[saag] OAuth IETF#105 Report

Hannes Tschofenig <Hannes.Tschofenig@arm.com> Thu, 25 July 2019 15:41 UTC

Return-Path: <Hannes.Tschofenig@arm.com>
X-Original-To: saag@ietfa.amsl.com
Delivered-To: saag@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 22F84120287 for <saag@ietfa.amsl.com>; Thu, 25 Jul 2019 08:41:10 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.9
X-Spam-Level:
X-Spam-Status: No, score=-1.9 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, HTML_MESSAGE=0.001, RCVD_IN_DNSWL_NONE=-0.0001, SPF_PASS=-0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (1024-bit key) header.d=armh.onmicrosoft.com header.b=73wYqPB7; dkim=fail (1024-bit key) reason="fail (body has been altered)" header.d=armh.onmicrosoft.com header.b=rQXhY8xD
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id Hlg2MfbP2gDi for <saag@ietfa.amsl.com>; Thu, 25 Jul 2019 08:41:07 -0700 (PDT)
Received: from EUR01-HE1-obe.outbound.protection.outlook.com (mail-eopbgr130089.outbound.protection.outlook.com [40.107.13.89]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id D8C9B12028F for <saag@ietf.org>; Thu, 25 Jul 2019 08:41:06 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=armh.onmicrosoft.com; s=selector2-armh-onmicrosoft-com; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-SenderADCheck; bh=Q7hSbqvTtzW8D3bsZfJmHZMv0Taz4qBTA0G4zjCyLlw=; b=73wYqPB7AnSfqOwR8Akpmuqdr7w+PICJvo1O5YKzjFoAqAjvexIiT1NgNsJH02isizaFLLewFDJWxFYrgs7aus0cQlNnzQZyWTeO/QYXEYOh1WWUNlHxLgUyhoSbA3VVcSIywVVVf80P1UB+RnL/7UrgFjCihTW59DG/T15JE2A=
Received: from VI1PR08CA0267.eurprd08.prod.outlook.com (20.178.125.40) by VI1PR0801MB1853.eurprd08.prod.outlook.com (10.168.67.22) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.20.2115.10; Thu, 25 Jul 2019 15:41:02 +0000
Received: from AM5EUR03FT057.eop-EUR03.prod.protection.outlook.com (2a01:111:f400:7e08::200) by VI1PR08CA0267.outlook.office365.com (2603:10a6:803:dc::40) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.20.2115.10 via Frontend Transport; Thu, 25 Jul 2019 15:41:02 +0000
Authentication-Results: spf=temperror (sender IP is 63.35.35.123) smtp.mailfrom=arm.com; ietf.org; dkim=pass (signature was verified) header.d=armh.onmicrosoft.com;ietf.org; dmarc=temperror action=none header.from=arm.com;
Received-SPF: TempError (protection.outlook.com: error in processing during lookup of arm.com: DNS Timeout)
Received: from 64aa7808-outbound-1.mta.getcheckrecipient.com (63.35.35.123) by AM5EUR03FT057.mail.protection.outlook.com (10.152.17.44) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.20.2052.18 via Frontend Transport; Thu, 25 Jul 2019 15:41:00 +0000
Received: ("Tessian outbound 220137ab7b0b:v26"); Thu, 25 Jul 2019 15:41:00 +0000
X-CR-MTA-TID: 64aa7808
Received: from 844c044c797b.1 (ip-172-16-0-2.eu-west-1.compute.internal [104.47.13.52]) by 64aa7808-outbound-1.mta.getcheckrecipient.com id 4B0302C0-F07D-4E2C-B230-9B730450B28C.1; Thu, 25 Jul 2019 15:40:55 +0000
Received: from EUR04-HE1-obe.outbound.protection.outlook.com (mail-he1eur04lp2052.outbound.protection.outlook.com [104.47.13.52]) by 64aa7808-outbound-1.mta.getcheckrecipient.com with ESMTPS id 844c044c797b.1 (version=TLSv1.2 cipher=ECDHE-RSA-AES256-GCM-SHA384); Thu, 25 Jul 2019 15:40:55 +0000
ARC-Seal: i=1; a=rsa-sha256; s=arcselector9901; d=microsoft.com; cv=none; b=bohgjIJ1N01ex8jkxXlTxrQej1eTeWhDJ3+I7vU57bdx9SYnVy8fZ7eZMKoFUjj2ZbKlCoPJqjNPB0JcaDTNkMLJFm56xgjQu/Unh9L73YJ6pdYE7Dw5GL+HEpmTfUdLiYnZBsQdoUUJoqjY1Svs0ECklv75E5Oz/RhU42vjdTMOC8AUBxa94GcsPZAHP3SWcTc2wtc6u+zACh3ZChRsnIQCL4bfdlzSdi1qmV74iuPMLJ5X05Vvc/IjyCVQ1iXQUudZYVFEBXxFeJNORJJKEfihGCF5d9R5FArSrtKogiIqkO34OeLbgjNnKZUQ9t4WTQwXnHqAVJRyDehIBM6wiw==
ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=microsoft.com; s=arcselector9901; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-SenderADCheck; bh=Vynj3znL6RdBkvz6zfYJYPZDF0dnM7ANpPCUFAEn5Lc=; b=i/NMIEsTEMo15yFOpR6FEIvZLtKizn7vF3a4Gbs0kyOQA9W/EhmB7FAwNsHIdf+MMA0BXRluipJl7siPU/LmUD2j2C8QLELiqcQiVBSvqHCtmRIJBw/T9uYAv2kwKllZWyl1K9TFn0QZ/tquWlV3nZzR2k1b4fAJ1ALMzb1KlVl+9e/wXfknfT6VRA7UdvDGs7NYcZKLO2WLiHVK95M3dBuaGWiaADYM7dC8CEXiWOUYzDsxBhtdmQAJoEAouTAOrozY4RDDwGB3EU3EgmhZiRw0m/mMAXLo03Wjf2k/LvNi+zCC/z0jVHp9OaziKBiufkkz2PyM7spuPeZEg+mDmA==
ARC-Authentication-Results: i=1; mx.microsoft.com 1;spf=pass smtp.mailfrom=arm.com;dmarc=pass action=none header.from=arm.com;dkim=pass header.d=arm.com;arc=none
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=armh.onmicrosoft.com; s=selector2-armh-onmicrosoft-com; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-SenderADCheck; bh=Vynj3znL6RdBkvz6zfYJYPZDF0dnM7ANpPCUFAEn5Lc=; b=rQXhY8xDMiqLm3ka2h426faB14KFJfl3QIGV3ckBHyth0DzRJagpVXcKOjfd4hWIEIkmZ3/9SO+2sOXjsWs6ho3kurhqCJexDr9zzdIvMyqY8N03qye/aZ5Xl+2gRl+RmUA3MYJMKHg4Ewmv1skTDkFmc9T3UmE5PIcA3HHdYLw=
Received: from VI1PR08MB5360.eurprd08.prod.outlook.com (52.133.244.88) by VI1PR08MB3902.eurprd08.prod.outlook.com (20.178.81.10) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.20.2115.10; Thu, 25 Jul 2019 15:40:53 +0000
Received: from VI1PR08MB5360.eurprd08.prod.outlook.com ([fe80::e8f0:b69b:7f7a:c486]) by VI1PR08MB5360.eurprd08.prod.outlook.com ([fe80::e8f0:b69b:7f7a:c486%3]) with mapi id 15.20.2115.005; Thu, 25 Jul 2019 15:40:53 +0000
From: Hannes Tschofenig <Hannes.Tschofenig@arm.com>
To: "saag@ietf.org" <saag@ietf.org>
Thread-Topic: OAuth IETF#105 Report
Thread-Index: AdVC/1U60AzOHl1oS8CK4sQ12jIL9Q==
Date: Thu, 25 Jul 2019 15:40:53 +0000
Message-ID: <VI1PR08MB5360E95DF38F66BC17F9216FFAC10@VI1PR08MB5360.eurprd08.prod.outlook.com>
Accept-Language: en-US
Content-Language: en-US
X-MS-Has-Attach:
X-MS-TNEF-Correlator:
x-ts-tracking-id: f006a27e-595f-47a9-b4d5-071e03519409.0
x-checkrecipientchecked: true
Authentication-Results-Original: spf=none (sender IP is ) smtp.mailfrom=Hannes.Tschofenig@arm.com;
x-originating-ip: [2001:67c:1232:144:2944:459:e8e8:e79b]
x-ms-publictraffictype: Email
X-MS-Office365-Filtering-Correlation-Id: 2bec9dd4-f3a0-482c-a104-08d711167ea8
X-MS-Office365-Filtering-HT: Tenant
X-Microsoft-Antispam-Untrusted: BCL:0; PCL:0; RULEID:(2390118)(7020095)(4652040)(8989299)(4534185)(4627221)(201703031133081)(201702281549075)(8990200)(5600148)(711020)(4605104)(1401327)(4618075)(2017052603328)(7193020); SRVR:VI1PR08MB3902;
X-MS-TrafficTypeDiagnostic: VI1PR08MB3902:|VI1PR0801MB1853:
X-Microsoft-Antispam-PRVS: <VI1PR0801MB18530E36C23148BF6A501579FAC10@VI1PR0801MB1853.eurprd08.prod.outlook.com>
x-checkrecipientrouted: true
x-ms-oob-tlc-oobclassifiers: OLM:7219;OLM:7219;
x-forefront-prvs: 0109D382B0
X-Forefront-Antispam-Report-Untrusted: SFV:NSPM; SFS:(10009020)(4636009)(396003)(366004)(376002)(136003)(346002)(39860400002)(199004)(189003)(46003)(476003)(14454004)(64756008)(52536014)(76116006)(5660300002)(2351001)(6506007)(66446008)(316002)(7736002)(66476007)(66556008)(102836004)(71200400001)(81166006)(74316002)(486006)(8676002)(66946007)(53936002)(81156014)(1730700003)(186003)(99286004)(25786009)(7696005)(6306002)(4744005)(9686003)(478600001)(6916009)(2501003)(71190400001)(8936002)(256004)(5640700003)(790700001)(6116002)(55016002)(86362001)(2906002)(6436002)(66574012)(68736007)(54896002)(14444005)(33656002); DIR:OUT; SFP:1101; SCL:1; SRVR:VI1PR08MB3902; H:VI1PR08MB5360.eurprd08.prod.outlook.com; FPR:; SPF:None; LANG:en; PTR:InfoNoRecords; A:1; MX:1;
received-spf: None (protection.outlook.com: arm.com does not designate permitted sender hosts)
X-MS-Exchange-SenderADCheck: 1
X-Microsoft-Antispam-Message-Info-Original: p/0fvj7S3KZQikb1KSDziUow7BVp+XVcD2GbgwQUfcJV2Ywurbm/bWrmEHgH96X75NtzzP1L8TCicQHmA/lZaygEkErjnEh1kHKno/JtZLFW24pvwDPfxgV+erdqjB325Op3ArlrhL1SLEilm2Sc+MzRtdvYpNtJh8x1KxE5M6byOWrR9e4IeCMS7cg8WULyPJwngJeSpiJDhqfw0FpWM7+a05D5u4qJTiNAvItq6hmwcA0mOUofrs63q/2lj1jCBK0Lnn9LpGXJFZ4acy1wlleOVCe6iTHrNFc4NoPwXu/OIvtGq8hUXcFMFNQB/wsU7x2/sPcP6iSHzkWXiwhclYKQpBeTE+S1f9PYIvUWxOmujTvob0678ppTKGJlwLKk04btlxBUa0X1ME9EvFikJm/YFOszYV35guzmiC+GVWM=
Content-Type: multipart/alternative; boundary="_000_VI1PR08MB5360E95DF38F66BC17F9216FFAC10VI1PR08MB5360eurp_"
MIME-Version: 1.0
X-MS-Exchange-Transport-CrossTenantHeadersStamped: VI1PR08MB3902
Original-Authentication-Results: spf=none (sender IP is ) smtp.mailfrom=Hannes.Tschofenig@arm.com;
X-EOPAttributedMessage: 0
X-MS-Exchange-Transport-CrossTenantHeadersStripped: AM5EUR03FT057.eop-EUR03.prod.protection.outlook.com
X-Forefront-Antispam-Report: CIP:63.35.35.123; IPV:CAL; SCL:-1; CTRY:IE; EFV:NLI; SFV:NSPM; SFS:(10009020)(4636009)(39860400002)(396003)(346002)(136003)(376002)(2980300002)(199004)(189003)(40434004)(790700001)(478600001)(6116002)(2351001)(36906005)(102836004)(5640700003)(55016002)(74316002)(316002)(54896002)(16586007)(6306002)(9686003)(336012)(6506007)(76130400001)(2501003)(70586007)(26005)(14454004)(7736002)(70206006)(86362001)(33656002)(26826003)(356004)(126002)(14444005)(81156014)(2906002)(52536014)(486006)(25786009)(6916009)(5024004)(5660300002)(61614004)(8936002)(1730700003)(8676002)(81166006)(186003)(99286004)(63370400001)(22756006)(66574012)(63350400001)(476003)(71190400001)(7696005); DIR:OUT; SFP:1101; SCL:1; SRVR:VI1PR0801MB1853; H:64aa7808-outbound-1.mta.getcheckrecipient.com; FPR:; SPF:TempError; LANG:en; PTR:ec2-63-35-35-123.eu-west-1.compute.amazonaws.com; A:1; MX:1;
X-MS-Office365-Filtering-Correlation-Id-Prvs: 4b3ec37c-d024-4175-237d-08d711167a81
X-Microsoft-Antispam: BCL:0; PCL:0; RULEID:(2390118)(7020095)(4652040)(8989299)(4534185)(4627221)(201703031133081)(201702281549075)(8990200)(5600148)(710020)(711020)(4605104)(1401327)(2017052603328)(7193020); SRVR:VI1PR0801MB1853;
X-Forefront-PRVS: 0109D382B0
X-Microsoft-Antispam-Message-Info: D3ZjORf/ggfMuxFFPI7oKPf+7AaigKUsciBiSOF7kMWHYooWAXLHfEjoozig38I+H+kcxbKjAeSf0poJ1FDAXJx3GcyAekACGqqMhSEqmbQzR4NqNEHntxQ9sLXD7eYIejztp5iNII/u+LNRiX9d3pavwsLjJZXUJOGZGohBMPiVjKDGbHQC8cE1BIF8t8O4XSD+CNxG5qCWqHysprjJ/gDiOIozoxOBge2uUMBt62BV5N1lRFQg+1j2yVWasJifQVixrRv4ClnJjDZSAtg8qEYAWoWNlrNMQmFbBGD1FbpB9xfVjQ2BkNY+OSUuAs3BcCxaKMpZl4RXB9baNV53dHwUal639cZtyvVg1AImylo3+/hYt1VQ8rt1T5m5rLFXw/X+y5pgDsXWSSRxeb4WDGD0wlVjxnCjs7LuhNWqwEg=
X-OriginatorOrg: arm.com
X-MS-Exchange-CrossTenant-OriginalArrivalTime: 25 Jul 2019 15:41:00.7377 (UTC)
X-MS-Exchange-CrossTenant-Network-Message-Id: 2bec9dd4-f3a0-482c-a104-08d711167ea8
X-MS-Exchange-CrossTenant-Id: f34e5979-57d9-4aaa-ad4d-b122a662184d
X-MS-Exchange-CrossTenant-OriginalAttributedTenantConnectingIp: TenantId=f34e5979-57d9-4aaa-ad4d-b122a662184d; Ip=[63.35.35.123]; Helo=[64aa7808-outbound-1.mta.getcheckrecipient.com]
X-MS-Exchange-CrossTenant-FromEntityHeader: HybridOnPrem
X-MS-Exchange-Transport-CrossTenantHeadersStamped: VI1PR0801MB1853
Archived-At: <https://mailarchive.ietf.org/arch/msg/saag/bCf5Bq9-GvFwdDypcZEJXB52zLc>
Subject: [saag] OAuth IETF#105 Report
X-BeenThere: saag@ietf.org
X-Mailman-Version: 2.1.29
Precedence: list
List-Id: Security Area Advisory Group <saag.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/saag>, <mailto:saag-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/saag/>
List-Post: <mailto:saag@ietf.org>
List-Help: <mailto:saag-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/saag>, <mailto:saag-request@ietf.org?subject=subscribe>
X-List-Received-Date: Thu, 25 Jul 2019 15:41:13 -0000

Multiple documents that have been stuck for some time have now progressed:

Three drafts in IETF LC:
* JWT Response for OAuth Token Introspection
* OAuth 2.0 Mutual TLS Client Authentication and Certificate-Bound Access Tokens
* Resource Indicators for OAuth 2.0

Two drafts within the RFC Editor:
* OAuth 2.0 Token Exchange
* OAuth 2.0 Device Authorization Grant

We have two sessions: the first one was on Tuesday and the group discussed
the following WG documents:
* Reciprocal OAuth
* Security BCP

The group discussed the idea of developing a new version of the OAuth protocol.
The chairs will discuss next steps with the area director.

The second session is on Friday and the group is planning to discuss the following WG documents:
* JWT profile for ATs
* OAuth for browser based apps

The group will also discuss few more non-WG documents.
IMPORTANT NOTICE: The contents of this email and any attachments are confidential and may also be privileged. If you are not the intended recipient, please notify the sender immediately and do not disclose the contents to any other person, use it for any purpose, or store or copy the information in any medium. Thank you.