[Wimse] Re: Token Exchange design team update
"Saxe, Dean" <deansaxe@amazon.com> Thu, 13 June 2024 18:03 UTC
Return-Path: <prvs=88783d612=deansaxe@amazon.com>
X-Original-To: wimse@ietfa.amsl.com
Delivered-To: wimse@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 2C406C1CAE81 for <wimse@ietfa.amsl.com>; Thu, 13 Jun 2024 11:03:02 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -4.402
X-Spam-Level:
X-Spam-Status: No, score=-4.402 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIMWL_WL_HIGH=-0.001, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, HTML_MESSAGE=0.001, RCVD_IN_DNSWL_MED=-2.3, RCVD_IN_MSPIKE_H4=0.001, RCVD_IN_MSPIKE_WL=0.001, RCVD_IN_ZEN_BLOCKED_OPENDNS=0.001, SPF_HELO_NONE=0.001, SPF_NONE=0.001, T_SCC_BODY_TEXT_LINE=-0.01, UNPARSEABLE_RELAY=0.001, URIBL_DBL_BLOCKED_OPENDNS=0.001, URIBL_ZEN_BLOCKED_OPENDNS=0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (1024-bit key) header.d=amazon.com
Received: from mail.ietf.org ([50.223.129.194]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id mZbEV8rm7FTo for <wimse@ietfa.amsl.com>; Thu, 13 Jun 2024 11:02:58 -0700 (PDT)
Received: from smtp-fw-80007.amazon.com (smtp-fw-80007.amazon.com [99.78.197.218]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 73EBEC14F747 for <wimse@ietf.org>; Thu, 13 Jun 2024 11:02:58 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=amazon.com; i=@amazon.com; q=dns/txt; s=amazon201209; t=1718301778; x=1749837778; h=from:to:date:message-id:references:in-reply-to: mime-version:subject; bh=ffcsEFuT/CQwZzRWVQxKWo3M7xDKpBS9Om4kz/0u7tU=; b=H+U+JOFPRLH1nil+pCuUPEfIdvSB0g0w2cihRM3Pa8iJtpdJFlM2byqa /pgVQAeMtHp1T5gNMF1GUJd/+Ge4wwKywNOFDWHcxrLcgQG/5mgLqeFPF OYGxM7EWriZ8EyQA97ETDTzi5aYXSTJbvhvyNe8yWTdv6zX4ELJA8Rg3F c=;
X-IronPort-AV: E=Sophos;i="6.08,235,1712620800"; d="scan'208,217";a="303239061"
Thread-Topic: [Wimse] Token Exchange design team update
Received: from pdx4-co-svc-p1-lb2-vlan2.amazon.com (HELO smtpout.prod.us-west-2.prod.farcaster.email.amazon.dev) ([10.25.36.210]) by smtp-border-fw-80007.pdx80.corp.amazon.com with ESMTP/TLS/ECDHE-RSA-AES256-GCM-SHA384; 13 Jun 2024 18:02:58 +0000
Received: from EX19MTAUWC002.ant.amazon.com [10.0.38.20:6539] by smtpin.naws.us-west-2.prod.farcaster.email.amazon.dev [10.0.35.14:2525] with esmtp (Farcaster) id c5aa9bca-dc4e-4f47-bfa6-ed183c4343ea; Thu, 13 Jun 2024 18:02:57 +0000 (UTC)
X-Farcaster-Flow-ID: c5aa9bca-dc4e-4f47-bfa6-ed183c4343ea
Received: from EX19D003UWC002.ant.amazon.com (10.13.138.169) by EX19MTAUWC002.ant.amazon.com (10.250.64.143) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.2.1258.34; Thu, 13 Jun 2024 18:02:57 +0000
Received: from EX19D003UWC004.ant.amazon.com (10.13.138.150) by EX19D003UWC002.ant.amazon.com (10.13.138.169) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_128_CBC_SHA) id 15.2.1258.34; Thu, 13 Jun 2024 18:02:57 +0000
Received: from EX19D003UWC004.ant.amazon.com ([fe80::38e:f9f6:c9f7:63fa]) by EX19D003UWC004.ant.amazon.com ([fe80::38e:f9f6:c9f7:63fa%4]) with mapi id 15.02.1258.034; Thu, 13 Jun 2024 18:02:57 +0000
From: "Saxe, Dean" <deansaxe@amazon.com>
To: "wimse@ietf.org" <wimse@ietf.org>
Thread-Index: AQHavB/CD6LyNb5Btk+sxHL9/+Mq07HFij0A
Date: Thu, 13 Jun 2024 18:02:57 +0000
Message-ID: <A6CC88F8-D289-4AA7-8F75-519EEEEFC9CD@amazon.com>
References: <CAMtubr2c=c=pE5xV4f1N84y8ACAk98nvf7=F1CCwp3PaQMU_bw@mail.gmail.com>
In-Reply-To: <CAMtubr2c=c=pE5xV4f1N84y8ACAk98nvf7=F1CCwp3PaQMU_bw@mail.gmail.com>
Accept-Language: en-US
Content-Language: en-US
X-MS-Has-Attach:
X-MS-TNEF-Correlator:
user-agent: Microsoft-MacOutlook/16.85.24051916
x-originating-ip: [10.187.171.60]
Content-Type: multipart/alternative; boundary="_000_A6CC88F8D2894AA78F75519EEEEFC9CDamazoncom_"
MIME-Version: 1.0
Message-ID-Hash: FYWUFG6ATMTSKDPQX3GPGJXO5YAVWNTI
X-Message-ID-Hash: FYWUFG6ATMTSKDPQX3GPGJXO5YAVWNTI
X-MailFrom: prvs=88783d612=deansaxe@amazon.com
X-Mailman-Rule-Misses: dmarc-mitigation; no-senders; approved; emergency; loop; banned-address; member-moderation; nonmember-moderation; administrivia; implicit-dest; max-recipients; max-size; news-moderation; no-subject; digests; suspicious-header
X-Mailman-Version: 3.3.9rc4
Precedence: list
Subject: [Wimse] Re: Token Exchange design team update
List-Id: WIMSE Workload Identity in Multi-Service Environment <wimse.ietf.org>
Archived-At: <https://mailarchive.ietf.org/arch/msg/wimse/TBBMf992TpP2Qe2_eQvT0leAA7I>
List-Archive: <https://mailarchive.ietf.org/arch/browse/wimse>
List-Help: <mailto:wimse-request@ietf.org?subject=help>
List-Owner: <mailto:wimse-owner@ietf.org>
List-Post: <mailto:wimse@ietf.org>
List-Subscribe: <mailto:wimse-join@ietf.org>
List-Unsubscribe: <mailto:wimse-leave@ietf.org>
Thank you for the update, Yaroslav. I apologize for the delay in my own update, I was out of the office for a few days. Following up on the note below, the design team has not yet achieved consensus, but we have had good discussions that helped us set a direction. The team identified a set of eight requirements for a token translation mechanism: * Token Format Change * Token Encoding Change * Changes to Cryptographic Properties of the Token * Embedding One Token in Another * Change of Embedded Context in Token * Change of Validity Constraint of the Token * Changing or Adding Subjects of the Token * Adding Sender Constraint to the Token Second, we have come to the conclusion that token exchange has a distinct meaning due to the use of the term in RFC 8693<https://datatracker.ietf.org/doc/html/rfc8693>. Recognizing that WIMSE is broader than OAuth 2.0 and that there may be exchanges that are lossy between different token types, we have embraced the idea of “token translation” as a term to express that there may be information “lost in translation” in such exchanges. Where WIMSE can use the existing mechanisms in RFC 8693, we will continue to refer to that as “token exchange”. In my opinion, token translation is a superset which includes the existing OAuth Token Exchange protocol. I look forward to broader discussion on this idea with the WIMSE WG. We have two documents in progress as noted in Yaroslav’s note. First, is the requirements and use cases found at https://github.com/yaroslavros/wimse-tokentranslation-requirements. Second, there’s a repository for the WIMSE Token Exchange and Translation draft available at https://github.com/dhs-aws/wimse-token-exch-design-team. I look forward to your feedback as we continue to work on the drafts in preparation for IETF120. Thanks to my partners in the design team, Yaroslav Rosomakho, George Fletcher, Andrii Deinega, and Dmitry Izumskiy, I look forward to continuing to work together. As well, thank you to the WIMSE WG chairs, Justin Richer and Pieter Kasselman, for their guidance over the past ~8 weeks. -dhs -- Dean H. Saxe, CIDPRO<https://idpro.org/cidpro/> (he/him) Senior Security Engineer, AWS Identity Security Team | Amazon Web Services (AWS) E: deansaxe@amazon.com<mailto:deansaxe@amazon.com> | M: 206-659-7293<tel:206-659-7293> From: Yaroslav Rosomakho <yrosomakho=40zscaler.com@dmarc.ietf.org> Date: Tuesday, June 11, 2024 at 9:52 AM To: "wimse@ietf.org" <wimse@ietf.org> Subject: [EXTERNAL] [Wimse] Token Exchange design team update CAUTION: This email originated from outside of the organization. Do not click links or open attachments unless you can confirm the sender and know the content is safe. Dear working group, After many weekly meetings, the Token Exchange design team is progressing on two documents: Token Translation Requirements and Token Translation Abstract and Introduction. The repository for requirements document is now public and available at https://github.com/yaroslavros/wimse-tokentranslation-requirements. We are still actively working on this document and plan to submit the first draft by July 8th. Looking forward to feedback and suggestions on the list or via GitHub issues. Abstract and Introduction document repo will be shared shortly. Thanks! Best Regards, Yaroslav on behalf of Andrii, Dean, Dmitry and George
- [Wimse] Token Exchange design team update Yaroslav Rosomakho
- [Wimse] Re: Token Exchange design team update Saxe, Dean
- [Wimse] Re: Token Exchange design team update John Kemp
- [Wimse] Re: Token Exchange design team update Saxe, Dean
- [Wimse] Re: Token Exchange design team update Evan Gilman