[OAUTH-WG] Re: I-D Action: draft-ietf-oauth-selective-disclosure-jwt-21.txt
Brian Campbell <bcampbell@pingidentity.com> Thu, 29 May 2025 16:51 UTC
Return-Path: <bcampbell@pingidentity.com>
X-Original-To: oauth@mail2.ietf.org
Delivered-To: oauth@mail2.ietf.org
Received: from localhost (localhost [127.0.0.1]) by mail2.ietf.org (Postfix) with ESMTP id 375672E61FB3 for <oauth@mail2.ietf.org>; Thu, 29 May 2025 09:51:30 -0700 (PDT)
X-Virus-Scanned: amavisd-new at ietf.org
X-Spam-Flag: NO
X-Spam-Score: -2.097
X-Spam-Level:
X-Spam-Status: No, score=-2.097 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, HTML_MESSAGE=0.001, RCVD_IN_DNSWL_NONE=-0.0001, SPF_HELO_NONE=0.001, SPF_NONE=0.001] autolearn=ham autolearn_force=no
Authentication-Results: mail2.ietf.org (amavisd-new); dkim=pass (2048-bit key) header.d=pingidentity.com
Received: from mail2.ietf.org ([166.84.6.31]) by localhost (mail2.ietf.org [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id n5qtfnKVUhXd for <oauth@mail2.ietf.org>; Thu, 29 May 2025 09:51:29 -0700 (PDT)
Received: from mail-vk1-xa33.google.com (mail-vk1-xa33.google.com [IPv6:2607:f8b0:4864:20::a33]) (using TLSv1.3 with cipher TLS_AES_128_GCM_SHA256 (128/128 bits) key-exchange X25519 server-signature ECDSA (P-256) server-digest SHA256) (No client certificate requested) by mail2.ietf.org (Postfix) with ESMTPS id 692C42E61FA2 for <oauth@ietf.org>; Thu, 29 May 2025 09:51:29 -0700 (PDT)
Received: by mail-vk1-xa33.google.com with SMTP id 71dfb90a1353d-52f036ef186so296871e0c.1 for <oauth@ietf.org>; Thu, 29 May 2025 09:51:29 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=pingidentity.com; s=google; t=1748537489; x=1749142289; darn=ietf.org; h=cc:to:subject:message-id:date:from:in-reply-to:references :mime-version:from:to:cc:subject:date:message-id:reply-to; bh=8CWSPLuNPPnICkLgFCFvGuUV26Gbxmtf2Xi7k30qsac=; b=UeL7gmVyKMKQeRWY3vYWfkOG+HjSsylhUNi1m2YPaqEOtmpEsyrHqmdD8t864EPvf8 /cwt8csa+J/2dX9oeJhedPEjP9AWtVJhoLJBAf23NQGScpLzY45DQ4I9I5wQPAPtWjzM 51CGcWHlQyo7zqQOoirWNnwLk05VQ/WpMBF/fz934DGO4GvD0iFEwo4F8WGhO2x2RswR OEstI6wbwcCYAqsecxbiqUW+y91p6Pd+j8Ok/qPeyjhuBWy5/UFDMs+pkoX4oyV/3GuN 6cMBhHU+tjrTBsYUzqEGplPHHUZLuO6DRuBAi+JWNFV6JGf3ZUL7NVIfzgaQI/0E2uwF cPww==
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20230601; t=1748537489; x=1749142289; h=cc:to:subject:message-id:date:from:in-reply-to:references :mime-version:x-gm-message-state:from:to:cc:subject:date:message-id :reply-to; bh=8CWSPLuNPPnICkLgFCFvGuUV26Gbxmtf2Xi7k30qsac=; b=Kf9jAIrZXRmI3Gk7LXTzS4LcwvCli40C9h6IX8W784rsgjKRM4ykNGuO4KhW4yR4Rg /ylmH9Q9bhcifmO2h5ZiNHpzZf64NE8j/5wNjnRXy1CMvPRehoy6nlGTitg5oE7/+fpf QG8jYtGe7zFKRMvfwpMWNX9BxtKezGeSa4buK9nTCbiaKskQXib9KThTVnVpMmfcgCHa pbEVrdVp8uuLeOVJ0bELwTMEOu4iEHWa/UukGMdSry6fyArNFQ0Hdg0DYTPcX2yJHXdk xdt5trcHEfq27UBxyn3eSh1LBUUZJrsDHk9I7zE9+8mQOoPs97Lr+L3t/pozYvjgUJv/ RSxQ==
X-Gm-Message-State: AOJu0YxHquMlEqsSxlcTCxsZxifkSjWMVIKkwv2Kd+2GHjQnLOmuVOVH 0oplrg3kBcwdNAyogjlf4ld11zyX4gdpuCddYiSDAe0I6VqL7hpqhf9D2/9P5amyG1sWwDmHrBS dJ+AFKgZO4W0lEj6cytuRYVCt0wtHiEQHJrhxv9RltywKEKy+Qk1Bb+SfB8gqptmoq1nSdLYLXM /NruVNsmhboUkscuL1a0l7aN54QY0=
X-Gm-Gg: ASbGnctKZirHkD2jFxz5Db1k9QMcz1UJT6q3gw2wURJGIMKKe9r6n+C60oBfivvS4aL SISZD5wdAWEnXhe2dCbGHwdpE32cALp0rKnimxv5uUhGZDunOgvcqMEccZLdSbTfMkAa/g1iFl2 rgGtr3qy5tm3X+BriX3ucdPSUy4ZyMLdlgKu+l4UUJWw==
X-Google-Smtp-Source: AGHT+IHPSlCB/32vhI/0wnSI4LhAEKUx3giw+z/demPjsb0+0j5FLRNyUxzQwsFJ0WH7pUHQEBwC6inJfvtG7R/9SpM=
X-Received: by 2002:a05:6122:180f:b0:52a:ee1d:f7fd with SMTP id 71dfb90a1353d-5308110979emr134294e0c.8.1748537488693; Thu, 29 May 2025 09:51:28 -0700 (PDT)
MIME-Version: 1.0
References: <174845433682.1933608.15498051404908838603@dt-datatracker-59b84fc74f-84jsl> <CAKUhyqEn3-4MSHs8vQGmgrvuGVWWHguVeo0z=sUF+OQx+E6FQg@mail.gmail.com> <CA+k3eCTcJJfaFqh60RB=s6wfWoWaehvg4fj5SVE=ur-+Ki2dqQ@mail.gmail.com>
In-Reply-To: <CA+k3eCTcJJfaFqh60RB=s6wfWoWaehvg4fj5SVE=ur-+Ki2dqQ@mail.gmail.com>
From: Brian Campbell <bcampbell@pingidentity.com>
Date: Thu, 29 May 2025 10:51:02 -0600
X-Gm-Features: AX0GCFt-9uHdRUTItG2IQqYyECJ2G6f7WyjzAXBC9z4rw-k0-g0cW8ZmdHRuJB8
Message-ID: <CA+k3eCTNZH46rHVBwv6SMLFrvmDByVKA5ozspXO474yPLQ=YKQ@mail.gmail.com>
To: Dan Moore <dan=40fusionauth.io@dmarc.ietf.org>
Content-Type: multipart/alternative; boundary="000000000000e4044d0636491bd0"
Message-ID-Hash: MLC6COJECQGMQWEGLFRJONEIP5ERS6AJ
X-Message-ID-Hash: MLC6COJECQGMQWEGLFRJONEIP5ERS6AJ
X-MailFrom: bcampbell@pingidentity.com
X-Mailman-Rule-Misses: dmarc-mitigation; no-senders; approved; emergency; loop; banned-address; member-moderation; header-match-oauth.ietf.org-0; nonmember-moderation; administrivia; implicit-dest; max-recipients; max-size; news-moderation; no-subject; digests; suspicious-header
CC: oauth@ietf.org
X-Mailman-Version: 3.3.9rc6
Precedence: list
Subject: [OAUTH-WG] Re: I-D Action: draft-ietf-oauth-selective-disclosure-jwt-21.txt
List-Id: OAUTH WG <oauth.ietf.org>
Archived-At: <https://mailarchive.ietf.org/arch/msg/oauth/RWOYFYRjPufiVWIRbU3FWbjGmSQ>
List-Archive: <https://mailarchive.ietf.org/arch/browse/oauth>
List-Help: <mailto:oauth-request@ietf.org?subject=help>
List-Owner: <mailto:oauth-owner@ietf.org>
List-Post: <mailto:oauth@ietf.org>
List-Subscribe: <mailto:oauth-join@ietf.org>
List-Unsubscribe: <mailto:oauth-leave@ietf.org>
Thanks again for catching that Dan. It should be fixed in -22 https://datatracker.ietf.org/doc/html/draft-ietf-oauth-selective-disclosure-jwt-22#name-array-elements On Thu, May 29, 2025 at 6:03 AM Brian Campbell <bcampbell@pingidentity.com> wrote: > Thanks Dan, > > You aren't missing anything. That's an inconsistency I introduced about 3 > weeks ago when I added the "US" element to the array in hopes of giving a > better visual distinction between the two arrays in the examples at > https://datatracker.ietf.org/doc/html/draft-ietf-oauth-selective-disclosure-jwt-18#section-4.2.2-4 > but overlooked updating the associated text a little later > https://datatracker.ietf.org/doc/html/draft-ietf-oauth-selective-disclosure-jwt-18#section-4.2.4.2-4 > that explains usage of those arrays. > > I've created this > https://github.com/oauth-wg/oauth-selective-disclosure-jwt/pull/580 PR to > bring the explanatory text inline with the content in the example. > > I'm a little unsure of the proper process at this point (the IESG approved > the draft yesterday) but I'll work with the powers that be to figure out > the most appropriate way to get this fix incorporated. > > > > On Wed, May 28, 2025 at 8:27 PM Dan Moore <dan= > 40fusionauth.io@dmarc.ietf.org> wrote: > >> Hi folks, >> >> I saw one confusing item in this document. In section 4.2.4.2. at the >> end, it states: >> >> In the example above, the verification process would >> output an array with only one element unless a matching Disclosure >> for the second element is received. >> >> But the example looks like this: >> >> { >> "nationalities": >> ["DE", {"...":"w0I8EKcdCtUPkGCNUrfwVp2xEgNjtoIDlOxc9-PlOhs"}, "US"] >> } >> >> My reading is that the second element of the array would be omitted if >> the verifier didn't receive the matching disclosure, but the first and >> third elements would be delivered. Therefore the array would have two >> elements if no disclosure was received. >> >> I reviewed section 7 but didn't see anything about removing elements of >> an array after an element that was selectively disclosed (as the >> {"...":"w0I8EKcdCtUPkGCNUrfwVp2xEgNjtoIDlOxc9-PlOhs"} is). >> >> What am I missing? >> >> Dan >> >> On Wed, May 28, 2025 at 11:47 AM <internet-drafts@ietf.org> wrote: >> >>> Internet-Draft draft-ietf-oauth-selective-disclosure-jwt-21.txt is now >>> available. It is a work item of the Web Authorization Protocol (OAUTH) >>> WG of >>> the IETF. >>> >>> Title: Selective Disclosure for JWTs (SD-JWT) >>> Authors: Daniel Fett >>> Kristina Yasuda >>> Brian Campbell >>> Name: draft-ietf-oauth-selective-disclosure-jwt-21.txt >>> Pages: 96 >>> Dates: 2025-05-28 >>> >>> Abstract: >>> >>> This specification defines a mechanism for the selective disclosure >>> of individual elements of a JSON data structure used as the payload >>> of a JSON Web Signature (JWS). The primary use case is the selective >>> disclosure of JSON Web Token (JWT) claims. >>> >>> The IETF datatracker status page for this Internet-Draft is: >>> >>> https://datatracker.ietf.org/doc/draft-ietf-oauth-selective-disclosure-jwt/ >>> >>> There is also an HTML version available at: >>> >>> https://www.ietf.org/archive/id/draft-ietf-oauth-selective-disclosure-jwt-21.html >>> >>> A diff from the previous version is available at: >>> >>> https://author-tools.ietf.org/iddiff?url2=draft-ietf-oauth-selective-disclosure-jwt-21 >>> >>> Internet-Drafts are also available by rsync at: >>> rsync.ietf.org::internet-drafts >>> >>> >>> _______________________________________________ >>> OAuth mailing list -- oauth@ietf.org >>> To unsubscribe send an email to oauth-leave@ietf.org >>> >> >> >> >> >> >> >> >> >> _______________________________________________ >> OAuth mailing list -- oauth@ietf.org >> To unsubscribe send an email to oauth-leave@ietf.org >> > -- _CONFIDENTIALITY NOTICE: This email may contain confidential and privileged material for the sole use of the intended recipient(s). Any review, use, distribution or disclosure by others is strictly prohibited. If you have received this communication in error, please notify the sender immediately by e-mail and delete the message and any file attachments from your computer. Thank you._
- [OAUTH-WG] I-D Action: draft-ietf-oauth-selective… internet-drafts
- [OAUTH-WG] Re: I-D Action: draft-ietf-oauth-selec… Dan Moore
- [OAUTH-WG] Re: I-D Action: draft-ietf-oauth-selec… Brian Campbell
- [OAUTH-WG] Re: I-D Action: draft-ietf-oauth-selec… Michael Jones
- [OAUTH-WG] Re: I-D Action: draft-ietf-oauth-selec… Brian Campbell