[secdir] Secdir review of draft-ietf-oauth-jwt-bcp-04

Radia Perlman <radiaperlman@gmail.com> Sun, 31 March 2019 05:34 UTC

Return-Path: <radiaperlman@gmail.com>
X-Original-To: secdir@ietfa.amsl.com
Delivered-To: secdir@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id AD47412016D; Sat, 30 Mar 2019 22:34:04 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.999
X-Spam-Level:
X-Spam-Status: No, score=-1.999 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, FREEMAIL_FROM=0.001, HTML_MESSAGE=0.001, RCVD_IN_DNSWL_NONE=-0.0001, SPF_PASS=-0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (2048-bit key) header.d=gmail.com
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id stfBCqiLZkuN; Sat, 30 Mar 2019 22:34:03 -0700 (PDT)
Received: from mail-lj1-x22b.google.com (mail-lj1-x22b.google.com [IPv6:2a00:1450:4864:20::22b]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 95DFD120169; Sat, 30 Mar 2019 22:34:02 -0700 (PDT)
Received: by mail-lj1-x22b.google.com with SMTP id f18so5228909lja.10; Sat, 30 Mar 2019 22:34:02 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20161025; h=mime-version:references:in-reply-to:from:date:message-id:subject:to; bh=Zf+Wt3zG42Mfb+Oxxt0rCbfk7l+YA4NsvIsUiCKje6M=; b=pFVkD+wPYFOjGMPHGv1Hs323HP4z8HQCvPdq19M8qg3LFAdhcNmGyWuHNwKxSvYYz0 B5+Qr8u8R1HS/UcJEr4HXpKxJONpo2iDIROTEUdxhv1866sqpfbaNHRl5ejzz/BRIOH6 /hsAOPlPVUzY5R8OM9ncLnxfINBpi0e6JMCikvBRivyzcZYcYaoQ1WlbBgrEqnKelpf2 SACbLHJOCWXsB3Z08Lt1HEpOHSkpL/uTmmVwAziOVjsgRvVAr3wkSS8q8v4037WyrjmG cKb+gs+IHXVc7ZcQeCm1XhWwwSV+nikQMDiJSDCX8F2YjQqa4D0/0TXpeDDDI3R0XEKU Af4g==
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20161025; h=x-gm-message-state:mime-version:references:in-reply-to:from:date :message-id:subject:to; bh=Zf+Wt3zG42Mfb+Oxxt0rCbfk7l+YA4NsvIsUiCKje6M=; b=p6FZY4x5yAgLI4HdZgE00zFD+o9haDmaYGDPybpghqXoda5JUp0WBEAZNXZp5xeHIl 5pmWpvTJnJFUp0lLf8wUkyIfBhlnUXxzwnW3GPMfnhWCBLzWkwpmezJQ6tUVDLi9kpyV ptMepPE2kPOM0L9ekKvuc5b9xR8z5mjz/+KU6oZd9mch5Q6zUuMbTbx7NUfMYcs3lN9d Vua5Ch2fR3WLeSesbEQvf3n/dmDVP1DI+oKNsqHBm1lSccov2LGCgnNU4/9Ha5OZGClC HF+WkBCZvm9fgAIhPklgAQeK8nP3aeynQPRjikcABcAsxhPeaZOA6RK/E3XMMlLFT58V emKA==
X-Gm-Message-State: APjAAAXN3i4cEbpc6IJLR0EEX675RmcevOF2PpQ2CB55dWiXSd62Uogv 8y4o/14wRkp0d6uTswgAtuENYg5UP6CZAxjqdl4iVrek
X-Google-Smtp-Source: APXvYqyq7DSsDAfJ257uG7ZY6orZjdsnEVpPvYaQUY+4iKFIAZI3ayMh4MqijmxzhS4yMg5ccte4lL2er5GyulnOW8I=
X-Received: by 2002:a2e:2b04:: with SMTP id q4mr734035lje.175.1554010440739; Sat, 30 Mar 2019 22:34:00 -0700 (PDT)
MIME-Version: 1.0
References: <CAFOuuo4pZQ_ojPW-i=ni+SgC9aUCvUubH64qrf_=OqtaWCLXbQ@mail.gmail.com>
In-Reply-To: <CAFOuuo4pZQ_ojPW-i=ni+SgC9aUCvUubH64qrf_=OqtaWCLXbQ@mail.gmail.com>
From: Radia Perlman <radiaperlman@gmail.com>
Date: Sat, 30 Mar 2019 22:33:49 -0700
Message-ID: <CAFOuuo5AVoAQjXwiu0Mqo5Cf+UbO26uy_ijDccWuKWJ_zrR6Mg@mail.gmail.com>
To: draft-ietf-sheffer-oauth-jwt-bcp.all@ietf.org, The IESG <iesg@ietf.org>, secdir@ietf.org
Content-Type: multipart/alternative; boundary="0000000000004c311b05855d4001"
Archived-At: <https://mailarchive.ietf.org/arch/msg/secdir/rDvPCGlbZHavBdlU0hLC8vy6968>
Subject: [secdir] Secdir review of draft-ietf-oauth-jwt-bcp-04
X-BeenThere: secdir@ietf.org
X-Mailman-Version: 2.1.29
Precedence: list
List-Id: Security Area Directorate <secdir.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/secdir>, <mailto:secdir-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/secdir/>
List-Post: <mailto:secdir@ietf.org>
List-Help: <mailto:secdir-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/secdir>, <mailto:secdir-request@ietf.org?subject=subscribe>
X-List-Received-Date: Sun, 31 Mar 2019 05:34:05 -0000

Sorry...mistyped the recipients, so I'm resending

---------- Forwarded message ---------
From: Radia Perlman <radiaperlman@gmail.com>;
Date: Sat, Mar 30, 2019 at 10:27 PM
Subject: Secdir review of draft-ietf-oauth-jwt-bcp-04
To: <draft-ietf-draft-sheffer-oauth-jwt-bcp.all@ietf.org>;, iesg@ietf.org <
iesg@ietf.org>;, secdir@ietf.org <secdir@ietf.org>;


I have reviewed this document as part of the security directorate's ongoing
effort to review all IETF documents being processed by the IESG. These
comments were written primarily for the benefit of the security area
directors. Document editors and WG chairs should treat these comments just
like any other last call comments.

The summary is READY

This document is a well-written and well-thought-through listing of best
practices for using JSON web tokens.  I could not find any of the advice
that I disagreed with, nor could I think of any more issues that the draft
could have addressed.


Radia