[Unbearable] Warren Kumari's No Objection on draft-ietf-tokbind-negotiation-12: (with COMMENT)

Warren Kumari <warren@kumari.net> Wed, 09 May 2018 15:04 UTC

Return-Path: <warren@kumari.net>
X-Original-To: unbearable@ietf.org
Delivered-To: unbearable@ietfa.amsl.com
Received: from ietfa.amsl.com (localhost [IPv6:::1]) by ietfa.amsl.com (Postfix) with ESMTP id B5A971242F5; Wed, 9 May 2018 08:04:56 -0700 (PDT)
MIME-Version: 1.0
Content-Type: text/plain; charset="utf-8"
Content-Transfer-Encoding: 7bit
From: Warren Kumari <warren@kumari.net>
To: "The IESG" <iesg@ietf.org>
Cc: draft-ietf-tokbind-negotiation@ietf.org, John Bradley <ve7jtb@ve7jtb.com>, tokbind-chairs@ietf.org, ve7jtb@ve7jtb.com, unbearable@ietf.org, liushucheng@huawei.com
X-Test-IDTracker: no
X-IETF-IDTracker: 6.80.0
Auto-Submitted: auto-generated
Precedence: bulk
Message-ID: <152587829673.3921.15943204349783206766.idtracker@ietfa.amsl.com>
Date: Wed, 09 May 2018 08:04:56 -0700
Archived-At: <https://mailarchive.ietf.org/arch/msg/unbearable/Ry1PpMLiYxA5weaSVIVzynQ3yE0>
Subject: [Unbearable] Warren Kumari's No Objection on draft-ietf-tokbind-negotiation-12: (with COMMENT)
X-BeenThere: unbearable@ietf.org
X-Mailman-Version: 2.1.22
List-Id: "\"This list is for discussion of proposals for doing better than bearer tokens \(e.g. HTTP cookies, OAuth tokens etc.\) for web applications. The specific goal is chartering a WG focused on preventing security token export and replay attacks.\"" <unbearable.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/unbearable>, <mailto:unbearable-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/unbearable/>
List-Post: <mailto:unbearable@ietf.org>
List-Help: <mailto:unbearable-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/unbearable>, <mailto:unbearable-request@ietf.org?subject=subscribe>
X-List-Received-Date: Wed, 09 May 2018 15:04:57 -0000

Warren Kumari has entered the following ballot position for
draft-ietf-tokbind-negotiation-12: No Objection

When responding, please keep the subject line intact and reply to all
email addresses included in the To and CC lines. (Feel free to cut this
introductory paragraph, however.)


Please refer to https://www.ietf.org/iesg/statement/discuss-criteria.html
for more information about IESG DISCUSS and COMMENT positions.


The document, along with other ballot positions, can be found here:
https://datatracker.ietf.org/doc/draft-ietf-tokbind-negotiation/



----------------------------------------------------------------------
COMMENT:
----------------------------------------------------------------------

Please also see Will LIU's OpsDir review here:
https://datatracker.ietf.org/doc/review-ietf-tokbind-negotiation-10-opsdir-lc-liu-2017-12-04/
It suggests a simple change which will remove confusion/ambiguity.

The document says (in the Introduction):
"The negotiation of the Token Binding protocol and key parameters in
combination with TLS 1.3 and later versions is beyond the scope of this
document."

How hard would it be to make it work with TLS 1.3? Actually, what part of it
doesn't already? (I'm guessing I'm missing something super-obvious)...