Re: [saag] IETF 93 Agenda Request - Key Discovery

Benjamin Kaduk <kaduk@MIT.EDU> Fri, 24 July 2015 03:48 UTC

Return-Path: <kaduk@mit.edu>
X-Original-To: saag@ietfa.amsl.com
Delivered-To: saag@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 504231A8983 for <saag@ietfa.amsl.com>; Thu, 23 Jul 2015 20:48:37 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -4.211
X-Spam-Level:
X-Spam-Status: No, score=-4.211 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, RCVD_IN_DNSWL_MED=-2.3, SPF_PASS=-0.001, T_RP_MATCHES_RCVD=-0.01] autolearn=ham
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id IWYjDEMzE1pg for <saag@ietfa.amsl.com>; Thu, 23 Jul 2015 20:48:35 -0700 (PDT)
Received: from dmz-mailsec-scanner-5.mit.edu (dmz-mailsec-scanner-5.mit.edu [18.7.68.34]) by ietfa.amsl.com (Postfix) with ESMTP id 32A781A1B84 for <saag@ietf.org>; Thu, 23 Jul 2015 20:48:34 -0700 (PDT)
X-AuditID: 12074422-f79d26d0000026d6-05-55b1b592fc35
Received: from mailhub-auth-2.mit.edu ( [18.7.62.36]) (using TLS with cipher DHE-RSA-AES256-SHA (256/256 bits)) (Client did not present a certificate) by dmz-mailsec-scanner-5.mit.edu (Symantec Messaging Gateway) with SMTP id 2A.7B.09942.295B1B55; Thu, 23 Jul 2015 23:48:34 -0400 (EDT)
Received: from outgoing.mit.edu (outgoing-auth-1.mit.edu [18.9.28.11]) by mailhub-auth-2.mit.edu (8.13.8/8.9.2) with ESMTP id t6O3mX5Q024826 for <saag@ietf.org>; Thu, 23 Jul 2015 23:48:34 -0400
Received: from multics.mit.edu (system-low-sipb.mit.edu [18.187.2.37]) (authenticated bits=56) (User authenticated as kaduk@ATHENA.MIT.EDU) by outgoing.mit.edu (8.13.8/8.12.4) with ESMTP id t6O3mUgP017747 (version=TLSv1/SSLv3 cipher=DHE-RSA-AES256-SHA bits=256 verify=NOT) for <saag@ietf.org>; Thu, 23 Jul 2015 23:48:33 -0400
Received: (from kaduk@localhost) by multics.mit.edu (8.12.9.20060308) id t6O3mUQM021657; Thu, 23 Jul 2015 23:48:30 -0400 (EDT)
Date: Thu, 23 Jul 2015 23:48:30 -0400
From: Benjamin Kaduk <kaduk@MIT.EDU>
To: saag@ietf.org
In-Reply-To: <20150723132637.GQ4347@mournblade.imrryr.org>
Message-ID: <alpine.GSO.1.10.1507232336040.22210@multics.mit.edu>
References: <20150721222308.GU28047@mournblade.imrryr.org> <20150721231021.59110.qmail@ary.lan> <CAL02cgQ3aTwpt43YYWSL-pEGcA5v1a10BskuA7-U1YN1Jk+G2w@mail.gmail.com> <20150723130501.GO4347@mournblade.imrryr.org> <D14EE2BF-6AAE-456C-A4C0-9AA96E80937B@oracle.com> <20150723132637.GQ4347@mournblade.imrryr.org>
User-Agent: Alpine 1.10 (GSO 962 2008-03-14)
MIME-Version: 1.0
Content-Type: TEXT/PLAIN; charset="US-ASCII"
X-Brightmail-Tracker: H4sIAAAAAAAAA+NgFrrOIsWRmVeSWpSXmKPExsUixG6nojtp68ZQg+WPpC2m9HcyOTB6LFny kymAMYrLJiU1J7MstUjfLoEr4/Y27YIpHBVfDnWwNjAeZeti5OSQEDCRONazkx3CFpO4cG89 UJyLQ0hgMZPEogP3wIqEBI4ySmy4pgGRuMYk8ergDVYIp4FR4tyedrAqFgFticv/D4GNYhNQ kZj5ZiNYXERAUOJB3yQWEFtYwEri8dwJzCA2J5B9e/8bsBpeAUeJjdf2MkIM3cIk8eX1e7Ai UQEdidX7p7BAFAlKnJz5BMxmFtCSWD59G8sERoFZSFKzkKQWMDKtYpRNya3SzU3MzClOTdYt Tk7My0st0jXVy80s0UtNKd3ECA4/F6UdjD8PKh1iFOBgVOLhzZiwMVSINbGsuDL3EKMkB5OS KO/dpUAhvqT8lMqMxOKM+KLSnNTiQ4wSHMxKIryaC4ByvCmJlVWpRfkwKWkOFiVx3k0/+EKE BNITS1KzU1MLUotgsjIcHEoSvOpbgBoFi1LTUyvSMnNKENJMHJwgw3mAhjuB1PAWFyTmFmem Q+RPMSpKifNe2QyUEABJZJTmwfXC0sMrRnGgV4R5S0HaeYCpBa77FdBgJqDBPH0bQAaXJCKk pBoYGTu/Gll937Pd7E7P9L09K+SEO79feLtx1eKyrp4NKZUvJmu9mMfWEXaxIFPPNPXak9MR V8MOZyVqbL7p6H09x6u1zXpmaZL0zl1X7SbWqvDN/bLcVd3l0AuNimmMOgfXL3gS7hL350n3 9Adn3QqzxJ48K3Mp3qVZFnHjFUf51lzp+wanQ3X5lFiKMxINtZiLihMB9z0DR+oCAAA=
Archived-At: <http://mailarchive.ietf.org/arch/msg/saag/JA5vSzs_fjC5s0LoolJvjx8RgGw>
Subject: Re: [saag] IETF 93 Agenda Request - Key Discovery
X-BeenThere: saag@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: Security Area Advisory Group <saag.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/saag>, <mailto:saag-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/saag/>
List-Post: <mailto:saag@ietf.org>
List-Help: <mailto:saag-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/saag>, <mailto:saag-request@ietf.org?subject=subscribe>
X-List-Received-Date: Fri, 24 Jul 2015 03:48:37 -0000

On Thu, 23 Jul 2015, Viktor Dukhovni wrote:

> On Thu, Jul 23, 2015 at 03:15:49PM +0200, Phil Hunt wrote:
>
> > > WebFinger requires email server operators to also deploy HTTP
> > > WebFinger servers, or email servers to support an additional request
> > > protocol.  Neither seems necessary.
> >
> > I wonder of this is true (not wanting http) for those supporting the oauth
> > sasl extension.
>
> Firstly, SASL is for MUA to MSA, not MSA/MTA to MTA.  Lookups of
> keys for recipients is at the receving end, not the sending end.
>
> Even if some large email provideds do end up supporting oauth SASL
> for various web services, it seems unlikely that they would do so
> for email accounts, where federated authentication seems rather
> out of place.  [...]

I do not think it is a question of "even if" --
https://www.ietf.org/mail-archive/web/kitten/current/msg03528.html is
one example of Google declaring intent to implement the final version of
draft-ietf-kitten-sasl-oauth, and explicitly mentions email.

-Ben