Re: [OAUTH-WG] Richard Barnes' Discuss on draft-ietf-oauth-saml2-bearer-21: (with DISCUSS)

Brian Campbell <bcampbell@pingidentity.com> Fri, 17 October 2014 16:29 UTC

Return-Path: <bcampbell@pingidentity.com>
X-Original-To: oauth@ietfa.amsl.com
Delivered-To: oauth@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id BAA551A1BED for <oauth@ietfa.amsl.com>; Fri, 17 Oct 2014 09:29:50 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -3.578
X-Spam-Level:
X-Spam-Status: No, score=-3.578 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, FM_FORGED_GMAIL=0.622, HTML_MESSAGE=0.001, RCVD_IN_DNSWL_MED=-2.3, SPF_PASS=-0.001] autolearn=ham
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id 2dSStqVzpjqK for <oauth@ietfa.amsl.com>; Fri, 17 Oct 2014 09:29:46 -0700 (PDT)
Received: from na3sys009aog138.obsmtp.com (na3sys009aog138.obsmtp.com [74.125.149.19]) (using TLSv1 with cipher DHE-RSA-AES256-SHA (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id D82E41A1BEF for <oauth@ietf.org>; Fri, 17 Oct 2014 09:29:45 -0700 (PDT)
Received: from mail-ig0-f171.google.com ([209.85.213.171]) (using TLSv1) by na3sys009aob138.postini.com ([74.125.148.12]) with SMTP ID DSNKVEFD+fIUzXSgFL41PSDWy6h4FtxFKC4z@postini.com; Fri, 17 Oct 2014 09:29:45 PDT
Received: by mail-ig0-f171.google.com with SMTP id h15so1878941igd.16 for <oauth@ietf.org>; Fri, 17 Oct 2014 09:29:45 -0700 (PDT)
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20130820; h=x-gm-message-state:mime-version:in-reply-to:references:from:date :message-id:subject:to:cc:content-type; bh=DvwHHY9mTVXiyJCyfKSQzfwftS04TgPVULvEFAMheL4=; b=aubo0S0LDJGJAlXGvdcCq6zMGYq06+tL2lBWic1n5fXcHwu9FJ+3kVzliD5GUK7IK+ JAUpScy4rjxg6NmC/Hjw9YZfWa0rxU389VHJiigTAkEmMKB/fWVSLx1DHV2dokJWQhBO wKt0cCYah+h/qoQJ3rNzrbXsl2SMUbgcepWA4it15Z/Ue0cxBHrK87bq7YnvgOQcqJG/ JJ/iPIayZ7UYLt41jmIJArZk+CV+hnEKeaOmIpNjmpiDyFXRxaE0/O2FI+QqxUjqsj2v 6RA4bz8RlNXiXR5yNqNlMPz8A3aVHswe8rdaNZGGNnrty/LrWPmWV4fLJgunG6e03D2d DVeA==
X-Gm-Message-State: ALoCoQlHGvWDDEveugGUdeD68s5IOudBHDUwVFTzmgk1VxYwYIdwWGVIeH98PJfPIbQP2leJ8umcFkhlWEQNZb76t2McwevCCsgw/qgB03ONkH6VGNBfyxtRc2F+Hr/0ykkV0kUdLWKl
X-Received: by 10.107.163.142 with SMTP id m136mr10041746ioe.32.1413563385294; Fri, 17 Oct 2014 09:29:45 -0700 (PDT)
X-Received: by 10.107.163.142 with SMTP id m136mr10041726ioe.32.1413563385134; Fri, 17 Oct 2014 09:29:45 -0700 (PDT)
MIME-Version: 1.0
Received: by 10.64.12.137 with HTTP; Fri, 17 Oct 2014 09:29:15 -0700 (PDT)
In-Reply-To: <CAL02cgSKHNSgPwS6_yUHpkpa=bO3D8nUNKwti604TzLHazxKfw@mail.gmail.com>
References: <20141016035640.25108.27277.idtracker@ietfa.amsl.com> <CA+k3eCT=mQyZvEuUF+t4G9pRbFavP85TjAgJMkOOSarCBFk8mw@mail.gmail.com> <CAL02cgSKHNSgPwS6_yUHpkpa=bO3D8nUNKwti604TzLHazxKfw@mail.gmail.com>
From: Brian Campbell <bcampbell@pingidentity.com>
Date: Fri, 17 Oct 2014 10:29:15 -0600
Message-ID: <CA+k3eCQXg-_Z4LE__rVeGprkzh5-bHvrrLGor7jeSEuRhynRFg@mail.gmail.com>
To: Richard Barnes <rlb@ipv.sx>
Content-Type: multipart/alternative; boundary="001a11403ff87061aa0505a0df7c"
Archived-At: http://mailarchive.ietf.org/arch/msg/oauth/ycTFrAY-b-M8l_RGFn3v02fd6QA
Cc: "oauth-chairs@tools.ietf.org" <oauth-chairs@tools.ietf.org>, draft-ietf-oauth-saml2-bearer@tools.ietf.org, The IESG <iesg@ietf.org>, oauth <oauth@ietf.org>
Subject: Re: [OAUTH-WG] Richard Barnes' Discuss on draft-ietf-oauth-saml2-bearer-21: (with DISCUSS)
X-BeenThere: oauth@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: OAUTH WG <oauth.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/oauth>, <mailto:oauth-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/oauth/>
List-Post: <mailto:oauth@ietf.org>
List-Help: <mailto:oauth-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/oauth>, <mailto:oauth-request@ietf.org?subject=subscribe>
X-List-Received-Date: Fri, 17 Oct 2014 16:29:50 -0000

Touché... ;)

On Thu, Oct 16, 2014 at 4:36 PM, Richard Barnes <rlb@ipv.sx> wrote:

> That's what you get for duplicating all the text :)
>
> On Thu, Oct 16, 2014 at 2:00 PM, Brian Campbell <
> bcampbell@pingidentity.com> wrote:
>
>> Basically the same response to the basically same question as from
>> http://www.ietf.org/mail-archive/web/oauth/current/msg13608.html
>>
>> On Wed, Oct 15, 2014 at 9:56 PM, Richard Barnes <rlb@ipv.sx> wrote:
>>
>>> Richard Barnes has entered the following ballot position for
>>> draft-ietf-oauth-saml2-bearer-21: Discuss
>>>
>>> When responding, please keep the subject line intact and reply to all
>>> email addresses included in the To and CC lines. (Feel free to cut this
>>> introductory paragraph, however.)
>>>
>>>
>>> Please refer to http://www.ietf.org/iesg/statement/discuss-criteria.html
>>> for more information about IESG DISCUSS and COMMENT positions.
>>>
>>>
>>> The document, along with other ballot positions, can be found here:
>>> http://datatracker.ietf.org/doc/draft-ietf-oauth-saml2-bearer/
>>>
>>>
>>>
>>> ----------------------------------------------------------------------
>>> DISCUSS:
>>> ----------------------------------------------------------------------
>>>
>>> As with draft-ietf-oauth-assertions, the requirement for an <Audience>
>>> element seems entirely unnecessary.  Holding this DISCUSS point pending
>>> that discussion and its reflection in this document.
>>>
>>> "Assertions that do not identify the Authorization Server as an intended
>>> audience MUST be rejected." -- What does it mean for an assertion to
>>> "identify the Authorization Server"?  Does the specified <Audience> need
>>> to match the entire URL of the relevant OAuth endpoint?  Just the origin?
>>>  Just the domain?  Does the URL need to be canonicalized?
>>>
>>>
>>>
>>>
>>> _______________________________________________
>>> OAuth mailing list
>>> OAuth@ietf.org
>>> https://www.ietf.org/mailman/listinfo/oauth
>>>
>>
>>
>