[Web-bot-auth] Re: What does draft-meunier-webbotauth-httpsig-protocol do?
Martin Thomson <mt@lowentropy.net> Mon, 20 July 2026 14:08 UTC
Return-Path: <mt@lowentropy.net>
X-Original-To: web-bot-auth@mail2.ietf.org
Delivered-To: web-bot-auth@mail2.ietf.org
Received: from localhost (localhost [127.0.0.1]) by mail2.ietf.org (Postfix) with ESMTP id 64B6911A78BA2 for <web-bot-auth@mail2.ietf.org>; Mon, 20 Jul 2026 07:08:49 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=ietf.org; s=ietf1; t=1784556529; bh=48o8Fvo/r6hW1SNYviaZKb/mlluGdOTLFBBKMppNNJE=; h=Date:From:To:Cc:In-Reply-To:References:Subject; b=MQl0IgYMYjUr4iYVMgYkGN/hBr2nVHI+i1tWI0oeEMOvOMN71AOHxTKMO2cq3VslD 14E2H1ztSDBCpHjtU4gLiCHNESwlsPYocS/mqQkAfVfioN8SZ7l2QT2HeeuafXZyYU e/Ctg5Zfk641VcnxF4eeOC2UhREZm4BL6WkMKmUo=
X-Virus-Scanned: amavisd-new at ietf.org
X-Spam-Flag: NO
X-Spam-Score: -2.799
X-Spam-Level:
X-Spam-Status: No, score=-2.799 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, RCVD_IN_DNSWL_LOW=-0.7, RCVD_IN_VALIDITY_CERTIFIED_BLOCKED=0.001, RCVD_IN_VALIDITY_RPBL_BLOCKED=0.001, SPF_PASS=-0.001] autolearn=ham autolearn_force=no
Authentication-Results: mail2.ietf.org (amavisd-new); dkim=pass (2048-bit key) header.d=lowentropy.net header.b="h/wLI5mh"; dkim=pass (2048-bit key) header.d=messagingengine.com header.b="leHvZm6/"
Received: from mail2.ietf.org ([166.84.6.31]) by localhost (mail2.ietf.org [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id oMJKg0t88ANR for <web-bot-auth@mail2.ietf.org>; Mon, 20 Jul 2026 07:08:48 -0700 (PDT)
Received: from fhigh-b8-smtp.messagingengine.com (fhigh-b8-smtp.messagingengine.com [202.12.124.159]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature ECDSA (P-256) server-digest SHA256) (No client certificate requested) by mail2.ietf.org (Postfix) with ESMTPS id A6FC911A78B99 for <web-bot-auth@ietf.org>; Mon, 20 Jul 2026 07:08:48 -0700 (PDT)
Received: from phl-compute-04.internal (phl-compute-04.internal [10.202.2.44]) by mailfhigh.stl.internal (Postfix) with ESMTP id CB7B37A0064; Mon, 20 Jul 2026 10:08:47 -0400 (EDT)
Received: from phl-imap-15 ([10.202.2.104]) by phl-compute-04.internal (MEProxy); Mon, 20 Jul 2026 10:08:47 -0400
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=lowentropy.net; h=cc:cc:content-transfer-encoding:content-type:content-type :date:date:from:from:in-reply-to:in-reply-to:message-id :mime-version:references:reply-to:subject:subject:to:to; s=fm3; t=1784556527; x=1784642927; bh=C5XJjXYKKDtczMoabf94GuoNKZ3bEKuS 7GI4GluZ3MQ=; b=h/wLI5mhwWZ4jYjTF0vL/6Xdhqa6GiHf0DjzUkEcL8puETqv /o3oud6NhGrEFKwrCdmmFuVdApynzQ0TieHP6wwUL1VnlZZHIVuiW12ogByUxhN+ xXLD3Pf9P6KIA4z7o9LONQylSsVFgbC7MIcl7GPaKMbAIT/w1PB8QLJ+XgSrAtjn 5COv/YxKhnRlj62ncmu0oDOpLNjEgLTtFRI6waiyEUWiweOVBL8Ab+Se/C1NRljr H95CR/wbyeFd9sB1d7cnKFGh3Xa+0sH1nr/N9xJzTk/A76wDs2cquHE+ZJaA8Qsw NxMs2iLCjkC4zC3ZMXYHxD9QPCq2Kk9qmC3RGA==
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d= messagingengine.com; h=cc:cc:content-transfer-encoding :content-type:content-type:date:date:feedback-id:feedback-id :from:from:in-reply-to:in-reply-to:message-id:mime-version :references:reply-to:subject:subject:to:to:x-me-proxy :x-me-sender:x-me-sender:x-sasl-enc; s=fm2; t=1784556527; x= 1784642927; bh=C5XJjXYKKDtczMoabf94GuoNKZ3bEKuS7GI4GluZ3MQ=; b=l eHvZm6/iusVhuHp7cEfGCT4Q/521ODiLuTEzSNZvuVnVYcVPGiCtBLUSEj4CboGS SQNoTcl6WsZ2tJqyX8DXvrAGt4CLmViCJPdaBTJue3x2EwDGS/NvZ5mYEucVkFxJ VR38UX8zXDHpWTOOZAIWxGwjLTla7VPa1VSUJlL7afN7AGIdqIVEMn6G7Ul4fN6g YWgNrGcTPYuK0yL7MtYJv96UFRNqDTpETbIv0Crg/cf7PLxhlRa0A/PVH5gkbk2e JKEnn/PMZgltGHJU5yo4QrJ5bWl796alKG85AF6dln8xDb8gZLfJNKC+I9mNbBVs GSkB/kZDmfrZZ590FA+rQ==
X-ME-Sender: <xms:7yteagWK7Vy-mZBUAHIqtrva96SpKwiyVBQbERk9WygZBJq64LMpNQ> <xme:7yteavYVT2kRWevxwawUylHdM0I8LC0AxILnpQlhnQaKaKwv8fdnLr8o99CZGCQcH co_s6Ek_HZIw9VX1Vo_7jObGzT1EEbcxg64NzVznQeozmfuImZoLg>
X-ME-Proxy-Cause: dmFkZTFyb2TdeFEhrdBiizMzjh6GFEGBD47s2hMWhmrNfGkc0oInVhUOf/tt8gKp6ZgNO5 m/S4T88BMhhfzoQMmDIFzAMKDDlP/pqAyMmKFJMrYMjrkUM0lbJn2yKOaX6GsTEaWo6LVy q9jxbqqPWVh35t/xxY1KnQpPlWvXN7XER8I50wSYKikE1k8kIKtN3v/fNUbWFEOBM0BFjV itPknsVXvbpqD8ix0xiHFkbDYkkd7REwoCLOLIVlUqemsBliQxHArr0nDGNgtQQ998zOZ+ 0TIw4XB6yCcF45B6QsT9oXAi798KB5i0BdzrbIEUCBdzIARKHmyeSzpHhWNCBsevLASKST Gpbx8cygg0T5Vs1yi9Dg0ndNE0ygnmYIfYctSWvfQ05z71LrTh2gDuxG+vHFkggbbOTaLP oxSH+nFB5hQrnUVA3wg4HiNk5+2X2hsUtnc3Re4/+UBE4WjFeuoMAw6xvMDzTHnzZoRzh3 77H5uO5iDiMHlmwEOHP1LIPYzLJsCm40icu/eajSKicRV30NJ0jriipScfSV7JRmR7MwbT lRELZ+B4Kk4d/oGha8BJ6tN27yByCGQcLJaPAhsUmiRXWyvzIhCvEV/F8bpeMMxH/mdkfS 6hOyCD5OBPZN3OK7Q6bfBt0/5I+dUyls/qxQZWFb1SCm052e4U4aLmZh+Rjw
X-ME-Proxy: <xmx:7yteat5UG5omOCG3GJcHAO0F4AKc5IVmfzrg1_LDgety41aajSOtXA> <xmx:7yteasbAK3LWY64iZOsDyhsuD5nqWJSd5H7AABUjQUEwuvwaRggjYw> <xmx:7yteaki1cIvOmdp0OxkBq92lV5C6BAoCzgGTwavYGtrt_4GeYk0hhA> <xmx:7yteal85ODTm6DsL4MI4nkPRJiqHYG06M8WtXOI3Tnn2ypKLb1FuFg> <xmx:7ytearH--S2BCIQwRoa6cdyI4jwvYl1aX7JZSqprZMwP-AkOt5sW3gjt>
Feedback-ID: ic129442d:Fastmail
Received: by mailuser.phl.internal (Postfix, from userid 501) id 5B8DC780070; Mon, 20 Jul 2026 10:08:47 -0400 (EDT)
X-Mailer: MessagingEngine.com Webmail Interface
MIME-Version: 1.0
X-ThreadId: Ap18vIvpVsWZ
Date: Mon, 20 Jul 2026 16:08:23 +0200
From: Martin Thomson <mt@lowentropy.net>
To: Thibault Meunier <ot-ietf@thibault.uk>, Thibault Meunier <ot-ietf=40thibault.uk@dmarc.ietf.org>
Message-Id: <4b4b86f9-3cd3-4347-aba4-c9654cb5c46b@app.fastmail.com>
In-Reply-To: <jSCOoJZUKctrfnGVlqGgZHEcbr4LTBQreuUD4k5YiLpxtzoI0pJqf6r1QVlLE88bzMijhygy73E5yhlHFbdjNRdHNncApTpAWk8D6zCf06E=@thibault.uk>
References: <a7aaf631-62b5-41e5-ac8c-afcc77315010@app.fastmail.com> <CAD9ie-ub73p9H+O4es9bXZc_kKR05SPC6j5CLYg29yM2g0YreQ@mail.gmail.com> <6Uh4o62syQCrUGBgIvGWY8p2XuJnR2g2-t-ytwufIobpatO6CIxbQbQdjP72y97wKlDNsiKYruCVCJmh2mFYqg86rIHhwAl2B6P2n1GqBAQ=@thibault.uk> <CABcZeBO+Ex0LaEQhG7_uG2AgnpCMx3-9DaJ4s5KLWpp7Z5nCuA@mail.gmail.com> <BCzWjORZZUC4K58Bytl8Mm-LN67lhB5lcpLG2arabxxKjcxdo0nxBaJgegbbURJrykdYgxFzGOAR4lD_RZx3JiQNVIk63BtDPq-bin8kPAM=@thibault.uk> <CABcZeBOUrp5JviOxEy-8HfL83aQkM9HsA7_a==M0-fK+omzQfA@mail.gmail.com> <mWfbDJM5ddF0QJYsY5xpEGJLpWceHXVwwNeS_b3AeyIvhD4NtvrH_yFomaRx7x-MY11ZdK9XLbMgV-zqunL-CIU-cxBKUFa8nBNsKlY9tuc=@thibault.uk> <CABcZeBP2tw6tmYnOuo5PVDPG+VkFpfxyXo2xDFtQW5HDw2dotw@mail.gmail.com> <DUr5uNNNl8l2V3D-qP9raBuVF8gzIGv4fb5HXSQKCJScrzcJBolhnmMaDSysqEf1yDC7z-G7DdOVHGKN3o11rFGSx1-7qy6XcmYHlGcUl1s=@thibault.uk> <jSCOoJZUKctrfnGVlqGgZHEcbr4LTBQreuUD4k5YiLpxtzoI0pJqf6r1QVlLE88bzMijhygy73E5yhlHFbdjNRdHNncApTpAWk8D6zCf06E=@thibault.uk>
Content-Type: text/plain
Content-Transfer-Encoding: 7bit
Message-ID-Hash: N7UEEZ2VIL5UWSW77J75JQDNPGLYXYUL
X-Message-ID-Hash: N7UEEZ2VIL5UWSW77J75JQDNPGLYXYUL
X-MailFrom: mt@lowentropy.net
X-Mailman-Rule-Misses: dmarc-mitigation; no-senders; approved; emergency; loop; banned-address; member-moderation; nonmember-moderation; administrivia; implicit-dest; max-recipients; max-size; news-moderation; no-subject; digests; suspicious-header
CC: Eric Rescorla <ekr@rtfm.com>, Dick Hardt <Dick.Hardt@gmail.com>, web-bot-auth@ietf.org
X-Mailman-Version: 3.3.9rc6
Precedence: list
Subject: [Web-bot-auth] Re: What does draft-meunier-webbotauth-httpsig-protocol do?
List-Id: Authentication of non-human users to human-oriented Web sites <web-bot-auth.ietf.org>
Archived-At: <https://mailarchive.ietf.org/arch/msg/web-bot-auth/GBKRh2uR0zKVXRxWzYkx0vSEpBc>
List-Archive: <https://mailarchive.ietf.org/arch/browse/web-bot-auth>
List-Help: <mailto:web-bot-auth-request@ietf.org?subject=help>
List-Owner: <mailto:web-bot-auth-owner@ietf.org>
List-Post: <mailto:web-bot-auth@ietf.org>
List-Subscribe: <mailto:web-bot-auth-join@ietf.org>
List-Unsubscribe: <mailto:web-bot-auth-leave@ietf.org>
I'm not sure that "why not both" is the answer here. Can we make a decision? As noted, the purpose of binding to a real-world identity is to either enable a higher-layer continuity (for key rotation) or to bless a key pair with some existing reputation. It would be really good if we could work out what the principles are behind that decision can be articulated? -- I see something interesting in your text: > The binding is not exclusive: several domains may publish the same key. Your "I am Spartacus"[1] defenses in the directory draft seem a bit unwieldy. Are they really necessary? [1] https://knowyourmeme.com/memes/i-am-spartacus On Fri, Jul 17, 2026, at 09:14, Thibault Meunier wrote: > Following this thread, I started laying out a "trust model" section in > the protocol draft, prompted by Martin's original email. This thread > has helped a lot to sharpen it, and i've reused some of the modelling > and wording that came from this discussion (opaque > value/external-binding from ekr, key on a domain being distinct from > endorsement from Dick). > > You can see the new section in a rendered protocol draft [1] at the > below URL (given the submission window has passed) > https://thibmeu.github.io/http-message-signatures-directory/protocol-trust-model/draft-meunier-webbotauth-httpsig-protocol.html#name-identifiers-and-trust-model > > Beyond the new section, the PR also tightens the directory draft [2] by > removing parts which have not seen adoption in deployments such as the > delegation examples, and add a MUST for verifiers that rely on domain > binding. > > This proposal does not settle if the current draft makes the right > split with two modes. The goal is for it to help better inform the > discussion in Vienna. > > While there is a PR open [104], I believe that it's best to keep > comments on the list. > > [1] > https://thibmeu.github.io/http-message-signatures-directory/protocol-trust-model/draft-meunier-webbotauth-httpsig-protocol.html > [2] > https://thibmeu.github.io/http-message-signatures-directory/protocol-trust-model/draft-meunier-webbotauth-httpsig-directory.html > [104] > https://github.com/thibmeu/http-message-signatures-directory/pull/104 > > Thanks, > Thibault > > > > On Thursday, July 16th, 2026 at 18:44, Thibault Meunier > <ot-ietf=40thibault.uk@dmarc.ietf.org> wrote: > >> >> >> >> On Thursday, July 16th, 2026 at 14:38, Eric Rescorla <ekr@rtfm.com> wrote: >> >> > >> > >> > Well, we're not drafting a document right now, but rather trying to map out >> > the space. For that I find it most useful to try to separate questions into >> > objectives (what the mechanism tries to accomplish) and constraints >> > on that mechanism. You've listed one here, but it should also be efficient, >> > secure, etc. Those constraints are going to be crosscutting for all the >> > objectives and so I don't think it's helpful to list them as if they were >> > parallel; they are not alternatives. >> >> Fair. That's a good split. "no pre-established relationship", similar to security, efficiency, and others, is a constraint, crosscutting both of the objectives >> >> > I don't really think it's that helpful to think of these both as *names* in >> > a practical sense. Going back to my initial taxonomy, there are two things >> > we can do here, stated slightly differently. >> > >> > - Bind authentication to some opaque value which is not mapped >> > to any other external identity. >> > - Bind authentication to an identifier which is bound to some external >> > identity. >> >> I really like the term "opaque value". That's better than "key-alone" to qualify the model. >> >> > >> > Non-rotatable keys, keys signed by some root key, rotatable keys with >> > rotation stored in the ledger, keys stored in opaque URLs that aren't >> > attributable to the domain name (e.g., google drive) are all variants of >> > this same basic idea. You know someone is talking to you but you don't >> > know their identity. >> > >> > By contrast, proposals where the key is stored in DNS or in /.well-known >> > bind authentication to the domain name, which, by convention, is >> > a real-world identity [0]. I recognize that this *looks* similar to an >> > arbitary URL that stores the keys, but it's actually semantically quite >> > different. >> >> Agree. The URL shape is not what differentiate the opaque and the domain-bound model. >> >> > >> > -Ekr >> > >> > [0] What I mean here is we have a whole infrastructure buiilt up to >> > let you discover the mapping between domain names and real >> > world identities; for instance, you can search for "ExampleCo" >> > and see what result you get. >> > >> > >> > >> >> _______________________________________________ >> Web-bot-auth mailing list -- web-bot-auth@ietf.org >> To unsubscribe send an email to web-bot-auth-leave@ietf.org >>
- [Web-bot-auth] What does draft-meunier-webbotauth… Martin Thomson
- [Web-bot-auth] Re: What does draft-meunier-webbot… Dick Hardt
- [Web-bot-auth] Re: What does draft-meunier-webbot… Thibault Meunier
- [Web-bot-auth] Re: What does draft-meunier-webbot… Eric Rescorla
- [Web-bot-auth] Re: What does draft-meunier-webbot… Thibault Meunier
- [Web-bot-auth] Re: What does draft-meunier-webbot… Dick Hardt
- [Web-bot-auth] Re: What does draft-meunier-webbot… Eric Rescorla
- [Web-bot-auth] Re: What does draft-meunier-webbot… Thibault Meunier
- [Web-bot-auth] Re: What does draft-meunier-webbot… Dick Hardt
- [Web-bot-auth] Re: What does draft-meunier-webbot… Eric Rescorla
- [Web-bot-auth] Re: What does draft-meunier-webbot… Srecko Jovancevic
- [Web-bot-auth] Re: What does draft-meunier-webbot… Eric Rescorla
- [Web-bot-auth] Re: What does draft-meunier-webbot… Dick Hardt
- [Web-bot-auth] Re: What does draft-meunier-webbot… Thibault Meunier
- [Web-bot-auth] Re: What does draft-meunier-webbot… Thibault Meunier
- [Web-bot-auth] Re: What does draft-meunier-webbot… Martin Thomson
- [Web-bot-auth] Re: What does draft-meunier-webbot… Blake Morrison
- [Web-bot-auth] Re: What does draft-meunier-webbot… Kaveh Ranjbar
- [Web-bot-auth] Re: What does draft-meunier-webbot… Ben Schwartz
- [Web-bot-auth] Re: What does draft-meunier-webbot… Eric Rescorla