Re: [regext] Federated Authentication for Machine-to-Machine Interactions in RDAP

Mario Loffredo <mario.loffredo@iit.cnr.it> Fri, 29 July 2022 11:59 UTC

Return-Path: <mario.loffredo@iit.cnr.it>
X-Original-To: regext@ietfa.amsl.com
Delivered-To: regext@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 153B2C16ED1C for <regext@ietfa.amsl.com>; Fri, 29 Jul 2022 04:59:49 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -6.907
X-Spam-Level:
X-Spam-Status: No, score=-6.907 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, NICE_REPLY_A=-0.001, RCVD_IN_DNSWL_HI=-5, RCVD_IN_ZEN_BLOCKED_OPENDNS=0.001, SPF_HELO_NONE=0.001, SPF_PASS=-0.001, T_SCC_BODY_TEXT_LINE=-0.01, URIBL_BLOCKED=0.001, URIBL_DBL_BLOCKED_OPENDNS=0.001, URIBL_ZEN_BLOCKED_OPENDNS=0.001] autolearn=ham autolearn_force=no
Received: from mail.ietf.org ([50.223.129.194]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id jP-ffhAkFJli for <regext@ietfa.amsl.com>; Fri, 29 Jul 2022 04:59:45 -0700 (PDT)
Received: from smtp.iit.cnr.it (mx4.iit.cnr.it [146.48.58.11]) by ietfa.amsl.com (Postfix) with ESMTP id 34155C15A72F for <regext@ietf.org>; Fri, 29 Jul 2022 04:59:44 -0700 (PDT)
Received: from localhost (localhost [127.0.0.1]) by smtp.iit.cnr.it (Postfix) with ESMTP id 5A4A5B80513; Fri, 29 Jul 2022 13:59:42 +0200 (CEST)
X-Virus-Scanned: Debian amavisd-new at mx4.iit.cnr.it
Received: from smtp.iit.cnr.it ([127.0.0.1]) by localhost (mx4.iit.cnr.it [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id 2KF-oZZ1KMAa; Fri, 29 Jul 2022 13:59:39 +0200 (CEST)
Received: from [192.12.193.108] (pc-loffredo.staff.nic.it [192.12.193.108]) (using TLSv1.3 with cipher TLS_AES_128_GCM_SHA256 (128/128 bits)) (No client certificate requested) by smtp.iit.cnr.it (Postfix) with ESMTPSA id 6EAF3B803F3; Fri, 29 Jul 2022 13:59:39 +0200 (CEST)
Message-ID: <55f36ead-3377-5ba4-9846-932656434668@iit.cnr.it>
Date: Fri, 29 Jul 2022 13:57:04 +0200
MIME-Version: 1.0
User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:91.0) Gecko/20100101 Thunderbird/91.11.0
To: "Hollenbeck, Scott" <shollenbeck=40verisign.com@dmarc.ietf.org>, "regext@ietf.org" <regext@ietf.org>
References: <5a9b171385c5492e8d64492aa8cf6092@verisign.com>
From: Mario Loffredo <mario.loffredo@iit.cnr.it>
In-Reply-To: <5a9b171385c5492e8d64492aa8cf6092@verisign.com>
Content-Type: text/plain; charset="UTF-8"; format="flowed"
Content-Transfer-Encoding: 8bit
Archived-At: <https://mailarchive.ietf.org/arch/msg/regext/VVN32pfJnR5PyMx-R-m558og-nw>
Subject: Re: [regext] Federated Authentication for Machine-to-Machine Interactions in RDAP
X-BeenThere: regext@ietf.org
X-Mailman-Version: 2.1.39
Precedence: list
List-Id: Registration Protocols Extensions <regext.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/regext>, <mailto:regext-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/regext/>
List-Post: <mailto:regext@ietf.org>
List-Help: <mailto:regext-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/regext>, <mailto:regext-request@ietf.org?subject=subscribe>
X-List-Received-Date: Fri, 29 Jul 2022 11:59:49 -0000

Hi Scott,

please find my comments below.

Il 27/07/2022 23:48, Hollenbeck, Scott ha scritto:
> OAuth 2.0 includes the ability to authorize a class of clients known as
> "confidential clients" in a machine-to-machine manner using the "Client
> Credentials Grant". The grant is described here:
>
> https://datatracker.ietf.org/doc/html/rfc6749#section-4.4
>
> A description of confidential and public clients can be found here:
>
> https://datatracker.ietf.org/doc/html/rfc6749#section-2.1
>
> Note that this requires some sort of prior arrangement between the client and,
> in our case, an RDAP server, such that the client can be authenticated by an
> Authorization Server without explicitly identifying, authenticating, and
> authorizing the specific human users who might be using the client. For
> example, the client might have a password that's been assigned by the RDAP
> server operator. The federated authentication draft doesn't currently include
> anything to support this type of grant. Should it? Is there an RDAP use case
> for which this would be useful?

Think it should be addressed, though I'm not sure this is the right 
document.

The authentication flows explored so far fit well the use cases where a 
human occasionally submits a request. The case of authenticated software 
agents submitting a lot of requests routinely doesn't find a practical 
solution in this draft. I would like to remind everyone that EU 
Parliament and EU Council has recently reached an agreement on core 
elements of the e-Evidence proposal. Therefore, I guess that soon we 
will have to figure out how to provide regular authenticated access to 
registration data to categories of users legitimated for their purposes 
such as authorities and cybercrime agencies.

That being said, I see two big drawbacks in using the Client Credential 
flow, at least as is:

- Client Credential flow is for trusted clients. Clients need to be 
registered by the OP before submitting a request for an access token. 
But, RDAP clients are generally untrusted and I don't consider scalable 
a solution where several RDAP clients are required to register by many 
OPs including the local ones. In the approach described in this draft, 
the trusted client is the RDAP server.

- Roles and access grants are generally assigned to users not to 
clients. In addition, think there would be a potential risk of providing 
access to illegitimate users via legitimate clients.

The Resource Owner Password Credential Flow would have fiited better but 
it has been rightly deprecated by OAuth. I'm afraid that a usage of CC 
Flow in a manner similar to the ROPC flow wouldn't be welcome by 
security experts.

I would suggest to explore another approach where a third-party 
authority interconnects clients and servers that are mutually authenticated.


Best,

Mario

>
>
>
> Scott
>
> _______________________________________________
> regext mailing list
> regext@ietf.org
> https://www.ietf.org/mailman/listinfo/regext

-- 
Dr. Mario Loffredo
Technological Unit “Digital Innovation”
Institute of Informatics and Telematics (IIT)
National Research Council (CNR)
via G. Moruzzi 1, I-56124 PISA, Italy
Phone: +39.0503153497
Web: http://www.iit.cnr.it/mario.loffredo