Re: [OAUTH-WG] New Version Notification for draft-campbell-oauth-tls-client-auth-00.txt

Justin Richer <jricher@mit.edu> Sun, 13 November 2016 04:40 UTC

Return-Path: <jricher@mit.edu>
X-Original-To: oauth@ietfa.amsl.com
Delivered-To: oauth@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 0212B12950D for <oauth@ietfa.amsl.com>; Sat, 12 Nov 2016 20:40:07 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -5.717
X-Spam-Level:
X-Spam-Status: No, score=-5.717 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, HTML_MESSAGE=0.001, RCVD_IN_DNSWL_MED=-2.3, RCVD_IN_MSPIKE_H3=-0.01, RCVD_IN_MSPIKE_WL=-0.01, RP_MATCHES_RCVD=-1.497, SPF_PASS=-0.001] autolearn=ham autolearn_force=no
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id 5ui1WKGBbnLf for <oauth@ietfa.amsl.com>; Sat, 12 Nov 2016 20:40:05 -0800 (PST)
Received: from dmz-mailsec-scanner-2.mit.edu (dmz-mailsec-scanner-2.mit.edu [18.9.25.13]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id C86E81294FA for <oauth@ietf.org>; Sat, 12 Nov 2016 20:40:04 -0800 (PST)
X-AuditID: 1209190d-ca3ff70000000ceb-28-5827eea35a58
Received: from mailhub-auth-2.mit.edu ( [18.7.62.36]) (using TLS with cipher DHE-RSA-AES256-SHA (256/256 bits)) (Client did not present a certificate) by (Symantec Messaging Gateway) with SMTP id 5A.96.03307.3AEE7285; Sat, 12 Nov 2016 23:40:03 -0500 (EST)
Received: from outgoing.mit.edu (outgoing-auth-1.mit.edu [18.9.28.11]) by mailhub-auth-2.mit.edu (8.13.8/8.9.2) with ESMTP id uAD4e27Q009968; Sat, 12 Nov 2016 23:40:02 -0500
Received: from dhcp-8693.meeting.ietf.org (dhcp-8693.meeting.ietf.org [31.133.134.147]) (authenticated bits=0) (User authenticated as jricher@ATHENA.MIT.EDU) by outgoing.mit.edu (8.13.8/8.12.4) with ESMTP id uAD4dtfS020255 (version=TLSv1/SSLv3 cipher=DHE-RSA-AES256-SHA bits=256 verify=NOT); Sat, 12 Nov 2016 23:39:59 -0500
Content-Type: multipart/alternative; boundary="Apple-Mail=_7CE3C1D0-6016-44D8-B4C3-E8292BD9811F"
Mime-Version: 1.0 (Mac OS X Mail 9.3 \(3124\))
From: Justin Richer <jricher@mit.edu>
In-Reply-To: <5827DE8A.4010807@lodderstedt.net>
Date: Sun, 13 Nov 2016 13:39:55 +0900
Message-Id: <4372F560-F98E-491B-BEDD-B02A2671D96C@mit.edu>
References: <147613227959.31428.2920748721017165266.idtracker@ietfa.amsl.com> <9CDE07EB-E5B4-43B2-B3C1-F12569CAB458@ve7jtb.com> <5827DE8A.4010807@lodderstedt.net>
To: Torsten Lodderstadt <torsten@lodderstedt.net>
X-Mailer: Apple Mail (2.3124)
X-Brightmail-Tracker: H4sIAAAAAAAAA+NgFlrPKsWRmVeSWpSXmKPExsUixG6norv4nXqEwdnjuhar/99ktDj59hWb xedbh1ktXh17ymKx+u5fNgdWjyVLfjJ5PN/Zz+RxrKef1ePu0YssHrdvb2QJYI3isklJzcks Sy3St0vgylgzaydrwbWyivlf5RoYl8Z1MXJySAiYSPyauZepi5GLQ0igjUli56w+RghnI6PE ncNP2CGcK0wStw5tYQZpYRZIkDj67SE7iM0roCexaf1bJhBbGCh+5lU7mM0moCoxfU0LmM0p oC/x+nA/WD0LUHzPsbdg65gFLjJKXH/TwgIxyEpi4YcnrBDbFjFKPPmynq2LkYNDRMBQ4tec TIhbZSWenFzEMoGRfxaSO2YhuQMiri2xbOFrZgjbQOJp5ytWTHF9iTfv5jAtYGRbxSibklul m5uYmVOcmqxbnJyYl5dapGukl5tZopeaUrqJERQXnJK8Oxj/3fU6xCjAwajEw7shTT1CiDWx rLgy9xCjJAeTkijvOxWgEF9SfkplRmJxRnxRaU5q8SFGCQ5mJRFe8ZdAOd6UxMqq1KJ8mJQ0 B4uSOO9/t6/hQgLpiSWp2ampBalFMFkZDg4lCV7Zt0CNgkWp6akVaZk5JQhpJg5OkOE8QMOV QWp4iwsSc4sz0yHypxh1Od7sevmASYglLz8vVUqc1/ANUJEASFFGaR7cHFA6k29tm/yKURzo LWHeFSCjeICpEG7SK6AlTEBLZsSpgCwpSURISTUw2ogfiGz9IBB50MHqqPatPfvCdj0WuG71 rfqu3+uvHDt+16yccT9RUdxEzJBNUmT2xKzLSvxMXdX3DHKsWy5c9lBUmvY9eXf+vw0bHgZe fMN15m3v5S7ZbZr13aGTFKfP2/FS84lxgX1Y1JQFN3sWPefa3FfpU6HCalW930iUmZ/XmYuh LFZNiaU4I9FQi7moOBEAlZKHgUIDAAA=
Archived-At: <https://mailarchive.ietf.org/arch/msg/oauth/uskzv5silqQMfu4BkPLPx6mVUkM>
Cc: Nat Sakimura via Openid-specs-fapi <openid-specs-fapi@lists.openid.net>, "<oauth@ietf.org>" <oauth@ietf.org>
Subject: Re: [OAUTH-WG] New Version Notification for draft-campbell-oauth-tls-client-auth-00.txt
X-BeenThere: oauth@ietf.org
X-Mailman-Version: 2.1.17
Precedence: list
List-Id: OAUTH WG <oauth.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/oauth>, <mailto:oauth-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/oauth/>
List-Post: <mailto:oauth@ietf.org>
List-Help: <mailto:oauth-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/oauth>, <mailto:oauth-request@ietf.org?subject=subscribe>
X-List-Received-Date: Sun, 13 Nov 2016 04:40:07 -0000

Torsten, I believe this is intended to be triggered by the tls_client_auth value specified in §3. 

Nit on that section, the field name for the client metadata in RFC7591 is token_endpoint_auth_method, the _supported version is from the corresponding discovery document.

 — Justin

> On Nov 13, 2016, at 12:31 PM, Torsten Lodderstedt <torsten@lodderstedt.net> wrote:
> 
> Hi John and Brian,
> 
> thanks for writting this draft.
> 
> One question: how does the AS determine the authentication method is TLS authentication? I think you assume this is defined by the client-specific policy, independent of whether the client is registered automatically or manually. Would you mind to explicitely state this in the draft?
> 
> best regards,
> Torsten.
> 
> Am 11.10.2016 um 05:59 schrieb John Bradley:
>> At the request of the OpenID Foundation Financial Services API Working group, Brian Campbell and I have documented 
>> mutual TLS client authentication.   This is something that lots of people do in practice though we have never had a spec for it.
>> 
>> The Banks want to use it for some server to server API use cases being driven by new open banking regulation.
>> 
>> The largest thing in the draft is the IANA registration of “tls_client_auth” Token Endpoint authentication method for use in Registration and discovery.
>> 
>> The trust model is intentionally left open so that you could use a “common name” and a restricted list of CA or a direct lookup of the subject public key against a reregistered value,  or something in between.
>> 
>> I hope that this is non controversial and the WG can adopt it quickly.
>> 
>> Regards
>> John B.
>> 
>> 
>> 
>> 
>>> Begin forwarded message:
>>> 
>>> From:  <mailto:internet-drafts@ietf.org>internet-drafts@ietf.org <mailto:internet-drafts@ietf.org>
>>> Subject: New Version Notification for draft-campbell-oauth-tls-client-auth-00.txt
>>> Date: October 10, 2016 at 5:44:39 PM GMT-3
>>> To: "Brian Campbell" < <mailto:brian.d.campbell@gmail.com>brian.d.campbell@gmail.com <mailto:brian.d.campbell@gmail.com>>, "John Bradley" <ve7jtb@ve7jtb.com <mailto:ve7jtb@ve7jtb.com>>
>>> 
>>> 
>>> A new version of I-D, draft-campbell-oauth-tls-client-auth-00.txt
>>> has been successfully submitted by John Bradley and posted to the
>>> IETF repository.
>>> 
>>> Name:		draft-campbell-oauth-tls-client-auth
>>> Revision:	00
>>> Title:		Mutual X.509 Transport Layer Security (TLS) Authentication for OAuth Clients
>>> Document date:	2016-10-10
>>> Group:		Individual Submission
>>> Pages:		5
>>> URL:            https://www.ietf.org/internet-drafts/draft-campbell-oauth-tls-client-auth-00.txt <https://www.ietf.org/internet-drafts/draft-campbell-oauth-tls-client-auth-00.txt>
>>> Status:         https://datatracker.ietf.org/doc/draft-campbell-oauth-tls-client-auth/ <https://datatracker.ietf.org/doc/draft-campbell-oauth-tls-client-auth/>
>>> Htmlized:       https://tools.ietf.org/html/draft-campbell-oauth-tls-client-auth-00 <https://tools.ietf.org/html/draft-campbell-oauth-tls-client-auth-00>
>>> 
>>> 
>>> Abstract:
>>>   This document describes X.509 certificates as OAuth client
>>>   credentials using Transport Layer Security (TLS) mutual
>>>   authentication as a mechanism for client authentication to the
>>>   authorization server's token endpoint.
>>> 
>>> 
>>> 
>>> 
>>> Please note that it may take a couple of minutes from the time of submission
>>> until the htmlized version and diff are available at tools.ietf.org <http://tools.ietf.org/>.
>>> 
>>> The IETF Secretariat
>>> 
>> 
>> 
>> 
>> _______________________________________________
>> OAuth mailing list
>> OAuth@ietf.org <mailto:OAuth@ietf.org>
>> https://www.ietf.org/mailman/listinfo/oauth <https://www.ietf.org/mailman/listinfo/oauth>
> 
> _______________________________________________
> OAuth mailing list
> OAuth@ietf.org
> https://www.ietf.org/mailman/listinfo/oauth