Re: [OAUTH-WG] MAC Tokens body hash

Phillip Hunt <> Wed, 03 August 2011 02:15 UTC

Return-Path: <>
Received: from localhost (localhost []) by (Postfix) with ESMTP id 5A38D11E80A7 for <>; Tue, 2 Aug 2011 19:15:19 -0700 (PDT)
X-Virus-Scanned: amavisd-new at
X-Spam-Flag: NO
X-Spam-Score: -2.638
X-Spam-Status: No, score=-2.638 tagged_above=-999 required=5 tests=[AWL=-1.436, BAYES_00=-2.599, HTML_MESSAGE=0.001, MIME_QP_LONG_LINE=1.396]
Received: from ([]) by localhost ( []) (amavisd-new, port 10024) with ESMTP id rn6qYtLoXMaE for <>; Tue, 2 Aug 2011 19:15:18 -0700 (PDT)
Received: from ( []) by (Postfix) with ESMTP id 6D2F011E8073 for <>; Tue, 2 Aug 2011 19:15:18 -0700 (PDT)
Received: from ( []) by (Switch-3.4.4/Switch-3.4.4) with ESMTP id p732F1cR021786 (version=TLSv1/SSLv3 cipher=DHE-RSA-AES256-SHA bits=256 verify=OK); Wed, 3 Aug 2011 02:15:03 GMT
Received: from ( []) by (8.14.4+Sun/8.14.4) with ESMTP id p732F0U9009647 (version=TLSv1/SSLv3 cipher=DHE-RSA-AES256-SHA bits=256 verify=NO); Wed, 3 Aug 2011 02:15:01 GMT
Received: from ( []) by ( with ESMTP id p732EtLb018700; Tue, 2 Aug 2011 21:14:55 -0500
Received: from [] (/ by default (Oracle Beehive Gateway v4.0) with ESMTP ; Tue, 02 Aug 2011 19:14:55 -0700
References: <90C41DD21FB7C64BB94121FBBC2E723450245F611B@P3PW5EX1MB01.EX1.SECURESERVER.NET> <> <90C41DD21FB7C64BB94121FBBC2E723450245F6626@P3PW5EX1MB01.EX1.SECURESERVER.NET>
In-Reply-To: <90C41DD21FB7C64BB94121FBBC2E723450245F6626@P3PW5EX1MB01.EX1.SECURESERVER.NET>
Mime-Version: 1.0 (iPhone Mail 8L1)
Content-Transfer-Encoding: 7bit
Content-Type: multipart/alternative; boundary="Apple-Mail-1--976955230"
Message-Id: <>
X-Mailer: iPhone Mail (8L1)
From: Phillip Hunt <>
Date: Tue, 02 Aug 2011 19:14:51 -0700
To: Eran Hammer-Lahav <>
X-Source-IP: []
X-Auth-Type: Internal IP
X-CT-RefId: str=0001.0A090206.4E38AF28.0018:SCFMA922111,ss=1,re=-6.300,fgs=0
Cc: Ben Adida <>, OAuth WG <>, "Adam Barth(" <>
Subject: Re: [OAUTH-WG] MAC Tokens body hash
X-Mailman-Version: 2.1.12
Precedence: list
List-Id: OAUTH WG <>
List-Unsubscribe: <>, <>
List-Archive: <>
List-Post: <>
List-Help: <>
List-Subscribe: <>, <>
X-List-Received-Date: Wed, 03 Aug 2011 02:15:19 -0000


On 2011-08-02, at 18:02, Eran Hammer-Lahav <> wrote:

> The idea is to drop 'ext' and 'bodyhash' due to being underspecified and therefore causing more harm than good. I added 'ext' to allow for application specific data to be included in the signed content. However, the name suggests this is an extension point for future specifications. I believe authentication schemes should not be extensible in ways that affect their security or interop properties and without additional text (registry, process, etc) for the 'ext' parameter, it will cause more issues than help.
> Instead of the 'ext' parameter I am suggesting the 'app' parameter which will do the same, but will be better positioned as an application-specific data. The prose will go a step further and recommend that the parameter value include a hash of the data, not the data itself. This is to ensure the parameter does not become part of the payload which is inappropriate for HTTP requests.
-1 what you describe appears to be a separate feature from ext
> As for the 'bodyhash' parameter, I would like to remove it because it is underspecified (we had an actual deployment experience showing that it doesn't produce interoperable implementations due to the many HTTP body transformation applied in most frameworks). Solving this issue is not possible due to the many different types of bodies and frameworks (and clearly operating on the "raw" body doesn't work). Instead, developers can use the new 'app' parameter to accomplish that.


> As for the normalized string, it will be adjusted to reflect these changes when they are made, so no placeholders which will require code change. Considering this is -00, it is clearly not a stable document.
> Will these changes work with your use cases?
>> -----Original Message-----
>> From: Skylar Woodward []
>> Sent: Tuesday, August 02, 2011 4:02 PM
>> To: Eran Hammer-Lahav
>> Cc: OAuth WG; Ben Adida; 'Adam Barth ('
>> Subject: Re: [OAUTH-WG] MAC Tokens body hash
>> hurrah!
>> (not necessarily for losing a way to sign the body, but for simplicity and
>> avoiding some of the potential inconsistencies w/ bodyhash).
>> Is your plan to reserve an empty line 6 for the Normalized Request String
>> (which was used for bodyhash) or eliminate it, brining the total to six
>> elements?
>> skylar
>> On Jul 30, 2011, at 3:43 AM, Eran Hammer-Lahav wrote:
>>> I plan to drop support for the bodyhash parameter in the next draft based
>> on bad implementation experience. Even with simple text body, UTF
>> encoding has introduced significant issues for us. The current draft does not
>> work using simple JS code between a browser and node.js even when both
>> use the same v8 engine due to differences in the body encoding. Basically,
>> the JS string used to send a request from the browser is not the actual string
>> sent on the wire.
>>> To fix that, we need to force UTF-8 encoding on both sides. However, that
>> is very much application specific. This will not work for non-text bodies.
>> Instead, the specification should offer a simple way to use the ext parameter
>> for such needs, including singing headers. And by offer I mean give
>> examples, but leave it application specific for now.
>>> I am open to suggestions but so far all the solutions I came up with will
>> introduce unacceptable complexity that will basically make this work useless.
>>> EHL
>>> _______________________________________________
>>> OAuth mailing list
> _______________________________________________
> OAuth mailing list