[OAUTH-WG] Microsoft feedback on DPoP during April 2020 IIW session

Mike Jones <Michael.Jones@microsoft.com> Fri, 01 May 2020 02:29 UTC

Return-Path: <Michael.Jones@microsoft.com>
X-Original-To: oauth@ietfa.amsl.com
Delivered-To: oauth@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 060E53A0966 for <oauth@ietfa.amsl.com>; Thu, 30 Apr 2020 19:29:15 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.1
X-Spam-Level:
X-Spam-Status: No, score=-2.1 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIMWL_WL_HIGH=-0.001, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, HTML_MESSAGE=0.001, SPF_PASS=-0.001, URIBL_BLOCKED=0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (1024-bit key) header.d=microsoft.com
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id RC_FJ59rZnL6 for <oauth@ietfa.amsl.com>; Thu, 30 Apr 2020 19:29:12 -0700 (PDT)
Received: from NAM06-DM3-obe.outbound.protection.outlook.com (mail-eopbgr640102.outbound.protection.outlook.com [40.107.64.102]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 585173A0965 for <oauth@ietf.org>; Thu, 30 Apr 2020 19:29:12 -0700 (PDT)
ARC-Seal: i=1; a=rsa-sha256; s=arcselector9901; d=microsoft.com; cv=none; b=k1w80ytdYhgCCk8hZ+hpuGZ5AbFYP4ZxZBQMwaka8OQqDVJWpvH6OSptNOO9VJADUj4vJUab4rEif68iU6yLrtk4QC2DaEyMQG3fRA6UzIx3TqrB2yXnqtY4MTeEbc5CAcNbg2o4+cpI4NdFfp/oCu6QPpnz0zaQm5ZO8Sc9lgIIXPNUm7JndA663ka/l7R/NHxuxTxTa/G0NkcABJnLSPE/Qybi06w05iPAYH4KjmmVfQcqqOyvVB65LsF9pBFGOHsNbbkNS20V2xsCJPykAvWWaOjztD7Ln3d4uXzXdhIhfRulWCTA0eUvagxTvylh1xr8vMQ6RxBy7HCh6TwlnA==
ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=microsoft.com; s=arcselector9901; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-SenderADCheck; bh=PpUcBpviF5oVdoMvv4nELBEv9QPp+UxaFMzeHvCoOp0=; b=kBN3yZYeeI9ux/NOL6y921pg7FGHLiEf4MqI3VQUBQ9PXrF1wcMcrUqb9W95RRsHPvGGvaooGwEhiAzZ9it26DAEl8gEiNaQwhusAiiN8juWb2flbPS5sRRd+aCLZR9jiG7ggzpbFMQLhjJpppmxR/ULyNn8l2Ni0OURgJ+uv95F/GO6cnlw4/hYQ7nE2Gf+7k0ZYq9gXk9NApvkZOnDhg5FRIoRxUtv7QrjvG4ZvDJSuKeOpFnibmTGchm386DGVR+xnIBCcs3m7qbkAgSN3m2Mwc5JgtpJrTCFQm7+XZQRc2h6fPyMyFZlrxSsnQis+bIzOfqo8suMz8ucycgHLQ==
ARC-Authentication-Results: i=1; mx.microsoft.com 1; spf=pass smtp.mailfrom=microsoft.com; dmarc=pass action=none header.from=microsoft.com; dkim=pass header.d=microsoft.com; arc=none
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=microsoft.com; s=selector2; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-SenderADCheck; bh=PpUcBpviF5oVdoMvv4nELBEv9QPp+UxaFMzeHvCoOp0=; b=jKzz4cZI1dCkaUZKP7H2y4gytCK4m5ljQxXFFeJPd5cIm5qok6LhGkOWfef40hYIkf29msh+I2L60uNl7FAoCsCwHFQxTKEMB38pdV1VGcYitvT4O+c54rI+GJgEeMqc6GFXQG6mve0RjmtroGxzK8gyj1PJ0omxmCzb46PujiI=
Received: from MN2PR00MB0686.namprd00.prod.outlook.com (2603:10b6:208:15f::13) by MN2PR00MB0717.namprd00.prod.outlook.com (2603:10b6:208:1df::11) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.20.3003.0; Fri, 1 May 2020 02:29:03 +0000
Received: from MN2PR00MB0686.namprd00.prod.outlook.com ([fe80::40e9:d9bf:410:3971]) by MN2PR00MB0686.namprd00.prod.outlook.com ([fe80::40e9:d9bf:410:3971%6]) with mapi id 15.20.3003.000; Fri, 1 May 2020 02:29:03 +0000
From: Mike Jones <Michael.Jones@microsoft.com>
To: "oauth@ietf.org" <oauth@ietf.org>
CC: Dmitri Zagidulin <dzagidulin@gmail.com>
Thread-Topic: Microsoft feedback on DPoP during April 2020 IIW session
Thread-Index: AdYfX/8GEMZtSZuLRhqv1yhDrQL0jA==
Date: Fri, 1 May 2020 02:29:02 +0000
Message-ID: <MN2PR00MB0686F8BDA731C6F478C35EFCF5AB0@MN2PR00MB0686.namprd00.prod.outlook.com>
Accept-Language: en-US
Content-Language: en-US
X-MS-Has-Attach:
X-MS-TNEF-Correlator:
msip_labels: MSIP_Label_f42aa342-8706-4288-bd11-ebb85995028c_ActionId=2701754c-70fd-45a1-a7f6-0000e2a50e78; MSIP_Label_f42aa342-8706-4288-bd11-ebb85995028c_ContentBits=0; MSIP_Label_f42aa342-8706-4288-bd11-ebb85995028c_Enabled=true; MSIP_Label_f42aa342-8706-4288-bd11-ebb85995028c_Method=Standard; MSIP_Label_f42aa342-8706-4288-bd11-ebb85995028c_Name=Internal; MSIP_Label_f42aa342-8706-4288-bd11-ebb85995028c_SetDate=2020-05-01T00:21:08Z; MSIP_Label_f42aa342-8706-4288-bd11-ebb85995028c_SiteId=72f988bf-86f1-41af-91ab-2d7cd011db47;
authentication-results: ietf.org; dkim=none (message not signed) header.d=none;ietf.org; dmarc=none action=none header.from=microsoft.com;
x-originating-ip: [50.47.87.252]
x-ms-publictraffictype: Email
x-ms-office365-filtering-ht: Tenant
x-ms-office365-filtering-correlation-id: 5e511b52-635b-435c-d551-08d7ed7769fc
x-ms-traffictypediagnostic: MN2PR00MB0717:
x-microsoft-antispam-prvs: <MN2PR00MB07177B1263B6BD5E4E69CBDBF5AB0@MN2PR00MB0717.namprd00.prod.outlook.com>
x-ms-oob-tlc-oobclassifiers: OLM:9508;
x-forefront-prvs: 0390DB4BDA
x-ms-exchange-senderadcheck: 1
x-microsoft-antispam: BCL:0;
x-microsoft-antispam-message-info: OEsk3GyvpK3S7SXZ8qpyfOqEKRtpsHnJ5k99+NUlGBbQ5cR7PnAy+cjKhDoS/ssg1cS8Di+9508Dkh0pPMCDi9kTSP93DA/9ee5rFBrA43/DSohtNAlGV0fsddeTJ2q6A766vVMq/qcHGqBH0L1su2ye97+NX3wyK5Pflnd5ydOi+jNKZDfrkn3nn0nM7izKft9eYP3w6zWHKLv+LMcWliiPUNhuoq7rRv8JIktHJH5+I8UaUmZPJrupjjnctfFasMW2cYl1iSOrIgmuJPon2lmiYSobI8hH4CGDezSbgfHK+bZehGfJP1XoMqP1EdK+aaoBxCm1+xsni4CkGQPNlwjdsDFzZVeqkvFD55gvCHSNie4xqKo3xWxFdxY9jMOJgGIsdUZqtokhZAfq9N7LTHGD+9J0cS3cNxhVHA5jP7il4pZ+4fvTgcIt47DOM27jJzJGyJqOVBYJEDSwFFern5ckQpFM/WQfroNvQ194Zw3Xcw01oHsAXUUhAl/LtobTuhUYx/tqI2W/lt0wzbgm7A==
x-forefront-antispam-report: CIP:255.255.255.255; CTRY:; LANG:en; SCL:1; SRV:; IPV:NLI; SFV:NSPM; H:MN2PR00MB0686.namprd00.prod.outlook.com; PTR:; CAT:NONE; SFTY:; SFS:(4636009)(376002)(346002)(136003)(366004)(396003)(39860400002)(47530400004)(52536014)(66946007)(66476007)(64756008)(6916009)(66556008)(66446008)(4326008)(71200400001)(8676002)(8936002)(2906002)(6506007)(8990500004)(7696005)(9686003)(55016002)(186003)(26005)(316002)(82960400001)(82950400001)(86362001)(76116006)(10290500003)(478600001)(5660300002)(33656002); DIR:OUT; SFP:1102;
x-ms-exchange-antispam-messagedata: mx1WkhtHbUATBZEf9Odsv7zSCkA7nEB9TRpMZgvs2ccDli0J84uTKWAM9U+yE7J7o7ydHGZanGBh9zjqRdRfUt3CiCD4IFleGEmmbumVCGxrYqRx/kaVIvj2IZCajm9FQiGmbQKz8Obcc+VQBdbAUXPjZwm8eOB6XJWLq4bS4YfjULRvJU57n4k0+8fOMGC7neBoH7CzaNnh7G/5evMPAFYRme5gRNIYMokaMY2ST1UBzCc77h7bjAaRMO5vFUSOMdKnzwxfEcawfedlMkjSQ/197FG0C1jgYgulxuIMWp+MPakfwEvO7xPrETIdCi2TnpdYxBlQa8G6YHip8mf1c2TMw7ZBUYsLxQapD87v2ubkzlUHpFBZ7NWl35awsyYtstZR4IFyJpKC95U51TVc6jj93KVvX9+8QNM7/yIbzo0gCwy0N02zEsorwzy8Lil/yRYdB8Y7tcUureHdBYQSM6qti2rUTVbCHxqRJpHcitaYj3CcBId497JqSo5Pwl9gflGKAqtioqTZBKReqTQkrvLHKgKDc5nWKsCHl8hTh/S25Xj1NV1Dbw6hDr3xsih4t4G3dGE2xxJptWZ/F5bAky4as0rDwbH97q3psBDIcAjNO3cpa6TqxFyTRIX/epVhxBe8agwSGNs8hokIyBH1/2srMsH1t+ec16kxdWWooz484OFuGKwpy4ImOs1f+0cm8HDXuudy3WnFpWltS4F4IvkllgxjFjRzBaVwEEhdWtnL54qA8hsRmhcCoMtS4g4ukLyFUVHCGZQTKCUiaCQlyE7ftIctJBJPTrkvYvWA2Ss=
x-ms-exchange-transport-forked: True
Content-Type: multipart/alternative; boundary="_000_MN2PR00MB0686F8BDA731C6F478C35EFCF5AB0MN2PR00MB0686namp_"
MIME-Version: 1.0
X-OriginatorOrg: microsoft.com
X-MS-Exchange-CrossTenant-AuthAs: Internal
X-MS-Exchange-CrossTenant-AuthSource: MN2PR00MB0686.namprd00.prod.outlook.com
X-MS-Exchange-CrossTenant-Network-Message-Id: 5e511b52-635b-435c-d551-08d7ed7769fc
X-MS-Exchange-CrossTenant-originalarrivaltime: 01 May 2020 02:29:02.9461 (UTC)
X-MS-Exchange-CrossTenant-fromentityheader: Hosted
X-MS-Exchange-CrossTenant-id: 72f988bf-86f1-41af-91ab-2d7cd011db47
X-MS-Exchange-CrossTenant-mailboxtype: HOSTED
X-MS-Exchange-CrossTenant-userprincipalname: i4Otq/tClsduuJ6pSjh2eRUbFgnSQCsqY4wgaT4zam8vAnPUMpzs/ZQU57LGALLZ9g4A4yPrx41kL7qa9GKNZA==
X-MS-Exchange-Transport-CrossTenantHeadersStamped: MN2PR00MB0717
Archived-At: <https://mailarchive.ietf.org/arch/msg/oauth/qjs6-Am90Mu47WVVx5OLf-zfA7Y>
Subject: [OAUTH-WG] Microsoft feedback on DPoP during April 2020 IIW session
X-BeenThere: oauth@ietf.org
X-Mailman-Version: 2.1.29
Precedence: list
List-Id: OAUTH WG <oauth.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/oauth>, <mailto:oauth-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/oauth/>
List-Post: <mailto:oauth@ietf.org>
List-Help: <mailto:oauth-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/oauth>, <mailto:oauth-request@ietf.org?subject=subscribe>
X-List-Received-Date: Fri, 01 May 2020 02:29:16 -0000

Daniel Fett and David Waite (DW) hosted a great session on OAuth 2.0 Demonstration of Proof-of-Possession at the Application Layer (DPoP)<https://tools.ietf.org/html/draft-ietf-oauth-dpop-00> at the virtualized IIW<https://internetidentityworkshop.com/> this week.  Attendees also included Vittorio Bertocci, Justin Richer, Dmitri Zagidulin, and Tim Cappalli.

After Daniel and DW finished doing their overview of DPoP, I used some of the time to discuss feedback on DPoP from Microsoft Azure Active Directory (AAD) engineers.  We discussed:

  *   How do we know if the resource server supports DPoP?  One suggestion was to use a 401 WWW-Authenticate response from the RS.  We learned at IIW that some are already doing this.  People opposed trying to do Resource Metadata for this purpose alone.  However, they were supportive of defining AS Metadata to declare support for DPoP and Registration Metadata to declare support for DPoP.  This might declare the supported token_type values.
  *   How do we know what DPoP signing algorithms are supported?  This could be done via AS Metadata and possibly Registration Metadata.  People were also in favor of having a default algorithm - probably ES256.  Knowing this is important to preventing downgrade attacks.
  *   Can we have server nonces?  A server nonce is a value provided by the server (RS or AS) to be signed as part of the PoP proof.  People agreed that having a server nonce would add additional security.  It turns out that Dmitri is already doing this, providing the nonce as a WWW-Authenticate challenge value.
  *   Difficulties with jti at scale.  Trying to prevent replay with jti is problematic for large-scale deployments.  Doing duplicate detection across replicas requires ACID consistency, which is too expensive to be cost-effective.  Instead, large-scale implementations often use short timeouts to limit replay, rather performing reliable duplicate detection.
  *   Is the DPoP signature really needed when requesting a bound token?  It seems like the worst that could happen would be to create a token bound to a key you don't control, which you couldn't use.  Daniel expressed concern about this enabling substitution attacks.
  *   It seems like the spec requires the same token_type for both access tokens and refresh tokens.  Whereas it would be useful to be able to have DPoP refresh tokens and Bearer access tokens as a transition step.  Justin pointed out that the OAuth 2 protocol only has one token_type value - not separate ones for the refresh token and access token.  People agreed that this deserves consideration.
  *   Symmetric keys are significantly more efficient than asymmetric keys.  In discussions between John Bradley, Brian Campbell, and Mike Jones at IETF 106, John worked out how to deliver the symmetric key to the Token Endpoint without an extra round trip, however it would likely be more complicated to deliver it to the resource without an extra round trip.  At past IETFs, both Amazon and Okta have also advocated for symmetric key support.
  *   What are the problems resulting from PoP key reuse?  The spec assumes that a client will use the same PoP key for singing multiple token requests, both for access token and refresh token requests.  Is this a security issue?  Daniel responded that key reuse is typically only a problem when the same key is used for different algorithms or in different application contexts, when this reuse enables substitution attacks.  It's also the case that clients can choose to use different PoP keys whenever they choose to.
  *   Could access tokens be signed?  Having the DPoP key hash in the access token is equivalent if the access token is integrity protected.  But people said that many deployments don't use structured access tokens in which the key hash can be included.  For instance, Ping Identity uses access tokens that are just database indexes.  Would access token signing be needed then?
  *   Why aren't query parameters signed?  Daniel said that canonicalization of query parameters that use different URL escape syntaxes for representations of the same characters would likely result in interop problems.  People said that while SOAP deployments might have many logical endpoints differentiated only by query parameters, that's no longer the normal pattern for REST systems.

Thanks for the great discussion!

                                                       -- Mike