[OAUTH-WG] self-issued access tokens
toshio9.ito@toshiba.co.jp Wed, 29 September 2021 01:54 UTC
Return-Path: <toshio9.ito@toshiba.co.jp>
X-Original-To: oauth@ietfa.amsl.com
Delivered-To: oauth@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 843DA3A1A3B for <oauth@ietfa.amsl.com>; Tue, 28 Sep 2021 18:54:28 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.898
X-Spam-Level:
X-Spam-Status: No, score=-1.898 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, RCVD_IN_MSPIKE_H4=0.001, RCVD_IN_MSPIKE_WL=0.001, SPF_PASS=-0.001, URIBL_BLOCKED=0.001] autolearn=ham autolearn_force=no
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id ESym8XF6qCN6 for <oauth@ietfa.amsl.com>; Tue, 28 Sep 2021 18:54:23 -0700 (PDT)
Received: from mo-csw.securemx.jp (mo-csw1515.securemx.jp [210.130.202.154]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 0D5553A1A3A for <oauth@ietf.org>; Tue, 28 Sep 2021 18:54:22 -0700 (PDT)
Received: by mo-csw.securemx.jp (mx-mo-csw1515) id 18T1sKNR024867; Wed, 29 Sep 2021 10:54:20 +0900
X-Iguazu-Qid: 34trdvrI7t0hCezh2C
X-Iguazu-QSIG: v=2; s=0; t=1632880459; q=34trdvrI7t0hCezh2C; m=QueMIXqTXC9x4kdfrg4mDsDCDfMPLIhat4Nhpio7giQ=
Received: from imx2-a.toshiba.co.jp (imx2-a.toshiba.co.jp [106.186.93.35]) by relay.securemx.jp (mx-mr1512) id 18T1sJAm030452 (version=TLSv1.2 cipher=AES128-GCM-SHA256 bits=128 verify=NOT); Wed, 29 Sep 2021 10:54:19 +0900
Received: from enc01.toshiba.co.jp (enc01.toshiba.co.jp [106.186.93.100]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by imx2-a.toshiba.co.jp (Postfix) with ESMTPS id 8551C1000A5 for <oauth@ietf.org>; Wed, 29 Sep 2021 10:54:19 +0900 (JST)
Received: from hop001.toshiba.co.jp ([133.199.164.63]) by enc01.toshiba.co.jp with ESMTP id 18T1sJTT029086 for <oauth@ietf.org>; Wed, 29 Sep 2021 10:54:19 +0900
ARC-Seal: i=1; a=rsa-sha256; s=arcselector9901; d=microsoft.com; cv=none; b=ClpGl4FzsWhOphfSSmGmN4G4kR4m6hyfPkXKmHWfKidTeX8ez9QGm1JNEK66WdsNu5gRXsPwat5EU3D3uRD+CNDYMcbUbCEVWJpggE48zhoXx5zFmcePzfzK5KBPGcolCwLGGHj+S6r5ZsiEV6smxLEztm8P4rueLm9YK7jqe/TgNA4QNuET+5/mxXXaR8yGiZf4rJTCMqBg9AXNhTTJmkPMAQDXH1hq1/WDaOJJh3hM+ogpc1ee4WgHGkVcDdhNR4KINSZT4wp4CSF5p66aOaB+vvod3aCVttvKYcUP7brNyy9xyzOSJNNLasaXptWXXisdizwXCA9ZATfYis4kVg==
ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=microsoft.com; s=arcselector9901; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version; bh=UhQkpkCVWBcuNovOmzmucx9EtlQXhUbOPon59XieDXw=; b=nC1laxiQNJzMZwh+RbsDA8jcS0F3xxGe5rIDB7Zkw1zQrjfj+2/wraMj89v0fN/mwM17taU2PbTuVYlAJuMDXToKKfabuEW3pRmbEo9G666f4+l8U6QbAjrCThzmgJxZ7cROTVIcDINchj5OqdG7+nyIUSmUo47LWl9VRYYs6Elak5HyT5foontds333dEBn1QBpypgfhZKiEYlVWsBUMhtQVGsUE7u2YWPpaDCOcGCFQH7V/MspkZUajkirwm3iMJ3ZJN9VtzVfZBeiSPwFUSdt+InCCN9jZxmMkKGQhmITejNz69ybp644JcOs3K4GmAaFiamI+n8SRODQIQ/q+w==
ARC-Authentication-Results: i=1; mx.microsoft.com 1; spf=pass smtp.mailfrom=toshiba.co.jp; dmarc=pass action=none header.from=toshiba.co.jp; dkim=pass header.d=toshiba.co.jp; arc=none
From: toshio9.ito@toshiba.co.jp
To: oauth@ietf.org
Thread-Topic: self-issued access tokens
Thread-Index: Ade01Nk+d5eF4L5tTXCgjU67TgIDjw==
Date: Wed, 29 Sep 2021 01:54:15 +0000
X-TSB-HOP: ON
Message-ID: <TYCPR01MB567859999FB3350D6A1C63E5E5A99@TYCPR01MB5678.jpnprd01.prod.outlook.com>
Accept-Language: ja-JP, en-US
Content-Language: ja-JP
authentication-results: ietf.org; dkim=none (message not signed) header.d=none;ietf.org; dmarc=none action=none header.from=toshiba.co.jp;
x-ms-publictraffictype: Email
x-ms-office365-filtering-correlation-id: 2b783175-cbbc-4af0-f0ea-08d982ec0ae4
x-ms-traffictypediagnostic: TYYPR01MB6794:
x-microsoft-antispam-prvs: <TYYPR01MB67949F78528519AC8551A8EAE5A99@TYYPR01MB6794.jpnprd01.prod.outlook.com>
x-ms-oob-tlc-oobclassifiers: OLM:9508;
x-ms-exchange-senderadcheck: 1
x-ms-exchange-antispam-relay: 0
x-microsoft-antispam: BCL:0;
x-microsoft-antispam-message-info: 0L3cJC1zPkZqdm0Nzim+5jXIXNaGMsJJz4081Hu2rpjwUDOfiN8aipr6Lz0uVgXalp7FKYRwr/sCg1yYvNlYyb5pWFQFXkeX7yCtS20PioSyEa0H4eJYHhhS5NmMKJgCbnxZOObwa0mRSniiW2gW/XU0jS2rsaU4gajvvVmq4ZUUG+Jhuf7BDOCFRv1jzKtCUmr0NLM2101nuan8QrLAEShAQmx4AKnukpsf9sacMdUy5vooEQwliX7FzJQCXjQpJARFPk5zaVIpx/WW8IGhSxHwO+WbyL4HSyIpq80I2xOiapep+5ecogKvkpe9mFAe9d89iGuPIm/NIDDBHmq1mnanuFjxaoNrepiw7yg/ySwf8PSD0aQRL0Ee/BvSlCZZjIq74hsEtOzVUeRT2WF/tJ5XUgDdszENIyNLT1hMdm9H2yFKWnFnuGqlO9GRmnzZHxQGUUkW8rWEQ+BuArC7BmNw2cDFPuHpI3C3pBdNxBQ7wtaeHsSWITFXNNBnBbCCTOJRl48Fg3q7kW3I7l91h7IDjMpNzmBGW67BGIuA48Lqa6M7C78KSr3jr0D0YEfSHj/5SgqQ+V/m8jdXpeFofvVo6rugTUJS1km5dCCFKcHmxerKhOfPl7bh9kdwq1eDVV/AgMHne/MwOvzVRxqTpqrXVDmrgAg7d+AfXsFR0AcqpSuPIRSq99bGBBCt1dx+s+7mG/4uBdAwVDYONizBAt1bLmuIkKHd0mUAo5Z66bmBF/aJW9CNFBeD1lFicv9+1D8xR74tIPxj0fJO2sFnjGvk9x1bYMuDfZM8v3RqjVc=
x-forefront-antispam-report: CIP:255.255.255.255; CTRY:; LANG:en; SCL:1; SRV:; IPV:NLI; SFV:NSPM; H:TYCPR01MB5678.jpnprd01.prod.outlook.com; PTR:; CAT:NONE; SFS:(4636009)(366004)(66476007)(66446008)(33656002)(3480700007)(122000001)(5660300002)(2906002)(6916009)(52536014)(7696005)(64756008)(83380400001)(86362001)(76116006)(26005)(66946007)(66556008)(9686003)(508600001)(38100700002)(55016002)(38070700005)(8676002)(71200400001)(6506007)(966005)(186003)(316002)(8936002); DIR:OUT; SFP:1101;
x-ms-exchange-antispam-messagedata-chunkcount: 1
x-ms-exchange-antispam-messagedata-0: aaDTAdTOL592E/xll/5MulLnkCxCeLrhHFmbQWSCnZZIYe9ZtyAJzTlsSC1r2cBjU6IQo6z20wnFUEgN/WznrdujDaP8tCGi4Y6pKqBR65GIw0OaneXlub5ayQupypW7vcX3dBr48lHfuf+6khIllTB+7ExLKp6IbrOLSo7v1D4lLH3LMxOcBmpCaAT3SNmn69KVs5b2t0aDZLyM6VywIrZbgPy6KMDDfpuXAsWVN/Lc8NkpaOKlf35aiNziOm3xL0aoTwLxAG+B6Rm2AD/q+2yDY6Mpz82OOo3FpRZJGA5YCePcvQXOx2shzpGoohp7yL0rgUCu8QM5WBsA7UfaTaRTsfz7iCAx9Cd+67fhZpe7zg+Cx/LViB244DOQkvRjz2IU4vBiQ5uucRm1+yoTqqZXCX9y1MxjTPEz/ZF1R0ecSgteRlcltD5kaq0MxKpjBm6NoXQie+wFcf1CfQLwBHyXUDNC0FPrZZYciNMNjC1b6M8uVDOjZys5ChTjGjVUoE4ivlNXqDSvd7/t2gXg0407LpO61eoUrsGcpt110EtxbNrUhu57RLMnwxMJtpmMSguPb6L7nsHk9mNPpsdjdhDHTVt1jkk7500PREcP9++0wWpU/Fe50nAbLDj6O+UfiyvglaphncJZ4m1KPoAYiwc98pl2IQyJIiZ4T7GBaPuXgMPbOY0A/Xd/V4+jctCvWP3vlm4B7tEbfpu2mgs66USSm2bJYVTpLlHp0wkKEiW3vsCZWsaEARj0B6jtC5KM8u7O7o58cOIh1ei9Nr64Dh61AEz2NlcoioKCiI6O6VmTCwfVrrl91edG0Lb0CXHzlYFr4ziENqW06x3CP3Va+HKpwwwdeUfmMw55qMf2k3Lvf6Drm7QdAika2kaT/G3jrkpUwKVqE1CEjwhH8PmcEQQotdQQ0kYL2jYzbvfgwxO3rSdCnvt8iz8JEATOnW3O0wXJovefIri1xBioYAogchA2aD2U04Qy63qjyd6512E2U0uZ4c7vo+RnM+hRj8wja1RsHIY5DAEz+20T2Ei3sSZynt86zmmBCn63T6pnliHcZ8JxqZltybB5k27/Ut5tB18dx2OUrVh64m9b1oEngpZCFVGW4tC/zE2BGEJA+XsBpFb9aszaIqWSekwtR+xz20zwTO96pVjoFKZv11Rvw1HSWpALF77AHCb7Cnlr4nNmVtYyzFHWqSVSXvxP349abNeU0Oxk0SjHCZx/4riJNKxqqdW0H5x8KpGpFyYrep4aabjrqb9CeHpoFmzrfosPL9k0i45gR4hdHqOdSXUGi2JEEifRzodPw/RbKx8zsz4=
x-ms-exchange-transport-forked: True
Content-Type: text/plain; charset="iso-2022-jp"
Content-Transfer-Encoding: quoted-printable
MIME-Version: 1.0
X-MS-Exchange-CrossTenant-AuthAs: Internal
X-MS-Exchange-CrossTenant-AuthSource: TYCPR01MB5678.jpnprd01.prod.outlook.com
X-MS-Exchange-CrossTenant-Network-Message-Id: 2b783175-cbbc-4af0-f0ea-08d982ec0ae4
X-MS-Exchange-CrossTenant-originalarrivaltime: 29 Sep 2021 01:54:15.5518 (UTC)
X-MS-Exchange-CrossTenant-fromentityheader: Hosted
X-MS-Exchange-CrossTenant-id: f109924e-fb71-4ba0-b2cc-65dcdf6fbe4f
X-MS-Exchange-CrossTenant-mailboxtype: HOSTED
X-MS-Exchange-CrossTenant-userprincipalname: mdFX0qVoG6aGaJgN1PGvXcbefwRshwtcTwmVXhB33x5tn2/7eB0saKHf0BbFE5S+grgNz5AmJD3mL/Qv5H7P5a/hu4yotwu6bAfm88EIVg8=
X-MS-Exchange-Transport-CrossTenantHeadersStamped: TYYPR01MB6794
MSSCP.TransferMailToMossAgent: 103
X-OriginatorOrg: toshiba.co.jp
Archived-At: <https://mailarchive.ietf.org/arch/msg/oauth/pi8rkr8zdugLArFpxEWvJO4Q-RY>
Subject: [OAUTH-WG] self-issued access tokens
X-BeenThere: oauth@ietf.org
X-Mailman-Version: 2.1.29
Precedence: list
List-Id: OAUTH WG <oauth.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/oauth>, <mailto:oauth-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/oauth/>
List-Post: <mailto:oauth@ietf.org>
List-Help: <mailto:oauth-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/oauth>, <mailto:oauth-request@ietf.org?subject=subscribe>
X-List-Received-Date: Wed, 29 Sep 2021 01:54:29 -0000
Hi OAuth folks, I have a question. Is there (or was there) any standardizing effort for "self-issued access tokens"? Self-issued access tokens are mentioned in a blog post by P. Siriwardena in 2014 [*1]. It's an Access Token issued by the Client and sent to the Resource Server. The token is basically a signed document (e.g. JWT) by the private key of the Client. The Resource Server verifies the token with the public key, which is provisioned in the RS in advance. I think self-issued access tokens are handy replacement for Client Credentials Grant flow in simple deployments, where it's not so necessary to separate AS and RS. In fact, Google supports this type of authentication for some services [*2][*3]. I'm wondering if there are any other services supporting self-signed access tokens. Any comments are welcome. [*1]: https://wso2.com/library/blog-post/2014/10/blog-post-self-issued-access-tokens/ [*2]: https://developers.google.com/identity/protocols/oauth2/service-account#jwt-auth [*3]: https://google.aip.dev/auth/4111 ------------- Toshio Ito Research and Development Center Toshiba Corporation
- [OAUTH-WG] self-issued access tokens toshio9.ito
- Re: [OAUTH-WG] self-issued access tokens Dick Hardt
- Re: [OAUTH-WG] self-issued access tokens Vittorio Bertocci
- Re: [OAUTH-WG] self-issued access tokens Sascha Preibisch
- Re: [OAUTH-WG] self-issued access tokens Daniel Fett
- Re: [OAUTH-WG] self-issued access tokens Sascha Preibisch
- Re: [OAUTH-WG] self-issued access tokens Nikos Fotiou
- Re: [OAUTH-WG] self-issued access tokens David Waite
- Re: [OAUTH-WG] self-issued access tokens Nikos Fotiou
- Re: [OAUTH-WG] self-issued access tokens toshio9.ito
- Re: [OAUTH-WG] self-issued access tokens toshio9.ito
- Re: [OAUTH-WG] self-issued access tokens toshio9.ito
- Re: [OAUTH-WG] self-issued access tokens Dick Hardt
- Re: [OAUTH-WG] self-issued access tokens toshio9.ito
- Re: [OAUTH-WG] self-issued access tokens Dick Hardt
- Re: [OAUTH-WG] self-issued access tokens David Waite
- Re: [OAUTH-WG] self-issued access tokens toshio9.ito
- Re: [OAUTH-WG] self-issued access tokens Warren Parad
- Re: [OAUTH-WG] self-issued access tokens David Chadwick
- Re: [OAUTH-WG] self-issued access tokens Dick Hardt
- Re: [OAUTH-WG] self-issued access tokens toshio9.ito