[Unbearable] Comments on draft-ietf-tokbind-https-08 (Token Binding over HTTP)
Denis <denis.ietf@free.fr> Sun, 19 March 2017 18:16 UTC
To: IETF Tokbind WG <unbearable@ietf.org>
From: Denis <denis.ietf@free.fr>
Date: Sun, 19 Mar 2017 19:16:36 +0100
Subject: [Unbearable] Comments on draft-ietf-tokbind-https-08 (Token Binding over HTTP)
On February 27, I sent an email with the following topic: WGLC 3 on core documents. On page 14 within the Security Considerations section, the same kind of change as the one requested for draft-ietf-tokbind-protocol-13 (The Token Binding Protocol Version 1.0) should be done, i.e. add a new section called: "7.2. Client collusion" with the following text: *Token Binding over HTTP does not prevent cooperating clients from* *sharing a bound token.A client could intentionally export a bound* *token with the corresponding Token Binding private key, or perform* *signatures using this key on behalf of another client.* The draft has not been revised accordingly for the Chicago meeting. Denis