Re: [Txauth] TxAuth Charter (Take 3.5)

Dick Hardt <dick.hardt@gmail.com> Wed, 29 January 2020 06:01 UTC

Return-Path: <dick.hardt@gmail.com>
X-Original-To: txauth@ietfa.amsl.com
Delivered-To: txauth@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 20A3712009C for <txauth@ietfa.amsl.com>; Tue, 28 Jan 2020 22:01:36 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.997
X-Spam-Level:
X-Spam-Status: No, score=-1.997 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, FREEMAIL_FROM=0.001, HTML_MESSAGE=0.001, RCVD_IN_DNSWL_NONE=-0.0001, SPF_HELO_NONE=0.001, SPF_PASS=-0.001, URIBL_BLOCKED=0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (2048-bit key) header.d=gmail.com
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id T0Ce7ThnvyMN for <txauth@ietfa.amsl.com>; Tue, 28 Jan 2020 22:01:34 -0800 (PST)
Received: from mail-lj1-x234.google.com (mail-lj1-x234.google.com [IPv6:2a00:1450:4864:20::234]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 22D6F1200EF for <txauth@ietf.org>; Tue, 28 Jan 2020 22:01:34 -0800 (PST)
Received: by mail-lj1-x234.google.com with SMTP id r19so17154189ljg.3 for <txauth@ietf.org>; Tue, 28 Jan 2020 22:01:34 -0800 (PST)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20161025; h=mime-version:references:in-reply-to:from:date:message-id:subject:to :cc; bh=bHoSLks/BlTCqrjkuC/D6xkY07KwkolAdNRghqPBJhc=; b=Sn3j0hkTFGVQtxZlQW4KZy6qfAl14faao7tehwNrFvwzFzhzjbz1uZT93D3ZqRH21j npXUljcOBmDc9uz6etypi7X1+YDf6cLPhdxB4gxlLbDFxzmcZRRmjQlmc+SNlmRe9bQR i5vAEEBgkN3o6zhvoNhf1mntDgeMbhsFIfRp80NuNZ0J/YSGgSdOPSJXJjidullqkQaY Kk5f1Kqx4oNdmcXEYmYVU0WUDIe5nUVkK373DVat5g90wHouhIagiT6RhUISjtDXsD7j nQs336rzaRPsDlyq4Lv6t728wH5YDmZXcDBqecy9WR/xe86MjwWCojmK3+1hwJL0Lm9B NWKQ==
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20161025; h=x-gm-message-state:mime-version:references:in-reply-to:from:date :message-id:subject:to:cc; bh=bHoSLks/BlTCqrjkuC/D6xkY07KwkolAdNRghqPBJhc=; b=h8qBnMHakZd57J/8O3RmUryrFJS7w/zHhQp1sBiXxfffr14Qhl3TpqgFZMZGAOQ2Ak m3C4SpO7+MsQp7oujhwoV+zRGGXHHMX7q3iln1LgcNMdlmU9H6bqqc1SiHXq/223Rimg M6sG0yvEA4lVYa08S2Fvj0IbFtOf9KW3+5KOYRKqTF5MGDOl34egZ2sRrurDNLypO50E KTItXVgD9gkmcYDMvyl0oiFkT+lzOSvXlyYF2lPsP50F5gTgY2jquhNqQ0mRj5DtgMQr zL40hnc9xRpaVxwu1LQE+lsq/ks/LgcMoPqIWB58+1BmAw4d39FnG19ls+nEobrJUD+x 0ygw==
X-Gm-Message-State: APjAAAVVNAt1igNSwV6TmrgIodwOW+snnjNq8oTrSqySmn+SEnRitMHv P6OU0/hBDzJpn6ddfkAokFg+xcPkhf0Bj8vai60=
X-Google-Smtp-Source: APXvYqwHN2DqiQifOGbf3FkTPMLxar5JEC7CetnAYncpJdythnII1MWqiSnDZr1MAwzWSMButGRsu+Hn7Lh+X+BjCIU=
X-Received: by 2002:a2e:84d0:: with SMTP id q16mr15555636ljh.138.1580277692318; Tue, 28 Jan 2020 22:01:32 -0800 (PST)
MIME-Version: 1.0
References: <CAD9ie-tb8V9vHNUxeHiyTV805Q6OwgKmb260wn9CyzeZxyWFJw@mail.gmail.com> <11F2690A-E36E-4877-B2B3-15ECB6812214@lodderstedt.net>
In-Reply-To: <11F2690A-E36E-4877-B2B3-15ECB6812214@lodderstedt.net>
From: Dick Hardt <dick.hardt@gmail.com>
Date: Tue, 28 Jan 2020 22:01:20 -0800
Message-ID: <CAD9ie-topDftG2XOMO0ri0iXQiJGrhH-9-nVndPC238e=EOskg@mail.gmail.com>
To: Torsten Lodderstedt <torsten@lodderstedt.net>
Cc: Roman Danyliw <rdd@cert.org>, "txauth@ietf.org" <txauth@ietf.org>
Content-Type: multipart/alternative; boundary="0000000000007f49dd059d411260"
Archived-At: <https://mailarchive.ietf.org/arch/msg/txauth/5azeR6GMD469dweR_3Qv0yEFPV4>
Subject: Re: [Txauth] TxAuth Charter (Take 3.5)
X-BeenThere: txauth@ietf.org
X-Mailman-Version: 2.1.29
Precedence: list
List-Id: <txauth.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/txauth>, <mailto:txauth-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/txauth/>
List-Post: <mailto:txauth@ietf.org>
List-Help: <mailto:txauth-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/txauth>, <mailto:txauth-request@ietf.org?subject=subscribe>
X-List-Received-Date: Wed, 29 Jan 2020 06:01:36 -0000

On Tue, Jan 28, 2020 at 9:09 PM Torsten Lodderstedt <torsten@lodderstedt.net>
wrote:

>
>
> > Am 29.01.2020 um 02:13 schrieb Dick Hardt <dick.hardt@gmail.com>:
> >
> > All identity claim use cases. A set of these are solved by OpenID
> Connect, which is an extension to OAuth 2.0. TxAuth would also be a
> superset of OpenID Connect in addition to OAuth.
>
> Don’t you think this would make TxAuth a bit complicated? What would be
> the benefit?


Not any more than today, as many consumer IdPs have both in the same flows,
and that is what is in the proposed charter.

Having the information all in one document would make it simpler to
implement and understand.

Did you have chance to look at XAuth Torsten?