Re: [Txauth] Working group name

Dick Hardt <dick.hardt@gmail.com> Fri, 05 June 2020 23:03 UTC

Return-Path: <dick.hardt@gmail.com>
X-Original-To: txauth@ietfa.amsl.com
Delivered-To: txauth@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 4E31C3A0F0D for <txauth@ietfa.amsl.com>; Fri, 5 Jun 2020 16:03:46 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.096
X-Spam-Level:
X-Spam-Status: No, score=-2.096 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, FREEMAIL_FROM=0.001, HTML_FONT_LOW_CONTRAST=0.001, HTML_MESSAGE=0.001, SPF_HELO_NONE=0.001, SPF_PASS=-0.001, URIBL_BLOCKED=0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (2048-bit key) header.d=gmail.com
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id b0b6drNpWhST for <txauth@ietfa.amsl.com>; Fri, 5 Jun 2020 16:03:44 -0700 (PDT)
Received: from mail-lj1-x236.google.com (mail-lj1-x236.google.com [IPv6:2a00:1450:4864:20::236]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 3FFAD3A0F0B for <txauth@ietf.org>; Fri, 5 Jun 2020 16:03:44 -0700 (PDT)
Received: by mail-lj1-x236.google.com with SMTP id b6so13726599ljj.1 for <txauth@ietf.org>; Fri, 05 Jun 2020 16:03:44 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20161025; h=mime-version:references:in-reply-to:from:date:message-id:subject:to :cc; bh=XjF1fkkPoI6qbZ7K/D8qvS37ok6gTgQI4CVW+kYNIog=; b=MV3ioddWXOZUSxMyK3Kv+SzhhnC1XokF4tLRhXKjClcaSbJivP+Pc+4ULfu03fZhmL Khan18dfWJmSmq83DiFsImGk7L5Q3caznMPOAaiY9POYBr7vsrx3K3RqJsDp1UBiIG1s 4UoCgVZqAyig5tUPbx0M5dxemB9WjeMbmteLXp5Q2gP4Qa4bFaVUsrc1ja+eB9sRFHX9 /MA8mKKPBxx9fbtH6cIzK7Uxp23YnS9kUoLuSxNMcUHoWlvDrn5BeXUUh+xCd9XCaLKO iFN6y5G1caz3IdoBEWN5rQ6uDpQWalqZM3lzHpCL4YuQi8C8lXbhsEestDMa/xLblDzJ obQA==
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20161025; h=x-gm-message-state:mime-version:references:in-reply-to:from:date :message-id:subject:to:cc; bh=XjF1fkkPoI6qbZ7K/D8qvS37ok6gTgQI4CVW+kYNIog=; b=a4qHwnp1n1krtYAJidfdHCeZD8dVhEIArVzsMHYhj32Utv/zW6+9pLRiBYnPliHwak mZcAElAJuIFH0/QKpehrGUxXtkZwTVq8wBAYG+7o0NfmBiuWEsUy4TZJAMeter1MckdS dmdn3BjyNjL0u9vylBhb7bonPZZY5oFnPF+0OcnYBRk0aK6mvkUKpkn2AikrhKydb3Oi RbYmjp4wJoeK63xm1Kg4U8QZxyrHEUFrTVTsmEbWz7P8GqrVx9cykuGTcp57lrMti5qn zGqngaltMaUHq/OSyCVJGORaV5v9jq/fmxbjKgo/O+upPsld1ENmlxAD9EMUbsmrOQ9Q P2MQ==
X-Gm-Message-State: AOAM530sGgjhrUVXOBuAApsoljDSj6fAID3cm1S1ifgPVacPEQh4cUCP /HkBHUBbxMIuavPqigl1A0fNEGUrv9EHTfyjvrA=
X-Google-Smtp-Source: ABdhPJxbg9qlQQxr2n9BV3oMp/S00HNsPn8iH6Ah20wInZgi3mYQeiQl4+3incriwG54P0DtzxtjC22XalL5CdAigko=
X-Received: by 2002:a2e:140a:: with SMTP id u10mr5842699ljd.56.1591398222297; Fri, 05 Jun 2020 16:03:42 -0700 (PDT)
MIME-Version: 1.0
References: <2626827D-194C-4BA7-A62C-22387942B571@gmail.com> <CAK2Cwb6EYk0v61Q0vcbTvEFhZvi_f7KxrHpDfRsTBcjzyV4agg@mail.gmail.com> <CAD9ie-v7y+nZ7MC4j3VUa-+97E=PPMHveXmyJ4enn84p1a1LOw@mail.gmail.com> <CAK2Cwb6STYARkCkRisK2NSrZQ0DwA-QS8JesYZhy7dWrJTsB0A@mail.gmail.com>
In-Reply-To: <CAK2Cwb6STYARkCkRisK2NSrZQ0DwA-QS8JesYZhy7dWrJTsB0A@mail.gmail.com>
From: Dick Hardt <dick.hardt@gmail.com>
Date: Fri, 05 Jun 2020 16:03:16 -0700
Message-ID: <CAD9ie-sHBmSnuFDYi2HnuNkWZ6mh9y7BrwoJ-nWAO1bQLXXfMg@mail.gmail.com>
To: Tom Jones <thomasclinganjones@gmail.com>
Cc: Yaron Sheffer <yaronf.ietf@gmail.com>, "txauth@ietf.org" <txauth@ietf.org>
Content-Type: multipart/alternative; boundary="000000000000bc7e8905a75e4538"
Archived-At: <https://mailarchive.ietf.org/arch/msg/txauth/s2vtPZiRBiPCR9xeKf-wk1-Havc>
Subject: Re: [Txauth] Working group name
X-BeenThere: txauth@ietf.org
X-Mailman-Version: 2.1.29
Precedence: list
List-Id: <txauth.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/txauth>, <mailto:txauth-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/txauth/>
List-Post: <mailto:txauth@ietf.org>
List-Help: <mailto:txauth-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/txauth>, <mailto:txauth-request@ietf.org?subject=subscribe>
X-List-Received-Date: Fri, 05 Jun 2020 23:03:46 -0000

Sortof

There are other aspects besides the grant contents that may be negotiated.

In my opinion, I don't see why steps 3 and 4 are needed if in step 1 the
client is clear on what is required, and what is optional.

I do think that the following flow is useful, what I call a multi step
negotiation:

1 Client -> AS give me a
2. AS -> Client here is a = 9
3. Client -> AS I also want x (the value of a determines what else, if
anything the Client may need)
4. AS -> Client x = foo



ᐧ

On Fri, Jun 5, 2020 at 3:55 PM Tom Jones <thomasclinganjones@gmail.com>
wrote:

> if it is to be a negotiation - irrespective of the user's direct
> involvement, then then I see this sort of flow
> 1 cl to as - give me a, b c
> 2 as to cl - here is a grant to a
> 3 cl to as - no, i really need b or i can't let you in
> 4 as to cl - here is a grant to a, b
> of course an alternate is that might be
> 1 cl to as i want a, b, c and b is essential (I know justin hates that -
> but california law requires it)
>
> That is what i think negotiation is, or is some other kind of negotiation
> imagined
>
> Peace ..tom
>
>
> On Fri, Jun 5, 2020 at 3:36 PM Dick Hardt <dick.hardt@gmail.com> wrote:
>
>> Hi Tom
>>
>> The charter is here https://datatracker.ietf.org/wg/txauth/about/
>>
>> As I understand it, one of the items we are standardizing
>> is negotiation protocol between the client and the server. How the server
>> gathers consent from the user is currently not in scope, and it is not
>> clear to me what could be standardized in the experience between the user
>> and the server that would be in scope for the IETF. Similarly for consent
>> revocation. Additionally, a user may not be involved in the
>> negotiation process at all.
>>
>>
>>
>> ᐧ
>>
>> On Fri, Jun 5, 2020 at 1:59 PM Tom Jones <thomasclinganjones@gmail.com>
>> wrote:
>>
>>> Before we settle on this name, I must ask if the work group is prepared
>>> for the creation of a negotiation protocol, which as I understand it will
>>> include the client asking for grants, the user responding with their intent
>>> (potentially either can start the flow) and the grant jwt (jose, whatever).
>>> Presumably to complete the lifecycle some means for the user to revoke the
>>> grants and query the grants would also be provided.
>>>
>>> That seems like more of an integrated solution than prior work efforts
>>> have involved.
>>> What is the current status of the charter?
>>> Peace ..tom
>>>
>>>
>>> On Fri, Jun 5, 2020 at 1:35 PM Yaron Sheffer <yaronf.ietf@gmail.com>
>>> wrote:
>>>
>>>> Thank you to all who participated in the two rounds of name selection.
>>>> This process has been longer than we ever expected, and I’m glad we can
>>>> declare consensus now and move forward.
>>>>
>>>> Based on the last two weeks’ worth of discussion, we have rough
>>>> consensus on a name for the proposed working group:
>>>>
>>>>         GNAP: Grant Negotiation and Authorization Protocol
>>>>
>>>> This decision will now enable our AD to put our charter [1] on the
>>>> IESG's table, where I hope we will be approved as a working group.
>>>>
>>>> Heads up: we intend to meet in the upcoming all-virtual IETF 108 in
>>>> late July, either as a BoF or as a newly chartered WG.
>>>>
>>>> Thanks,
>>>>         Yaron
>>>>
>>>>
>>>> [1] https://datatracker.ietf.org/doc/charter-ietf-txauth/
>>>>
>>>>
>>>> --
>>>> Txauth mailing list
>>>> Txauth@ietf.org
>>>> https://www.ietf.org/mailman/listinfo/txauth
>>>>
>>> --
>>> Txauth mailing list
>>> Txauth@ietf.org
>>> https://www.ietf.org/mailman/listinfo/txauth
>>>
>>