Re: [Unbearable] Opsdir last call review of draft-ietf-tokbind-negotiation-10

Andrei Popov <Andrei.Popov@microsoft.com> Mon, 04 December 2017 18:37 UTC

Return-Path: <Andrei.Popov@microsoft.com>
X-Original-To: unbearable@ietfa.amsl.com
Delivered-To: unbearable@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 89FB71286AB; Mon, 4 Dec 2017 10:37:24 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -4.801
X-Spam-Level:
X-Spam-Status: No, score=-4.801 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, RCVD_IN_DNSWL_NONE=-0.0001, RCVD_IN_MSPIKE_H2=-2.8, SPF_PASS=-0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (1024-bit key) header.d=microsoft.com
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id mRM5NZX_uzsc; Mon, 4 Dec 2017 10:37:23 -0800 (PST)
Received: from NAM02-BL2-obe.outbound.protection.outlook.com (mail-bl2nam02on0138.outbound.protection.outlook.com [104.47.38.138]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id B2EF312025C; Mon, 4 Dec 2017 10:37:22 -0800 (PST)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=microsoft.com; s=selector1; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version; bh=k5HkEETQRugV35Ale/UR3M4pwl62kXdiZud4+8+w8iU=; b=UiYdMasfPSdZ89qmRN/80skgTJz3bvLdXoJvXsbw9WauPX+CVZKP5R95IP3kr620JJt66blYqbyzVTUXsxdOQzeTTP6VhW9sYnj2FJn4uzFyZlK88Tl84N9wpww/dssxsBqwJdhB81W7apAMsdpVSojZ4xqhv2ylmf9GZjrB/7I=
Received: from MWHPR21MB0189.namprd21.prod.outlook.com (10.173.52.135) by MWHPR21MB0781.namprd21.prod.outlook.com (10.173.51.147) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_CBC_SHA384_P256) id 15.20.323.1; Mon, 4 Dec 2017 18:37:20 +0000
Received: from MWHPR21MB0189.namprd21.prod.outlook.com ([10.173.52.135]) by MWHPR21MB0189.namprd21.prod.outlook.com ([10.173.52.135]) with mapi id 15.20.0323.001; Mon, 4 Dec 2017 18:37:20 +0000
From: Andrei Popov <Andrei.Popov@microsoft.com>
To: Will LIU <liushucheng@huawei.com>, "ops-dir@ietf.org" <ops-dir@ietf.org>
CC: "unbearable@ietf.org" <unbearable@ietf.org>, "draft-ietf-tokbind-negotiation.all@ietf.org" <draft-ietf-tokbind-negotiation.all@ietf.org>, "ietf@ietf.org" <ietf@ietf.org>
Thread-Topic: Opsdir last call review of draft-ietf-tokbind-negotiation-10
Thread-Index: AQHTbQJ+evumkg/udU2c4TkkZyAK5aMzg5CQ
Date: Mon, 4 Dec 2017 18:37:19 +0000
Message-ID: <MWHPR21MB0189488EFAF88482DEEA94908C3C0@MWHPR21MB0189.namprd21.prod.outlook.com>
References: <151239355490.6314.4963597716182552461@ietfa.amsl.com>
In-Reply-To: <151239355490.6314.4963597716182552461@ietfa.amsl.com>
Accept-Language: en-US
Content-Language: en-US
X-MS-Has-Attach:
X-MS-TNEF-Correlator:
x-originating-ip: [2001:4898:80e8:e::4ca]
x-ms-publictraffictype: Email
x-microsoft-exchange-diagnostics: 1; MWHPR21MB0781; 6:u6wQYAbNcMTrzMkuFdoTPLXNvsfVZNrp96KOSih1EcwJp4QVSqEwxS912ZF6jmGIGev9Ex+XH1y0RZlDelYYSuLCR489GxAHjlpOxeJh0EyjTqIOJlPC+E1BOiIPbvgF+W674gJAlAtLZUxWbezqFAWFAWLGlk+o0HqmPO8u+AuR47UogGm/YUDiWsHoyxFO8yqEg9xwieefWV8y9/v9oBTEDg11OFzgAAD1GhVCV8S2+0743XaLxdrwVy//qURKa4blO0YHGYOgOiMa/+ADlQWwYvQGTvPfUFRX/rA7zCsRvW7unWD//2sgPeUpxVT3j18gUQNkVzjD0HQTuRvJVJusoAxPJtHLwkAelCcKwik=; 5:p6qF/V6QPryK7IlUHIBRJMlO+HAYHf4/wdKZCyvLZZMqvewQCWWtCk4JPyzq2YDAj1GHn5fH7A70BvgBSl2+ebF2iPdGfyrmhQm4tjtMDP++Wcs8uEYfLHyHDuHQTWIf/0aP/Gjij0OHs9XZim3mkXXn2XJ5KQI0D1r5IFsrnac=; 24:lvUFGSQEddbssbz1PzaUZgdaJM4/Fdp9nGSkiVF0SxvnjEEWTP0lgdKCxXd03P3LXeiH3Q17fUGbCkCV3TUUNmMzppCNAeAaPmUEt1k4CbQ=; 7:b0xw30W/86Jmk6Bd9AJ+nWPgPfk2DXhIlH8F1UVNIbSb7pxuGoIqJTU+/6xvRX0NzhGfQkyOs70eVFAaPLCIgIv+UHz43FbftRXVINqP1HjYXH0pPpoRl74JFeZaolSkUEpS5gSQ44P0y1e0x7a3qzmXHuUdUINSwv3HojbsswXFTr2smr+Y1jsoaeAGifAz/utJX+rOAKNGYskA3AGWgYWJoOwXDipA3wjA+6WKKW85WHl9PwXsWrdlqqK8//Os
x-ms-exchange-antispam-srfa-diagnostics: SSOS;
x-ms-office365-filtering-correlation-id: 4a4d413c-79a4-41a4-c296-08d53b460d6c
x-ms-office365-filtering-ht: Tenant
x-microsoft-antispam: UriScan:; BCL:0; PCL:0; RULEID:(5600026)(4604075)(4534020)(4602075)(4627115)(201703031133081)(201702281549075)(48565401081)(2017052603286); SRVR:MWHPR21MB0781;
x-ms-traffictypediagnostic: MWHPR21MB0781:
authentication-results: spf=none (sender IP is ) smtp.mailfrom=Andrei.Popov@microsoft.com;
x-microsoft-antispam-prvs: <MWHPR21MB0781CA8C0F74279A68BC8D098C3C0@MWHPR21MB0781.namprd21.prod.outlook.com>
x-exchange-antispam-report-test: UriScan:(192374486261705)(50582790962513);
x-exchange-antispam-report-cfa-test: BCL:0; PCL:0; RULEID:(61425038)(6040450)(2401047)(8121501046)(5005006)(3231022)(93006095)(93001095)(10201501046)(3002001)(6055026)(61426038)(61427038)(6041248)(20161123562025)(20161123564025)(201703131423075)(201702281528075)(201703061421075)(201703061406153)(20161123558100)(20161123555025)(20161123560025)(6072148)(201708071742011); SRVR:MWHPR21MB0781; BCL:0; PCL:0; RULEID:(100000803101)(100110400095); SRVR:MWHPR21MB0781;
x-forefront-prvs: 051158ECBB
x-forefront-antispam-report: SFV:NSPM; SFS:(10019020)(6009001)(366004)(376002)(39860400002)(346002)(47760400005)(51914003)(189002)(13464003)(199003)(6436002)(86362001)(5660300001)(2900100001)(22452003)(86612001)(6506006)(316002)(54906003)(2950100002)(478600001)(77096006)(6116002)(102836003)(110136005)(25786009)(10290500003)(72206003)(229853002)(3660700001)(7736002)(74316002)(230783001)(189998001)(81156014)(81166006)(68736007)(8676002)(305945005)(106356001)(3280700002)(8990500004)(4326008)(8936002)(101416001)(105586002)(2906002)(54356011)(6246003)(9686003)(99286004)(76176011)(53936002)(2501003)(14454004)(7696005)(55016002)(97736004)(33656002)(53546010)(10090500001); DIR:OUT; SFP:1102; SCL:1; SRVR:MWHPR21MB0781; H:MWHPR21MB0189.namprd21.prod.outlook.com; FPR:; SPF:None; PTR:InfoNoRecords; MX:1; A:1; LANG:en;
received-spf: None (protection.outlook.com: microsoft.com does not designate permitted sender hosts)
spamdiagnosticoutput: 1:99
spamdiagnosticmetadata: NSPM
Content-Type: text/plain; charset="utf-8"
Content-Transfer-Encoding: base64
MIME-Version: 1.0
X-OriginatorOrg: microsoft.com
X-MS-Exchange-CrossTenant-Network-Message-Id: 4a4d413c-79a4-41a4-c296-08d53b460d6c
X-MS-Exchange-CrossTenant-originalarrivaltime: 04 Dec 2017 18:37:20.0055 (UTC)
X-MS-Exchange-CrossTenant-fromentityheader: Hosted
X-MS-Exchange-CrossTenant-id: 72f988bf-86f1-41af-91ab-2d7cd011db47
X-MS-Exchange-Transport-CrossTenantHeadersStamped: MWHPR21MB0781
Archived-At: <https://mailarchive.ietf.org/arch/msg/unbearable/lwp0iu6R4MF2Uly7mmruaHD62KI>
Subject: Re: [Unbearable] Opsdir last call review of draft-ietf-tokbind-negotiation-10
X-BeenThere: unbearable@ietf.org
X-Mailman-Version: 2.1.22
Precedence: list
List-Id: "\"This list is for discussion of proposals for doing better than bearer tokens \(e.g. HTTP cookies, OAuth tokens etc.\) for web applications. The specific goal is chartering a WG focused on preventing security token export and replay attacks.\"" <unbearable.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/unbearable>, <mailto:unbearable-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/unbearable/>
List-Post: <mailto:unbearable@ietf.org>
List-Help: <mailto:unbearable-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/unbearable>, <mailto:unbearable-request@ietf.org?subject=subscribe>
X-List-Received-Date: Mon, 04 Dec 2017 18:37:24 -0000

Thanks for the review; will use correct reference.

Cheers,

Andrei

-----Original Message-----
From: Will LIU [mailto:liushucheng@huawei.com] 
Sent: Monday, December 4, 2017 5:19 AM
To: ops-dir@ietf.org
Cc: unbearable@ietf.org; draft-ietf-tokbind-negotiation.all@ietf.org; ietf@ietf.org
Subject: Opsdir last call review of draft-ietf-tokbind-negotiation-10

Reviewer: Will LIU
Review result: Ready

I have reviewed draft-ietf-tokbind-negotiation-10 as part of the Operational directorate's ongoing effort to review all IETF documents being processed by the IESG.  These comments were written with the intent of improving the operational aspects of the IETF drafts. Comments that are not addressed in last call may be included in AD reviews during the IESG review.  Document editors and WG chairs should treat these comments just like any other last call comments.

“ This document specifies a Transport Layer Security (TLS) extension for the negotiation of Token Binding protocol version and key
   parameters.”

My overall view of the document is 'Ready with Nits' for publication.

Section 3
>   "token_binding_version" contains the lower of:
>  o  the Token Binding protocol version offered by the client in the
>      "token_binding" extension and
>   o  the highest version supported by the server.

"The highest version" means  the highest *Token Binding protocol* version? If yes, please indicate directly to eliminate confusion.

Section 8
>   [I-D.ietf-tokbind-protocol]
>             Popov, A., Nystrom, M., Balfanz, D., Langley, A., and J.
>             Hodges, "The Token Binding Protocol Version 1.0", draft-
>             ietf-tokbind-protocol-15 (work in progress), July 2017.

A later version (-16) should be put here.