Re: [OAUTH-WG] [Errata Verified] RFC7800 (6187)

"Rob Wilton (rwilton)" <rwilton@cisco.com> Mon, 01 June 2020 12:27 UTC

Return-Path: <rwilton@cisco.com>
X-Original-To: oauth@ietfa.amsl.com
Delivered-To: oauth@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id B04793A087C; Mon, 1 Jun 2020 05:27:14 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -9.598
X-Spam-Level:
X-Spam-Status: No, score=-9.598 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, RCVD_IN_MSPIKE_H3=0.001, RCVD_IN_MSPIKE_WL=0.001, SPF_PASS=-0.001, URIBL_BLOCKED=0.001, USER_IN_DEF_DKIM_WL=-7.5] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (1024-bit key) header.d=cisco.com header.b=D/Kv0VA9; dkim=pass (1024-bit key) header.d=cisco.onmicrosoft.com header.b=g/+Dnjos
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id lzh3-XhJYjWB; Mon, 1 Jun 2020 05:27:13 -0700 (PDT)
Received: from rcdn-iport-4.cisco.com (rcdn-iport-4.cisco.com [173.37.86.75]) (using TLSv1.2 with cipher DHE-RSA-SEED-SHA (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id C7A653A087B; Mon, 1 Jun 2020 05:27:12 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=cisco.com; i=@cisco.com; l=3161; q=dns/txt; s=iport; t=1591014432; x=1592224032; h=from:to:cc:subject:date:message-id:references: in-reply-to:content-transfer-encoding:mime-version; bh=/0qb8kYHEY25chwzeF25hJ5KGIo2pkwDv1XedlfYmz0=; b=D/Kv0VA9m+qhGCiCQJds/S6N1RJqvUmyXDOF3ySM2b8z9cUA5kaKmsM7 EwXVWg04KdtgCDplTiubLYkvCl8gr0dv+5mcRwfF8l9S15XrE+Wli1HiM x7z5kqYANNNybRKOkR73l9I6GbwQ/T6QfOlC/JHVSvrPxp3dwqtN4VB8W A=;
IronPort-PHdr: =?us-ascii?q?9a23=3A5bqK5BM9z3aaX0Mif9Il6mtXPHoupqn0MwgJ65?= =?us-ascii?q?Eul7NJdOG58o//OFDEvKw13lrIQcPW5+8Xw+bVsqW1X2sG7N7BtX0Za5VDWl?= =?us-ascii?q?cDjtlehA0vBsOJSCiZZP7nZiA3BoJOAVli+XzoNElJXsvyeg6arni79zVHHB?= =?us-ascii?q?L5OEJ8Lfj0HYiHicOx2qiy9pTfbh8OiiC6ZOZ5LQ69qkPascxFjA=3D=3D?=
X-IronPort-Anti-Spam-Filtered: true
X-IronPort-Anti-Spam-Result: =?us-ascii?q?A0CAAACe89Re/5xdJa1mDgsBAQEBAQE?= =?us-ascii?q?BAQEBAQEBAQEBAQESAQEBAQEBAQEBAQEBQIFKgVBSB29YLywKh2EDjUKYTIJ?= =?us-ascii?q?SA1ULAQEBDAEBIwoCBAEBhEQCgiUCJDgTAgMBAQsBAQUBAQECAQYEbYVZDIV?= =?us-ascii?q?yAQEBAQMSKAYBATcBCwQCAQgRBAEBAR4QMh0IAgQBDQUIGoMFgksDLgEOoks?= =?us-ascii?q?CgTmIYXSBNIMBAQEFhQgYgg4JgTgBgmOJYxqBQT+BEUOCTT6BBIEaSQOBZjC?= =?us-ascii?q?DFYItjmqCUKIZCoJXmQ2CZpsykF+BXphugy4CBAIEBQIOAQEFgWoigUAPB3A?= =?us-ascii?q?VGhcPex2BIykJRxcCDZBAg3KEWTuFBD50AjUCBggBAQMJfItjAYEPAQE?=
X-IronPort-AV: E=Sophos;i="5.73,460,1583193600"; d="scan'208";a="766567744"
Received: from rcdn-core-5.cisco.com ([173.37.93.156]) by rcdn-iport-4.cisco.com with ESMTP/TLS/DHE-RSA-SEED-SHA; 01 Jun 2020 12:27:11 +0000
Received: from XCH-ALN-002.cisco.com (xch-aln-002.cisco.com [173.36.7.12]) by rcdn-core-5.cisco.com (8.15.2/8.15.2) with ESMTPS id 051CRB7j030541 (version=TLSv1.2 cipher=AES256-SHA bits=256 verify=FAIL); Mon, 1 Jun 2020 12:27:11 GMT
Received: from xhs-rcd-003.cisco.com (173.37.227.248) by XCH-ALN-002.cisco.com (173.36.7.12) with Microsoft SMTP Server (TLS) id 15.0.1497.2; Mon, 1 Jun 2020 07:27:11 -0500
Received: from xhs-aln-002.cisco.com (173.37.135.119) by xhs-rcd-003.cisco.com (173.37.227.248) with Microsoft SMTP Server (TLS) id 15.0.1497.2; Mon, 1 Jun 2020 07:27:10 -0500
Received: from NAM12-DM6-obe.outbound.protection.outlook.com (173.37.151.57) by xhs-aln-002.cisco.com (173.37.135.119) with Microsoft SMTP Server (TLS) id 15.0.1497.2 via Frontend Transport; Mon, 1 Jun 2020 07:27:10 -0500
ARC-Seal: i=1; a=rsa-sha256; s=arcselector9901; d=microsoft.com; cv=none; b=BlkgoeNX+SovZO+CLiG1/wPXzmCO/5NVxtCkpocBKcahclWI06SniDknl28+/rBO8kQMVDB9Hjcx7jTI/4yXe7HMbaogJgVPdfagMHi6XzhIxroGt9Pf3Rqsitmva3ZqQ72Vb9lBZZFc9GUQhlPUrXWcqJc5o+MgWKD1PP17Ps7Sxg7xwJzemdgLZZWL/HAZo0yxiR/k5yjt64HVfG8vwjz384yP+DxICRy+FkVY+72+QfSOsjFoUmPXPNFkrSn6WIxcRST+/9dMsMkNdaQZMR2MaCUN/rOh3+ZcH/VgWzQ8TL8GOK6X/So89/GRj0OgH8MPtRSMtZk9ALags2XXlA==
ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=microsoft.com; s=arcselector9901; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-SenderADCheck; bh=71a0V/6Ub57K+IWSC1CMOeQU8Y923y8xKNXyZSPZ2x8=; b=AOZuKl9W5VGuzyuclsia0pbzKuRaMx3wtuOPwc6HUkOqgb3xLT13JiNsdNRRGjPJs0A49nXTnHL0BFu+e8YmaIqEYF+xzzrUnp0yWQEyVD/oFFmTGTFDVvwPsixAxMAZS2LDRbZWx3kh6QxsjLLzFqCfk+0DGjpn0z+JHA39QO4Mxb7GgaIWmS6cC2nubUEpBUWmOV/j7cFsqIsg8nwMtU0JOiPMlKRd31sH7NR3nDbf9q2wTJ/CFbsmlnnjizhNLbZ9+FgFtHjAkaWf/L7FeyWPtcBkpyceF9X5drX5ohDn7OrB1OaqAHej+FM5hj1o34K+vHFAPWruOytDFU1ajg==
ARC-Authentication-Results: i=1; mx.microsoft.com 1; spf=pass smtp.mailfrom=cisco.com; dmarc=pass action=none header.from=cisco.com; dkim=pass header.d=cisco.com; arc=none
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=cisco.onmicrosoft.com; s=selector2-cisco-onmicrosoft-com; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-SenderADCheck; bh=71a0V/6Ub57K+IWSC1CMOeQU8Y923y8xKNXyZSPZ2x8=; b=g/+DnjosIR1EX9XLlW0R744KKjElHUjOjnTSb5zOiixcGRLk9irtxQzB6Jc9HhMvmzNLjVGvHGhlp+Z+Ii8JDIGbaH5pgWGNVSHDzA70yndpp2YQFfo57zRPCpKRUSQPgGuc2sLUANycZ6rE4s9gv4x/S3hqCQCkoJ+/V0oQ9IA=
Received: from MN2PR11MB4366.namprd11.prod.outlook.com (2603:10b6:208:190::17) by MN2PR11MB4647.namprd11.prod.outlook.com (2603:10b6:208:262::10) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.20.3045.17; Mon, 1 Jun 2020 12:27:10 +0000
Received: from MN2PR11MB4366.namprd11.prod.outlook.com ([fe80::e9d4:79b5:aef1:be18]) by MN2PR11MB4366.namprd11.prod.outlook.com ([fe80::e9d4:79b5:aef1:be18%5]) with mapi id 15.20.3045.024; Mon, 1 Jun 2020 12:27:09 +0000
From: "Rob Wilton (rwilton)" <rwilton@cisco.com>
To: Benjamin Kaduk <kaduk@mit.edu>, Pete Resnick <resnick@episteme.net>
CC: "mbj@microsoft.com" <mbj@microsoft.com>, "iesg@ietf.org" <iesg@ietf.org>, "ve7jtb@ve7jtb.com" <ve7jtb@ve7jtb.com>, "Hannes.Tschofenig@gmx.net" <Hannes.Tschofenig@gmx.net>, "oauth@ietf.org" <oauth@ietf.org>, "RFC Errata System" <rfc-editor@rfc-editor.org>
Thread-Topic: [Errata Verified] RFC7800 (6187)
Thread-Index: AQHWNuulQReviV4PKkaVPVtDH4tsaqjBkK2AgAAEBACAAhv7EA==
Date: Mon, 1 Jun 2020 12:27:09 +0000
Message-ID: <MN2PR11MB436654658A3926B05A9CC79BB58A0@MN2PR11MB4366.namprd11.prod.outlook.com>
References: <20200531013404.4528BF40721@rfc-editor.org> <AA62FB03-89F3-4931-AB7C-0BE281970A2E@episteme.net> <20200531040924.GM58497@kduck.mit.edu>
In-Reply-To: <20200531040924.GM58497@kduck.mit.edu>
Accept-Language: en-US
Content-Language: en-US
X-MS-Has-Attach:
X-MS-TNEF-Correlator:
authentication-results: mit.edu; dkim=none (message not signed) header.d=none;mit.edu; dmarc=none action=none header.from=cisco.com;
x-originating-ip: [64.103.40.27]
x-ms-publictraffictype: Email
x-ms-office365-filtering-correlation-id: fc5c4492-504e-49d5-6643-08d806271b07
x-ms-traffictypediagnostic: MN2PR11MB4647:
x-microsoft-antispam-prvs: <MN2PR11MB46476F9C8C00DFE28A101365B58A0@MN2PR11MB4647.namprd11.prod.outlook.com>
x-ms-oob-tlc-oobclassifiers: OLM:9508;
x-forefront-prvs: 0421BF7135
x-ms-exchange-senderadcheck: 1
x-microsoft-antispam: BCL:0;
x-microsoft-antispam-message-info: vHdzUXi0k0ExSUJO5pgSPtAuHz+PLyhntv/4QrmX2kV4FwoqGV0wnMkkRrxyrTsBAuHflqsPmt75yAmWz3eiKKI1/EOegacnt2ifoKGqKZEXxwoPTRsUEarGr2aiyOLmmxGG1PrICj6be8RBC1LL2Buscw1T7dMd3ZJMHwbUepLfcYlEFl3Yzg3XnycT5S/7UByiRfIPAY8fyBWW86obduPnrNAxTB7ohRpkDZSHvVs/+YnwELlpi8kti5FMwa4456DBykdWP8Pd7xMTpFdKDDF4hpRU+eT39zPJMiiyTr8pymVV/Kw+ExUlRQzzoWY51NWpfBN+TnLpfVHG8aHMFk15GzeUjoof68KpIbc+qpYD2LwHoAAkGOGNaaglHOzAoOcEdSVht77VfD+F2gVS0Q==
x-forefront-antispam-report: CIP:255.255.255.255; CTRY:; LANG:en; SCL:1; SRV:; IPV:NLI; SFV:NSPM; H:MN2PR11MB4366.namprd11.prod.outlook.com; PTR:; CAT:NONE; SFTY:; SFS:(4636009)(136003)(376002)(366004)(346002)(396003)(39860400002)(186003)(45080400002)(5660300002)(6506007)(2906002)(86362001)(26005)(8676002)(8936002)(83380400001)(52536014)(478600001)(966005)(76116006)(64756008)(66476007)(66946007)(66556008)(33656002)(66446008)(110136005)(316002)(54906003)(71200400001)(15650500001)(4326008)(7696005)(9686003)(53546011)(55016002); DIR:OUT; SFP:1101;
x-ms-exchange-antispam-messagedata: 6sd+wyPLHgVWVqrCF731oS6S1OrlENF1DTPHZ/XvlJdVod506QPsdJxPc/h21xMWMzrYa4wLpkTkjVYJsr5ecITCrCW7HX/sqVqUODJu+YPLNgxDKsnVIFyV+H4ROCbzQSAmKBOF0t7JYTqHgfQ1m014oKWYtu72WK3IxsNi1sxvio17+QidSz0z0glwzr++k8+MH/cYe4TrClx1o8dbjPahq0jzUWzHa/k5fMlm3fiyaHbpmOPZ3ESZMZZne+4Zm3XRZMDhZTvlxiT7P2WvsOUA0JmfJvrGGjZAlmmhUj5AcbCwIOsWI96Qx0y/CgVDVvvxoAQ4HPZdjYs9CaOlwnkj9IBmEkKh5rT6XkEudwKluFL4IAiEieZka2I64wTbVct2rzNz6k67FxcaBDUakqeKMwFWIAS3J+jY1wPbaL8Yx5Le7K1qMEy4wFZiA8NYnXUk9sKOnq4y4yzmjyKAy+67poWWNbYJXXM8eHHqL8I=
x-ms-exchange-transport-forked: True
Content-Type: text/plain; charset="us-ascii"
Content-Transfer-Encoding: quoted-printable
MIME-Version: 1.0
X-MS-Exchange-CrossTenant-Network-Message-Id: fc5c4492-504e-49d5-6643-08d806271b07
X-MS-Exchange-CrossTenant-originalarrivaltime: 01 Jun 2020 12:27:09.7137 (UTC)
X-MS-Exchange-CrossTenant-fromentityheader: Hosted
X-MS-Exchange-CrossTenant-id: 5ae1af62-9505-4097-a69a-c1553ef7840e
X-MS-Exchange-CrossTenant-mailboxtype: HOSTED
X-MS-Exchange-CrossTenant-userprincipalname: hCWCXEtS8bzymRHoM/Fo8eXPEpc/4FM2k3bAs8FlYaYGF+W2/5NqVkBwWnbY1JnRRx+tW2e6sXCRLYJ1g4Ag/g==
X-MS-Exchange-Transport-CrossTenantHeadersStamped: MN2PR11MB4647
X-OriginatorOrg: cisco.com
X-Outbound-SMTP-Client: 173.36.7.12, xch-aln-002.cisco.com
X-Outbound-Node: rcdn-core-5.cisco.com
Archived-At: <https://mailarchive.ietf.org/arch/msg/oauth/ep2z7pj0h__ihdWqoaYVi4kc2Po>
Subject: Re: [OAUTH-WG] [Errata Verified] RFC7800 (6187)
X-BeenThere: oauth@ietf.org
X-Mailman-Version: 2.1.29
Precedence: list
List-Id: OAUTH WG <oauth.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/oauth>, <mailto:oauth-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/oauth/>
List-Post: <mailto:oauth@ietf.org>
List-Help: <mailto:oauth-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/oauth>, <mailto:oauth-request@ietf.org?subject=subscribe>
X-List-Received-Date: Mon, 01 Jun 2020 12:27:15 -0000


> -----Original Message-----
> From: iesg <iesg-bounces@ietf.org> On Behalf Of Benjamin Kaduk
> Sent: 31 May 2020 05:09
> To: Pete Resnick <resnick@episteme.net>
> Cc: mbj@microsoft.com; iesg@ietf.org; ve7jtb@ve7jtb.com;
> Hannes.Tschofenig@gmx.net; oauth@ietf.org; RFC Errata System <rfc-
> editor@rfc-editor.org>
> Subject: Re: [Errata Verified] RFC7800 (6187)
> 
> The new text is clearly the right thing, and there is no need
> to debate it if/when the document gets updated.  "Don't hold
> it; do it now", so to speak -- and noting that (my
> understanding/recollection of) the plan for
> https://www.rfc-editor.org/rfc/inline-errata/rfc7800.html is that only
> verified errata, not those in other states, will be displayed.
[RW] 

If this ends up being the plan, then I think that we may wish to modify the RFC guidance, or possibly have two different verified states:
 (i) Verified, could impact implementations
 (ii) Verified, editorial only.

Certainly, it seems to be makes sense for these sorts of errata to be displayed.

Regards,
Rob


> 
> (Yes, that link 404s at the moment, I assume a caching issue.)
> 
> -Ben
> 
> On Sat, May 30, 2020 at 10:55:01PM -0500, Pete Resnick wrote:
> > "Verified", not "Hold For Document Update"?
> >
> > pr
> >
> > On 30 May 2020, at 20:34, RFC Errata System wrote:
> >
> > > The following errata report has been verified for RFC7800,
> > > "Proof-of-Possession Key Semantics for JSON Web Tokens (JWTs)".
> > >
> > > --------------------------------------
> > > You may review the report below and at:
> > > https://www.rfc-editor.org/errata/eid6187
> > >
> > > --------------------------------------
> > > Status: Verified
> > > Type: Editorial
> > >
> > > Reported by: Pete Resnick <resnick@episteme.net>
> > > Date Reported: 2020-05-26
> > > Verified by: Benjamin Kaduk (IESG)
> > >
> > > Section: 7.1
> > >
> > > Original Text
> > > -------------
> > >    [JWK]      Jones, M., "JSON Web Key (JWK)", RFC 7517,
> > >               DOI 10.17487/RFC7157, May 2015,
> > >               <http://www.rfc-editor.org/info/rfc7517>.
> > >
> > >
> > > Corrected Text
> > > --------------
> > >    [JWK]      Jones, M., "JSON Web Key (JWK)", RFC 7517,
> > >               DOI 10.17487/RFC7517, May 2015,
> > >               <http://www.rfc-editor.org/info/rfc7517>.
> > >
> > >
> > > Notes
> > > -----
> > > DOI has a typo: 7157 instead of 7517.
> > >
> > > --------------------------------------
> > > RFC7800 (draft-ietf-oauth-proof-of-possession-11)
> > > --------------------------------------
> > > Title               : Proof-of-Possession Key Semantics for JSON Web
> > > Tokens (JWTs)
> > > Publication Date    : April 2016
> > > Author(s)           : M. Jones, J. Bradley, H. Tschofenig
> > > Category            : PROPOSED STANDARD
> > > Source              : Web Authorization Protocol
> > > Area                : Security
> > > Stream              : IETF
> > > Verifying Party     : IESG
> >
> >
> > --
> > Pete Resnick https://www.episteme.net/
> > All connections to the world are tenuous at best