Return-Path: <aaron@parecki.com>
X-Original-To: oauth@ietfa.amsl.com
Delivered-To: oauth@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1])
	by ietfa.amsl.com (Postfix) with ESMTP id BDC90C169402
	for <oauth@ietfa.amsl.com>; Tue, 21 Jan 2025 12:18:00 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.105
X-Spam-Level: 
X-Spam-Status: No, score=-2.105 tagged_above=-999 required=5
	tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1,
	DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, HTML_MESSAGE=0.001,
	RCVD_IN_DNSWL_NONE=-0.0001, RCVD_IN_ZEN_BLOCKED_OPENDNS=0.001,
	SPF_HELO_NONE=0.001, SPF_PASS=-0.001, T_SCC_BODY_TEXT_LINE=-0.01,
	URIBL_BLOCKED=0.001, URIBL_DBL_BLOCKED_OPENDNS=0.001,
	URIBL_ZEN_BLOCKED_OPENDNS=0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (2048-bit key)
	header.d=parecki.com
Received: from mail.ietf.org ([50.223.129.194])
	by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024)
	with ESMTP id pxSAg9MBTNut for <oauth@ietfa.amsl.com>;
	Tue, 21 Jan 2025 12:17:56 -0800 (PST)
Received: from mail-vs1-xe2c.google.com (mail-vs1-xe2c.google.com
 [IPv6:2607:f8b0:4864:20::e2c])
	(using TLSv1.3 with cipher TLS_AES_128_GCM_SHA256 (128/128 bits)
	 key-exchange X25519 server-signature ECDSA (P-256) server-digest SHA256)
	(No client certificate requested)
	by ietfa.amsl.com (Postfix) with ESMTPS id 0E78EC14F5E5
	for <oauth@ietf.org>; Tue, 21 Jan 2025 12:17:55 -0800 (PST)
Received: by mail-vs1-xe2c.google.com with SMTP id
 ada2fe7eead31-4afe4f1ce18so1638733137.3
        for <oauth@ietf.org>; Tue, 21 Jan 2025 12:17:55 -0800 (PST)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed;
        d=parecki.com; s=google; t=1737490674; x=1738095474; darn=ietf.org;
        h=cc:to:subject:message-id:date:from:in-reply-to:references
         :mime-version:from:to:cc:subject:date:message-id:reply-to;
        bh=APsjsS9uEVfg6WQCHjpkKPKlZX7/xZrpB42fo6wO87U=;
        b=F28j4nAd4uGiUdPgkO1PAJRisf76lKpgqmLdecH9h/eBJ8T4XkwMXKzdA6HoBiqLDH
         GZXwc9VG/QPRxDM5EH8tzBOJidyQ9Vfj34yMEuzyUDRK1Y5SJgcqAftyrj0ydrRpkgju
         0sm//PwtVtBKczRQReQ0mEIWUEdhPPvozEyFvIYkMdPGzrVHiKdqGEUEZjlfY69xav/H
         7vPg2+OZS8LS6WxVnW0AtxbUl+UsRKzK4Q7agm81T+OGJpnjOwYc3iE0Z+K95gmlnouX
         swevHl/GZ0IHzfA/D6kb1iFfPdrOh9ILyEdz9BYoeHquBRMGWel3l4omu5CgkvTyuC/G
         lkKA==
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed;
        d=1e100.net; s=20230601; t=1737490674; x=1738095474;
        h=cc:to:subject:message-id:date:from:in-reply-to:references
         :mime-version:x-gm-message-state:from:to:cc:subject:date:message-id
         :reply-to;
        bh=APsjsS9uEVfg6WQCHjpkKPKlZX7/xZrpB42fo6wO87U=;
        b=Cf+K4hQilXHSA/wGAxQ/2OEHO0Gu1c5POVBWXVmEpdSe3JXfurV1dxd99qWJdlSolk
         Izv5miajRq685jk5TzDnIbIWWCuaZAta4wPR83jMI9OWPBZRf9IDdJ3gHW4y2AzVH4pv
         f/Z2lT1gYrdWGvnbUOicxccnvB+mYqKSO4xaaSjBaZ9RArKsBWWufc/4woMde/cM19qG
         lGKP5ovU0RoR6kLMVwxDkIMi/fgntVs7Rrcz/7sla5+NoynHaQ5/jeqgz2JR/eftvUKr
         jzM3tLBb+ewwaGngbhiMqXzoy+1Z/VktaCZwZw+bmHiSPway9MJIhbe1eWCIThpRrdO7
         DYOw==
X-Gm-Message-State: AOJu0Yx50ryX7NrK0lQuxKNzoVxxTBQrcFqhKy4TtDSx0f7dRuRgyb8g
	JSmhdll6IC4hMDx5G/Hi4fpk2wdAxguaJ8JHiJX59llYudVBmlDDG+/GyNiNNktg4H/xkjfarYw
	=
X-Gm-Gg: ASbGnct/EI5bGHDg49XD0OUziVcHA8T2sOd5yJ2l8FatRUhbgpvpOF7tf5+YKLwCfXr
	NpUhTdwCHHENcd2sP6n6oZnvov/0IN8Xa3lt2P7wrJmMlB1sVUxJsUfcXm8f/ERXWAYAzhGrluo
	PAx5cqRbpX4Lha3yz+j/KIpTo8ZwCsTbADkvnXOZbCfEIUO+tnlqnteXvkpYIBy0/CVJP9VyrU+
	qSbHK9f8OqU8LgA2u/hHQskFnnB86fl+vATyIU2ox/boeSmctnWz40k4RvpZtwnvam5z+hl6Eod
	6KD69yBE8jDyznDU2p85Uefy1OhbzdPA
X-Google-Smtp-Source: 
 AGHT+IE+s+w7GEmJ3z+pn/LrTgecNhWh9hBBfxyVTeldR6NAHGosfnYKNYMTFzr4VBmaOJf8NQ9cRg==
X-Received: by 2002:a05:6102:374e:b0:4b6:d773:afca with SMTP id
 ada2fe7eead31-4b6d773b459mr3488976137.16.1737490674469;
        Tue, 21 Jan 2025 12:17:54 -0800 (PST)
Received: from mail-vk1-f175.google.com (mail-vk1-f175.google.com.
 [209.85.221.175])
        by smtp.gmail.com with ESMTPSA id
 a1e0cc1a2514c-8642ccac9d9sm2552423241.33.2025.01.21.12.17.53
        for <oauth@ietf.org>
        (version=TLS1_3 cipher=TLS_AES_128_GCM_SHA256 bits=128/128);
        Tue, 21 Jan 2025 12:17:53 -0800 (PST)
Received: by mail-vk1-f175.google.com with SMTP id
 71dfb90a1353d-518ae5060d4so1696090e0c.0
        for <oauth@ietf.org>; Tue, 21 Jan 2025 12:17:53 -0800 (PST)
X-Received: by 2002:a05:6122:8c5:b0:518:8bfe:d5f0 with SMTP id
 71dfb90a1353d-51d51a6e4f3mr13617201e0c.0.1737490672921; Tue, 21 Jan 2025
 12:17:52 -0800 (PST)
MIME-Version: 1.0
References: 
 <CAMm+Lwgykk+B2UspfXBcLipFiTifNBf-WG-DeXPpWT39syqqVg@mail.gmail.com>
 <CAD9ie-tYsCODGfNTBDZgr46s4O4B9-u79jR=G10y4sN5HBiKgQ@mail.gmail.com>
 <CAMm+Lwje3G7EPkapFfVksbNtPN11LOs7Gj3Jj09uuFyvAb4FRQ@mail.gmail.com>
 <CAJot-L06J-T7vK2FJY4JGFQj4Zu=xFyNnKpnNM2SktCpOuTDKw@mail.gmail.com>
 <CAMm+Lwg+OizX_+bW7gkFqE3S6OGdF=h=7hpMSgnREWiqawiA5g@mail.gmail.com>
 <CAJot-L1rbkYg3rooqLrWw5StrqJMFZp7puc4GK+ACOqPtVbaig@mail.gmail.com>
 <CAMm+Lwj6qFy+njAd1T1F70EieJfxHCnkEcVLiGf8u7gSjhg0Kw@mail.gmail.com>
In-Reply-To: 
 <CAMm+Lwj6qFy+njAd1T1F70EieJfxHCnkEcVLiGf8u7gSjhg0Kw@mail.gmail.com>
From: Aaron Parecki <aaron@parecki.com>
Date: Tue, 21 Jan 2025 12:17:42 -0800
X-Gmail-Original-Message-ID: 
 <CAGBSGjr_9zw6=9EhDM7X6pDu2FxtOcjHycZhw=0QKoFhq2Kfaw@mail.gmail.com>
X-Gm-Features: AbW1kvZg-HsppZ8krR8xIbdDQNKoK1EGPlwLkkRm8cb4A2JEexISRjlJ8VAKKk4
Message-ID: 
 <CAGBSGjr_9zw6=9EhDM7X6pDu2FxtOcjHycZhw=0QKoFhq2Kfaw@mail.gmail.com>
To: Phillip Hallam-Baker <phill@hallambaker.com>
Content-Type: multipart/alternative; boundary="0000000000005c3c5d062c3d12e9"
Message-ID-Hash: HFELFYSOTDIAJNC22ZMKGZFQ452BRNLI
X-Message-ID-Hash: HFELFYSOTDIAJNC22ZMKGZFQ452BRNLI
X-MailFrom: aaron@parecki.com
X-Mailman-Rule-Misses: dmarc-mitigation; no-senders; approved; emergency;
 loop; banned-address; member-moderation; header-match-oauth.ietf.org-0;
 nonmember-moderation; administrivia; implicit-dest; max-recipients; max-size;
 news-moderation; no-subject; digests; suspicious-header
CC: oauth@ietf.org
X-Mailman-Version: 3.3.9rc6
Precedence: list
Subject: =?utf-8?q?=5BOAUTH-WG=5D_Re=3A_DNS_Handles?=
List-Id: OAUTH WG <oauth.ietf.org>
Archived-At: 
 <https://mailarchive.ietf.org/arch/msg/oauth/rDQtnTLfVsROsnFpWAmv78b4MSc>
List-Archive: <https://mailarchive.ietf.org/arch/browse/oauth>
List-Help: <mailto:oauth-request@ietf.org?subject=help>
List-Owner: <mailto:oauth-owner@ietf.org>
List-Post: <mailto:oauth@ietf.org>
List-Subscribe: <mailto:oauth-join@ietf.org>
List-Unsubscribe: <mailto:oauth-leave@ietf.org>

--0000000000005c3c5d062c3d12e9
Content-Type: text/plain; charset="UTF-8"
Content-Transfer-Encoding: quoted-printable

Phillip, please take a look at this spec which is a complete description of
everything to implement a profile of OAuth based on DNS handles:

https://indieauth.spec.indieweb.org

I also have a blog post that talks about this architecture from an OAuth
POV: https://aaronparecki.com/2018/07/07/7/oauth-for-the-open-web

This has been deployed for many years, though not at the scale of BlueSky.
There's a few commercial services that use it, there's plugins for
Wordpress and Drupal, and a bunch of home-grown implementations.

I've been breaking up the spec into smaller I-Ds, most recently presenting
this at the OAuth interim meeting earlier this month:

https://datatracker.ietf.org/doc/html/draft-parecki-oauth-client-id-scheme
https://datatracker.ietf.org/doc/html/draft-parecki-oauth-client-id-metadat=
a-document

These are also what the BlueSky implementation is based on.

Aaron

On Tue, Jan 21, 2025 at 12:03=E2=80=AFPM Phillip Hallam-Baker <phill@hallam=
baker.com>
wrote:

> On Tue, Jan 21, 2025 at 2:43=E2=80=AFPM Warren Parad <wparad@rhosys.ch> w=
rote:
>
>> The only thing lacking is a base of authentication service providers tha=
t
>>> are willing to give users control.
>>
>>
>> As someone who works for one of those "authentication service providers"=
,
>> what exactly would we need to support that we don't already?
>>
>
> I am writing a draft. The short answer is almost nothing. But not nothing=
.
>
> The longer answer is that we need to have:
>
> 1) A detailed explanation that puts ALL the information needed to
> implement against the profile in one place. I am working on an Internet
> draft to do exactly that.
>
> 2) A discussion of how to best present the scheme as something whose
> primary purpose is as an authentication provider rather than an account
> with one social media property that can also be used elsewhere.
>
> 3) A discussion of how to use the DNS handles to enable end-to-end secure
> messaging. If Bob is reading a comment by Alice under @alice.example.com,
> that is the handle he is likely to want to use to message her.
>
> 4) A discussion about what else we might want a DNS handle provider to
> support. I have a prototype running that extends to supporting the IoT
> requirements raised in SETTLE.
>
> Right now, we have 'a' way to do this which is not necessarily the best
> way or the way that allows us to grow in all the ways we might want in th=
e
> future.
>
> I have a history of being able to market protocols and get them into
> widespread use. I haven't always been successful but have more successes
> than failures and I think I know what it takes to make DNS Handles widely
> used, which businesses I need to approach, etc. etc.
>
> The reason I am raising this here now, is that before I go round to the
> DNS registrars (and their affiliates) and the VPN providers and such to s=
ay
> this is the thing to do, I want to make sure we have everything straight =
at
> a technical level so we are all on the same page.
>
>
> _______________________________________________
> OAuth mailing list -- oauth@ietf.org
> To unsubscribe send an email to oauth-leave@ietf.org
>

--0000000000005c3c5d062c3d12e9
Content-Type: text/html; charset="UTF-8"
Content-Transfer-Encoding: quoted-printable

<div dir=3D"ltr">Phillip, please take a look at this spec which is a comple=
te description of everything to implement a profile of OAuth based on DNS h=
andles:<div><br></div><div><a href=3D"https://indieauth.spec.indieweb.org">=
https://indieauth.spec.indieweb.org</a></div><div><br></div><div>I also hav=
e a blog post that talks about this architecture from an OAuth POV:=C2=A0<a=
 href=3D"https://aaronparecki.com/2018/07/07/7/oauth-for-the-open-web">http=
s://aaronparecki.com/2018/07/07/7/oauth-for-the-open-web</a></div><div><br>=
</div><div>This has been deployed for many years, though not at the scale o=
f BlueSky. There&#39;s a few commercial services that use it, there&#39;s p=
lugins for Wordpress and Drupal, and a bunch of home-grown implementations.=
</div><div><br></div><div>I&#39;ve been breaking up the spec into smaller I=
-Ds, most recently presenting this at the OAuth interim meeting earlier thi=
s month:</div><div><br></div><div><a href=3D"https://datatracker.ietf.org/d=
oc/html/draft-parecki-oauth-client-id-scheme">https://datatracker.ietf.org/=
doc/html/draft-parecki-oauth-client-id-scheme</a></div><div><a href=3D"http=
s://datatracker.ietf.org/doc/html/draft-parecki-oauth-client-id-metadata-do=
cument">https://datatracker.ietf.org/doc/html/draft-parecki-oauth-client-id=
-metadata-document</a></div><div><br></div><div>These are also what the Blu=
eSky implementation is based on.</div><div><br></div><div>Aaron</div></div>=
<br><div class=3D"gmail_quote gmail_quote_container"><div dir=3D"ltr" class=
=3D"gmail_attr">On Tue, Jan 21, 2025 at 12:03=E2=80=AFPM Phillip Hallam-Bak=
er &lt;<a href=3D"mailto:phill@hallambaker.com">phill@hallambaker.com</a>&g=
t; wrote:<br></div><blockquote class=3D"gmail_quote" style=3D"margin:0px 0p=
x 0px 0.8ex;border-left:1px solid rgb(204,204,204);padding-left:1ex"><div d=
ir=3D"ltr"><div dir=3D"ltr"><div class=3D"gmail_default" style=3D"font-size=
:small">On Tue, Jan 21, 2025 at 2:43=E2=80=AFPM Warren Parad &lt;<a href=3D=
"mailto:wparad@rhosys.ch" target=3D"_blank">wparad@rhosys.ch</a>&gt; wrote:=
</div></div><div class=3D"gmail_quote"><blockquote class=3D"gmail_quote" st=
yle=3D"margin:0px 0px 0px 0.8ex;border-left:1px solid rgb(204,204,204);padd=
ing-left:1ex"><div dir=3D"ltr"><blockquote class=3D"gmail_quote" style=3D"m=
argin:0px 0px 0px 0.8ex;border-left:1px solid rgb(204,204,204);padding-left=
:1ex">The only thing lacking is a base of authentication service providers =
that are willing to give users control.</blockquote><div><br></div><div>As =
someone who works for one of those &quot;authentication service providers&q=
uot;, what exactly would we need to support that we don&#39;t already?</div=
></div></blockquote><div><br></div><div class=3D"gmail_default" style=3D"fo=
nt-size:small">I am writing a draft. The short answer is almost nothing. Bu=
t not nothing.</div><div class=3D"gmail_default" style=3D"font-size:small">=
<br></div><div class=3D"gmail_default" style=3D"font-size:small">The longer=
 answer is that we need to have:</div><div class=3D"gmail_default" style=3D=
"font-size:small"><br></div><div class=3D"gmail_default" style=3D"font-size=
:small">1) A detailed explanation that puts ALL the information needed to i=
mplement against the profile in one place. I am working on an Internet draf=
t to do exactly that.</div><div class=3D"gmail_default" style=3D"font-size:=
small"><br></div><div class=3D"gmail_default" style=3D"font-size:small">2) =
A discussion of how to best present the scheme as something whose primary p=
urpose is as an authentication provider rather than an account with one soc=
ial media property that can also be used elsewhere.</div><div class=3D"gmai=
l_default" style=3D"font-size:small"><br></div><div class=3D"gmail_default"=
 style=3D"font-size:small">3) A discussion of how to use the DNS handles to=
 enable end-to-end secure messaging. If Bob is reading a comment by Alice u=
nder=C2=A0@<a href=3D"http://alice.example.com" target=3D"_blank">alice.exa=
mple.com</a>, that is the handle he is likely to want to use to message her=
.=C2=A0</div><div class=3D"gmail_default" style=3D"font-size:small"><br></d=
iv><div class=3D"gmail_default" style=3D"font-size:small">4) A discussion a=
bout what else we might want a DNS handle provider to support. I have a pro=
totype running that extends to supporting the IoT requirements raised in SE=
TTLE.</div><div class=3D"gmail_default" style=3D"font-size:small"><br></div=
><div class=3D"gmail_default" style=3D"font-size:small">Right now, we have =
&#39;a&#39; way to do this which is not necessarily the best way or the way=
 that allows us to grow in all the ways we might want in the future.</div><=
div class=3D"gmail_default" style=3D"font-size:small"><br></div><div class=
=3D"gmail_default" style=3D"font-size:small">I have a history of being able=
 to market protocols and get them into widespread use. I haven&#39;t always=
 been successful but have more successes than failures and I think I know w=
hat it takes to make DNS Handles widely used, which businesses I need to ap=
proach, etc. etc.</div><div class=3D"gmail_default" style=3D"font-size:smal=
l"><br></div><div class=3D"gmail_default" style=3D"font-size:small">The rea=
son I am raising this here now, is that before I go round to the DNS regist=
rars (and their affiliates) and the VPN providers and such to say this is t=
he thing to do, I want to make sure we have everything straight at a techni=
cal level so we are all on the same page.</div><div class=3D"gmail_default"=
 style=3D"font-size:small"><br></div><div class=3D"gmail_default" style=3D"=
font-size:small"><br></div></div></div>
_______________________________________________<br>
OAuth mailing list -- <a href=3D"mailto:oauth@ietf.org" target=3D"_blank">o=
auth@ietf.org</a><br>
To unsubscribe send an email to <a href=3D"mailto:oauth-leave@ietf.org" tar=
get=3D"_blank">oauth-leave@ietf.org</a><br>
</blockquote></div>

--0000000000005c3c5d062c3d12e9--

