[OAUTH-WG] Re: HTTP Message Signatures
Andrii Deinega <andrii.deinega@gmail.com> Tue, 11 August 2026 23:34 UTC
Return-Path: <andrii.deinega@gmail.com>
X-Original-To: oauth@mail2.ietf.org
Delivered-To: oauth@mail2.ietf.org
Received: from localhost (localhost [127.0.0.1]) by mail2.ietf.org (Postfix) with ESMTP id 137181282E237 for <oauth@mail2.ietf.org>; Tue, 11 Aug 2026 16:34:41 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=ietf.org; s=ietf1; t=1786491281; bh=HTVACp5zb79cYqkQXIZCAgIwxo4T5gZsOwWM1J07CbE=; h=References:In-Reply-To:From:Date:Subject:To:Cc; b=jrSYlPbal0Wp1oYXYjoEohgm3E33rxFUU09qIzoHzVARiuGrzCAkkZ6GSNAfGUo3g JaXemw6LrEw8UYD7uPKKyVwbm+yDLeb8eG0a6y8Fx+NNi0Wg2Fj1lGSrQKlshjDQ7K 3/SyRodvYNWxvl5n2ZwW+Kjux9qg+Vib97XbNSOk=
X-Virus-Scanned: amavisd-new at ietf.org
X-Spam-Flag: NO
X-Spam-Score: -2.098
X-Spam-Level:
X-Spam-Status: No, score=-2.098 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, FREEMAIL_FROM=0.001, HTML_MESSAGE=0.001, RCVD_IN_DNSWL_NONE=-0.0001, SPF_HELO_NONE=0.001, SPF_PASS=-0.001] autolearn=ham autolearn_force=no
Authentication-Results: mail2.ietf.org (amavisd-new); dkim=pass (2048-bit key) header.d=gmail.com
Received: from mail2.ietf.org ([166.84.6.31]) by localhost (mail2.ietf.org [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id SguLa3aJ4s_M for <oauth@mail2.ietf.org>; Tue, 11 Aug 2026 16:34:40 -0700 (PDT)
Received: from mail-oi1-x229.google.com (mail-oi1-x229.google.com [IPv6:2607:f8b0:4864:20::229]) (using TLSv1.3 with cipher TLS_AES_128_GCM_SHA256 (128/128 bits) key-exchange X25519 server-signature ECDSA (P-256) server-digest SHA256) (No client certificate requested) by mail2.ietf.org (Postfix) with ESMTPS id 825751282E22E for <oauth@ietf.org>; Tue, 11 Aug 2026 16:34:40 -0700 (PDT)
Received: by mail-oi1-x229.google.com with SMTP id 5614622812f47-4a4cb36ae00so250229b6e.0 for <oauth@ietf.org>; Tue, 11 Aug 2026 16:34:40 -0700 (PDT)
ARC-Seal: i=1; a=rsa-sha256; t=1786491274; cv=none; d=google.com; s=arc-20260327; b=jQZy5tTO3gP8vPO3xEeTUSahKoLARku8SBBZcxS7VedD6G/hEs2VrzWt/DCj9Uj+TW vCJ6maimZ9NxGiqmwDvbP0iLbIyPC+N+vDYdsMaeP2bSHvDJE4QgRttKbWJfKKHzwhrh W6G7NnUOFSWkjK40jK+FQ6/EWpF7jKHNU/jeysZ/iQldqC1QuLQ4yoBWljLG6tUxERay yoFTqn0a20HlekCpaQXukZMpM/UT04AtMbyKurqohRfe8SVa1cOnj6tFWkypQ83v3adL R8m13ld5hd+bECDKqqT4FEN7ersNzMhZoJHG4AX+w3oY6GTsQpZ2H+BP1pvEOgtT/KYI 6qyA==
ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=arc-20260327; h=cc:to:subject:message-id:date:from:in-reply-to:references :mime-version:dkim-signature; bh=0BylN7XJjfle/w6Tnnx8AbMI9cjAELhJd/x12C3oWrk=; fh=v/57np0Rc+f45Phh6QjrtbahHEp4e87l7EasmlFpJ1Q=; b=GlwZRS1+scrjlRkl3rG9GXjDqaJJ1ihUSn0gnhaKW+tCp+CUl0HXTJYAkqCWYymiiT EmuHy8gYtzvapeBPub815y6iBV0+zufGR7trhfUQz2tKlfRtbeINbLlogY3mTujO3Vrv I+lFydXj69s3qjwCzO140Tqff7Do2I41Se4WSJvvLSQTOmmlSuD2/v7s3bwEFfbFLlo+ mx8uUgPUZttA4fn5eQjF6M5ZaqckrjpeNVpGmJepCOnhT3ZHkDDLPHuErJdok79YBler cKmQTKwzeQWolgCY9EllU3QgQXcwei4nP4kQd0NDkjRgk0cgJCom5riPkTi8qODbJMvU 7VMQ==; darn=ietf.org
ARC-Authentication-Results: i=1; mx.google.com; arc=none
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20251104; t=1786491274; x=1787096074; darn=ietf.org; h=content-type:cc:to:subject:message-id:date:from:in-reply-to :references:mime-version:from:to:cc:subject:date:message-id:reply-to :content-type; bh=0BylN7XJjfle/w6Tnnx8AbMI9cjAELhJd/x12C3oWrk=; b=bbmPY2o1PGeydZElKQAte3Uycgl44/yiQLLm6ETNmuz5TFC96LnH9cLNYyi4pq4Gf4 v+OHAubJTtrZEwmYn5Gr8SHUXF1GTTlTFXrgfRRDthngiCl5XR3jOncHFlPMrp1GxDrM 0tVv+KU9O3FbG2FaVK9DAdNgw1v9yU26FSvoY1HteHys8sMKNyhw1IAzFzYeZW4hTxTX 4EcFn7MDOzgIMll2q21jkGhqhaXPYbwEHB90yRu5iEaIrkTqqGUbN0VQFkUekHok8/6m pjtH5x3PrvFlFKLNJzGKHIWNm124puq2krRd5iGokencmcWJvXXL4uRdWLMaMT+AsPdl 0Xnw==
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1786491274; x=1787096074; h=content-type:cc:to:subject:message-id:date:from:in-reply-to :references:mime-version:x-gm-gg:x-gm-message-state:from:to:cc :subject:date:message-id:reply-to:content-type; bh=0BylN7XJjfle/w6Tnnx8AbMI9cjAELhJd/x12C3oWrk=; b=DCbFURzvBwxgk86+ezK56oX5yWurYOOhuhTQ7QrLekj3+xsLHp6K5B0e8whbzzjLmq TXlI5Lx5SbLOczTiOw5jnmkr96UriKO6tL+PYsMTvxQ9Va0NPsr4c/GPbF7klYDgRnXt ybJw9qDvj1g4fCW32lxZqbxJYXMtoh1LSeIQ/3uaONxAHEjQNEMwa6X9zxwr0Q08W0OJ nRalFvZYaz6D+dpeGgijh7KfvuS8Tww3+rglPsma9QZgQ8dJDYBCSlOCHTXjxYhNAk/O 8XgGYHuoRfI1qo7N6w72am8fF/H49yam4OoUjwW5jIjBTqArpNbTahLCpqwjcXSmsPYd WmDg==
X-Gm-Message-State: AOJu0Yw79XFT4/D3DsSTE2sD36UGGABzZKce6jo3op3+jBtw7eB04qLC dC5M5LB5wPPsUTdezFTpfXJROaYfTuty6DiHagnKux5nZeCA/j6ZgK2YnpawDMu4p6oRME+6fDj THH0lOWpzA/TWVXE86Dh5rcW80aeKZcY=
X-Gm-Gg: AR+sD10w/OKWRhL2uBAG7+otcjPXORGJqAD/mOcvbyV+Qbhr7C2XplR7S4U7AUiy/Xo /BcBhjsrKJR3YxmB8ZetRtGXv/LCFFoodgvGzrGmPSErSbUAqMtTK4HrwHZTEAwtCsjQGXRJiVf FBX4IqS7/vTd6ycMITZzY2OwMHILLZniy+F/OjJCsiFWsY40XBsKZpH50LZyG7uDfgNfMHUTyOG wCtfht2t1YfTiwzpCzVwPUqy+CS4hbnqNBQAp2w/37daG3eNL0r/reqnGQyRxiuJGyi4rxD3LPy g3ZOXoEAhedpbEnY8VDTyY0XPfxxEUyuJs47Oc11RfrVc4g=
X-Received: by 2002:a05:6808:4f08:b0:4aa:d5f:123e with SMTP id 5614622812f47-4b210ab294cmr886319b6e.9.1786491274314; Tue, 11 Aug 2026 16:34:34 -0700 (PDT)
MIME-Version: 1.0
References: <CH3PR01MB82855BD9FAF0C69812B18C6ABDCB2@CH3PR01MB8285.prod.exchangelabs.com>
In-Reply-To: <CH3PR01MB82855BD9FAF0C69812B18C6ABDCB2@CH3PR01MB8285.prod.exchangelabs.com>
From: Andrii Deinega <andrii.deinega@gmail.com>
Date: Tue, 11 Aug 2026 16:34:21 -0700
X-Gm-Features: AUfX_myKuF4qGmakIOR62vdK-6QTz6wKsYglcACQ3DahqlCNVW6bubCED-3Xdn0
Message-ID: <CALkShcvVRenvki+=icU8pvki-mFXADW7XC8jYOcc=xdputaznw@mail.gmail.com>
To: Justin Richer <jricher@mit.edu>
Content-Type: multipart/alternative; boundary="000000000000ccc7bb0658cde9de"
Message-ID-Hash: F753MPVYLZ2OEWM7K5UFG63AYPHSQFNO
X-Message-ID-Hash: F753MPVYLZ2OEWM7K5UFG63AYPHSQFNO
X-MailFrom: andrii.deinega@gmail.com
X-Mailman-Rule-Misses: dmarc-mitigation; no-senders; approved; emergency; loop; banned-address; member-moderation; header-match-oauth.ietf.org-0; nonmember-moderation; administrivia; implicit-dest; max-recipients; max-size; news-moderation; no-subject; digests; suspicious-header
CC: oauth <oauth@ietf.org>
X-Mailman-Version: 3.3.9rc6
Precedence: list
Subject: [OAUTH-WG] Re: HTTP Message Signatures
List-Id: OAUTH WG <oauth.ietf.org>
Archived-At: <https://mailarchive.ietf.org/arch/msg/oauth/SVJTBxArZpRc86S8rIa4Iz8ISZ4>
List-Archive: <https://mailarchive.ietf.org/arch/browse/oauth>
List-Help: <mailto:oauth-request@ietf.org?subject=help>
List-Owner: <mailto:oauth-owner@ietf.org>
List-Post: <mailto:oauth@ietf.org>
List-Subscribe: <mailto:oauth-join@ietf.org>
List-Unsubscribe: <mailto:oauth-leave@ietf.org>
Justin, I like this idea and draft, but I also want to raise a few questions and share some concerns for discussion. To start off, keys exposed through the client's registration (either via Dynamic Client Registration or the Client Id Metadata Document) should be explicitly marked for their intended "use", the standard "sig" value for that may not work alone. Then, how are we going to support (smooth) key rotation? As I recall, a JSON Web Key (JWK) doesn't include properties such as "exp", "iat", etc. One more... The Client Id Metadata Document is not signed so how can we validate that the client actually controls the corresponding private key? We did some exercises and addressed some of these challenges in GNAP back in the day, and all these Qs seem relevant here, right? We might also consider drawing some ideas from the The Update Framework (TUF) to address them. Regards, Andrii Deinega On Tue, Jul 28, 2026 at 10:55 AM Justin Richer <jricher@mit.edu> wrote: > After the meeting last Friday, a bunch of us joined up to work on the HTTP > Message Signatures draft — huge thanks to Paul, Christian, and Filip for > joining me and Aaron. > > Name: draft-richer-oauth-httpsig > Revision: 03 > Title: OAuth Proof of Possession Tokens with HTTP Message Signatures > Date: 2026-07-28 > Group: Individual Submission > Pages: 23 > URL: > https://www.ietf.org/archive/id/draft-richer-oauth-httpsig-03.txt > Status: https://datatracker.ietf.org/doc/draft-richer-oauth-httpsig/ > HTML: > https://www.ietf.org/archive/id/draft-richer-oauth-httpsig-03.html > HTMLized: https://datatracker.ietf.org/doc/html/draft-richer-oauth-httpsig > Diff: > https://author-tools.ietf.org/iddiff?url2=draft-richer-oauth-httpsig-03 > > This new version changes how we present inline public keys, and adds the > first step of considerations for RS-side validation of bound tokens. > > Please read through this when you can, and implement it if you can, and > give us your comments on here or on GitHub. We've asked the chairs to > schedule and interim to discuss this work and we'd like to bring this > forward for adoption modulo the interim discussion. > > > - Justin > > > > _______________________________________________ > OAuth mailing list -- oauth@ietf.org > To unsubscribe send an email to oauth-leave@ietf.org >
- [OAUTH-WG] HTTP Message Signatures Justin Richer
- [OAUTH-WG] Re: HTTP Message Signatures Andrii Deinega
- [OAUTH-WG] Re: HTTP Message Signatures Justin Richer
- [OAUTH-WG] Re: HTTP Message Signatures Andrii Deinega
- [OAUTH-WG] Re: HTTP Message Signatures Justin Richer