Re: [Unbearable] WG adoption of draft-campbell-tokbind-ttrp-00

Anthony Nadalin <tonynad@microsoft.com> Mon, 17 July 2017 20:35 UTC

Return-Path: <tonynad@microsoft.com>
X-Original-To: unbearable@ietfa.amsl.com
Delivered-To: unbearable@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 0C3A2131C3E for <unbearable@ietfa.amsl.com>; Mon, 17 Jul 2017 13:35:07 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.02
X-Spam-Level:
X-Spam-Status: No, score=-2.02 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, HTML_MESSAGE=0.001, RCVD_IN_DNSWL_NONE=-0.0001, RCVD_IN_MSPIKE_H3=-0.01, RCVD_IN_MSPIKE_WL=-0.01, SPF_HELO_PASS=-0.001, SPF_PASS=-0.001, URIBL_BLOCKED=0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (1024-bit key) header.d=microsoft.com
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id hDm2RFxiug7D for <unbearable@ietfa.amsl.com>; Mon, 17 Jul 2017 13:35:04 -0700 (PDT)
Received: from NAM01-SN1-obe.outbound.protection.outlook.com (mail-sn1nam01on0116.outbound.protection.outlook.com [104.47.32.116]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 8860B131B33 for <unbearable@ietf.org>; Mon, 17 Jul 2017 13:35:04 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=microsoft.com; s=selector1; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version; bh=oiBbMZsVtGItACsxuXCPHpY6tLpb/lnyLiKdmHQL2Gs=; b=Qa0u+kc22Fbfpc2GXC+k2kVx/LZxKhHtvcvaNLieHuY3RrEctQlPDPU3UuEhG7n5DMhpr3sHtbcgDo8zC/fcfGlyZlgyCbHXvxqLapnossYlMubCYoaVhwaekjX68WeTa1tCbBcJRVuGrHfJwiHMsW79sgjywEMGMYF1ULcXym4=
Received: from DM5PR21MB0284.namprd21.prod.outlook.com (10.173.174.19) by DM5PR21MB0124.namprd21.prod.outlook.com (10.173.173.11) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_128_CBC_SHA256_P256) id 15.1.1282.2; Mon, 17 Jul 2017 20:35:03 +0000
Received: from DM5PR21MB0284.namprd21.prod.outlook.com ([10.173.174.19]) by DM5PR21MB0284.namprd21.prod.outlook.com ([10.173.174.19]) with mapi id 15.01.1282.008; Mon, 17 Jul 2017 20:35:03 +0000
From: Anthony Nadalin <tonynad@microsoft.com>
To: Leif Johansson <leifj@sunet.se>, IETF Tokbind WG <unbearable@ietf.org>
Thread-Topic: [Unbearable] WG adoption of draft-campbell-tokbind-ttrp-00
Thread-Index: AQHS/xRvpKAPfchK1kW7724yuY/xe6JYeitc
Date: Mon, 17 Jul 2017 20:35:02 +0000
Message-ID: <DM5PR21MB0284C327BDC667EE11EC722DA6A00@DM5PR21MB0284.namprd21.prod.outlook.com>
References: <853ba12d-5859-1545-611d-74f0b1fbf533@sunet.se>
In-Reply-To: <853ba12d-5859-1545-611d-74f0b1fbf533@sunet.se>
Accept-Language: en-US
Content-Language: en-US
X-MS-Has-Attach:
X-MS-TNEF-Correlator:
authentication-results: sunet.se; dkim=none (message not signed) header.d=none;sunet.se; dmarc=none action=none header.from=microsoft.com;
x-originating-ip: [13.90.24.116]
x-ms-publictraffictype: Email
x-microsoft-exchange-diagnostics: 1; DM5PR21MB0124; 7:R5j1gbL+1M8xxrcRvB809qs3x+2AVyZDfyNNz5auNyOvtMHIt01R4V4c47M9bYB33AoHtZG0fmyr8ncN6Y6N/p3qzXmnaaRgExQpFyxa+lbiWDqzsuZ3X0wjK9metTjVVVrsQhbm0j/1taB/84M3SmK/IUAMFtq8Pz6D9Mu6Ds7VF8xgFaByeD63OrvE+JTwnS1i2tnqadfLTqw6YWvQXvTDsRFP6lB8AkytSb1jXkk5GVUA0atI9SG5A41arq/mYfkd1WyDAcmC8PW9vazyqLOvauzPJQjacn1O7rJcv2yhrHjAJtpb1qe5huqZqqXK7UHYRMMB3ltaPtviOeMFdEOLiQ1yo/r0paAqHNLZijZPb3OeLpPIc8CLyncUN+0RhzB9pcqalzY+UbWG49tp3xla9BwFInZj4HJN/EfeZCCXEooiJIv1xh4S4XOFdP+VnbTx9qj8tq8+Fd4xnsNTRPCD+KpcZAEgiQFVPNSYvXvHHU5sa/bcvehoJ8vvhHwwlBKOMri56GAuSleE5fAOR+rxqYgoBr/N7S6RDYAdRxj1aVNFE3l1/qrinb0zm9h37axzAYT4xYqDSI4ep+lxgdpARqvkGSps234x1T6NRxIcve8e7Yju9AKRmSLqdoEXBBGgLyvnjgG96AOZ0rINSyS4Zp/IoV2f68m0KHVH7/AvGGk42qMa5fSAOsPnNarwz3SKH+VjqSLReyCyffCUfKIiVguJd3un+wAqki1t5117/nqtjaF3cW45zagKT1ll3FzNYsI7FBwLWiXfJUvyV8HyFPhA59Hg98NSM1qBbXaLENzhr9cjj0foaxAGHxr/
x-ms-office365-filtering-correlation-id: 812f5e47-0c55-4a3f-1640-08d4cd534d74
x-ms-office365-filtering-ht: Tenant
x-microsoft-antispam: UriScan:; BCL:0; PCL:0; RULEID:(300000500095)(300135000095)(300000501095)(300135300095)(22001)(300000502095)(300135100095)(2017030254075)(48565401081)(300000503095)(300135400095)(2017052603031)(201703131423075)(201703031133081)(300000504095)(300135200095)(300000505095)(300135600095)(300000506095)(300135500095); SRVR:DM5PR21MB0124;
x-ms-traffictypediagnostic: DM5PR21MB0124:
x-exchange-antispam-report-test: UriScan:(158342451672863)(26388249023172)(236129657087228)(189930954265078)(100405760836317)(81439100147899)(219752817060721)(69029272430364)(164587983369549);
x-microsoft-antispam-prvs: <DM5PR21MB01242263DA7D78D49FF3F5D2A6A00@DM5PR21MB0124.namprd21.prod.outlook.com>
x-exchange-antispam-report-cfa-test: BCL:0; PCL:0; RULEID:(100000700101)(100105000095)(100000701101)(100105300095)(100000702101)(100105100095)(61425038)(6040450)(601004)(2401047)(2017060910075)(8121501046)(5005006)(100000703101)(100105400095)(10201501046)(93006095)(93001095)(3002001)(6055026)(61426038)(61427038)(6041248)(20161123564025)(20161123562025)(20161123560025)(20161123555025)(201703131423075)(201702281528075)(201703061421075)(201703061406153)(20161123558100)(6072148)(100000704101)(100105200095)(100000705101)(100105500095); SRVR:DM5PR21MB0124; BCL:0; PCL:0; RULEID:(100000800101)(100110000095)(100000801101)(100110300095)(100000802101)(100110100095)(100000803101)(100110400095)(100000804101)(100110200095)(100000805101)(100110500095); SRVR:DM5PR21MB0124;
x-forefront-prvs: 0371762FE7
x-forefront-antispam-report: SFV:NSPM; SFS:(10019020)(39840400002)(39410400002)(39850400002)(39450400003)(39860400002)(39400400002)(377454003)(7736002)(8936002)(14454004)(74316002)(966005)(189998001)(6506006)(230783001)(77096006)(6246003)(5005710100001)(99286003)(478600001)(10290500003)(236005)(55016002)(81166006)(38730400002)(6436002)(25786009)(9686003)(229853002)(53546010)(54896002)(606006)(6306002)(53936002)(8676002)(3280700002)(7696004)(10090500001)(3846002)(2906002)(3660700001)(102836003)(6116002)(66066001)(2900100001)(2950100002)(33656002)(5660300001)(86362001)(50986999)(76176999)(54356999)(42262002); DIR:OUT; SFP:1102; SCL:1; SRVR:DM5PR21MB0124; H:DM5PR21MB0284.namprd21.prod.outlook.com; FPR:; SPF:None; MLV:sfv; LANG:en;
spamdiagnosticoutput: 1:99
spamdiagnosticmetadata: NSPM
Content-Type: multipart/alternative; boundary="_000_DM5PR21MB0284C327BDC667EE11EC722DA6A00DM5PR21MB0284namp_"
MIME-Version: 1.0
X-OriginatorOrg: microsoft.com
X-MS-Exchange-CrossTenant-originalarrivaltime: 17 Jul 2017 20:35:02.7712 (UTC)
X-MS-Exchange-CrossTenant-fromentityheader: Hosted
X-MS-Exchange-CrossTenant-id: 72f988bf-86f1-41af-91ab-2d7cd011db47
X-MS-Exchange-Transport-CrossTenantHeadersStamped: DM5PR21MB0124
Archived-At: <https://mailarchive.ietf.org/arch/msg/unbearable/O8oJpz-6DhwgvlBHyfbXKkAaucM>
Subject: Re: [Unbearable] WG adoption of draft-campbell-tokbind-ttrp-00
X-BeenThere: unbearable@ietf.org
X-Mailman-Version: 2.1.22
Precedence: list
List-Id: "\"This list is for discussion of proposals for doing better than bearer tokens \(e.g. HTTP cookies, OAuth tokens etc.\) for web applications. The specific goal is chartering a WG focused on preventing security token export and replay attacks.\"" <unbearable.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/unbearable>, <mailto:unbearable-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/unbearable/>
List-Post: <mailto:unbearable@ietf.org>
List-Help: <mailto:unbearable-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/unbearable>, <mailto:unbearable-request@ietf.org?subject=subscribe>
X-List-Received-Date: Mon, 17 Jul 2017 20:35:07 -0000

So I'm not sure of the value of this as we and the their companies have already implemented solutions that are different than what is being proposed. This also does not work for a lot of our use cases where there is an untrusted proxy. Most of our cases are also within our own infrastructure so no question the need for standardization.

________________________________
From: Unbearable <unbearable-bounces@ietf.org> on behalf of Leif Johansson <leifj@sunet.se>
Sent: Monday, July 17, 2017 5:50:20 PM
To: IETF Tokbind WG
Subject: [Unbearable] WG adoption of draft-campbell-tokbind-ttrp-00


In the f2f meeting in Prague there was clear consensus to adopt
draft-campbell-tokbind-ttrp-00 as draft-ietf-tokbind-ttrp-00
making this a WG document.

If anyone on the list disagrees, now is the time to speak up.

        Cheers Leif & John

_______________________________________________
Unbearable mailing list
Unbearable@ietf.org
https://na01.safelinks.protection.outlook.com/?url=https%3A%2F%2Fwww.ietf.org%2Fmailman%2Flistinfo%2Funbearable&data=02%7C01%7Ctonynad%40microsoft.com%7C06e4b840a7a94372b5e008d4cd2b8f26%7C72f988bf86f141af91ab2d7cd011db47%7C1%7C0%7C636359034357583877&sdata=hW8BlMQm1Sf%2BjDXeAQ9%2BeHIxXMroROFSuegdWpdX8DA%3D&reserved=0