Re: [OAUTH-WG] AD review of draft-ietf-oauth-iss-auth-resp-02

Warren Parad <wparad@rhosys.ch> Wed, 27 October 2021 20:10 UTC

Return-Path: <wparad@rhosys.ch>
X-Original-To: oauth@ietfa.amsl.com
Delivered-To: oauth@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id C1DB73A117A for <oauth@ietfa.amsl.com>; Wed, 27 Oct 2021 13:10:57 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.088
X-Spam-Level:
X-Spam-Status: No, score=-2.088 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, HTML_MESSAGE=0.001, SPF_HELO_NONE=0.001, SPF_PASS=-0.001, T_KAM_HTML_FONT_INVALID=0.01, URIBL_BLOCKED=0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (2048-bit key) header.d=rhosys.ch
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id pCvx41YYxLgi for <oauth@ietfa.amsl.com>; Wed, 27 Oct 2021 13:10:53 -0700 (PDT)
Received: from mail-yb1-xb32.google.com (mail-yb1-xb32.google.com [IPv6:2607:f8b0:4864:20::b32]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 1AC253A1177 for <oauth@ietf.org>; Wed, 27 Oct 2021 13:10:53 -0700 (PDT)
Received: by mail-yb1-xb32.google.com with SMTP id a6so9311324ybq.9 for <oauth@ietf.org>; Wed, 27 Oct 2021 13:10:53 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=rhosys.ch; s=google; h=mime-version:references:in-reply-to:from:date:message-id:subject:to :cc; bh=6ZTcFarIBBwKqzpooB5G353YSMNuekNa+bNCYaWmVv0=; b=b5YPns932GvC9oAF4+SbCahyb/yroyLZSdb4iLW0EPovjYNujDz2qx2qb3aIzi2MU9 jyp6cMfQPoRGSJQIvhYtbbnlIZCO50z3waZPClNO7PhGrWNm8FRqlBOGGfp7khJK40eY wxLrErPm8y8GBV5V+Got+O+s//2NuWdmnvuUTQmtyzCn2LIDxB4oGT/zI4BqNgZhKYoO rmGhZkApvawss3XERk9P2Ag47jB2YtdgAxESE7QKCh2D7eGuar54wRsdz7PEtRclDzDi nxBgMJbLzw5GqpOAx0Mqqzgb4hBHBG7PezEz8C5oBLPDllBr4tu6nR6sPTKQfeFMxuQz PLRQ==
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20210112; h=x-gm-message-state:mime-version:references:in-reply-to:from:date :message-id:subject:to:cc; bh=6ZTcFarIBBwKqzpooB5G353YSMNuekNa+bNCYaWmVv0=; b=fIFm7NUOmh7WqiB19cDN7eoA6puJsO/WozWzbRzV2fyN5r/PyRGtbrU3imfUVs+fUO /9nN4iS/jqYHDwJfDbLkGrxeptYbMFoH1RALk2RdeNWQZASCOKwMqe9wUxNzs/1rV2fn Jkx3LElbSV//nIQqj0l0LLFfFtCF1UXW4SwIW2UuYtcmaBbi1vtT5Y/BMcZ2IR2Ts8uG D2IYmIiClO+evskxkX5kGp84vn3jO/3MOY243D9Kvdh28O/DWsfULP9afV1gcS+qNsfW 9PuSByL7wzr1coSPwToSqngrIwouE+/Nx/Pdk50C5CXBkLDEc9kcjsqEnDV933xiD4X1 oz2Q==
X-Gm-Message-State: AOAM530UjTDKOaHpUh0nX8tHqvafiRdlv0rCCxKB3PJ9/fZIeI/C2Y6/ vp/FhZTH2Xicv06IAyZTS67vaXXs/cEXhx+dqlQL
X-Google-Smtp-Source: ABdhPJxiSpoHcj7kx7phWVRFLvyIcmJBD+fKhmQNib7lp9owB+ZmOEEipCA9SfQhoizLenN1rwhR3PNMIYEJqQ2QJGU=
X-Received: by 2002:a25:e652:: with SMTP id d79mr32369989ybh.291.1635365450740; Wed, 27 Oct 2021 13:10:50 -0700 (PDT)
MIME-Version: 1.0
References: <BN1P110MB0939DFB7DCA3DBBE3CCA7B53DC859@BN1P110MB0939.NAMP110.PROD.OUTLOOK.COM>
In-Reply-To: <BN1P110MB0939DFB7DCA3DBBE3CCA7B53DC859@BN1P110MB0939.NAMP110.PROD.OUTLOOK.COM>
From: Warren Parad <wparad@rhosys.ch>
Date: Wed, 27 Oct 2021 22:10:40 +0200
Message-ID: <CAJot-L26xWtTpu=zyBYyRYLoxO2jW5PDt5oQG8JdzxEcsYMHDg@mail.gmail.com>
To: Roman Danyliw <rdd@cert.org>
Cc: "oauth@ietf.org" <oauth@ietf.org>
Content-Type: multipart/alternative; boundary="000000000000c50c9f05cf5b30ca"
Archived-At: <https://mailarchive.ietf.org/arch/msg/oauth/VdQ8V7q9hvEDQlM14j-dSDYeoo4>
Subject: Re: [OAUTH-WG] AD review of draft-ietf-oauth-iss-auth-resp-02
X-BeenThere: oauth@ietf.org
X-Mailman-Version: 2.1.29
Precedence: list
List-Id: OAUTH WG <oauth.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/oauth>, <mailto:oauth-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/oauth/>
List-Post: <mailto:oauth@ietf.org>
List-Help: <mailto:oauth-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/oauth>, <mailto:oauth-request@ietf.org?subject=subscribe>
X-List-Received-Date: Wed, 27 Oct 2021 20:10:58 -0000

Would making it even simpler also work? (and is more consistent with the
6749 language)
>
> The decision of whether to accept such responses is beyond the scope of
> this specification.


Warren Parad

Founder, CTO
Secure your user data with IAM authorization as a service. Implement
Authress <https://authress.io/>.


On Wed, Oct 27, 2021 at 9:41 PM Roman Danyliw <rdd@cert.org> wrote:

> Hi!
>
> I performed an AD review of draft-ietf-oauth-iss-auth-resp-02.  Thanks for
> documenting this mitigation.
>
> The document is in good shape so I am advancing it to IETF LC.  Please
> treat these minor comments as part of that feedback:
>
> ** Section 2.4.  Editorial.
>
>    The decision of whether to accept such
>    responses is individual for every scenario and it is not in the scope
>    of this specification.
>
> Would it be more clear to say:
>
> "Local policy or configuration can determine whether to accept such
> responses and specific guidance is out of scope for this specification."
>
> There is also similar language in the next paragraph.
>
> ** Section 5.1 and 5.2.  Per the "Change Control" field, please
> s/IESG/IETF/
>
> Thanks,
> Roman
>
> _______________________________________________
> OAuth mailing list
> OAuth@ietf.org
> https://www.ietf.org/mailman/listinfo/oauth
>