Re: [Webauthn-reg-review] Request to add payment extension to WebAuthn Registry

Michael Jones <michael_b_jones@hotmail.com> Wed, 13 September 2023 15:48 UTC

Return-Path: <michael_b_jones@hotmail.com>
X-Original-To: webauthn-reg-review@ietfa.amsl.com
Delivered-To: webauthn-reg-review@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 833C4C151991 for <webauthn-reg-review@ietfa.amsl.com>; Wed, 13 Sep 2023 08:48:12 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -6.234
X-Spam-Level:
X-Spam-Status: No, score=-6.234 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, FORGED_HOTMAIL_RCVD2=0.874, FREEMAIL_FROM=0.001, RCVD_IN_DNSWL_HI=-5, RCVD_IN_MSPIKE_H2=-0.001, RCVD_IN_ZEN_BLOCKED_OPENDNS=0.001, SPF_PASS=-0.001, T_SCC_BODY_TEXT_LINE=-0.01, URIBL_DBL_BLOCKED_OPENDNS=0.001, URIBL_ZEN_BLOCKED_OPENDNS=0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (2048-bit key) header.d=hotmail.com
Received: from mail.ietf.org ([50.223.129.194]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id OX-spIKNkiwP for <webauthn-reg-review@ietfa.amsl.com>; Wed, 13 Sep 2023 08:48:08 -0700 (PDT)
Received: from NAM11-DM6-obe.outbound.protection.outlook.com (mail-dm6nam11olkn2026.outbound.protection.outlook.com [40.92.19.26]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 694B3C15198F for <webauthn-reg-review@ietf.org>; Wed, 13 Sep 2023 08:48:08 -0700 (PDT)
ARC-Seal: i=1; a=rsa-sha256; s=arcselector9901; d=microsoft.com; cv=none; b=N6dPjctKJ1RnMrX2rLpmHl60YBC4xf57dpi7eK+R0RkGp6g7pQ/vqWFv9IDXGKlNGa9GK2oq5nPZ8jFDgpUFZyjEWBBIzFP++iLdP8Nh1dUYhOJbFfUS6XGAu1hIawrzwDlD1pGNFpQBbOHWv/cPYQh7y7OjsDgYFllLcwFBvVkvC1U/UXh0GJGrgVJkfg2ajnNVqeJzHXxKIL3/vH873yTc3OJfMz+Mc6WZ4rVqEd00XBvWhzpcX44txTW0/x+ZuI2ckLuPBXA9ICfSMHBQiFJLw7EnCusUag5o470ufjBC/q8RXm4/OmkI1y+jFXZrNOCbtHSmiQKuBzll97cYOw==
ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=microsoft.com; s=arcselector9901; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-AntiSpam-MessageData-ChunkCount:X-MS-Exchange-AntiSpam-MessageData-0:X-MS-Exchange-AntiSpam-MessageData-1; bh=UQvQuzHo/uXhpeuwLFfjN7c0POcpvmri09a59OchL2A=; b=RNrRcSJkZJOVX0oQDg8/KhO1n9AiDjHeEWmry/eS7glkjj1agT3QFMJjQ2oS4nhIICh9ZTDXIlbAbTM55w7s77+50ZVDLmNDm4mty1/MBVlBC8KdlxIlWbcsmxQ7VnHUCa0Jl4POeyybFkc81392hAKfRmWaoatgysPw+ce0l4kxsVPhKspFFjGnvKJvf534+j6tSWjHNQj8Q9J3pBPX02iGHVDmqevzTjahFffvFkgdAyfRDWku7hPkfp4Y2lQaboBuiqfkdID4qtNV1ldGtnois+nl10zbK8+xc1WRE77B/oGpRoYA9X+gJxOqL/KJunNhTybv3pxEsDL/GG+aFw==
ARC-Authentication-Results: i=1; mx.microsoft.com 1; spf=none; dmarc=none; dkim=none; arc=none
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=hotmail.com; s=selector1; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-SenderADCheck; bh=UQvQuzHo/uXhpeuwLFfjN7c0POcpvmri09a59OchL2A=; b=BEYjxVpYrPF38VcEKJAZROHMSG7xAYYtyFS6GL8FS2wyMFKawOdpErP9vPMNe/NOyLOLUPT7KMzI+WlYoKi74W7OXh5lBDY+NBx6nNoX30QvZdDpyG5J+OtM7o8kl/yIg7gHGXoWysuvI6h6RLQ1Bxef68v4JOjJxCVcJvegeeGvrOctHGv8WlEN+5dvJ8YngyvcjNItN+623H3rvgBfDBCheykfm5mgYqVbtCGUGDld3mQ+p4tsJgQSnCOkEy2y8lL5zfBJ6mX/WxFVLRE45elJRm9beh1Iq24XWua+JiJ2VVFG8PNmimk2dVj8/mKD05Tx8zkO3epa+hPSKvgAmg==
Received: from MW4PR02MB7428.namprd02.prod.outlook.com (2603:10b6:303:71::5) by CH2PR02MB7046.namprd02.prod.outlook.com (2603:10b6:610:8c::20) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.20.6792.19; Wed, 13 Sep 2023 15:48:06 +0000
Received: from MW4PR02MB7428.namprd02.prod.outlook.com ([fe80::36ca:d688:8cee:d6f7]) by MW4PR02MB7428.namprd02.prod.outlook.com ([fe80::36ca:d688:8cee:d6f7%6]) with mapi id 15.20.6768.036; Wed, 13 Sep 2023 15:48:06 +0000
From: Michael Jones <michael_b_jones@hotmail.com>
To: "iana-prot-param@iana.org" <iana-prot-param@iana.org>
CC: Giridhar Mandyam <mandyam@qti.qualcomm.com>, Ian Jacobs <ij@w3.org>, "webauthn-reg-review@ietf.org" <webauthn-reg-review@ietf.org>, Stephen McGruer <smcgruer@google.com>, Philippe Le Hégaret <plh@w3.org>
Thread-Topic: [Webauthn-reg-review] Request to add payment extension to WebAuthn Registry
Thread-Index: AQHZjL3oecRotg+LAEWy8vAMDU1k5q9niFfQgABHyICAAABG0IAAMkOAgAAGqXCAAAjxAIAAAeTugAGGkgCAIllDgIAyjJyAgA8MW6CABsfwAIAXx7MAgAAwvfCAAFakcIABRt+AgAkBWYCAAGAP8IAiTPMA
Date: Wed, 13 Sep 2023 15:48:06 +0000
Message-ID: <MW4PR02MB74282207FCB5296CA462A9E3B7F0A@MW4PR02MB7428.namprd02.prod.outlook.com>
References: <3C072A37-E257-4915-808F-1313634FF9E7@w3.org> <SJ0PR02MB83532B5F557C73B00F62FC3F81409@SJ0PR02MB8353.namprd02.prod.outlook.com> <8B3FB6B1-A6C1-4AD3-B5E5-89C088185AEC@w3.org> <SJ0PR02MB83534413068CE1C9B4E976EC81409@SJ0PR02MB8353.namprd02.prod.outlook.com> <B3E2CD8D-9714-40C3-B3EA-1309A85BDB59@w3.org> <SJ0PR02MB8353DF6FFE1584C2B560D32A81409@SJ0PR02MB8353.namprd02.prod.outlook.com> <91F93224-BD6D-4566-AF4B-4D40D57436A8@w3.org> <SJ0PR02MB835344D3D5688BC50D4A822B81409@SJ0PR02MB8353.namprd02.prod.outlook.com> <B34A0B9D-FF17-4B7C-A017-C4ECA857EF88@w3.org> <38F5B4F5-BD99-44FA-A646-03AEEA012C8D@w3.org> <2442E340-BE6E-44DA-A123-2107A20DC9EA@w3.org> <SJ0PR02MB8353B04770B85C82BA4519328101A@SJ0PR02MB8353.namprd02.prod.outlook.com> <91F71F16-E748-4F07-99DC-68B6CA946627@w3.org> <02B1ECC6-7EF9-4467-8280-23067E53C826@w3.org> <SJ0PR02MB8353A8B4884ABE1D1F386DCD8114A@SJ0PR02MB8353.namprd02.prod.outlook.com> <MW4PR02MB7428F9F937371AE0FCFD21AAB715A@MW4PR02MB7428.namprd02.prod.outlook.com> <F6715EF3-F66D-43CD-8FA7-87657A3BB358@w3.org> <240DCB22-3C7E-4972-AB72-51D9F0D1779A@w3.org> <SJ0PR02MB8353E54BD082BBDFA13CD9D6811FA@SJ0PR02MB8353.namprd02.prod.outlook.com>
In-Reply-To: <SJ0PR02MB8353E54BD082BBDFA13CD9D6811FA@SJ0PR02MB8353.namprd02.prod.outlook.com>
Accept-Language: en-US
Content-Language: en-US
X-MS-Has-Attach:
X-MS-TNEF-Correlator:
x-tmn: [tDZIoYZDfet2PSyiyvGEabiYWCX1MDLQ]
x-ms-publictraffictype: Email
x-ms-traffictypediagnostic: MW4PR02MB7428:EE_|CH2PR02MB7046:EE_
x-ms-office365-filtering-correlation-id: efd599e1-197c-451c-52f1-08dbb470d275
x-microsoft-antispam: BCL:0;
x-microsoft-antispam-message-info: u1PmZnn4TEdUrQAFiYV0/FNzvcDzswm2qicQb2TJ2YF8l2h65YThkEpcxQtTF4jkyP61I/hOmvxOyGslaNzjnoNUfuNI+/F/QMmpWj/4d6Rs7SezlMdGUOagqj4J/ph0rVwT5pATPi7gy02FllwHhxB3nEY8RUlBHO/9MXhGTOawNKAtDbaYzbVgGiJri2jxVfylMG+t3oAUyMXRCqUkFBKagzJdwcjn6HJ5fB6rYcxlG8Hz73KrSMFdq1mcWep2b9431HDGo8WxfBpYBHtn6jfbRks3tZHGMgfWeSn/3qQzDhJOiD05v7Y4zlvMz2F4LYud3acht226o6TyFHYtpP9ADLitXn0xajdACyIFqD/n6uq1QJQtqUTOwkx05GmHjvu+MFEyV3Q6xYb3v7HM3vYgDtcriwG1lPPfDpbPWQDnCp4AXOX287vuq9sCwwEkS9C71LFfK6nsApdoRbG25d8wXkhhnl25DZLJoxykP4DKnA5reGyBBFpIjz5svxIDhfg9dJIvW+Jvc4Drz5XJrF0D9b9Zs9Bo2Hk/7pM3DAlojEqus4sRzco7imcY4n4InedEDYodGQyHffCnASqAj80ARBb2S527rH40+J4Rb1c=
x-ms-exchange-antispam-messagedata-chunkcount: 1
x-ms-exchange-antispam-messagedata-0: zNCC4y+xnNvB9qRvWzffSTWkx+PdoEqDv8kK00KTIfI7kDOlSTQBnJnmHX4cjWWnohTNMCnPsZkhGaQfDbAJSH6NT/XQ2CkzQuOdm5qRbYOAxxYdPMP6WkbXePtk2tUOqiOpdmynfiHmmRoakdv1v3OK1ahlGEWEIvZgkrG2g/0RuWoNlMF5cr0TxsLRba3F6vOJ6srxiFw4cgpeGnKXEj9ezHDTwdDjt3E1b+Gk+u2cIacn9a18imCj+q+dbOB1PShkpAHBMtDjSEHXW4E+GtMcAJSzVYSE5wK61vSAGex/DGzmylQZxFCqnhlWuoSs/oA4KDHXbtQQSX28RzjkBImnEQLOLWa0YhZBe9GcqwgH10fgNesTXah2C3MbFhxqzRhKANry/UgIPa5Ourg1uybDO/CIogxMBKSOVRf9TMlsF6yZP1qkcQRp/5PiIWizb/PdNEs7jNOr5Pg/8KOq94f8IrTa5Tnc6tD+uFSNg1gFdilMFfqpvSZHDoUI9pVQozX34Wyee1cfknl32UjzUGlXfRyfIBWQciPXUCsijdDcxs743eZPmBsPQrtM1LXbizna2EcVhUa5vL1WWUBs43/Vu916W424JsIFK3lD4jrFrzxKvLjIQDehlRqTgItNMkhkReMobla70L5jehK/0UwfM3T/ay7TRmEwa/m59GHQdr+iFpKWt0pjgF3cxDfTU0PKc2uB+Af7IImCp+hdRXKTaCCOCeATtvcNVoARaGxH7z79Rg3G1Lk1ka5ikRHdXQWxwf++n4fFGdcdpV80EyRCI+CyhKU6Y+4KWIgMg5yOH1Y5+mzv2LJAXJBI8Rn3oXNnwXoJwoEeTc7PzN3chUxG+jdIsHm2jfBMNAEeSQpdrO4OsE1uIEHjOERV058/zPfL9tpLsekD3/flnPpSLgE4TtODUgA5da+PPe5BeIghAZoznllqWr7bpU6/NUYl1+e2MoDAQEVywUz1YTpuVXNJ44GO8eUKhCFbHs57nSvAUAF+wYVSJWqi0Vo4rWRYC13nnZBiiLyot/4H1bdUc+lxD/zADUCBmjxC9aVJiBBXC3yoT0re6F0mXFcH6vjI0Va1aeGRLy1rSv1eJL9onpUSBYpdIEq4YF08ELTUjegZlC5QTmSiFPM9kNf85lvOXfMo9Mc9vCqVK0ssKFHfuFnp39p9YFxF8CVt7KiAWB9JNTe+sLSxZgDwn1taaQmiB14BClpD/VbyyPpJXbQ99A==
Content-Type: text/plain; charset="iso-8859-1"
Content-Transfer-Encoding: quoted-printable
MIME-Version: 1.0
X-OriginatorOrg: sct-15-20-4755-11-msonline-outlook-3d941.templateTenant
X-MS-Exchange-CrossTenant-AuthAs: Internal
X-MS-Exchange-CrossTenant-AuthSource: MW4PR02MB7428.namprd02.prod.outlook.com
X-MS-Exchange-CrossTenant-RMS-PersistedConsumerOrg: 00000000-0000-0000-0000-000000000000
X-MS-Exchange-CrossTenant-Network-Message-Id: efd599e1-197c-451c-52f1-08dbb470d275
X-MS-Exchange-CrossTenant-rms-persistedconsumerorg: 00000000-0000-0000-0000-000000000000
X-MS-Exchange-CrossTenant-originalarrivaltime: 13 Sep 2023 15:48:06.3200 (UTC)
X-MS-Exchange-CrossTenant-fromentityheader: Hosted
X-MS-Exchange-CrossTenant-id: 84df9e7f-e9f6-40af-b435-aaaaaaaaaaaa
X-MS-Exchange-Transport-CrossTenantHeadersStamped: CH2PR02MB7046
Archived-At: <https://mailarchive.ietf.org/arch/msg/webauthn-reg-review/cJHbMQokVfDxlyZ7nVJS_XbZgPQ>
Subject: Re: [Webauthn-reg-review] Request to add payment extension to WebAuthn Registry
X-BeenThere: webauthn-reg-review@ietf.org
X-Mailman-Version: 2.1.39
Precedence: list
List-Id: "Registration requests should be sent to the mailing list described in \[draft-hodges-webauthn-registries, Section 17\]." <webauthn-reg-review.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/webauthn-reg-review>, <mailto:webauthn-reg-review-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/webauthn-reg-review/>
List-Post: <mailto:webauthn-reg-review@ietf.org>
List-Help: <mailto:webauthn-reg-review-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/webauthn-reg-review>, <mailto:webauthn-reg-review-request@ietf.org?subject=subscribe>
X-List-Received-Date: Wed, 13 Sep 2023 15:48:12 -0000

I agree.  IANA - please apply the IANA actions at https://w3c.github.io/secure-payment-confirmation/#sctn-iana-considerations.

                                Thank you,
                -- Mike (writing as a Designated Expert)

-----Original Message-----
From: Giridhar Mandyam <mandyam@qti.qualcomm.com>
Sent: Tuesday, August 22, 2023 9:59 PM
To: Ian Jacobs <ij@w3.org>; Michael Jones <michael_b_jones@hotmail.com>
Cc: webauthn-reg-review@ietf.org; Stephen McGruer <smcgruer@google.com>; Philippe Le Hégaret <plh@w3.org>
Subject: RE: [Webauthn-reg-review] Request to add payment extension to WebAuthn Registry

Thanks.  I think this addresses the requirements of https://www.rfc-editor.org/rfc/rfc8809.html#name-registering-extension-ident, but this is pending Mike's review.

-Giri

-----Original Message-----
From: Ian Jacobs <ij@w3.org>
Sent: Tuesday, August 22, 2023 7:14 AM
To: Michael Jones <michael_b_jones@hotmail.com>
Cc: Giridhar Mandyam <mandyam@qti.qualcomm.com>; webauthn-reg-review@ietf.org; Stephen McGruer <smcgruer@google.com>; Philippe Le Hégaret <plh@w3.org>
Subject: Re: [Webauthn-reg-review] Request to add payment extension to WebAuthn Registry

WARNING: This email originated from outside of Qualcomm. Please be wary of any links or attachments, and do not enable macros.

Hi Michael,

There is now an IANA Considerations section in the SPC specification:
  https://w3c.github.io/secure-payment-confirmation/#sctn-iana-considerations

Thank you!

Ian


> On Aug 16, 2023, at 3:42 PM, Ian Jacobs <ij@w3.org> wrote:
>
> Hi Mike and Giridhar,
>
> I've created a pull request to add an IANA considerations section to the spec:
> https://github.com/w3c/secure-payment-confirmation/pull/257
>
> All feedback and corrections welcome. Thank you!
>
> Ian
>
>> On Aug 15, 2023, at 8:19 PM, Michael Jones <michael_b_jones@hotmail.com> wrote:
>>
>> The specification does not contain an IANA Considerations section requesting registration of the extension, nor does it contain the information required to register the extension.  In particular, the information from the registration template at https://www.rfc-editor.org/rfc/rfc8809.html#section-2.2.1 is missing.
>>
>> Please update the specification to add an IANA Considerations section supplying the information necessary to register the extension.  Quoting from RFC 8809, that information is:
>>
>>  WebAuthn Extension Identifier:
>>     An identifier meeting the requirements given in Section 2.2.
>>
>>  Description:
>>     A relatively short description of the extension.
>>
>>  Specification Document(s):
>>     Reference to the document or documents that specify the extension.
>>
>>  Change Controller:
>>     For Standards Track RFCs, list "IETF".  For others, give the name
>>     of the responsible party.  Other details (e.g., postal address,
>>     email address, home page URI) may also be included.
>>
>>  Notes:
>>     [optional]
>>
>> After the specification is updated, I should be able to approve the registration.
>>
>>                               -- Mike
>>
>> -----Original Message-----
>> From: Giridhar Mandyam <mandyam@qti.qualcomm.com>
>> Sent: Tuesday, August 15, 2023 1:03 PM
>> To: Ian Jacobs <ij@w3.org>; michael_b_jones@hotmail.com
>> Cc: webauthn-reg-review@ietf.org; Stephen McGruer <smcgruer@google.com>; Philippe Le Hégaret <plh@w3.org>
>> Subject: RE: [Webauthn-reg-review] Request to add payment extension to WebAuthn Registry
>>
>> Nothing from my end.  Awaiting Mike's review.
>>
>> -Giri
>>
>> -----Original Message-----
>> From: Ian Jacobs <ij@w3.org>
>> Sent: Tuesday, August 15, 2023 10:08 AM
>> To: Giridhar Mandyam <mandyam@qti.qualcomm.com>; michael_b_jones@hotmail.com
>> Cc: webauthn-reg-review@ietf.org; Stephen McGruer <smcgruer@google.com>; Philippe Le Hégaret <plh@w3.org>
>> Subject: Re: [Webauthn-reg-review] Request to add payment extension to WebAuthn Registry
>>
>> WARNING: This email originated from outside of Qualcomm. Please be wary of any links or attachments, and do not enable macros.
>>
>> Hi Giridhar,
>>
>> I wanted to let you know that we've merged the pull request, so the statement you referred to below no longer appears.
>>
>> If there's any other information you need to complete your evaluation, let me know. Thanks again!
>>
>> Ian
>>
>>> On Jul 31, 2023, at 8:59 AM, Ian Jacobs <ij@w3.org> wrote:
>>>
>>> Thanks Giridhar,
>>>
>>> I've proposed a pull request to remove the note:
>>> https://github.com/w3c/secure-payment-confirmation/pull/255
>>>
>>> Ian
>>>
>>>> On Jul 27, 2023, at 1:32 AM, Giridhar Mandyam <mandyam@qti.qualcomm.com> wrote:
>>>>
>>>> Hi Ian,
>>>>
>>>> Mike needs to sign off,  but I have reviewed this an am satisfied that the extension can be registered.
>>>>
>>>> Please consider removing the following in any future revision:
>>>>
>>>> "Note: Reading [webauthn-3] literally, these steps don't work; extensions are injected at step 12 of [[Create]] and cannot really modify anything. However other extensions ignore that entirely and assume they can modify any part of any WebAuthn algorithm!"
>>>>
>>>> I don't think the above statement is an accurate reading of the WebAuthn spec, as the steps outlined in the Webauthn spec do not have to be executed in sequence.  This is because the cited section in Webauthn is for an internal method, which as per the ECMA description is left up to the implementation (https://tc39.es/ecma262/#sec-object-internal-methods-and-internal-slots).
>>>>
>>>> Mike,
>>>> Please provide your feedback.
>>>>
>>>> -Giri
>>
>> --
>> Ian Jacobs <ij@w3.org>
>> https://www.w3.org/People/Jacobs/
>> Tel: +1 917 450 8783
>>
>>
>>
>>
>>
>
> --
> Ian Jacobs <ij@w3.org>
> https://www.w3.org/People/Jacobs/
> Tel: +1 917 450 8783
>
>
>
>
>

--
Ian Jacobs <ij@w3.org>
https://www.w3.org/People/Jacobs/
Tel: +1 917 450 8783