Re: [OAUTH-WG] MTLS and in-browser clients using the token endpoint

George Fletcher <gffletch@aol.com> Fri, 01 February 2019 21:28 UTC

Return-Path: <gffletch@aol.com>
X-Original-To: oauth@ietfa.amsl.com
Delivered-To: oauth@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 46DA8130EC2 for <oauth@ietfa.amsl.com>; Fri, 1 Feb 2019 13:28:47 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.998
X-Spam-Level:
X-Spam-Status: No, score=-1.998 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, FREEMAIL_FROM=0.001, HTML_MESSAGE=0.001, RCVD_IN_DNSWL_NONE=-0.0001, SPF_PASS=-0.001, URIBL_BLOCKED=0.001] autolearn=unavailable autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (2048-bit key) header.d=aol.com
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id bCMpOYTtOGuS for <oauth@ietfa.amsl.com>; Fri, 1 Feb 2019 13:28:44 -0800 (PST)
Received: from sonic307-3.consmr.mail.bf2.yahoo.com (sonic307-3.consmr.mail.bf2.yahoo.com [74.6.134.42]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 3D357130EB4 for <oauth@ietf.org>; Fri, 1 Feb 2019 13:28:44 -0800 (PST)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=aol.com; s=a2048; t=1549056523; bh=6EToU2jEcGhQE9Qzwk8gvAqPQt2q9DupbJiS0iXrBPQ=; h=Subject:To:Cc:References:From:Date:In-Reply-To:From:Subject; b=fBzSM+NHU3Q3ktd4ujb973lh514Z4lpPXdaT0qKwIxxNCfEMfxjDQbYo2BP1yeh9KQUiJ4aLr4i+kSC3IrdUZYrvM/BKV80VWCVQR/qgPEdKqgBZ4okxaP84S/H/Mb5YRSI05bPp3OP29+difpkc6tRVU8H1X1ZN9BwfuTbmN1+e4McbH0RBEHClyiaSRW5QiGi01I0TlrDnDGyI9wRnNQ7ufahn8juyg1Qnn1HvfwtYzItRA86c+Ic9lxA+ghRWTOqE9TW6cEuatvNM5/ILUAjfpmi3b364LjZY5oYd+mrHORcvaMY1pC6Kxk4kvAvTqwSbY5DNXXVm9QWApr38Rw==
X-YMail-OSG: wQSLpY4VM1l.mG0xkGcH0Hi4nVc1_Ck3..BGE.i6zVJdTW7Xy67BueoLT_.BtfS S1hySL29s32AOWIMxtUqqCzXStnm4wQxgENDvbiqekS2YLf3HKRRly33q.6P8ydFThPrPaOAqR5y YWI3bjdw6Y9pK6EP7wlTzZ_UVGA.Yz2yB0LrMvHsEtjvLurTClAxmf0C1SvLJUKLZigRjSyEjhHA rOeVkoVN3sAT6pZLDUTLZEFjpsto4uZXUrDp.5qhB3Y2fjTokAO6ishb.hEk56FW5WVIvHVQ77RC q2_4nlMC1Im.Xd05QYJ_GvFPcqQWkugHLb5YfMyjoeqVDy2iZ_ufQAL.Z9ue44efC2X4yv4cCga6 aU5dPSNXXI0HUuDz8TJT0IX4INVzABDeq96np6wQWgXBrFxdtfTxQ5mY7hWg0_aybJN3_fXiDvy9 9s3ZMA5FcORP6roVYgZE0bxhr7mIQ8a7yB98yYO_T2Cuazs8eeUzeKhEeDdpNF.0vhUXPgthEYSz 3ueuo0IPoVzx7DV7LLLbjnxcEJCVMjNCypOYL.B2zglxCBkppDrjJG0GnqVXquVNJkjpSTmHFWR3 08SPycBZFoM6yjtvwLBHmdQKMHeZVhu35nyYYeHbOr9BidEG.ejVq34KoyfSrNXJl0_8OL.ymZ85 FyZjet4yJARZ2AY7Fl.ZbejqUaZSr0WAOwRO1FNk_tLRFpzZpB._g6WU_QHzS1ryLSVAyzM9Fy6o LXAXrPfl0T2pCi3QoFQGIQ1o1uAp1XYcADAcbagYzR9Ud3WNyYG9qU35aLU4ca7ouuqq0u44WlSt XaN6pCzWpY9rB01s.LrcLue8I9FsUoPPD_qLawNu0HN1g6Phwsi92j5i5uP.hFzpKvfj7fMv__lP DiOCIbTIW0HutMWzjbEXo5EBy02eq9JqaxJIPQX_bxU0HtoYUBUfzxn6U_7k2sRXxToiQInasB1D eh04fq6Q3YAN5ZiASjT.4SpTmURpScss.Vgfq2RQPXYOGszhOp0Bd3i531BrTNg_N6mH5osb8tkI oM.kUFr7Lpj3Y0iU3Cfp2e84cq2f77C4lnGFmfylY1hmS0taDetYXGS.SI._4IQSBpGkx
Received: from sonic.gate.mail.ne1.yahoo.com by sonic307.consmr.mail.bf2.yahoo.com with HTTP; Fri, 1 Feb 2019 21:28:43 +0000
Received: from nat-wireless-users3.cfw-a-gci.net.dulles.office.oath (EHLO [172.130.136.180]) ([184.165.3.238]) by smtp423.mail.bf1.yahoo.com (Oath Hermes SMTP Server) with ESMTPA ID 52694e526060e0e71cf3171dda78c39b; Fri, 01 Feb 2019 21:28:40 +0000 (UTC)
To: Brian Campbell <bcampbell=40pingidentity.com@dmarc.ietf.org>, Dave Tonge <dave.tonge@momentumft.co.uk>
Cc: oauth <oauth@ietf.org>
References: <CA+k3eCTKSFiiTw8--qBS0R2YVQ0MY0eKrMBvBNE4pauSr1rHcA@mail.gmail.com> <6A614742-290D-47E2-B3E9-A4D49DB32DD7@forgerock.com> <CA+k3eCSoNRGrsxeLYd6DEqU+U6TB_aXV2aPUa07Um2X0ZH_ZEw@mail.gmail.com> <548FF68E-7775-4FE0-829F-1E9CC6EA8E3F@alkaline-solutions.com> <1119DDAE-8044-43C9-A6D4-6032B3BB62B8@forgerock.com> <9D007408-3BCC-4165-BCA4-083BD7602E7D@alkaline-solutions.com> <CA+k3eCQi1sz2bDOMEATpN9ZvXd+VJydQXG03WKuLczG5kz2z+Q@mail.gmail.com> <CAP-T6TTD-nLGoPHqJ042SzotLorb2mzoWgLxsausWHhRPZr8xA@mail.gmail.com> <CA+k3eCQtgku68usoCFsTeHVnNOLqWs6NweOgpQKsa7_9=wK7Vw@mail.gmail.com>
From: George Fletcher <gffletch@aol.com>
Organization: AOL LLC
Message-ID: <99d38517-0e25-789f-83ae-9f33e5620475@aol.com>
Date: Fri, 01 Feb 2019 16:28:39 -0500
User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10.14; rv:60.0) Gecko/20100101 Thunderbird/60.5.0
MIME-Version: 1.0
In-Reply-To: <CA+k3eCQtgku68usoCFsTeHVnNOLqWs6NweOgpQKsa7_9=wK7Vw@mail.gmail.com>
Content-Type: multipart/alternative; boundary="------------C32420BF4274A28571B079D1"
Content-Language: en-US
Archived-At: <https://mailarchive.ietf.org/arch/msg/oauth/rKovfz3qQ2bfiLY0aKRl--JvULs>
Subject: Re: [OAUTH-WG] MTLS and in-browser clients using the token endpoint
X-BeenThere: oauth@ietf.org
X-Mailman-Version: 2.1.29
Precedence: list
List-Id: OAUTH WG <oauth.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/oauth>, <mailto:oauth-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/oauth/>
List-Post: <mailto:oauth@ietf.org>
List-Help: <mailto:oauth-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/oauth>, <mailto:oauth-request@ietf.org?subject=subscribe>
X-List-Received-Date: Fri, 01 Feb 2019 21:28:47 -0000

What if the AS wants to ONLY support MTLS connections. Does it not 
specify the optional "mtls_endpoints" and just use the normal metadata 
values?

On 1/15/19 8:48 AM, Brian Campbell wrote:
> It would definitely be optional, apologies if that wasn't made clear. 
> It'd be something to the effect of optional for the AS to include and 
> clients doing MTLS would use it when present in AS metadata.
>
> On Tue, Jan 15, 2019 at 2:04 AM Dave Tonge 
> <dave.tonge@momentumft.co.uk <mailto:dave.tonge@momentumft.co.uk>> wrote:
>
>     I'm in favour of the `mtls_endpoints` metadata parameter -
>     although it should be optional.
>
>
> /CONFIDENTIALITY NOTICE: This email may contain confidential and 
> privileged material for the sole use of the intended recipient(s). Any 
> review, use, distribution or disclosure by others is strictly 
> prohibited..  If you have received this communication in error, please 
> notify the sender immediately by e-mail and delete the message and any 
> file attachments from your computer. Thank you./
>
> _______________________________________________
> OAuth mailing list
> OAuth@ietf.org
> https://www.ietf.org/mailman/listinfo/oauth