Re: [OAUTH-WG] DPoP followup III: client auth

Filip Skokan <panva.ip@gmail.com> Thu, 03 December 2020 09:47 UTC

Return-Path: <panva.ip@gmail.com>
X-Original-To: oauth@ietfa.amsl.com
Delivered-To: oauth@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id D69E63A0DE8 for <oauth@ietfa.amsl.com>; Thu, 3 Dec 2020 01:47:02 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.096
X-Spam-Level:
X-Spam-Status: No, score=-2.096 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, FREEMAIL_FROM=0.001, HTML_IMAGE_RATIO_04=0.001, HTML_MESSAGE=0.001, SPF_HELO_NONE=0.001, SPF_PASS=-0.001, URIBL_BLOCKED=0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (2048-bit key) header.d=gmail.com
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id 9eBp8lgc1uaQ for <oauth@ietfa.amsl.com>; Thu, 3 Dec 2020 01:47:01 -0800 (PST)
Received: from mail-yb1-xb2d.google.com (mail-yb1-xb2d.google.com [IPv6:2607:f8b0:4864:20::b2d]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id EC81C3A0DE6 for <oauth@ietf.org>; Thu, 3 Dec 2020 01:47:00 -0800 (PST)
Received: by mail-yb1-xb2d.google.com with SMTP id s8so1418502yba.13 for <oauth@ietf.org>; Thu, 03 Dec 2020 01:47:00 -0800 (PST)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20161025; h=mime-version:references:in-reply-to:from:date:message-id:subject:to :cc; bh=Y4Ds04624udTmqMpCtcjor7A0jMER/z+U5tx+BdKxPg=; b=d8oIOxN4a7AcTn605t4GnHI1UxvJSU9tNsjX+7OepiwzUXDzeIyCZ9Hz5foz5c6HI6 bolBZCnUTuE2fQBhpG7uHv/yX01tnMdM6k1ENskrnXofGdrNONqag92v+YMXLxRZWkF6 IieRKMCfdW0UMw2IB6SmFKv6zNPCAThQy3R3uszIno7r6HymRoW9u6ab4WA5eM7h8EY8 8xTqi8MXek17qMd3P53KcG+zuMjAmcGmKiKDVQEnLNUdUjoyYpNgcoCX1V8txzHtv694 3xECSM71GrA5kBK0FCgVFaEljjfTWCaae7MLsqdAPyQGizoDpcmqCHstuI110PYmtnzp NpHQ==
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20161025; h=x-gm-message-state:mime-version:references:in-reply-to:from:date :message-id:subject:to:cc; bh=Y4Ds04624udTmqMpCtcjor7A0jMER/z+U5tx+BdKxPg=; b=YfDLG37KN2qjJrXX869VCXOeOTbiLMyFRSaauUlwZzcQ9fqXZFA30fUyHLWYYiGkaB B17df45yiJJdGZtFG1LBX930cibBgBwkpTw+QW/D4+EVlBi2XLHyujKoRtHf0py5x+Kc 89orv8zdMTl+K8b5sy0B/ve7UQdtygJNvFfK3gF4Fni3FRtbO/PFztI1LMws6kIoAm3g 2W67yEdlYZ2EeDARROD0+tSEzSSm+e4hc+rFMgv8nBGWjNu5Q3tS3OcQKRJUZYJ1i4FG b8sZAsT+8MxCUmFni1RoJPcNE71TgTeHXvzjLPJEZNlkH56WtU9mJhrWn5rtcXwF/voy FEMg==
X-Gm-Message-State: AOAM533x865VacDDmJO3kt+bng+ZIdzGoVIOMXDqa6vR51egM3YGofg8 POiGgYoYr505IWJxktPp3q4XdlfoBHzXPoleJw==
X-Google-Smtp-Source: ABdhPJw6Uh+n1kq5F8Oi8NCo/ESXjtiYHNZ8KsVKgb+lbDvLDeCqcOoGjVRMQZzJ8PEG60dIgmD86OYOfrNoUiCYBEs=
X-Received: by 2002:a25:fc20:: with SMTP id v32mr3054441ybd.351.1606988819496; Thu, 03 Dec 2020 01:46:59 -0800 (PST)
MIME-Version: 1.0
References: <CA+k3eCQjCjbcHxmTFn_Ce1aQ-gn31mAXNp9PGp7d6mXkfyDWPA@mail.gmail.com>
In-Reply-To: <CA+k3eCQjCjbcHxmTFn_Ce1aQ-gn31mAXNp9PGp7d6mXkfyDWPA@mail.gmail.com>
From: Filip Skokan <panva.ip@gmail.com>
Date: Thu, 03 Dec 2020 10:46:23 +0100
Message-ID: <CALAqi_-6ovK4otw9JW+c5H3qjnFrUqbwn-AoyGnA_EHfCSgQNw@mail.gmail.com>
To: Brian Campbell <bcampbell=40pingidentity.com@dmarc.ietf.org>
Cc: oauth <oauth@ietf.org>
Content-Type: multipart/related; boundary="000000000000c1439b05b58c3d64"
Archived-At: <https://mailarchive.ietf.org/arch/msg/oauth/fbhX1JP2Xq-hCWCb-KEzYoS9rWE>
Subject: Re: [OAUTH-WG] DPoP followup III: client auth
X-BeenThere: oauth@ietf.org
X-Mailman-Version: 2.1.29
Precedence: list
List-Id: OAUTH WG <oauth.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/oauth>, <mailto:oauth-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/oauth/>
List-Post: <mailto:oauth@ietf.org>
List-Help: <mailto:oauth-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/oauth>, <mailto:oauth-request@ietf.org?subject=subscribe>
X-List-Received-Date: Thu, 03 Dec 2020 09:47:03 -0000

🤫, better not open up the possibility of thinking of DPoP Proof keys as
pre-registered (i.e. not "ephemeral").

Best,
*Filip*


On Wed, 2 Dec 2020 at 23:30, Brian Campbell <bcampbell=
40pingidentity.com@dmarc.ietf.org> wrote:

> There were a few items discussed somewhat during the recent interim
> <https://datatracker.ietf.org/meeting/interim-2020-oauth-16/session/oauth>
> that I committed to bringing back to the list. The slide below (also
> available with a few extra spelling errors as slide #19 from the interim
> presentation
> <https://datatracker.ietf.org/meeting/interim-2020-oauth-16/materials/slides-interim-2020-oauth-16-sessa-dpop-01.pdf>)
> is the last of them.
>
> To summarize, I'm wondering if there's WG interest in working to formalize
> a client-to-AS authentication mechanism based on DPoP. I think it
> potentially would be problematic to put into the current document (for a
> number of reasons) so am preemptively ruling out that option. Thus,
> basically, I'm asking the WG if there is some/much interest in the idea? In
> which case I'll find some time (at some point) to write up an I-D for it
> and bring that back to the group for consideration. Or if I should, as the
> slide says, "shut up and never speak of this again"?
>
> [image: Slide19.jpeg]
>
>
> *CONFIDENTIALITY NOTICE: This email may contain confidential and
> privileged material for the sole use of the intended recipient(s). Any
> review, use, distribution or disclosure by others is strictly prohibited.
> If you have received this communication in error, please notify the sender
> immediately by e-mail and delete the message and any file attachments from
> your computer. Thank you.*_______________________________________________
> OAuth mailing list
> OAuth@ietf.org
> https://www.ietf.org/mailman/listinfo/oauth
>