[Unbearable] HTTPSTB-18

Andrei Popov <Andrei.Popov@microsoft.com> Tue, 26 June 2018 21:22 UTC

Return-Path: <Andrei.Popov@microsoft.com>
X-Original-To: unbearable@ietfa.amsl.com
Delivered-To: unbearable@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 40D62130E3E for <unbearable@ietfa.amsl.com>; Tue, 26 Jun 2018 14:22:26 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.01
X-Spam-Level:
X-Spam-Status: No, score=-2.01 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, HTML_MESSAGE=0.001, RCVD_IN_DNSWL_NONE=-0.0001, SPF_PASS=-0.001, T_DKIMWL_WL_HIGH=-0.01] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (1024-bit key) header.d=microsoft.com
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id G8NHv55JKf2n for <unbearable@ietfa.amsl.com>; Tue, 26 Jun 2018 14:22:24 -0700 (PDT)
Received: from NAM01-SN1-obe.outbound.protection.outlook.com (mail-sn1nam01on0137.outbound.protection.outlook.com [104.47.32.137]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 156C0130E2E for <unbearable@ietf.org>; Tue, 26 Jun 2018 14:22:24 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=microsoft.com; s=selector1; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-SenderADCheck; bh=aG1brBqYyGALQUJo1BJXkL65V0lcp8AgBj1jZ7J7rIA=; b=g6JYzW3qzxeBb5ENpATUJGKbUAc+eFFJzxkLSYgoc8X2p4r/fojOMycln2p1/zQGUJ3W6JRX+aprE44Z+0ls6fMjOKaw1CcDilvf6+LRgQ/yXkg5dD9wM88Gol7sQRRg0CQjwsinBdMsR9H9rrs6jUSKhxsQJAJcqvaTlmsbaEI=
Received: from CY4PR21MB0774.namprd21.prod.outlook.com (10.173.192.20) by CY4PR21MB0757.namprd21.prod.outlook.com (10.173.192.11) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_CBC_SHA384_P256) id 15.20.930.0; Tue, 26 Jun 2018 21:22:22 +0000
Received: from CY4PR21MB0774.namprd21.prod.outlook.com ([fe80::9d01:113b:290a:750b]) by CY4PR21MB0774.namprd21.prod.outlook.com ([fe80::9d01:113b:290a:750b%3]) with mapi id 15.20.0930.005; Tue, 26 Jun 2018 21:22:22 +0000
From: Andrei Popov <Andrei.Popov@microsoft.com>
To: Tokbind WG <unbearable@ietf.org>
Thread-Topic: HTTPSTB-18
Thread-Index: AdQNk5H8p5oo2RcgQv2QVz9fJITo4w==
Date: Tue, 26 Jun 2018 21:22:22 +0000
Message-ID: <CY4PR21MB0774BB9DCFE944A2013C5C278C490@CY4PR21MB0774.namprd21.prod.outlook.com>
Accept-Language: en-US
Content-Language: en-US
X-MS-Has-Attach:
X-MS-TNEF-Correlator:
x-originating-ip: [2001:4898:80e8:8:28b5:a023:971b:e42c]
x-ms-publictraffictype: Email
x-microsoft-exchange-diagnostics: 1; CY4PR21MB0757; 7:7pXgy5Fqq3PbZvmfZvq/GeRcRlWnVKvFQru9dSJE7FPAB9MSoy/lngbQIBt9uGazWqsv0Toth1O17eKquvEX+Yb/Z6W6460lx76gqF+OaiLB2inHs2U4tEfbmpuFXYCwY74QERtd32M0ulOYD8tMI13aRhaotIKCi2rI5gWXNjxVxE+IjbGmROBopWzltsAeUcYQkGbwu9bKy44+WQxt1Ra+ykuRAE8R6cI36upAeq8uryXvVbZJZ8cch79LzkfN
x-ms-exchange-antispam-srfa-diagnostics: SOS;
x-ms-office365-filtering-correlation-id: d8f5a592-c21c-421a-e9bb-08d5dbaae7fd
x-ms-office365-filtering-ht: Tenant
x-microsoft-antispam: UriScan:; BCL:0; PCL:0; RULEID:(7020095)(4652020)(8989117)(4534165)(4627221)(201703031133081)(201702281549075)(8990107)(5600026)(711020)(48565401081)(2017052603328)(7193020); SRVR:CY4PR21MB0757;
x-ms-traffictypediagnostic: CY4PR21MB0757:
authentication-results: spf=none (sender IP is ) smtp.mailfrom=Andrei.Popov@microsoft.com;
x-microsoft-antispam-prvs: <CY4PR21MB075752586FE55650C1E228B98C490@CY4PR21MB0757.namprd21.prod.outlook.com>
x-exchange-antispam-report-test: UriScan:(28532068793085)(21748063052155);
x-ms-exchange-senderadcheck: 1
x-exchange-antispam-report-cfa-test: BCL:0; PCL:0; RULEID:(8211001083)(6040522)(2401047)(8121501046)(5005006)(10201501046)(3231254)(2018427008)(944501410)(52105095)(3002001)(93006095)(93001095)(6055026)(149027)(150027)(6041310)(201703131423095)(201702281528075)(20161123555045)(201703061421075)(201703061406153)(20161123564045)(20161123562045)(20161123558120)(20161123560045)(6072148)(201708071742011)(7699016); SRVR:CY4PR21MB0757; BCL:0; PCL:0; RULEID:; SRVR:CY4PR21MB0757;
x-forefront-prvs: 071518EF63
x-forefront-antispam-report: SFV:NSPM; SFS:(10019020)(396003)(346002)(376002)(366004)(39860400002)(136003)(189003)(199004)(2906002)(105586002)(6506007)(97736004)(102836004)(99286004)(25786009)(53936002)(106356001)(86612001)(186003)(7696005)(8990500004)(10290500003)(5250100002)(33656002)(68736007)(478600001)(22452003)(316002)(46003)(558084003)(6916009)(14454004)(5660300001)(6436002)(6116002)(486006)(790700001)(476003)(7736002)(2900100001)(8936002)(81166006)(86362001)(72206003)(81156014)(9686003)(10090500001)(54896002)(55016002)(8676002)(74316002)(6306002)(14444005)(256004); DIR:OUT; SFP:1102; SCL:1; SRVR:CY4PR21MB0757; H:CY4PR21MB0774.namprd21.prod.outlook.com; FPR:; SPF:None; LANG:en; PTR:InfoNoRecords; MX:1; A:1;
received-spf: None (protection.outlook.com: microsoft.com does not designate permitted sender hosts)
x-microsoft-antispam-message-info: u66hzLtInGw21Yc2nItoXjK0hOKxJhLbRR6m1ZupoKCdvaDVQxh6A4zyTa0INwZCD9XlMWQsAsmec3S8nqyGlfwKkxPuBi/JoEGyCpJirWY36yz49k/X1tFyApddr10lwKyhzC1vwhgIpzgYKCccnrqwcp1vZq0Ke+qkTKkD2pw4BoBoR1kkRxYm8a6IowVctF1GghyOFYAS/NPKjCmmMY6o3iRHhxdYpIvJoraznUDhJ7gDYKwfzY98L10rerlaN+Iskh7x7T7V0LW7HJ+3Zuw2KR47TGWrXvXh8VjXIRqPkxNGz3zoityBJARYqE//ECI2h/52lMmwvsrJx0dRbOcALHJREIJPshdTCoA1vns=
spamdiagnosticoutput: 1:99
spamdiagnosticmetadata: NSPM
Content-Type: multipart/alternative; boundary="_000_CY4PR21MB0774BB9DCFE944A2013C5C278C490CY4PR21MB0774namp_"
MIME-Version: 1.0
X-OriginatorOrg: microsoft.com
X-MS-Exchange-CrossTenant-Network-Message-Id: d8f5a592-c21c-421a-e9bb-08d5dbaae7fd
X-MS-Exchange-CrossTenant-originalarrivaltime: 26 Jun 2018 21:22:22.4652 (UTC)
X-MS-Exchange-CrossTenant-fromentityheader: Hosted
X-MS-Exchange-CrossTenant-id: 72f988bf-86f1-41af-91ab-2d7cd011db47
X-MS-Exchange-Transport-CrossTenantHeadersStamped: CY4PR21MB0757
Archived-At: <https://mailarchive.ietf.org/arch/msg/unbearable/P-3IZ0PL098x62cK4Df-cORt-Co>
Subject: [Unbearable] HTTPSTB-18
X-BeenThere: unbearable@ietf.org
X-Mailman-Version: 2.1.26
Precedence: list
List-Id: "\"This list is for discussion of proposals for doing better than bearer tokens \(e.g. HTTP cookies, OAuth tokens etc.\) for web applications. The specific goal is chartering a WG focused on preventing security token export and replay attacks.\"" <unbearable.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/unbearable>, <mailto:unbearable-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/unbearable/>
List-Post: <mailto:unbearable@ietf.org>
List-Help: <mailto:unbearable-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/unbearable>, <mailto:unbearable-request@ietf.org?subject=subscribe>
X-List-Received-Date: Tue, 26 Jun 2018 21:22:27 -0000

Another editorial update of HTTPSTB has been uploaded, with Section 6 clarified in response to GEN-ART review.

Cheers,

Andrei