Re: [Unbearable] Thurs 9am-10am in Lugano: additional TB TTRP meeting

Brian Campbell <bcampbell@pingidentity.com> Fri, 30 June 2017 00:18 UTC

Return-Path: <bcampbell@pingidentity.com>
X-Original-To: unbearable@ietfa.amsl.com
Delivered-To: unbearable@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id C95D3126D45 for <unbearable@ietfa.amsl.com>; Thu, 29 Jun 2017 17:18:49 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: 0.201
X-Spam-Level:
X-Spam-Status: No, score=0.201 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, HTML_MESSAGE=0.001, RCVD_IN_DNSWL_NONE=-0.0001, SPF_PASS=-0.001, THIS_AD=2.2, URIBL_BLOCKED=0.001] autolearn=no autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (1024-bit key) header.d=pingidentity.com
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id GzWEETUh8ady for <unbearable@ietfa.amsl.com>; Thu, 29 Jun 2017 17:18:47 -0700 (PDT)
Received: from mail-pf0-x236.google.com (mail-pf0-x236.google.com [IPv6:2607:f8b0:400e:c00::236]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id B12931243FE for <unbearable@ietf.org>; Thu, 29 Jun 2017 17:18:47 -0700 (PDT)
Received: by mail-pf0-x236.google.com with SMTP id q86so58117722pfl.3 for <unbearable@ietf.org>; Thu, 29 Jun 2017 17:18:47 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=pingidentity.com; s=gmail; h=mime-version:in-reply-to:references:from:date:message-id:subject:to; bh=CmxDjc5Nyif9lYacJ3tX2ruliS3woZc6s4m9wlEwXHU=; b=hgRTj7AJRrI5TUwvtuvCGOct30ol+uuvqsBw0h//HThWoUNba2mNVNh1N4X7/d4ONW IAcjJadgLE9ixAz9CdeCfPF7jModBDzd2CZbptgq6TmJAUq3+ecjBmPgZ0ik3/kpwp0F 98NQYbEvs3OqJeFN/IbeuBJpbAp4qfd8/CFCw=
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20161025; h=x-gm-message-state:mime-version:in-reply-to:references:from:date :message-id:subject:to; bh=CmxDjc5Nyif9lYacJ3tX2ruliS3woZc6s4m9wlEwXHU=; b=qqfFcfeP8jkNSO5100jvg06EIKxHyuDFSUAZEJo9DDbAiwfqwA9rN51uNTjZagNFUz vrtX+zZa3/z3hgxuXwIdJP+0OB96OF99HMG+xBums2WZpTS8r6DqUH0zArVYDvQZJnCK CA5a38rD+Eywl0JCzhJefm+4fXJx+mFXtqAh1ZwyKVN5pYzsYFZyyK0A/WANRk3fsDZ4 +k4AiYGZ9Br3VJCEToFc8AiNqqyYH/b9d+vbRHhuH+EmblF2a/MMaqtXSNkB4iXqhcYV 0CzZx48EDM/y60TgxhlxdRUBFcz+4pF4xkUBnEFLyhR1kIjtGAz7xQtrgstan4eRvZ97 dn7g==
X-Gm-Message-State: AKS2vOzkpGAZ/9kyrEGNHRCrHLqKQJVL9POBX5vxj3WyjW4lM03dj4mF OKyzeiaeAyQs426GVkpW1YQ6kWZFJFT9JHusT9LnoHi84IEjEhgJDkh9ZqZyG3pbNaTgCF4X5X+ 60mPmwQIP41dsig==
X-Received: by 10.99.44.206 with SMTP id s197mr18542466pgs.116.1498781927050; Thu, 29 Jun 2017 17:18:47 -0700 (PDT)
MIME-Version: 1.0
Received: by 10.100.129.130 with HTTP; Thu, 29 Jun 2017 17:18:16 -0700 (PDT)
In-Reply-To: <CA+k3eCQs+j3yR4bUQtC1DpEnXRSbA92MSzhynR9YQ0wFemrM1Q@mail.gmail.com>
References: <CA+k3eCQ4Xvea_iqcanPwGECe8+eL_-aKjB4mMnpXfp06OPsJGQ@mail.gmail.com> <CA+k3eCQs+j3yR4bUQtC1DpEnXRSbA92MSzhynR9YQ0wFemrM1Q@mail.gmail.com>
From: Brian Campbell <bcampbell@pingidentity.com>
Date: Thu, 29 Jun 2017 18:18:16 -0600
Message-ID: <CA+k3eCRayp6k30CfFYy5MgtunTpP=xq3Nxar8e_LgonYnZY5fg@mail.gmail.com>
To: IETF Tokbind WG <unbearable@ietf.org>
Content-Type: multipart/alternative; boundary="001a1145a2dc5ba9360553225c9c"
Archived-At: <https://mailarchive.ietf.org/arch/msg/unbearable/RMLOg2L6ExN9XDmLJlWybq6sB3s>
Subject: Re: [Unbearable] Thurs 9am-10am in Lugano: additional TB TTRP meeting
X-BeenThere: unbearable@ietf.org
X-Mailman-Version: 2.1.22
Precedence: list
List-Id: "\"This list is for discussion of proposals for doing better than bearer tokens \(e.g. HTTP cookies, OAuth tokens etc.\) for web applications. The specific goal is chartering a WG focused on preventing security token export and replay attacks.\"" <unbearable.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/unbearable>, <mailto:unbearable-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/unbearable/>
List-Post: <mailto:unbearable@ietf.org>
List-Help: <mailto:unbearable-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/unbearable>, <mailto:unbearable-request@ietf.org?subject=subscribe>
X-List-Received-Date: Fri, 30 Jun 2017 00:18:50 -0000

And here is that new draft that reflects that preference of having the TTRP
do the validation and pass the TB IDs to the backend.

---------- Forwarded message ----------
From: <internet-drafts@ietf.org>
Date: Thu, Jun 29, 2017 at 6:03 PM
Subject: New Version Notification for draft-campbell-tokbind-ttrp-00.txt

A new version of I-D, draft-campbell-tokbind-ttrp-00.txt
has been successfully submitted by Brian Campbell and posted to the
IETF repository.

Name:           draft-campbell-tokbind-ttrp
Revision:       00
Title:          HTTPS Token Binding with TLS Terminating Reverse Proxies
Document date:  2017-06-29
Group:          Individual Submission
Pages:          10
URL:            https://www.ietf.org/internet-drafts/draft-campbell-tokbind-
ttrp-00.txt
Status:         https://datatracker.ietf.org/doc/draft-campbell-tokbind-ttr
p/
Htmlized:       https://tools.ietf.org/html/draft-campbell-tokbind-ttrp-00
Htmlized:       https://datatracker.ietf.org/doc/html/draft-campbell-tokbin
d-ttrp-00


Abstract:
   This document defines common HTTP header fields that enable a TLS
   terminating reverse proxy to convey information about the validated
   Token Binding Message sent by the client to a backend server, which
   enables that backend server to bind, or verify the binding of,
   cookies and other security tokens to the client's Token Binding key.



Please note that it may take a couple of minutes from the time of submission
until the htmlized version and diff are available at tools.ietf.org.

The IETF Secretariat

On Mon, Apr 3, 2017 at 12:07 PM, Brian Campbell <bcampbell@pingidentity.com>
wrote:

> Thanks to the several people who came out on Thursday morning to discuss
> the approach around TTRP & TB.
>
> The (more than rough) consensus that morning was that it was more
> appropriate for the TTRP to do the validation of the Token Binding Message
> in the Sec-Token-Binding header. That is contrary to the approach described
> in -00 of draft-campbell-tokbind-tls-term
> <https://tools.ietf.org/html/draft-campbell-tokbind-tls-term-00>. In
> order to move forward and facilitate discussion,I plan to write a new draft
> that reflects that preference of having the TTRP do the validation. Don't
> have an ETA on that just yet but I'll post it to this list when I have
> something readable.
>
>
>
>
>
> On Tue, Mar 28, 2017 at 8:57 AM, Brian Campbell <
> bcampbell@pingidentity.com> wrote:
>
>> Unfortunately, the presentation and discussion on Token Binding and TLS
>> Terminating Reverse Proxies was cut short by the end of Monday's meeting.
>> I would like to invite (or maybe beg) anyone who's interested in, or has
>> input into, the topic to meet again this week to discuss it more. Ideally
>> I'd like to have some sense of consensus on a preferred approach so I can
>> proceed with document work.
>>
>> I've reserved Lugano, the attendee sign-up room, for an hour starting at
>> 9am on Thursday (trying to find a good time was hard, sorry, I hope this
>> works okay for folks) for this ad hoc meeting.
>>
>> Lugano is on the 2nd floor. See https://datatracker.ietf.org/m
>> eeting/98/floor-plan?room=lugano#chicago-swissotel-floor-2
>>
>> The slides that were partially presented at yesterday's meeting are
>> attached for background and context.
>>
>> Hope to see many of you there!
>>
>
>

-- 
*CONFIDENTIALITY NOTICE: This email may contain confidential and privileged 
material for the sole use of the intended recipient(s). Any review, use, 
distribution or disclosure by others is strictly prohibited.  If you have 
received this communication in error, please notify the sender immediately 
by e-mail and delete the message and any file attachments from your 
computer. Thank you.*