Re: [webfinger] Automated Service Configuration now uses webfinger

Jesse Thompson <jesse.thompson@doit.wisc.edu> Mon, 08 July 2013 13:11 UTC

Return-Path: <jesse.thompson@doit.wisc.edu>
X-Original-To: webfinger@ietfa.amsl.com
Delivered-To: webfinger@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 4DA7421F99BF for <webfinger@ietfa.amsl.com>; Mon, 8 Jul 2013 06:11:58 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.599
X-Spam-Level:
X-Spam-Status: No, score=-2.599 tagged_above=-999 required=5 tests=[BAYES_00=-2.599]
Received: from mail.ietf.org ([12.22.58.30]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id DKX0KsIpfpit for <webfinger@ietfa.amsl.com>; Mon, 8 Jul 2013 06:11:53 -0700 (PDT)
Received: from smtpauth2.wiscmail.wisc.edu (wmauth2.doit.wisc.edu [144.92.197.222]) by ietfa.amsl.com (Postfix) with ESMTP id A176021F99A1 for <webfinger@ietf.org>; Mon, 8 Jul 2013 06:11:52 -0700 (PDT)
MIME-version: 1.0
Content-transfer-encoding: 7bit
Content-type: text/plain; CHARSET="US-ASCII"; format="flowed"
Received: from avs-daemon.smtpauth2.wiscmail.wisc.edu by smtpauth2.wiscmail.wisc.edu (Oracle Communications Messaging Server 7u4-27.01(7.0.4.27.0) 64bit (built Aug 30 2012)) id <0MPM00100C60N300@smtpauth2.wiscmail.wisc.edu> for webfinger@ietf.org; Mon, 08 Jul 2013 08:11:52 -0500 (CDT)
X-Spam-PmxInfo: Server=avs-2, Version=6.0.2.2308539, Antispam-Engine: 2.7.2.2107409, Antispam-Data: 2013.7.8.130327, SenderIP=0.0.0.0
Received: from [192.168.1.129] (24-159-240-219.dhcp.mdsn.wi.charter.com [24.159.240.219]) by smtpauth2.wiscmail.wisc.edu (Oracle Communications Messaging Server 7u4-27.01(7.0.4.27.0) 64bit (built Aug 30 2012)) with ESMTPSA id <0MPM005B5CNQ0D20@smtpauth2.wiscmail.wisc.edu> for webfinger@ietf.org; Mon, 08 Jul 2013 08:11:50 -0500 (CDT)
Message-id: <51DABAC6.4090305@doit.wisc.edu>
Date: Mon, 08 Jul 2013 08:12:38 -0500
From: Jesse Thompson <jesse.thompson@doit.wisc.edu>
User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10.8; rv:17.0) Gecko/20130620 Thunderbird/17.0.7
To: webfinger@ietf.org
References: <F23E5FFF11431C634EC5CA18@caldav.corp.apple.com>
In-reply-to: <F23E5FFF11431C634EC5CA18@caldav.corp.apple.com>
Subject: Re: [webfinger] Automated Service Configuration now uses webfinger
X-BeenThere: webfinger@ietf.org
X-Mailman-Version: 2.1.12
Precedence: list
List-Id: Discussion of the Webfinger protocol proposal in the Applications Area <webfinger.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/webfinger>, <mailto:webfinger-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/webfinger>
List-Post: <mailto:webfinger@ietf.org>
List-Help: <mailto:webfinger-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/webfinger>, <mailto:webfinger-request@ietf.org?subject=subscribe>
X-List-Received-Date: Mon, 08 Jul 2013 13:11:58 -0000

On 7/5/13 9:17 AM, Cyrus Daboo wrote:
> Hi folks,
> I have recently posted a new version of the Automated Service
> Configuration draft (formerly known as Aggregated Service Discovery):
> <https://datatracker.ietf.org/doc/draft-daboo-aggregated-service-discovery/>.
>
>
> This protocol now makes use of webfinger to "bootstrap" discovery of the
> config document. Hopefully it will serve as a useful example of how
> webfinger can be used by specific applications. I would appreciate
> feedback from the webfinger community on how we have gone about using
> webfinger, thanks.

Since "the target FQDN is not in the queried domain" will apply to the 
vast majority of email/calendar domains (hosted by Google, Microsoft, etc):

When it comes to practical implementation, essentially no clients will 
bother to "verify with the user that the link URI target FQDN is 
suitable for use before executing any connections to the host", 
especially if they already have an auto-config scheme that doesn't 
prompt the user (e.g. Thunderbird).

It might be beneficial to the adoption of this standard to bake in a 
method of secure delegation that could work from day one.

Jesse