Re: [Teep] OTrP over HTTP

Dave Thaler <dthaler@microsoft.com> Wed, 06 February 2019 02:22 UTC

Return-Path: <dthaler@microsoft.com>
X-Original-To: teep@ietfa.amsl.com
Delivered-To: teep@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 7E9DB1288BD for <teep@ietfa.amsl.com>; Tue, 5 Feb 2019 18:22:56 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -4.564
X-Spam-Level:
X-Spam-Status: No, score=-4.564 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIMWL_WL_HIGH=-4.553, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, HTML_MESSAGE=0.001, HTTPS_HTTP_MISMATCH=1.989, RCVD_IN_DNSWL_NONE=-0.0001, SPF_PASS=-0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (1024-bit key) header.d=microsoft.com
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id 3fos-hicv2f3 for <teep@ietfa.amsl.com>; Tue, 5 Feb 2019 18:22:54 -0800 (PST)
Received: from NAM02-SN1-obe.outbound.protection.outlook.com (mail-eopbgr770109.outbound.protection.outlook.com [40.107.77.109]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 23F87126C7E for <teep@ietf.org>; Tue, 5 Feb 2019 18:22:53 -0800 (PST)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=microsoft.com; s=selector1; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-SenderADCheck; bh=IrP/YuB2AlfNuzpdbm4B/JtYw5pdAO3qEriyMbQz3B0=; b=I6e5D9sCprhI90fiAzLWaSObvWiTgNiXi8SpQF8qswKtWmmdu2bpUE/63P0+GCZvW/Ust6VvJhUZmTwtiVGIt+PPrmmpg+iKJnwnC5gxsBxp9n1RB5BcSDekt1LNDE9YvLfcW8f75aKN6H4z8rRQrdmMteiHG4aa8+VzdeiUkHc=
Received: from CY4PR21MB0168.namprd21.prod.outlook.com (10.173.192.150) by CY4PR21MB0792.namprd21.prod.outlook.com (10.175.121.146) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.20.1622.5; Wed, 6 Feb 2019 02:22:52 +0000
Received: from CY4PR21MB0168.namprd21.prod.outlook.com ([fe80::522:452b:589b:44fb]) by CY4PR21MB0168.namprd21.prod.outlook.com ([fe80::522:452b:589b:44fb%5]) with mapi id 15.20.1622.000; Wed, 6 Feb 2019 02:22:52 +0000
From: Dave Thaler <dthaler@microsoft.com>
To: teep <teep@ietf.org>
Thread-Topic: OTrP over HTTP
Thread-Index: AdS9wXAaqizfVmN1TYKP4hMhsRQ1rAAAQ5jw
Date: Wed, 06 Feb 2019 02:22:51 +0000
Message-ID: <CY4PR21MB0168231BD0C479575B5E4272A36F0@CY4PR21MB0168.namprd21.prod.outlook.com>
References: <CY4PR21MB016805C1A96C8610AABB9B0FA36F0@CY4PR21MB0168.namprd21.prod.outlook.com>
In-Reply-To: <CY4PR21MB016805C1A96C8610AABB9B0FA36F0@CY4PR21MB0168.namprd21.prod.outlook.com>
Accept-Language: en-US
Content-Language: en-US
X-MS-Has-Attach:
X-MS-TNEF-Correlator:
msip_labels: MSIP_Label_f42aa342-8706-4288-bd11-ebb85995028c_Enabled=True; MSIP_Label_f42aa342-8706-4288-bd11-ebb85995028c_SiteId=72f988bf-86f1-41af-91ab-2d7cd011db47; MSIP_Label_f42aa342-8706-4288-bd11-ebb85995028c_Owner=dthaler@ntdev.microsoft.com; MSIP_Label_f42aa342-8706-4288-bd11-ebb85995028c_SetDate=2019-02-06T02:18:01.1042138Z; MSIP_Label_f42aa342-8706-4288-bd11-ebb85995028c_Name=General; MSIP_Label_f42aa342-8706-4288-bd11-ebb85995028c_Application=Microsoft Azure Information Protection; MSIP_Label_f42aa342-8706-4288-bd11-ebb85995028c_ActionId=bdc865f6-dc2b-4b7e-a64b-db62ff1e8092; MSIP_Label_f42aa342-8706-4288-bd11-ebb85995028c_Extended_MSFT_Method=Automatic
authentication-results: spf=none (sender IP is ) smtp.mailfrom=dthaler@microsoft.com;
x-originating-ip: [73.59.106.235]
x-ms-publictraffictype: Email
x-microsoft-exchange-diagnostics: 1; CY4PR21MB0792; 6:XGNA2FLgkx58bYil/j8l+AoS6UblQ31NP6BM4aUzEGEc5L/mGnBzoq8QMa+QB7u4TT9PphAulo2/qDffxm1vdoMvablRm/of6IEO5UMdNVAbFrla5BSJfM0aDtX0iv3NGe93TKUJFNz+cfZ7Qw4lasXpvJevn5AIuTpcfs/LtkFaplb1uWEkKcw+zIVcFVaDk7bhDoI50PgK+zMfV+a75ZZJkm6Z3KjQk+o499W4Q6iGgFD5CvT/Wsu6rD0BLefp7RBRphXceKaE58XLDKQibXikWu5Q65EZzPAeyL6B8iY3BMKE/a1VXWGRzc93836GGTWhMmjhs7+wUZVaEfItY2o9OgA+r1F2qz3OCGA4TGWv7tE3J1GbCvAXPfMme2F8V5uzpnw48sXPDWFziiU+u7vSADIYPvZSRLZDGtzfbJ3YJstf9m80T9azUhz81MqLDDDG1EkqVCiu4MY5i4+DsA==; 5:v6uZZXyrpe2srh5kc0jx02Rzv9vByMaZ379kneoOveUCs0iryV/gYj8T3Jhz/Z9BS3zmlNGGB6e9VypNkVnPWgZHvKcI3UqgtrxcuMGXAbyhS+UOSagA3NcU7+XhIeMB0pXHJOrZlA5g3yHFZWH69swhNDyCoynN53eRTUI5rsWU+27hPb7sZFbGSVUC1y8zAa3LIRRf32+y6m8Y6K0Zcg==; 7:n4gz3FB7FqjsXsR6ZSCp6oTufTSo68cFO9Kq+g//mXtcawOI3hH6Xa3HLTLMty4PHYguhXzjr+hH0X1sxK2h4YV5tlgZGjJXqjHmcPv+sMNmnxEEv38wbAbH0/zVrtJlTcM8xG610SJMGgHMsqI88Q==
x-ms-office365-filtering-correlation-id: f23c5185-3ec0-47c6-86fb-08d68bd9fee7
x-ms-office365-filtering-ht: Tenant
x-microsoft-antispam: BCL:0; PCL:0; RULEID:(2390118)(7020095)(4652040)(8989299)(4534185)(4627221)(201703031133081)(201702281549075)(8990200)(5600110)(711020)(4605077)(4618075)(2017052603328)(7193020); SRVR:CY4PR21MB0792;
x-ms-traffictypediagnostic: CY4PR21MB0792:
x-ms-exchange-purlcount: 1
x-microsoft-antispam-prvs: <CY4PR21MB0792AF442A1110C11AE0E12BA36F0@CY4PR21MB0792.namprd21.prod.outlook.com>
x-forefront-prvs: 0940A19703
x-forefront-antispam-report: SFV:NSPM; SFS:(10019020)(136003)(366004)(39860400002)(376002)(396003)(346002)(13464003)(51444003)(199004)(189003)(10290500003)(81166006)(966005)(10090500001)(236005)(55016002)(7116003)(478600001)(8676002)(14444005)(76176011)(256004)(6306002)(8936002)(81156014)(14454004)(229853002)(86362001)(3846002)(71190400001)(97736004)(2940100002)(6916009)(6436002)(446003)(316002)(71200400001)(22452003)(86612001)(486006)(476003)(11346002)(6506007)(2906002)(8990500004)(26005)(74316002)(3480700005)(66066001)(53546011)(93156006)(53936002)(606006)(102836004)(186003)(6116002)(6246003)(106356001)(7696005)(33656002)(9686003)(105586002)(54896002)(25786009)(99286004)(68736007)(7736002)(790700001); DIR:OUT; SFP:1102; SCL:1; SRVR:CY4PR21MB0792; H:CY4PR21MB0168.namprd21.prod.outlook.com; FPR:; SPF:None; LANG:en; PTR:InfoNoRecords; A:1; MX:1;
received-spf: None (protection.outlook.com: microsoft.com does not designate permitted sender hosts)
x-ms-exchange-senderadcheck: 1
x-microsoft-antispam-message-info: AYlF5hdMGZTIKXgChyk4GuZNr1hJdKvYYkptrLhe1FyQgcGVDe/2p+oI0mJQ2T45NPxlFJWSVdhUDxqcTeIsHGgf7xx7rddgJyL+QOYC5qMHgqbYebCbe4uAjE7myS7SYN8zw+MujPmYFt4ojUko5rXcfiBKX1uZTiGuXaUTigH+LgPnbwKaucYBl8BKcSRvbPdnMYVfwhM8nogDGOSIEKNgRT46oCDrDnYaG37IBSYCmCO0IyAhuhYa5Ae0SZZKTgnq88ZF7jAV4erk22SnFz+cAVtIGM+Xq8EBeANDBLlV98fzSmuJ753AUEyZm3Mp+9K8HJ1pMVGb7AwAYen2y25XAfPAmgix8DZkff+QYsX/+qp6xVqYQmBee9GhMcG+/fivGtQ15oJVRL/fuOs4NfLeIW8xYCYHLwp9+iAxlW0=
Content-Type: multipart/alternative; boundary="_000_CY4PR21MB0168231BD0C479575B5E4272A36F0CY4PR21MB0168namp_"
MIME-Version: 1.0
X-OriginatorOrg: microsoft.com
X-MS-Exchange-CrossTenant-Network-Message-Id: f23c5185-3ec0-47c6-86fb-08d68bd9fee7
X-MS-Exchange-CrossTenant-originalarrivaltime: 06 Feb 2019 02:22:51.9703 (UTC)
X-MS-Exchange-CrossTenant-fromentityheader: Hosted
X-MS-Exchange-CrossTenant-id: 72f988bf-86f1-41af-91ab-2d7cd011db47
X-MS-Exchange-CrossTenant-mailboxtype: HOSTED
X-MS-Exchange-Transport-CrossTenantHeadersStamped: CY4PR21MB0792
Archived-At: <https://mailarchive.ietf.org/arch/msg/teep/tzpiinv9R0yq8C_G3GbA6iSbcrg>
Subject: Re: [Teep] OTrP over HTTP
X-BeenThere: teep@ietf.org
X-Mailman-Version: 2.1.29
Precedence: list
List-Id: A Protocol for Dynamic Trusted Execution Environment Enablement <teep.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/teep>, <mailto:teep-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/teep/>
List-Post: <mailto:teep@ietf.org>
List-Help: <mailto:teep-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/teep>, <mailto:teep-request@ietf.org?subject=subscribe>
X-List-Received-Date: Wed, 06 Feb 2019 02:22:56 -0000

> I've now written up in I-D form what we discussed, and submitted it as an individual
> document for the WG to consider:
> https://tools.ietf.org/html/draft-thaler-teep-otrp-over-http-00<https://nam06.safelinks.protection.outlook.com/?url=https%3A%2F%2Ftools.ietf.org%2Fhtml%2Fdraft-thaler-teep-otrp-over-http-00&data=02%7C01%7Cdthaler%40microsoft.com%7C40fb41b0073b4b42f33a08d68bd95769%7C72f988bf86f141af91ab2d7cd011db47%7C1%7C1%7C636850162927524953&sdata=OmzVt0UmzQYObpZEgvsOdFDLuh4EJgpeaq6MC%2BrGomU%3D&reserved=0>

I also asked Mark Nottingham (author of the "Building Protocols with HTTP" draft)
to review it.  His feedback, which I agree with, is quoted below with Mark's permission.

Dave


> -----Original Message-----

> From: Mark Nottingham <mnot@mnot.net<mailto:mnot@mnot.net>>

> Sent: Monday, February 4, 2019 9:42 PM

> To: Dave Thaler <dthaler@microsoft.com<mailto:dthaler@microsoft.com>>

> Subject: Re: OTrP over HTTP

>

> Hi Dave,

>

> Overall, I think this is reasonable. It was a bit difficult to read, but I suspect that's mostly because I'm not up to speed with TEEP. Defining terms like "TAM URI" at the beginning might help.

>

> The one technical question the I had was about using GET for session creation; I think that's probably better as a POST with a 0-length body, since GET returns the state of the TAM URI, and that's not what's happening here.

>

> Also:

>

>>  Redirects MAY be automatically followed, and no request headers need

>> be modified or removed upon a following such a redirect.

>

> That probably needs to say something like "...no additional request headers beyond those specified by HTTP need be modified..."

>

> It'd be great if you could pass this buy the HTTP WG mailing list, so that other folks can have a look.