Re: [OAUTH-WG] CORRECTION: Re: Basic signature support in the core specification

Dick Hardt <dick.hardt@gmail.com> Mon, 27 September 2010 17:48 UTC

Return-Path: <dick.hardt@gmail.com>
X-Original-To: oauth@core3.amsl.com
Delivered-To: oauth@core3.amsl.com
Received: from localhost (localhost [127.0.0.1]) by core3.amsl.com (Postfix) with ESMTP id 2B8B43A6AD5 for <oauth@core3.amsl.com>; Mon, 27 Sep 2010 10:48:05 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.5
X-Spam-Level:
X-Spam-Status: No, score=-2.5 tagged_above=-999 required=5 tests=[AWL=0.099, BAYES_00=-2.599]
Received: from mail.ietf.org ([64.170.98.32]) by localhost (core3.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id daI48k6id+Fb for <oauth@core3.amsl.com>; Mon, 27 Sep 2010 10:48:04 -0700 (PDT)
Received: from mail-px0-f172.google.com (mail-px0-f172.google.com [209.85.212.172]) by core3.amsl.com (Postfix) with ESMTP id 8F8CF3A6B49 for <oauth@ietf.org>; Mon, 27 Sep 2010 10:48:03 -0700 (PDT)
Received: by pxi6 with SMTP id 6so1946519pxi.31 for <oauth@ietf.org>; Mon, 27 Sep 2010 10:48:43 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=gamma; h=domainkey-signature:received:received:subject:mime-version :content-type:from:in-reply-to:date:cc:content-transfer-encoding :message-id:references:to:x-mailer; bh=4A3SSxgwdvepfqDzFGjxW3oiHwjyXrbvl79HYR4bGpE=; b=mRQyZ9MR85WWYOAOhr88nr+i/bXUywWW4QjOYVceaWw/4dcc5snBvT1h4TpJlRXx/Q ZT63jEdl7O3TbELJkbfQFweBlFhlD2RksjI4VrEpuwkvGrTeplk5brhnJiiL+mwtXWWS UF/GKiKM8+xWiNluni2UBdfxx17ItKDQNZGcc=
DomainKey-Signature: a=rsa-sha1; c=nofws; d=gmail.com; s=gamma; h=subject:mime-version:content-type:from:in-reply-to:date:cc :content-transfer-encoding:message-id:references:to:x-mailer; b=EoKLuhuelPuVSEWtx22ObvGXaan7iwztmhT7IIIrXc81J4ojzcoWF1yF/vRnaWpfGI BAs1xfBBd1G5WCGBZZm2hM2AQ8LmDlo6fULWoWDsbLifppobtbpL49ijQlxYE9rnd4HC 7Qs62emK3VaJPSePKho3++2lXIU2PT3WjIEoo=
Received: by 10.142.142.8 with SMTP id p8mr6774827wfd.316.1285609722153; Mon, 27 Sep 2010 10:48:42 -0700 (PDT)
Received: from [192.168.1.5] ([24.130.32.55]) by mx.google.com with ESMTPS id c14sm7703078wfe.2.2010.09.27.10.48.39 (version=TLSv1/SSLv3 cipher=RC4-MD5); Mon, 27 Sep 2010 10:48:40 -0700 (PDT)
Mime-Version: 1.0 (Apple Message framework v1081)
Content-Type: text/plain; charset="us-ascii"
From: Dick Hardt <dick.hardt@gmail.com>
In-Reply-To: <4CA0CDEE.1000703@alcatel-lucent.com>
Date: Mon, 27 Sep 2010 10:48:38 -0700
Content-Transfer-Encoding: quoted-printable
Message-Id: <6FF3C6A7-2594-4A21-BFD1-8B421A086DC5@gmail.com>
References: <C8C2AB33.3AD38%eran@hueniverse.com> <BFD0447E-42BB-441F-A7B3-B0CFB0F6317B@gmail.com> <E0B0A685-4BA7-451B-B0DF-C0FC429595D1@xmlgrrl.com> <4CA0C96E.8090907@alcatel-lucent.com> <4CA0CDEE.1000703@alcatel-lucent.com>
To: igor.faynberg@alcatel-lucent.com
X-Mailer: Apple Mail (2.1081)
Cc: OAuth WG <oauth@ietf.org>
Subject: Re: [OAUTH-WG] CORRECTION: Re: Basic signature support in the core specification
X-BeenThere: oauth@ietf.org
X-Mailman-Version: 2.1.9
Precedence: list
List-Id: OAUTH WG <oauth.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/listinfo/oauth>, <mailto:oauth-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/oauth>
List-Post: <mailto:oauth@ietf.org>
List-Help: <mailto:oauth-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/oauth>, <mailto:oauth-request@ietf.org?subject=subscribe>
X-List-Received-Date: Mon, 27 Sep 2010 17:48:05 -0000

Myself and others feel that a spec for how to sign a request would be useful for other specifications. As I noted in a previous email, there was dismay when the signing of an OpenID message was very similar, but different than the signing in OAuth 1.0A. 

Signing messages was a huge stumbling block for OAuth 1.0A deployment. Having a more general signing specification that leads to generic libraries for signing and verifying would be a GOOD THING IMHO.

To be clear, I am not saying we should ignore signing, I see that it can be complex, particularly when you start looking at key discovery and multi algorithm support. I think it would be better to do it right in a spec rather than just including the OAUth 1.0A algorithm and it being cumbersome to deal with key management and alternative algorithm support.


On 2010-09-27, at 10:01 AM, Igor Faynberg wrote:

> 
> I mistyped, and just noticed that it looked strange.  I meant to type:
> Igor Faynberg wrote:
>> ...
>> But if both the OAuth signatures and the OAuth core specifications are complete and going for approval at the same time, why not actually have them in the same spec, especially given that THE (not "we") experts who have agreed working on this and ARE working on this?
>> 
>> Igor
>> 
>> 
>> 
>>>