Re: [OAUTH-WG] Token Binding Presentations?

Anthony Nadalin <tonynad@microsoft.com> Fri, 17 March 2017 17:59 UTC

Return-Path: <tonynad@microsoft.com>
X-Original-To: oauth@ietfa.amsl.com
Delivered-To: oauth@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id EECC21273E2 for <oauth@ietfa.amsl.com>; Fri, 17 Mar 2017 10:59:05 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -4.796
X-Spam-Level:
X-Spam-Status: No, score=-4.796 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, HTML_MESSAGE=0.001, RCVD_IN_DNSWL_NONE=-0.0001, RCVD_IN_MSPIKE_H2=-2.796, SPF_HELO_PASS=-0.001, SPF_PASS=-0.001, URIBL_BLOCKED=0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (1024-bit key) header.d=microsoft.com
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id W_UrPGlo858k for <oauth@ietfa.amsl.com>; Fri, 17 Mar 2017 10:59:04 -0700 (PDT)
Received: from NAM02-BL2-obe.outbound.protection.outlook.com (mail-bl2nam02on0135.outbound.protection.outlook.com [104.47.38.135]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id E0175127735 for <oauth@ietf.org>; Fri, 17 Mar 2017 10:59:03 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=microsoft.com; s=selector1; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version; bh=Z1pVLPA5wpfpZFFGrof1NSOzhXjrcR2XnNR/eXX2PxU=; b=KlKxTDSlm2lUEXP34cHO5tXQgamQKWruscRHerYbpwD/ag7HiHSBY7ZDYFI9HsqR39pUJmyqNO6uPK9CmXmpAUKDJQ8vAWQFY5XGTQJ8mNOXBqoMzaVDKF7fqJE7HHMz9hJdC839zNLIG3MrbP40Y9RydxDddyPXAX4lyf2GbtU=
Received: from SN1PR0301MB2029.namprd03.prod.outlook.com (10.163.226.27) by SN1PR0301MB2030.namprd03.prod.outlook.com (10.163.226.28) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_128_CBC_SHA256_P256) id 15.1.977.11; Fri, 17 Mar 2017 17:59:01 +0000
Received: from SN1PR0301MB2029.namprd03.prod.outlook.com ([10.163.226.27]) by SN1PR0301MB2029.namprd03.prod.outlook.com ([10.163.226.27]) with mapi id 15.01.0977.013; Fri, 17 Mar 2017 17:59:01 +0000
From: Anthony Nadalin <tonynad@microsoft.com>
To: John Bradley <ve7jtb@ve7jtb.com>, Jim Manico <jim@manicode.com>
CC: IETF OAUTH <oauth@ietf.org>
Thread-Topic: [OAUTH-WG] Token Binding Presentations?
Thread-Index: AQHSnzCVs9lfOXXa+0qTHJmybfCijaGZTXSAgAAD5RA=
Date: Fri, 17 Mar 2017 17:59:01 +0000
Message-ID: <SN1PR0301MB20291FD3A379F49B97867DCDA6390@SN1PR0301MB2029.namprd03.prod.outlook.com>
References: <411649D9-563A-49DA-8151-80DF5F45F3F8@manicode.com> <7D4461D3-A779-4FFF-A467-9C2FA4BAE991@ve7jtb.com>
In-Reply-To: <7D4461D3-A779-4FFF-A467-9C2FA4BAE991@ve7jtb.com>
Accept-Language: en-US
Content-Language: en-US
X-MS-Has-Attach:
X-MS-TNEF-Correlator:
authentication-results: ve7jtb.com; dkim=none (message not signed) header.d=none;ve7jtb.com; dmarc=none action=none header.from=microsoft.com;
x-originating-ip: [2001:4898:80e8:4::2b9]
x-microsoft-exchange-diagnostics: 1; SN1PR0301MB2030; 7:d7D+3Uy1dInDybBvvXYk9mA0D/oeMhIj8U4fvHEWKgXS1v1GTMNqkQQna2qvIKhnB98vMJkQ9/oVikFEKcwi4aCzmSWFZHdazY8wLrV2w51kwTI7ssjyhhejE665iZn+Y+PoWTr+PO+ppqu1S9HupvsH84qQovuXsBvBDBkfaYGbAxWbz0h0NU0LqEqDw9mVYk2fEeChFhJmNkIyCORiMWktQCOtXSFzEbFkkYVPK/cnNlM7wz1MX1TPTBeXuL2vc9EPowYM+vgPVvOPET5IjYNH0QPQ2lEtqhMH5HZ09uNvBAWrXEGqGwlAzP/Rnb0rYcAKtDfunoOWZ3/FujogK5kKsKakntf0bBH8vlLQ22E=
x-ms-office365-filtering-correlation-id: 12434dfb-d173-428c-34ea-08d46d5f4b3b
x-ms-office365-filtering-ht: Tenant
x-microsoft-antispam: UriScan:; BCL:0; PCL:0; RULEID:(22001)(2017030254051)(48565401081); SRVR:SN1PR0301MB2030;
x-microsoft-antispam-prvs: <SN1PR0301MB2030463FCC652E5E12691B8EA6390@SN1PR0301MB2030.namprd03.prod.outlook.com>
x-exchange-antispam-report-test: UriScan:(21748063052155);
x-exchange-antispam-report-cfa-test: BCL:0; PCL:0; RULEID:(61425038)(6040375)(601004)(2401047)(8121501046)(5005006)(3002001)(10201501046)(6055026)(61426038)(61427038)(6041248)(20161123562025)(20161123564025)(20161123555025)(20161123560025)(20161123558025)(6072148); SRVR:SN1PR0301MB2030; BCL:0; PCL:0; RULEID:; SRVR:SN1PR0301MB2030;
x-forefront-prvs: 0249EFCB0B
x-forefront-antispam-report: SFV:NSPM; SFS:(10019020)(979002)(39840400002)(39860400002)(39450400003)(39410400002)(39850400002)(377454003)(24454002)(10290500002)(7696004)(10090500001)(8990500004)(2900100001)(5005710100001)(8936002)(122556002)(81166006)(74316002)(77096006)(86612001)(86362001)(2950100002)(19609705001)(236005)(53936002)(5660300001)(6246003)(38730400002)(53546008)(7906003)(229853002)(7736002)(6506006)(6436002)(606005)(4326008)(3660700001)(3280700002)(76176999)(54356999)(50986999)(25786008)(9686003)(33656002)(8676002)(2906002)(966004)(189998001)(790700001)(102836003)(99286003)(6116002)(54896002)(6306002)(55016002)(42262002)(969003)(989001)(999001)(1009001)(1019001); DIR:OUT; SFP:1102; SCL:1; SRVR:SN1PR0301MB2030; H:SN1PR0301MB2029.namprd03.prod.outlook.com; FPR:; SPF:None; MLV:ovrnspm; PTR:InfoNoRecords; LANG:en;
spamdiagnosticoutput: 1:99
spamdiagnosticmetadata: NSPM
Content-Type: multipart/alternative; boundary="_000_SN1PR0301MB20291FD3A379F49B97867DCDA6390SN1PR0301MB2029_"
MIME-Version: 1.0
X-OriginatorOrg: microsoft.com
X-MS-Exchange-CrossTenant-originalarrivaltime: 17 Mar 2017 17:59:01.5699 (UTC)
X-MS-Exchange-CrossTenant-fromentityheader: Hosted
X-MS-Exchange-CrossTenant-id: 72f988bf-86f1-41af-91ab-2d7cd011db47
X-MS-Exchange-Transport-CrossTenantHeadersStamped: SN1PR0301MB2030
Archived-At: <https://mailarchive.ietf.org/arch/msg/oauth/wGyPFsTQ0O_QJU3bRM6BV2XTg4w>
Subject: Re: [OAUTH-WG] Token Binding Presentations?
X-BeenThere: oauth@ietf.org
X-Mailman-Version: 2.1.22
Precedence: list
List-Id: OAUTH WG <oauth.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/oauth>, <mailto:oauth-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/oauth/>
List-Post: <mailto:oauth@ietf.org>
List-Help: <mailto:oauth-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/oauth>, <mailto:oauth-request@ietf.org?subject=subscribe>
X-List-Received-Date: Fri, 17 Mar 2017 17:59:06 -0000

I'm unaware of any support for "OAuth" Token Binding from Microsoft, so I assume you are talking just about Token Binding cookies

From: OAuth [mailto:oauth-bounces@ietf.org] On Behalf Of John Bradley
Sent: Friday, March 17, 2017 10:43 AM
To: Jim Manico <jim@manicode.com>
Cc: IETF OAUTH <oauth@ietf.org>
Subject: Re: [OAUTH-WG] Token Binding Presentations?

This has some of the basic info, but needs some updating.   http://www.browserauth.net/

Other than that there are the specs in the Token binding WG and the one we just updated for OAuth.

With Microsoft supporting it in RS2 coming out in a month or so I would hope to see some developer documentation from them soon.

John B.

On Mar 17, 2017, at 12:09 PM, Jim Manico <jim@manicode.com<mailto:jim@manicode.com>> wrote:

Hello OAuthers,

I'm trying to get my head around token binding beyond the RFC. Are there any presentations or other media on token binding that any of you are aware of? My google-fu is coming up empty.

Thanks and Aloha,
- Jim
_______________________________________________
OAuth mailing list
OAuth@ietf.org<mailto:OAuth@ietf.org>
https://www.ietf.org/mailman/listinfo/oauth