Return-Path: <thomasclinganjones@gmail.com>
X-Original-To: txauth@ietfa.amsl.com
Delivered-To: txauth@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1])
 by ietfa.amsl.com (Postfix) with ESMTP id A6F1E3A078F
 for <txauth@ietfa.amsl.com>; Thu,  2 Jul 2020 10:56:08 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.098
X-Spam-Level: 
X-Spam-Status: No, score=-2.098 tagged_above=-999 required=5
 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1,
 DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, FREEMAIL_FROM=0.001,
 HTML_MESSAGE=0.001, SPF_HELO_NONE=0.001, SPF_PASS=-0.001]
 autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (2048-bit key)
 header.d=gmail.com
Received: from mail.ietf.org ([4.31.198.44])
 by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024)
 with ESMTP id JtZNTs4Lv6-I for <txauth@ietfa.amsl.com>;
 Thu,  2 Jul 2020 10:56:07 -0700 (PDT)
Received: from mail-oi1-x233.google.com (mail-oi1-x233.google.com
 [IPv6:2607:f8b0:4864:20::233])
 (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits))
 (No client certificate requested)
 by ietfa.amsl.com (Postfix) with ESMTPS id 326343A078C
 for <txauth@ietf.org>; Thu,  2 Jul 2020 10:56:07 -0700 (PDT)
Received: by mail-oi1-x233.google.com with SMTP id t4so6548014oij.9
 for <txauth@ietf.org>; Thu, 02 Jul 2020 10:56:07 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20161025; 
 h=mime-version:references:in-reply-to:from:date:message-id:subject:to
 :cc; bh=f/wcJ91dA375XbEP6ATBvZ9VovGkkb87EQA6DAUAtYw=;
 b=TtLUyKUro9GcQiOGynI1oBVxnloO6LmNQMqZ0Z3gduw0OzFbDIJbb8gqRpCXL9YC/j
 j+46GU3YTW/nFVF2kHS+rytVnq9uhzNT2wISYXVoXDx0u6nHsPZmadfwmoMqmSSZojTP
 JmGIypBESNbhhuUqbBf5nDKt7AtZ/aXQVJa6oFogee+QyCtdvX75nHds5wM31wLfXmod
 1M4ZExqPRq1OklmOQ6e6zmrQIktL3KYk57M6fdVxBD/iSzFT3cPacdyRiDmBgo9Ni2DJ
 NoOf6hLUBVaKyXknX+ARrrJnP8ehqOtDY8Hq1AKb7N5aXjqLngAhiKK5ua2JbVtt7J6q
 2q7g==
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed;
 d=1e100.net; s=20161025;
 h=x-gm-message-state:mime-version:references:in-reply-to:from:date
 :message-id:subject:to:cc;
 bh=f/wcJ91dA375XbEP6ATBvZ9VovGkkb87EQA6DAUAtYw=;
 b=FJNG4rDtTGH+DTlT4y1iwY50LYxxlKqNyv3lL+SvqpG3KYQX3pyGltTA+a4j+U8mFP
 z1xXHbAp5dpI3khx6fED3B6BppBQq1i+s9QcqGJsXWxitmU27JiQKLWkuoM4L7xCaUlo
 gr00tNWK4P05IsF7AbMQ6skcAZ7Xf78ntBNVjU8Sce7HwQkx0QZ2ToLhDorUYGsXXKk8
 fSxRsiAa3/UzLVAJRUu1pOAAq09m6Rt1leaDBy8nK2Mm/bgBupKAGjZ9tQbOn6No2nlN
 xAupv3QdBonWO4bBuyY/00TiL2vXtaVBQ1gOyiku6kT1Ktb9PliBubayDDewSZHjVRYF
 P9pA==
X-Gm-Message-State: AOAM531ik3Uo6lkdq/6U1oU3v6SpigGd7bakUavqj5iTQDotk4+rGk0B
 hAz2FJ1hja/2mu2ZCBwqZURiCsJTANeBX4TD37Q=
X-Google-Smtp-Source: ABdhPJy/C9ckP7nZUOS2U9zDPuEO8s15A7L8fP1klcF967lQ1O5fXsWkEU6nc0zqrE0rf5HYUR9qKYJPpZFmtMGURbE=
X-Received: by 2002:aca:43c6:: with SMTP id q189mr24578036oia.63.1593712566478; 
 Thu, 02 Jul 2020 10:56:06 -0700 (PDT)
MIME-Version: 1.0
References: <4F145676-A126-4D35-8890-A0DDF891EA06@mit.edu>
 <32ae1a93-fc9d-cd15-798e-ec493482dd26@free.fr>
 <90F181EE-8E34-4486-BCFB-ADACE55A55CF@mit.edu>
 <dd8ef917-c63a-0070-810a-aecfd9aac0a0@free.fr>
 <CAJmmfSRMWRMQbfZ2ktaRRq1oVeZtXSRf0TGiCJmcLi1FJF6N+w@mail.gmail.com>
 <6CCD515B-BE87-452B-9034-777D90E110DD@mit.edu>
 <CAK2Cwb4RMRT-_AJerg6DbGJ08naO1=aHOD3r-RKaU0N5BVvDjw@mail.gmail.com>
 <3b49cf41-883c-66d9-ac92-b34301161eca@free.fr>
 <CAD9ie-sSA8EHXA_y4KErvbhWw243EM17C2kEm_T3hCZGqxNqjA@mail.gmail.com>
In-Reply-To: <CAD9ie-sSA8EHXA_y4KErvbhWw243EM17C2kEm_T3hCZGqxNqjA@mail.gmail.com>
From: Tom Jones <thomasclinganjones@gmail.com>
Date: Thu, 2 Jul 2020 10:55:55 -0700
Message-ID: <CAK2Cwb6Kadvv97D+yH4oD9qPwOwdpG72DjiApSFa4gzH5LyLyw@mail.gmail.com>
To: Dick Hardt <dick.hardt@gmail.com>
Cc: Denis <denis.ietf@free.fr>, Justin Richer <jricher@mit.edu>,
 txauth@ietf.org, Tobias Looker <tobias.looker@mattr.global>
Content-Type: multipart/alternative; boundary="000000000000662aa405a9791ff6"
Archived-At: <https://mailarchive.ietf.org/arch/msg/txauth/27obo37CVJLGA2oBfmfsj99Hqdo>
Subject: Re: [Txauth] Use Case: Directed Tokens
X-BeenThere: txauth@ietf.org
X-Mailman-Version: 2.1.29
Precedence: list
List-Id: <txauth.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/txauth>,
 <mailto:txauth-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/txauth/>
List-Post: <mailto:txauth@ietf.org>
List-Help: <mailto:txauth-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/txauth>,
 <mailto:txauth-request@ietf.org?subject=subscribe>
X-List-Received-Date: Thu, 02 Jul 2020 17:56:09 -0000

--000000000000662aa405a9791ff6
Content-Type: text/plain; charset="UTF-8"

Dick, the statement about the AS and RS is not always true. In federations
we are always concerned that information is not leaked outside the approved
parties and the AS messages will likely be encrypted for the sole use of
the RS.
Peace ..tom


On Thu, Jul 2, 2020 at 10:44 AM Dick Hardt <dick.hardt@gmail.com> wrote:

> Apologies for the delayed response:
>
> On Fri, Jun 26, 2020 at 9:04 AM Denis <denis.ietf@free.fr> wrote:
>
>> The principle where a RS would only have relationships with one AS would
>> make the model non scalable.
>> It would prevent to get attributes from two different ASs,  for example:
>> identity attributes from a bank and a master degree diploma from a
>> university.
>>
>
> Where do you see that the RS can have a relationship with only one AS?
>
>
>>
>> For privacy reasons, every AS should know as little as possible about the
>> interactions between a client and multiple RSs.
>> It is even possible that this goes as little as knowing *nothing at all*.
>>
>
> OAuth 2.0 works this way now.
>
>
>>
>> The OAuth 2.0 assumption where the AS is in a position to know all the
>> interactions of a given user has with all the RSs
>> that an AS server has a relationship with should not be re-iterated.
>>
>
> I am still confused why you think the AS knows anything abou the
> interactions a given use has with all the RSs. The AS knows which clients
> the user is using, but does not need to have any knowledge of which RSs a
> client is accessing.
>
>
> The AS does not need to know anything about the RS. The RS clearly needs
> to trust the AS, as it is trusting the access granted by the AS to the
> client, but it is unidirectional trust between the RS and the AS.
>
> /Dick
>

--000000000000662aa405a9791ff6
Content-Type: text/html; charset="UTF-8"
Content-Transfer-Encoding: quoted-printable

<div dir=3D"ltr">Dick, the statement about the AS and RS is not always true=
. In federations we are always concerned that information is not leaked out=
side the approved parties and the AS messages will likely be encrypted for =
the sole use of the RS.<br clear=3D"all"><div><div dir=3D"ltr" class=3D"gma=
il_signature" data-smartmail=3D"gmail_signature"><div dir=3D"ltr"><div>Peac=
e ..tom</div></div></div></div><br></div><br><div class=3D"gmail_quote"><di=
v dir=3D"ltr" class=3D"gmail_attr">On Thu, Jul 2, 2020 at 10:44 AM Dick Har=
dt &lt;<a href=3D"mailto:dick.hardt@gmail.com">dick.hardt@gmail.com</a>&gt;=
 wrote:<br></div><blockquote class=3D"gmail_quote" style=3D"margin:0px 0px =
0px 0.8ex;border-left:1px solid rgb(204,204,204);padding-left:1ex"><div dir=
=3D"ltr"><div>Apologies for the delayed response:</div><br><div class=3D"gm=
ail_quote"><div dir=3D"ltr" class=3D"gmail_attr">On Fri, Jun 26, 2020 at 9:=
04 AM Denis &lt;<a href=3D"mailto:denis.ietf@free.fr" target=3D"_blank">den=
is.ietf@free.fr</a>&gt; wrote:<br></div><blockquote class=3D"gmail_quote" s=
tyle=3D"margin:0px 0px 0px 0.8ex;border-left:1px solid rgb(204,204,204);pad=
ding-left:1ex">
 =20
   =20
 =20
  <div>
    <div>The principle where a RS would only
      have relationships with one AS would make the model non scalable.<br>=
</div><div>
      It would prevent to get attributes from two different ASs,=C2=A0 for
      example:=C2=A0 <br>
      identity attributes from a bank and a master degree diploma from a
      university.<br></div></div></blockquote><div><br></div><div>Where do =
you see that the RS can have a relationship with only one AS?</div><div>=C2=
=A0<br></div><blockquote class=3D"gmail_quote" style=3D"margin:0px 0px 0px =
0.8ex;border-left:1px solid rgb(204,204,204);padding-left:1ex"><div><div>
    </div>
    <div><br>
    </div>
    For privacy reasons, every AS should know as little as possible
    about the interactions between a client and multiple RSs.<br>
    <div>It is even possible that this goes as
      little as knowing <i>nothing at all</i>.</div></div></blockquote><div=
><br></div><div>OAuth 2.0 works this way now.=C2=A0</div><div>=C2=A0</div><=
blockquote class=3D"gmail_quote" style=3D"margin:0px 0px 0px 0.8ex;border-l=
eft:1px solid rgb(204,204,204);padding-left:1ex"><div>
    <div><br>
    </div>
    <div>
      <div>The OAuth 2.0 assumption where the AS
        is in a position to know all the interactions of a given user
        has with all the RSs <br>
        that an AS server has a relationship with should not be
        re-iterated.</div></div></div></blockquote><div><br></div><div>I am=
 still confused why you think the AS knows anything abou the interactions a=
 given use has with all the RSs. The AS knows which clients the user is usi=
ng, but does not need to have any knowledge of which RSs a client is access=
ing.</div><div>=C2=A0</div><div>=C2=A0</div><div>The AS does not need to kn=
ow anything about the RS. The RS clearly needs to trust the AS, as it is tr=
usting the access granted by the AS to the client, but it is unidirectional=
 trust between the RS and the AS.</div><div><br></div><div>/Dick</div></div=
></div>
</blockquote></div>

--000000000000662aa405a9791ff6--

