[WIMSE] Re: I-D Action: draft-ietf-wimse-http-signature-05.txt
Yaron Sheffer <yaronf.ietf@gmail.com> Tue, 21 July 2026 20:54 UTC
Return-Path: <yaronf.ietf@gmail.com>
X-Original-To: wimse@mail2.ietf.org
Delivered-To: wimse@mail2.ietf.org
Received: from localhost (localhost [127.0.0.1]) by mail2.ietf.org (Postfix) with ESMTP id 7325111BB88BB for <wimse@mail2.ietf.org>; Tue, 21 Jul 2026 13:54:01 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=ietf.org; s=ietf1; t=1784667241; bh=c8aWCUzCQj2zLEUj7Id5BoHuFqy9Tg+rx1vP9jJCxIQ=; h=Date:Subject:To:Cc:References:From:In-Reply-To; b=yX87XxwzfXK50cJ4vbIS975qL/vt4ioGS6jN/uBvtf6Khlqdt1ALLtTpaBzBhokzB Xnyv6+8D2bF0wq+raMMYsOmqvnyyOYBgrbtP25VpleORPtEq/+GokLyXNoRCsVABRR s0qX+Sk9rr8dGP/3j/y+loEF3hAcMQug512tzVlU=
X-Virus-Scanned: amavisd-new at ietf.org
X-Spam-Flag: NO
X-Spam-Score: -1.988
X-Spam-Level:
X-Spam-Status: No, score=-1.988 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, FREEMAIL_FROM=0.001, HTML_MESSAGE=0.001, MIME_HTML_ONLY=0.1, RCVD_IN_DNSWL_NONE=-0.0001, SPF_HELO_NONE=0.001, SPF_PASS=-0.001, T_KAM_HTML_FONT_INVALID=0.01] autolearn=ham autolearn_force=no
Authentication-Results: mail2.ietf.org (amavisd-new); dkim=pass (2048-bit key) header.d=gmail.com
Received: from mail2.ietf.org ([166.84.6.31]) by localhost (mail2.ietf.org [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id ioERfBB3y9u9 for <wimse@mail2.ietf.org>; Tue, 21 Jul 2026 13:54:00 -0700 (PDT)
Received: from mail-wm1-x333.google.com (mail-wm1-x333.google.com [IPv6:2a00:1450:4864:20::333]) (using TLSv1.3 with cipher TLS_AES_128_GCM_SHA256 (128/128 bits) key-exchange X25519 server-signature ECDSA (P-256) server-digest SHA256) (No client certificate requested) by mail2.ietf.org (Postfix) with ESMTPS id 9C6C511BB88B2 for <wimse@ietf.org>; Tue, 21 Jul 2026 13:54:00 -0700 (PDT)
Received: by mail-wm1-x333.google.com with SMTP id 5b1f17b1804b1-4954f5e8020so17853835e9.2 for <wimse@ietf.org>; Tue, 21 Jul 2026 13:54:00 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20251104; t=1784667240; x=1785272040; darn=ietf.org; h=content-transfer-encoding:content-type:in-reply-to:from :content-language:references:cc:to:subject:user-agent:mime-version :date:message-id:from:to:cc:subject:date:message-id:reply-to :content-type; bh=umkWVOPej2lANoIDOtNjnRqt5gKnplkQ7nxfbg+iGoQ=; b=ncKISzIiuKQHFLZgRt5B7YRKgtcN8VgoYDDkGdnQtA/9saMFOuFfrm1LF88i6B9NHY bBOMe2NmhfK83cD3/cJu7+9nxRJpYGw6BqUyKeDE8R0FRufYm718QUI6rMU0IsfRplmY LuAESDeHYsk3b8o2kQSuvYPMQ6GFrR3G++tDavCoAGAkWlwm3e0CDHPJn6SkeBzjfY8Z wiV6WODho/yp1CKcbud14FVaqfhoRtPV59DshGCjtHhbKRtCGfEtYNwvZ9t15uycUAbs t/AGXsqvl5GTEIvGStdJ4vMrVjexWnX5tf7iNzde9wDXEYKMumwV05lqbPGKvzxbbziQ FYLA==
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1784667240; x=1785272040; h=content-transfer-encoding:content-type:in-reply-to:from :content-language:references:cc:to:subject:user-agent:mime-version :date:message-id:x-gm-gg:x-gm-message-state:from:to:cc:subject:date :message-id:reply-to:content-type; bh=umkWVOPej2lANoIDOtNjnRqt5gKnplkQ7nxfbg+iGoQ=; b=Wl6H0SSyNRJUqDEZ/YJH8v6FV4M8Uo0c1FKvJmG01ZRk5k7k6EUOjSwsVmEiERSFYs u3c3mawxP2grWgFnmEhXANZIM1On0tRuhZQ5LeskMUUJzUTuy5gTFFinxntU0Lm1iJUU AY6pUaTtOxJGE+Tigdhj0rlpvqad91iOqyJ0qWsBt6dRDGQ9GLz0Ue+VLjoWyj+d00WY 3vYAYWF6WUftfUInOmAfvvj3CGho7ZpE2m+5wMhT/umfFWBgYmqtPeKksWQW9uKc78+8 4p+esyDn8IRLN6qdZv1rU7PdrJnsFWXKvmyx68A2GIkwc9FVu7rMCh3b41XHuucWFrBD 6fBg==
X-Gm-Message-State: AOJu0YzumDMUuYtvjqGYJr/2g1Nvtbr9i+Lnnp8RyKgZiFTM7MhN5ha6 jPgMSii5V9PEytX5o52ceMKwFzKbI4xhOoOBeYUlvDASUAJ1W4wgtt3xIrHHQQ==
X-Gm-Gg: AfdE7cmPEgMnb9PvKAP1OuJy3YKQMC1ZiHlSQ8n3QEU8J5OPZd6omF3NDhKBcgTMzkb rBpfvN9vM6dLKEm/6QRS5ISRrtklKHvdqPMZUHnfYIy2VQ0sEzomMbsxXztnmpNFDApZ1Jk+Bcd PIFjkbrAgBJwjTlZArKbDmvU338z1bIhUWkoNOT9gMllhekPmdIA6sgOuiyLcNLTdqQU7vpEGIn 8Nggud0tQus5DU2l28eVvDRHz2B9aQah7imvGEkycfdgsz6qziR4Hs4IhLfJAHZzl3VbuHdEsGr dtw5JfwYxRqv23Zm1l2oxrdHLM8UD5eUvpQGM8NVCSaj2dkP69mbZM3UKHCZWVAo681fe9h3J8o VAWS3b4dqjtrHNbSoccFUG4gF/FIbpEQr2CvWjRS2oyQDSQC+FE5b40Oielgbhn5f7qqZQbJzME MBV+wQeYa7D9DI3WSDYcw63BitzGC06a2c2otTHvLSzUyT6g1YYxyxVPs=
X-Received: by 2002:a05:600c:19c9:b0:495:665d:75df with SMTP id 5b1f17b1804b1-495665d8542mr54069305e9.23.1784667239462; Tue, 21 Jul 2026 13:53:59 -0700 (PDT)
Received: from [10.10.10.82] (83-64-94-118.static.upcbusiness.at. [83.64.94.118]) by smtp.gmail.com with ESMTPSA id 5b1f17b1804b1-4956b030a64sm5688995e9.3.2026.07.21.13.53.58 (version=TLS1_3 cipher=TLS_AES_128_GCM_SHA256 bits=128/128); Tue, 21 Jul 2026 13:53:58 -0700 (PDT)
Message-ID: <26cdf490-a01f-4540-a676-7f6d3c9c1b67@gmail.com>
Date: Tue, 21 Jul 2026 22:53:57 +0200
MIME-Version: 1.0
User-Agent: Betterbird (Windows)
To: Andrii Deinega <andrii.deinega@gmail.com>
References: <178453791135.190016.4758518598328392880@dt-datatracker-d4d6ff9d9-ql5mb> <6adf3a04-367c-48b4-8c12-eaecc2fc7e83@gmail.com> <CALkShcuomnHSYB3P4881B540i=Fx1tBS1K3bgOwvDhDOjiXBYA@mail.gmail.com>
Content-Language: en-US
From: Yaron Sheffer <yaronf.ietf@gmail.com>
In-Reply-To: <CALkShcuomnHSYB3P4881B540i=Fx1tBS1K3bgOwvDhDOjiXBYA@mail.gmail.com>
Content-Type: text/html; charset="UTF-8"
Content-Transfer-Encoding: 8bit
Message-ID-Hash: N6XOWNC3HP4WWZDPJBZSNETXE2SR2ERL
X-Message-ID-Hash: N6XOWNC3HP4WWZDPJBZSNETXE2SR2ERL
X-MailFrom: yaronf.ietf@gmail.com
X-Mailman-Rule-Misses: dmarc-mitigation; no-senders; approved; emergency; loop; banned-address; member-moderation; nonmember-moderation; administrivia; implicit-dest; max-recipients; max-size; news-moderation; no-subject; digests; suspicious-header
CC: wimse@ietf.org
X-Mailman-Version: 3.3.9rc6
Precedence: list
Subject: [WIMSE] Re: I-D Action: draft-ietf-wimse-http-signature-05.txt
List-Id: WIMSE Workload Identity in Multi-Service Environment <wimse.ietf.org>
Archived-At: <https://mailarchive.ietf.org/arch/msg/wimse/Sv6K4mN5VfBE0reEFxU5emPu1E0>
List-Archive: <https://mailarchive.ietf.org/arch/browse/wimse>
List-Help: <mailto:wimse-request@ietf.org?subject=help>
List-Owner: <mailto:wimse-owner@ietf.org>
List-Post: <mailto:wimse@ietf.org>
List-Subscribe: <mailto:wimse-join@ietf.org>
List-Unsubscribe: <mailto:wimse-leave@ietf.org>
Hi Andrii,
I'm not sure I'm following. Both the WPT solution and the HTTP-Sig solution are end-to-end. So if there's information that an intermediary can legitimately strip away, then it CANNOT be covered by either mechanism. What am I missing?
Thanks,
Yaron
Hi Yaron,
Have there been any discussions or maybe, even proposals within the WIMSE WG regarding passing additional information along with WITs, somewhat similar to the https://opentelemetry.io/docs/specs/otel/baggage/api/" rel="nofollow">OpenTelemetry (OTel) Baggage API and the https://www.w3.org/TR/baggage/" rel="nofollow">W3C Baggage specification?
Of course, I mean passing (additional) information in some standardized way that makes sense for workloads + makes sense when HTTP Signatures are in "use".
A few examples where it could be useful?
- Workload1 wants to share additional information to Workload2 (this info isn't included in its WIT)
- Intermediary1 wants to strip some info from a call from Workload1 to Workload2 (say information about its instance that Workload2 doesn't need to see)
- Intermediary2 wants to add some info from a call from Workload1 to Workload2
I recall some discussions took place in other WGs like "wouldn't it be great if we could attach some attribute to an issued AT and then be able to cryptographically validate that".
A combination of HTTP Signatures, SD (Selective Disclosures), a WIT + the private key associated with this WIT seems like allowing doing that in my eyes.
Thank you.
Best regards,
Andrii
--This version updates the sample signed messages, in line with the latest normative text.
Thanks,
Joe and Yaron
Internet-Draft draft-ietf-wimse-http-signature-05.txt is now available. It is a work item of the Workload Identity in Multi System Environments (WIMSE) WG of the IETF. Title: WIMSE Workload-to-Workload Authentication with HTTP Signatures Authors: Joe Salowey Yaron Sheffer Name: draft-ietf-wimse-http-signature-05.txt Pages: 21 Dates: 2026-07-20 Abstract: The WIMSE architecture defines authentication and authorization for software workloads in a variety of runtime environments, from the most basic ones to complex multi-service, multi-cloud, multi-tenant deployments. This document defines one of the mechanisms to provide workload authentication, using HTTP Signatures. While only applicable to HTTP traffic, the protocol provides end-to-end protection of requests (and optionally, responses), even when service traffic is not end-to-end encrypted, that is, when TLS proxies and load balancers are used. Authentication is based on the Workload Identity Token (WIT). The IETF datatracker status page for this Internet-Draft is: https://datatracker.ietf.org/doc/draft-ietf-wimse-http-signature/" target="_blank" class="moz-txt-link-freetext" rel="nofollow">https://datatracker.ietf.org/doc/draft-ietf-wimse-http-signature/ There is also an HTML version available at: https://www.ietf.org/archive/id/draft-ietf-wimse-http-signature-05.html" target="_blank" class="moz-txt-link-freetext" rel="nofollow">https://www.ietf.org/archive/id/draft-ietf-wimse-http-signature-05.html A diff from the previous version is available at: https://author-tools.ietf.org/iddiff?url2=draft-ietf-wimse-http-signature-05" target="_blank" class="moz-txt-link-freetext" rel="nofollow">https://author-tools.ietf.org/iddiff?url2=draft-ietf-wimse-http-signature-05 Internet-Drafts are also available by rsync at: rsync.ietf.org::internet-drafts
WIMSE mailing list -- wimse@ietf.org
To unsubscribe send an email to wimse-leave@ietf.org
- [WIMSE] I-D Action: draft-ietf-wimse-http-signatu… internet-drafts
- [WIMSE] Re: I-D Action: draft-ietf-wimse-http-sig… Yaron Sheffer
- [WIMSE] Re: I-D Action: draft-ietf-wimse-http-sig… Andrii Deinega
- [WIMSE] Re: I-D Action: draft-ietf-wimse-http-sig… Yaron Sheffer
- [WIMSE] Re: I-D Action: draft-ietf-wimse-http-sig… Andrii Deinega
- [WIMSE] Re: I-D Action: draft-ietf-wimse-http-sig… Yaron Sheffer
- [WIMSE] Re: I-D Action: draft-ietf-wimse-http-sig… Jaryn Sabey