Re: [OAUTH-WG] Fwd: I-D Action: draft-ietf-oauth-pop-key-distribution-03.txt

Ludwig Seitz <ludwig@sics.se> Fri, 03 March 2017 12:10 UTC

Return-Path: <ludwig@sics.se>
X-Original-To: oauth@ietfa.amsl.com
Delivered-To: oauth@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id A243912984A for <oauth@ietfa.amsl.com>; Fri, 3 Mar 2017 04:10:47 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.701
X-Spam-Level:
X-Spam-Status: No, score=-2.701 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, RCVD_IN_DNSWL_LOW=-0.7, SPF_PASS=-0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (2048-bit key) header.d=sics.se
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id Y0_WoXrdvy5b for <oauth@ietfa.amsl.com>; Fri, 3 Mar 2017 04:10:46 -0800 (PST)
Received: from mail-lf0-x22f.google.com (mail-lf0-x22f.google.com [IPv6:2a00:1450:4010:c07::22f]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id D8E531297F7 for <oauth@ietf.org>; Fri, 3 Mar 2017 04:10:45 -0800 (PST)
Received: by mail-lf0-x22f.google.com with SMTP id y193so46435419lfd.3 for <oauth@ietf.org>; Fri, 03 Mar 2017 04:10:45 -0800 (PST)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=sics.se; s=google; h=subject:to:references:from:message-id:date:user-agent:mime-version :in-reply-to; bh=5/UuHQUU7ES4AJasupLV90w7Cgr/vnOgO0tPA86Isn4=; b=KjOat1fQMYkVasvAUKGnEWS/9EkGVaSCDR21qpMlY2CNvjDH7lCqxrjCMk/VmQxJiz JE5aMVy349gl1ePfjQvdGWrPK9i/kdzFo8nPIIKcVRbx9mOWF1mEfBZaqMAHSK0zGbYm qdmOvXxw32C84JyfF+io/6rtoRJzcpLtQL3FplEHyz7ZMuzVhlWsXSrSqIhnKpF5H2aB BokY0w51VIEp4ejByB2zbCg9iLupkiabMCKzRtuyvxb5qhRcFOuqRP6y08fYk4ZQiwXN uzKnFu5dSsTJgK9m0w0WMYkD3PBHQdLT3PbpfyMiggYHnuRfyaG8plciuO4/38kQYXWN dG/A==
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20161025; h=x-gm-message-state:subject:to:references:from:message-id:date :user-agent:mime-version:in-reply-to; bh=5/UuHQUU7ES4AJasupLV90w7Cgr/vnOgO0tPA86Isn4=; b=q6esf2TbgaSrmDvVPPp9/UBPkZfg2GzlK7xqPdVJh9An5puStzKrnS2YE6cM8l7+VO OiQN2CWUaBuqH2dCwyAXvf67mIocySsC3MV7AFk2XK0Ah1DSH/vWepvKLYT4NPmLeg8J lp1ietmV1k++DW+oIxY9zyCqlnO33XmresHvVZLdrf9cApEafDTBC39gYvTCUabyITg/ vIqJ2cJP09ZfjAJ4AO88QRwTl5KT2JyhePI2vm0GYt1Pb4d/H6k1EH4suASegy1pZVpC 9cy5PSx2KVIhMSZ1U6btY5iqxiTfUMufaDmZpsOBDf5VztOLSEs0s8TuvdJOgpgDmVzD tNCQ==
X-Gm-Message-State: AMke39l6qX+6hHJhY2vjij4lubNYGGTcKz/Ue4QQ378JJCo/hL237GYd652kGmhUHxn49pVY
X-Received: by 10.25.221.195 with SMTP id w64mr750855lfi.31.1488543043655; Fri, 03 Mar 2017 04:10:43 -0800 (PST)
Received: from [192.168.0.166] ([85.235.12.155]) by smtp.gmail.com with ESMTPSA id a11sm2305395lfh.37.2017.03.03.04.10.42 for <oauth@ietf.org> (version=TLS1_2 cipher=ECDHE-RSA-AES128-GCM-SHA256 bits=128/128); Fri, 03 Mar 2017 04:10:42 -0800 (PST)
To: oauth@ietf.org
References: <148797332573.3278.6515135380852468551.idtracker@ietfa.amsl.com> <D2329C0E-C3F8-4F69-88AE-584561E45B65@ve7jtb.com>
From: Ludwig Seitz <ludwig@sics.se>
Message-ID: <be3b92bc-323a-70ca-b675-4596c7adbd26@sics.se>
Date: Fri, 03 Mar 2017 13:10:41 +0100
User-Agent: Mozilla/5.0 (X11; Linux x86_64; rv:45.0) Gecko/20100101 Thunderbird/45.7.0
MIME-Version: 1.0
In-Reply-To: <D2329C0E-C3F8-4F69-88AE-584561E45B65@ve7jtb.com>
Content-Type: multipart/signed; protocol="application/pkcs7-signature"; micalg="sha-256"; boundary="------------ms010906030509020008000900"
Archived-At: <https://mailarchive.ietf.org/arch/msg/oauth/T95jdUj2VAM95jUFstoH8XjaV58>
Subject: Re: [OAUTH-WG] Fwd: I-D Action: draft-ietf-oauth-pop-key-distribution-03.txt
X-BeenThere: oauth@ietf.org
X-Mailman-Version: 2.1.17
Precedence: list
List-Id: OAUTH WG <oauth.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/oauth>, <mailto:oauth-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/oauth/>
List-Post: <mailto:oauth@ietf.org>
List-Help: <mailto:oauth-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/oauth>, <mailto:oauth-request@ietf.org?subject=subscribe>
X-List-Received-Date: Fri, 03 Mar 2017 12:10:47 -0000

On 2017-02-24 22:58, John Bradley wrote:
> I updated the references but haven't made any other changes.
>
> I had some questions about it so though it was worth keeping alive
> at-least for discussion.
>
> There have been some other questions and proposed changes.
>
> I will take a look through them and see if what may be worth updating.
>
> John B.
>
>

Question about the 'aud' parameter: Wouldn't it be useful to allow other 
values than URIs for that one?

One could easily imagine a group identifier as value of that field, 
where the RS internally resolves whether it is part of that group and 
therefore the target audience of that token.

Regards,

Ludwig

-- 
Ludwig Seitz, PhD
Security Lab, RISE ICT/SICS
Phone +46(0)70-349 92 51