Re: [stir] JWT/JSON (was - Re: Review of: draft-ietf-stir-passport-05)

Christer Holmberg <christer.holmberg@ericsson.com> Wed, 24 August 2016 07:49 UTC

Return-Path: <christer.holmberg@ericsson.com>
X-Original-To: stir@ietfa.amsl.com
Delivered-To: stir@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 34D7E12D50B for <stir@ietfa.amsl.com>; Wed, 24 Aug 2016 00:49:39 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -4.221
X-Spam-Level:
X-Spam-Status: No, score=-4.221 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, RCVD_IN_DNSWL_MED=-2.3, RCVD_IN_MSPIKE_H3=-0.01, RCVD_IN_MSPIKE_WL=-0.01, SPF_PASS=-0.001] autolearn=ham autolearn_force=no
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id NvhuiGtx8EyK for <stir@ietfa.amsl.com>; Wed, 24 Aug 2016 00:49:36 -0700 (PDT)
Received: from sesbmg23.ericsson.net (sesbmg23.ericsson.net [193.180.251.37]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 5626A12D08D for <stir@ietf.org>; Wed, 24 Aug 2016 00:49:36 -0700 (PDT)
X-AuditID: c1b4fb25-8bfff70000001071-38-57bd518c3e3c
Received: from ESESSHC022.ericsson.se (Unknown_Domain [153.88.183.84]) by (Symantec Mail Security) with SMTP id 7F.60.04209.C815DB75; Wed, 24 Aug 2016 09:49:34 +0200 (CEST)
Received: from ESESSMB209.ericsson.se ([169.254.9.211]) by ESESSHC022.ericsson.se ([153.88.183.84]) with mapi id 14.03.0301.000; Wed, 24 Aug 2016 09:49:32 +0200
From: Christer Holmberg <christer.holmberg@ericsson.com>
To: "Peterson, Jon" <jon.peterson@neustar.biz>, "dcrocker@bbiw.net" <dcrocker@bbiw.net>, Eric Rescorla <ekr@rtfm.com>
Thread-Topic: [stir] JWT/JSON (was - Re: Review of: draft-ietf-stir-passport-05)
Thread-Index: AQHR/JI0ubFrdbKggkCO9F2iW0BZU6BWhCyAgAABtACAACpqMP//4L4AgABXHuCAALDnAIAAN+CA
Date: Wed, 24 Aug 2016 07:49:31 +0000
Message-ID: <D3E32D09.D808%christer.holmberg@ericsson.com>
References: <07e0eb16-6758-cdf1-c571-1f1ed768e741@dcrocker.net> <D3C152B2.1A69BA%jon.peterson@neustar.biz> <b096b541-c8af-9617-c9d7-5a1beb5230e8@dcrocker.net> <D3C16040.1A6A09%jon.peterson@neustar.biz> <d66d91f0-9ea2-6295-e749-e48ea37b4892@dcrocker.net> <cfd714ce-6145-1b60-aca2-ae702a8c133d@dcrocker.net> <CABcZeBNQgsjDOrW2k4WOucTVXSMHjEUjKgGkhYT119Z3yoUv1g@mail.gmail.com> <7594FB04B1934943A5C02806D1A2204B4BC29AD9@ESESSMB209.ericsson.se> <72ca2036-610e-2226-ed4f-34efbf0e9552@dcrocker.net> <D3E21244.D708%christer.holmberg@ericsson.com> <31ee21c4-ac59-2dec-3ce2-82ae650ea7c8@dcrocker.net> <7594FB04B1934943A5C02806D1A2204B4BC3506B@ESESSMB209.ericsson.se> <3b89d32f-3090-d883-b0d1-26c021f94ce9@dcrocker.net> <7594FB04B1934943A5C02806D1A2204B4BC35CC8@ESESSMB209.ericsson.se> <D3E22A20.1A90A4%jon.peterson@neustar.biz>
In-Reply-To: <D3E22A20.1A90A4%jon.peterson@neustar.biz>
Accept-Language: en-US
Content-Language: en-US
X-MS-Has-Attach:
X-MS-TNEF-Correlator:
user-agent: Microsoft-MacOutlook/14.6.5.160527
x-originating-ip: [153.88.183.16]
Content-Type: text/plain; charset="us-ascii"
Content-ID: <1CAB0F4928421D4ABEB6715F5EFDD7A4@ericsson.com>
Content-Transfer-Encoding: quoted-printable
MIME-Version: 1.0
X-Brightmail-Tracker: H4sIAAAAAAAAA+NgFtrIIsWRmVeSWpSXmKPExsUyM2J7iG5f4N5wg2/XVCx+f/rAZrHi9Tl2 izMNlhbL125jcmDxuLTzJJvHkiU/mTx2NDxn9pj8uI05gCWKyyYlNSezLLVI3y6BK6Pz6Rvm gnd8FX9X7mRqYGzj6WLk5JAQMJFo/X2dqYuRi0NIYD2jxNcpc9lBEkICSxglrq2w6WLk4GAT sJDo/qcNEhYRKJd40DYbrIRZQF3ixaM3YLawQKBEz4W/LBA1QRInX7xkh7CjJDbfPcEEYrMI qErMb9rIBjKSV8BK4viOXIhN59gkXk4uALE5BcwlXk+ZAVbOKCAm8f3UGiaIVeISt57MZ4I4 WUBiyZ7zzBC2qMTLx/9YQWxRAT2J719nQ8UVJXaebWeG6NWRWLD7ExuEbS3xbe5zRghbW2LZ wtdgNbwCghInZz5hmcAoPgvJullI2mchaZ+FpH0WkvYFjKyrGEWLU4uTctONjPVSizKTi4vz 8/TyUks2MQIj8uCW36o7GC+/cTzEKMDBqMTD+yBsT7gQa2JZcWXuIUYJDmYlEd5Ir73hQrwp iZVVqUX58UWlOanFhxilOViUxHn9XyqGCwmkJ5akZqemFqQWwWSZODilGhiFV1qv47O+HTO1 9sljwZ1zXYVqZ8Sc+qXgpdaQOevm2ttLKrlkdP6uusRXfFWI59LSoubNU62ULj/5nhP/7OY/ 7gOtv01EVxmtnJe9r0Fk3snFGmrfXB9c6NzsfVFr3xT2k4vXJZi3nMsomTJX799tOYH4P3dC 7327d02G3+vPrivq16YYuqZ4K7EUZyQaajEXFScCAKpiaIvEAgAA
Archived-At: <https://mailarchive.ietf.org/arch/msg/stir/g7gWXWNgs33N60XZDseTYqsHVFQ>
Cc: IETF STIR Mail List <stir@ietf.org>
Subject: Re: [stir] JWT/JSON (was - Re: Review of: draft-ietf-stir-passport-05)
X-BeenThere: stir@ietf.org
X-Mailman-Version: 2.1.17
Precedence: list
List-Id: Secure Telephone Identity Revisited <stir.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/stir>, <mailto:stir-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/stir/>
List-Post: <mailto:stir@ietf.org>
List-Help: <mailto:stir-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/stir>, <mailto:stir-request@ietf.org?subject=subscribe>
X-List-Received-Date: Wed, 24 Aug 2016 07:49:39 -0000

Yes, I mean RFC 7515. For some strange reason I keep on getting the
numbers of the RFCs associated with the STIR work wrong all the time :)

Regards,

Christer

On 24/08/16 10:33, "Peterson, Jon" <jon.peterson@neustar.biz> wrote:

>>I guess Jon should reply to that question, but one reasons was related to
>>the suggestion (I don't think that WG has made a decision, but please
>>correct me if I'm wrong) that it should be optional to send the headers
>>representation of the JWS, as that information (cipher suite etc) can be
>>found in other SIP elements.
>
>What I see minuted from IETF 96 as a decision for this question was "keep
>what we have now," in other words, keep "canon" optional. As long as
>"canon" is optional, then we need at least to have the ability to convey
>"alg" and "ppt" in the Identity header (field!). Practically speaking
>though, "alg" exists only to give us some flexibility in case it turns out
>in the future that the one algorithm we've specified won't work for us. I
>doubt "alg" will be present over the wire much.
>
>> However, Appendix F of RFC 7575 is unclear on whether it's allowed
>>remove the headers representation from the JWS - the Appendix seems to
>>only talk about not sending the payload representation (which, in the
>>case of SIP, can also be found in other SIP elements). So, there could be
>>cases were one would only send the signature representation of the JWS.
>
>RFC7515, you mean. And yes, it basically just says "you can have
>detachable content" without detailing what that means. The new text in
>rfc4474bis-11 will, as promised, go into more detail about this, and
>furnish an example.
>
>Jon Peterson
>Neustar, Inc.
>
>> 
>>
>>Regards,
>>
>>Christer
>>
>>_______________________________________________
>>stir mailing list
>>stir@ietf.org
>>https://www.ietf.org/mailman/listinfo/stir
>