Re: [OAUTH-WG] MAC Cookies

Eran Hammer-Lahav <eran@hueniverse.com> Thu, 24 November 2011 17:19 UTC

Return-Path: <eran@hueniverse.com>
X-Original-To: oauth@ietfa.amsl.com
Delivered-To: oauth@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 9466621F8A6C for <oauth@ietfa.amsl.com>; Thu, 24 Nov 2011 09:19:51 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.49
X-Spam-Level:
X-Spam-Status: No, score=-2.49 tagged_above=-999 required=5 tests=[AWL=0.109, BAYES_00=-2.599]
Received: from mail.ietf.org ([12.22.58.30]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id ycJHfCuNZRZV for <oauth@ietfa.amsl.com>; Thu, 24 Nov 2011 09:19:51 -0800 (PST)
Received: from p3plex1out02.prod.phx3.secureserver.net (p3plex1out02.prod.phx3.secureserver.net [72.167.180.18]) by ietfa.amsl.com (Postfix) with SMTP id F2EE421F8A57 for <oauth@ietf.org>; Thu, 24 Nov 2011 09:19:50 -0800 (PST)
Received: (qmail 26503 invoked from network); 24 Nov 2011 17:19:50 -0000
Received: from unknown (HELO smtp.ex1.secureserver.net) (72.167.180.20) by p3plex1out02.prod.phx3.secureserver.net with SMTP; 24 Nov 2011 17:19:50 -0000
Received: from P3PW5EX1MB01.EX1.SECURESERVER.NET ([10.6.135.19]) by P3PW5EX1HT002.EX1.SECURESERVER.NET ([72.167.180.20]) with mapi; Thu, 24 Nov 2011 10:19:50 -0700
From: Eran Hammer-Lahav <eran@hueniverse.com>
To: Phil Hunt <phil.hunt@oracle.com>, Peter Wolanin <peter.wolanin@acquia.com>
Date: Thu, 24 Nov 2011 10:19:40 -0700
Thread-Topic: [OAUTH-WG] MAC Cookies
Thread-Index: Acyqe7vZbe1a7D/tQWaWbxp2Vq9s7gAUVCUw
Message-ID: <90C41DD21FB7C64BB94121FBBC2E7234526735F32B@P3PW5EX1MB01.EX1.SECURESERVER.NET>
References: <90C41DD21FB7C64BB94121FBBC2E7234526735EDF0@P3PW5EX1MB01.EX1.SECURESERVER.NET> <CAH0thKDCzvTkXB-OONghna2MEPTtqsJsYtL1tKR6SkcwooH48A@mail.gmail.com> <2E9E2454-C524-405A-8E05-48146566656B@oracle.com>
In-Reply-To: <2E9E2454-C524-405A-8E05-48146566656B@oracle.com>
Accept-Language: en-US
Content-Language: en-US
X-MS-Has-Attach:
X-MS-TNEF-Correlator:
acceptlanguage: en-US
Content-Type: text/plain; charset="us-ascii"
Content-Transfer-Encoding: quoted-printable
MIME-Version: 1.0
Cc: Ben Adida <ben@adida.net>, OAuth WG <oauth@ietf.org>, "Adam Barth (adam@adambarth.com)" <adam@adambarth.com>
Subject: Re: [OAUTH-WG] MAC Cookies
X-BeenThere: oauth@ietf.org
X-Mailman-Version: 2.1.12
Precedence: list
List-Id: OAUTH WG <oauth.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/oauth>, <mailto:oauth-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/oauth>
List-Post: <mailto:oauth@ietf.org>
List-Help: <mailto:oauth-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/oauth>, <mailto:oauth-request@ietf.org?subject=subscribe>
X-List-Received-Date: Thu, 24 Nov 2011 17:19:51 -0000

MAC tokens are a solution, not a use case :-)

As for reaching out, I'll leave it to the chairs to decide how to want to proceed.

EHL


> -----Original Message-----
> From: Phil Hunt [mailto:phil.hunt@oracle.com]
> Sent: Wednesday, November 23, 2011 11:36 PM
> To: Peter Wolanin
> Cc: Eran Hammer-Lahav; Ben Adida; OAuth WG; Adam Barth
> (adam@adambarth.com)
> Subject: Re: [OAUTH-WG] MAC Cookies
> 
> Eran,
> 
> I see value (at least for servers) in having browser and HTTP clients work with
> common tokens (e.g. MAC) - even though the mechanism for exchange may
> vary.
> 
> I had an email exchange with Harry Halpin. He suggests cross posting to the
> w3c public-identity list.
> 
> They are discussing web cryptography and MAC tokens may be an important
> use case.
> 
> Phil
> 
> @independentid
> www.independentid.com
> phil.hunt@oracle.com
> 
> 
> 
> 
> 
> On 2011-11-23, at 4:57 PM, Peter Wolanin wrote:
> 
> > No objection from me, but it's too bad the browser vendors aren't
> interested.
> >
> > -Peter
> >
> > On Sat, Nov 19, 2011 at 10:33 AM, Eran Hammer-Lahav
> <eran@hueniverse.com> wrote:
> >> I would like to drop the cookies support defined in the MAC document
> >> due to lack of interest from the browser vendors. At this point it is
> >> most likely going to be an unimplemented proposal. If there is
> >> interest in the future, it can be proposed in a separate document.
> >> This will allow us to bring this work to a quick conclusion.
> >>
> >>
> >>
> >> Any objections?
> >>
> >>
> >>
> >> EHL
> >>
> >>
> >> _______________________________________________
> >> OAuth mailing list
> >> OAuth@ietf.org
> >> https://www.ietf.org/mailman/listinfo/oauth
> >>
> >
> >
> >
> > --
> > Peter M. Wolanin, Ph.D.      : Momentum Specialist,  Acquia. Inc.
> > peter.wolanin@acquia.com : 781-313-8322
> >
> > "Get a free, hosted Drupal 7 site: http://www.drupalgardens.com"
> > _______________________________________________
> > OAuth mailing list
> > OAuth@ietf.org
> > https://www.ietf.org/mailman/listinfo/oauth