[Unbearable] [TokenBinding/Internet-Drafts] 45c086: HTTPSTB: init -08

balfanz <dirk@balfanz.net> Thu, 26 January 2017 18:55 UTC

Return-Path: <bounce+3a3868.40f-unbearable=ietf.org@github.com>
X-Original-To: unbearable@ietfa.amsl.com
Delivered-To: unbearable@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 3761612998F for <unbearable@ietfa.amsl.com>; Thu, 26 Jan 2017 10:55:45 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.899
X-Spam-Level:
X-Spam-Status: No, score=-1.899 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, HEADER_FROM_DIFFERENT_DOMAINS=0.001, RCVD_IN_DNSWL_NONE=-0.0001, SPF_PASS=-0.001, URIBL_BLOCKED=0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (1024-bit key) header.d=github.com; domainkeys=pass (1024-bit key) header.sender=dirk=balfanz.net@github.com header.d=github.com
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id W7s-5mwItnTY for <unbearable@ietfa.amsl.com>; Thu, 26 Jan 2017 10:55:43 -0800 (PST)
Received: from m71-131.mailgun.net (m71-131.mailgun.net [166.78.71.131]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 51B2D129974 for <unbearable@ietf.org>; Thu, 26 Jan 2017 10:55:42 -0800 (PST)
DKIM-Signature: a=rsa-sha256; v=1; c=relaxed/relaxed; d=github.com; q=dns/txt; s=mailo; t=1485456941; h=Content-Transfer-Encoding: Content-Type: Mime-Version: Subject: Message-ID: To: Reply-To: From: Date: Sender; bh=vnzYTztR7BKcxe0xEO8ZTAoImg+/W5p2AMa02codefY=; b=YEITM2p0wDMw6873eSbpbwWQy+Mz6p787ucXCILBX+oN3oQUAEpR+YVL4Hp4TKR6BGJZ55xF x5uTFZVmcxEAi1Xt1LBoj6UGSa4PyPd1CSv8i3nzMpZ4pDcJYGRmk7Ye4Sr3xoeUyLppOCQD 8jNIBXDaTqes3fKxHDNmbei3Mac=
DomainKey-Signature: a=rsa-sha1; c=nofws; d=github.com; s=mailo; q=dns; h=Sender: Date: From: Reply-To: To: Message-ID: Subject: Mime-Version: Content-Type: Content-Transfer-Encoding; b=CdrQRK5JymDOLrTjofw3isHLg6JwQQsLQAOeXCB60Ii+Ut9INxpfAaUlNbaElBZwPZeIpo gHGaaYoiK5iUJpD7xYOmKfkNve2EfswJAm0/+L4LFDfkZFOZPcaPzlvE6aNAXKpPKFtnTCoE yAzNM4Pj48OakvNN/nInlWUf+SK8k=
Sender: dirk=balfanz.net@github.com
X-Mailgun-Sending-Ip: 166.78.71.131
X-Mailgun-Sid: WyIzMTNlNyIsICJ1bmJlYXJhYmxlQGlldGYub3JnIiwgIjQwZiJd
Received: from github.com (Unknown [192.30.252.45]) by mxa.mailgun.org with ESMTP id 588a462c.7f7fbc2f2f90-smtp-out-n03; Thu, 26 Jan 2017 18:55:40 -0000 (UTC)
Date: Thu, 26 Jan 2017 10:55:39 -0800
From: balfanz <dirk@balfanz.net>
To: unbearable@ietf.org
Message-ID: <588a462be5f94_21653fa4b59cb14033423@hookshot-fe3-cp1-prd.iad.github.net.mail>
Mime-Version: 1.0
Content-Type: multipart/mixed; boundary="--==_mimepart_588a462be5ae0_21653fa4b59cb14033363"; charset="UTF-8"
Content-Transfer-Encoding: 7bit
Archived-At: <https://mailarchive.ietf.org/arch/msg/unbearable/9dPy-7xjAFxR2E3KpkM2pm74PEg>
X-Mailman-Approved-At: Thu, 26 Jan 2017 11:16:03 -0800
Subject: [Unbearable] [TokenBinding/Internet-Drafts] 45c086: HTTPSTB: init -08
X-BeenThere: unbearable@ietf.org
X-Mailman-Version: 2.1.17
Precedence: list
Reply-To: balfanz <dirk@balfanz.net>
List-Id: "\"This list is for discussion of proposals for doing better than bearer tokens \(e.g. HTTP cookies, OAuth tokens etc.\) for web applications. The specific goal is chartering a WG focused on preventing security token export and replay attacks.\"" <unbearable.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/unbearable>, <mailto:unbearable-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/unbearable/>
List-Post: <mailto:unbearable@ietf.org>
List-Help: <mailto:unbearable-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/unbearable>, <mailto:unbearable-request@ietf.org?subject=subscribe>
X-List-Received-Date: Thu, 26 Jan 2017 18:55:45 -0000

  Branch: refs/heads/master
  Home:   https://github.com/TokenBinding/Internet-Drafts
  Commit: 45c0866107ef64b428f408b082bc196b335fd234
      https://github.com/TokenBinding/Internet-Drafts/commit/45c0866107ef64b428f408b082bc196b335fd234
  Author: JeffH <Jeff.Hodges@PayPal.com>
  Date:   2016-12-08 (Thu, 08 Dec 2016)

  Changed paths:
    R draft-ietf-tokbind-https-07.xml
    A draft-ietf-tokbind-https-08.xml

  Log Message:
  -----------
  HTTPSTB: init -08


  Commit: 141b203fe6e13b1121fd90abbb6bbeff766bf15d
      https://github.com/TokenBinding/Internet-Drafts/commit/141b203fe6e13b1121fd90abbb6bbeff766bf15d
  Author: JeffH <Jeff.Hodges@PayPal.com>
  Date:   2016-12-09 (Fri, 09 Dec 2016)

  Changed paths:
    M draft-ietf-tokbind-https-08.xml

  Log Message:
  -----------
  HTTPSTB: spelling fixups


  Commit: 25653615a5c43d1e9e27031e6a7680a80d6b66a8
      https://github.com/TokenBinding/Internet-Drafts/commit/25653615a5c43d1e9e27031e6a7680a80d6b66a8
  Author: JeffH <Jeff.Hodges@PayPal.com>
  Date:   2016-12-09 (Fri, 09 Dec 2016)

  Changed paths:
    M draft-ietf-tokbind-https-08.xml

  Log Message:
  -----------
  HTTPSTB: may->MAY in section 2. The Sec-Token-Binding Header Field


  Commit: c79388e234b7508d6fcce1c0cf88daab24286fb8
      https://github.com/TokenBinding/Internet-Drafts/commit/c79388e234b7508d6fcce1c0cf88daab24286fb8
  Author: JeffH <Jeff.Hodges@PayPal.com>
  Date:   2016-12-09 (Fri, 09 Dec 2016)

  Changed paths:
    M draft-ietf-tokbind-https-08.xml

  Log Message:
  -----------
  HTTPSTB: fix minor grammar


  Commit: c13966b8395a76f7ecdd000d522511ad9e8dbc3e
      https://github.com/TokenBinding/Internet-Drafts/commit/c13966b8395a76f7ecdd000d522511ad9e8dbc3e
  Author: JeffH <Jeff.Hodges@PayPal.com>
  Date:   2016-12-09 (Fri, 09 Dec 2016)

  Changed paths:
    M draft-ietf-tokbind-https-08.xml

  Log Message:
  -----------
  HTTPSTB: polish 'Security Token Replay' section


  Commit: 4560edafb723cfe741d42184343a48d82640d65f
      https://github.com/TokenBinding/Internet-Drafts/commit/4560edafb723cfe741d42184343a48d82640d65f
  Author: JeffH <Jeff.Hodges@PayPal.com>
  Date:   2016-12-09 (Fri, 09 Dec 2016)

  Changed paths:
    M draft-ietf-tokbind-https-08.xml

  Log Message:
  -----------
  HTTPSTB: minor clarifying edit


  Commit: 39ab776bfa87bde83a05e0feaf83eefb7fbf21d4
      https://github.com/TokenBinding/Internet-Drafts/commit/39ab776bfa87bde83a05e0feaf83eefb7fbf21d4
  Author: JeffH <Jeff.Hodges@PayPal.com>
  Date:   2016-12-13 (Tue, 13 Dec 2016)

  Changed paths:
    M draft-ietf-tokbind-https-08.xml

  Log Message:
  -----------
  HTTPSTB: origin->{eTLD+1,server}, as appropriate, fixes #85


  Commit: 5515d24533d43498e825831033f98d9ccbf59dd4
      https://github.com/TokenBinding/Internet-Drafts/commit/5515d24533d43498e825831033f98d9ccbf59dd4
  Author: JeffH <Jeff.Hodges@PayPal.com>
  Date:   2016-12-14 (Wed, 14 Dec 2016)

  Changed paths:
    M README.md
    M draft-ietf-tokbind-https-08.xml
    R draft-ietf-tokbind-protocol-11.xml
    A draft-ietf-tokbind-protocol-12.xml

  Log Message:
  -----------
  Merge branch 'master' into HTTPSTB-cleanup1


  Commit: 77006e22b38f5c58e36dc91319c6492dd8e12b2d
      https://github.com/TokenBinding/Internet-Drafts/commit/77006e22b38f5c58e36dc91319c6492dd8e12b2d
  Author: JeffH <Jeff.Hodges@PayPal.com>
  Date:   2016-12-14 (Wed, 14 Dec 2016)

  Changed paths:
    M draft-ietf-tokbind-https-08.xml

  Log Message:
  -----------
  HTTPSTB: TB msg -> TB structure in sensitivity of TB hdr section


  Commit: 0763313e165847941d358259dab23e2a01f096f8
      https://github.com/TokenBinding/Internet-Drafts/commit/0763313e165847941d358259dab23e2a01f096f8
  Author: JeffH <Jeff.Hodges@PayPal.com>
  Date:   2016-12-14 (Wed, 14 Dec 2016)

  Changed paths:
    M draft-ietf-tokbind-https-08.xml

  Log Message:
  -----------
  HTTPSTB: key -> key pairs in privacy-cons


  Commit: afe11ab03944865f802b76ea728fe2c0bb8670ee
      https://github.com/TokenBinding/Internet-Drafts/commit/afe11ab03944865f802b76ea728fe2c0bb8670ee
  Author: JeffH <Jeff.Hodges@PayPal.com>
  Date:   2016-12-14 (Wed, 14 Dec 2016)

  Changed paths:
    M draft-ietf-tokbind-https-08.xml

  Log Message:
  -----------
  HTTPSTB: equate 'first-party' to 'same-site' in 1st-party use cases


  Commit: e5d37ae47198a326a0153052154c60acfd57074d
      https://github.com/TokenBinding/Internet-Drafts/commit/e5d37ae47198a326a0153052154c60acfd57074d
  Author: JeffH <Jeff.Hodges@PayPal.com>
  Date:   2016-12-14 (Wed, 14 Dec 2016)

  Changed paths:
    M draft-ietf-tokbind-https-08.xml

  Log Message:
  -----------
  HTTPSTB: update change log


  Commit: 1be576f9b1198ae8dce3a3c9b2f3dd3266b79a10
      https://github.com/TokenBinding/Internet-Drafts/commit/1be576f9b1198ae8dce3a3c9b2f3dd3266b79a10
  Author: JeffH <Jeff.Hodges@PayPal.com>
  Date:   2016-12-15 (Thu, 15 Dec 2016)

  Changed paths:
    M draft-ietf-tokbind-protocol-12.xml

  Log Message:
  -----------
  Merge branch 'master' into HTTPSTB-cleanup1


  Commit: 178104c70e2f7e329cd7e6633277f082e2a9cf5e
      https://github.com/TokenBinding/Internet-Drafts/commit/178104c70e2f7e329cd7e6633277f082e2a9cf5e
  Author: JeffH <Jeff.Hodges@PayPal.com>
  Date:   2016-12-15 (Thu, 15 Dec 2016)

  Changed paths:
    M draft-ietf-tokbind-https-08.xml

  Log Message:
  -----------
  HTTPSTB: delete dangling


  Commit: 7070626e339a5ac35754562ef82af7e236fde095
      https://github.com/TokenBinding/Internet-Drafts/commit/7070626e339a5ac35754562ef82af7e236fde095
  Author: balfanz <dirk@balfanz.net>
  Date:   2017-01-26 (Thu, 26 Jan 2017)

  Changed paths:
    M draft-ietf-tokbind-https-08.xml

  Log Message:
  -----------
  Merge pull request #86 from equalsJeffH/HTTPSTB-cleanup1

HTTPSTB WGLC  editorial cleanup 1


Compare: https://github.com/TokenBinding/Internet-Drafts/compare/5fd553bd306e...7070626e339a