to use it. Some protocols work that way, which is what this spec is intended to enable. For instance, the Self-Issued OpenID Provider (SIOP) v1 and v2 protocols send the public key separately in a “sub_jwk” claim. In other use cases, it may already be known to the receiving party – for instance, from a prior discovery step. It would be fine to separately also define a URI representation communicating an entire JWK, but that would be for different use cases, and not the goal of this (intentionally narrowly scoped) specification. Cheers, -- Mike From: OAuth <oauth-bounces@ietf.org> On Behalf Of David Chadwick Sent: Wednesday, November 24, 2021 12:36 PM To: oauth@ietf.org Subject: Re: [OAUTH-WG] JWK Thumbprint URI Specification On 24/11/2021 20:07, Mike Jones wrote: The JSON Web Key (JWK) Thumbprint specification [RFC 7638<https://www.rfc-editor.org/rfc/rfc7638.html>] defines a method for computing a hash value over a JSON Web Key (JWK) [RFC 7517<https://www.rfc-editor.org/rfc/rfc7517.html>] and encoding that hash in a URL-safe manner. Kristina Yasuda<https://twitter.com/kristinayasuda> and I have just created the JWK Thumbprint URI<https://www.ietf.org/archive/id/draft-jones-oauth-jwk-thumbprint-uri-00.html> specification, which defines how to represent JWK Thumbprints as URIs. This enables JWK Thumbprints to be communicated in contexts requiring URIs, including in specific JSON Web Token (JWT) [RFC 7519<https://www.rfc-editor.org/rfc/rfc7519.html>] claims. My immediate observation is why are you sending the thumbprint of the JSON Web Key and not sending the actual key value in the URI? Sending the thumbprint means the recipient still has to have some other way of obtaining the actual public key, whereas sending the public key as a URI means that no other way is needed. Kind regards David Use cases for this specification were developed in the OpenID Connect Working Group<https://openid.net/wg/connect/> of the OpenID Foundation. Specifically, its use is planned in future versions of the Self-Issued OpenID Provider v2<https://openid.net/specs/openid-connect-self-issued-v2-1_0.html> specification. The specification is available at: 1. https://www.ietf.org/archive/id/draft-jones-oauth-jwk-thumbprint-uri-00.html -- Mike P.S. This note was also published at https://self-issued.info/?p=2211 and as @selfissued<https://twitter.com/selfissued/>. _______________________________________________ OAuth mailing list OAuth@ietf.org<mailto:OAuth@ietf.org> https://www.ietf.org/mailman/listinfo/oauth
- [OAUTH-WG] JWK Thumbprint URI Specification Mike Jones
- Re: [OAUTH-WG] JWK Thumbprint URI Specification David Chadwick
- Re: [OAUTH-WG] JWK Thumbprint URI Specification Mike Jones
- Re: [OAUTH-WG] JWK Thumbprint URI Specification David Waite
- Re: [OAUTH-WG] JWK Thumbprint URI Specification David Chadwick
- Re: [OAUTH-WG] JWK Thumbprint URI Specification Mike Jones
- Re: [OAUTH-WG] JWK Thumbprint URI Specification David Chadwick