Return-Path: <ajstein.standards@gmail.com>
X-Original-To: wimse@ietfa.amsl.com
Delivered-To: wimse@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1])
	by ietfa.amsl.com (Postfix) with ESMTP id 61953C1DFD56
	for <wimse@ietfa.amsl.com>; Mon, 12 Aug 2024 20:28:39 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.106
X-Spam-Level: 
X-Spam-Status: No, score=-2.106 tagged_above=-999 required=5
	tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1,
	DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, FREEMAIL_FROM=0.001,
	HTML_MESSAGE=0.001, RCVD_IN_DNSWL_NONE=-0.0001, SPF_HELO_NONE=0.001,
	SPF_PASS=-0.001, T_SCC_BODY_TEXT_LINE=-0.01,
	URIBL_DBL_BLOCKED_OPENDNS=0.001, URIBL_ZEN_BLOCKED_OPENDNS=0.001]
	autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (2048-bit key)
	header.d=gmail.com
Received: from mail.ietf.org ([50.223.129.194])
	by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024)
	with ESMTP id N7Wrh_M59woz for <wimse@ietfa.amsl.com>;
	Mon, 12 Aug 2024 20:28:38 -0700 (PDT)
Received: from mail-il1-x141.google.com (mail-il1-x141.google.com
 [IPv6:2607:f8b0:4864:20::141])
	(using TLSv1.3 with cipher TLS_AES_128_GCM_SHA256 (128/128 bits)
	 key-exchange X25519 server-signature ECDSA (P-256) server-digest SHA256)
	(No client certificate requested)
	by ietfa.amsl.com (Postfix) with ESMTPS id BA355C1DFD53
	for <wimse@ietf.org>; Mon, 12 Aug 2024 20:28:33 -0700 (PDT)
Received: by mail-il1-x141.google.com with SMTP id
 e9e14a558f8ab-39b3c36d247so20802385ab.3
        for <wimse@ietf.org>; Mon, 12 Aug 2024 20:28:33 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed;
        d=gmail.com; s=20230601; t=1723519713; x=1724124513; darn=ietf.org;
        h=cc:to:subject:message-id:date:from:in-reply-to:references
         :mime-version:from:to:cc:subject:date:message-id:reply-to;
        bh=68VKENLPxuNOdIZ0XotleLIy8vQfOZSUbfEGMR0WX9k=;
        b=cRFsqLdv1oqxRq6KABjsD9cJFADYOtw5q+qpePWNrHRG3BZriLq6r4snblqR5cuI6W
         Y1Jwlxz2PScyUdoMGQoLtWX7zXeYdkWuaiB9+pF8MgtxT8lrjLRUj3Ras9Fg2Sqvzqrt
         L728VIso9ZFX8gUxPZww4PwaIPLFkmrSMlXpGOFAq0g6V8zHiUVLh5jAIImTSl3khqc6
         NabpbZJI0jL5B9nAEQJKJ44K5qnY7AITTyQYyypGXFiLbfCmboe/9pLELWNgS32Z1tt8
         xd34qskIccSh7643JNSIPZU4UwxZE3rxMt8TJuxd9sFIT5SG10P1qHLpTjn/f9GKiHZK
         DhJg==
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed;
        d=1e100.net; s=20230601; t=1723519713; x=1724124513;
        h=cc:to:subject:message-id:date:from:in-reply-to:references
         :mime-version:x-gm-message-state:from:to:cc:subject:date:message-id
         :reply-to;
        bh=68VKENLPxuNOdIZ0XotleLIy8vQfOZSUbfEGMR0WX9k=;
        b=ko0+Yx9sGN34VGRw4wO+ky4wM8jSKrv+n0nI3vdhvdFwnVeWLwkbe2Fl2g92Irvacy
         kT4bc78OYzyGvJlkSf+x2yPBL5Zt8Gh0Pep4D46RJDcnzbLPuIsq4ClXS72ShCU+7zb6
         dFh4ErQMPNEwIbmIfiHLpUGsiknsmIYOGBjOUAcGJ7w3OVZacQxnppYuZbnZYRJE8seO
         kBHW1dHpIILYWMJLbqm7qhH6TDOkeqd/oT/oGcf8Xw9FiLQTJ1nDLvg/fZskmJj7hJMo
         0dLpxoxqK/DzonTAB7nnbXdU9lKeMF27ZW+pphtU/hiJE+GtwGCqJ1y4TJU8/g7UxF48
         3ToQ==
X-Forwarded-Encrypted: i=1;
 AJvYcCVbyagHbn4JDO48+6z6c5/gugFT4EohYm01yjuv9upPNFgvQ+s8+0y1BQb6p6J3QD2g8cSOYDJbWCCrXY7X9A==
X-Gm-Message-State: AOJu0YzK7tcXhkG6lfbqV+3d5jP6v64VMdDp7wCsCzkta0R1gshqBltB
	o7KB8erQ2dnH4zE2+5oMEqFqpkGiR9l93L4kFZgmtJ4nDqBBKfmYA6sKrHEx4EhUlawamW95Wyv
	SrA79cw91WOtqby+VLitI/TFXKwo=
X-Google-Smtp-Source: 
 AGHT+IH59elSz+R+vk++F9UeHOBBIWId8zba9klbbIqhz43Iq4p1yKAhTy4FdsstofFyTNrD9X4eMMLgIzPXO6OkqOY=
X-Received: by 2002:a05:6e02:2185:b0:39b:28d1:169b with SMTP id
 e9e14a558f8ab-39c4786413bmr26340145ab.15.1723519712426; Mon, 12 Aug 2024
 20:28:32 -0700 (PDT)
MIME-Version: 1.0
References: <9F066930-20F3-4273-8E2A-8D42B087E668@mit.edu>
 <CAMvBLPK9xwivYV27fqYrJE1zxjxQ-KdT=1wCHEsybGh26HgptQ@mail.gmail.com>
 <DBAPR83MB04374828D370755D268AF23391B72@DBAPR83MB0437.EURPRD83.prod.outlook.com>
In-Reply-To: 
 <DBAPR83MB04374828D370755D268AF23391B72@DBAPR83MB0437.EURPRD83.prod.outlook.com>
From: "A.J. Stein" <ajstein.standards@gmail.com>
Date: Mon, 12 Aug 2024 23:28:21 -0400
Message-ID: 
 <CAMvBLPLsBXwNanqNqcrMYXpzFYXT1PO=cp8j6A6=VT+S6x_N+Q@mail.gmail.com>
To: Pieter Kasselman <pieter.kasselman@microsoft.com>
Content-Type: multipart/alternative; boundary="00000000000039046a061f8834e8"
Message-ID-Hash: CQRQQAB5MPBHU5BBEVI2KDS4BMOEOU6E
X-Message-ID-Hash: CQRQQAB5MPBHU5BBEVI2KDS4BMOEOU6E
X-MailFrom: ajstein.standards@gmail.com
X-Mailman-Rule-Misses: dmarc-mitigation; no-senders; approved; emergency;
 loop; banned-address; member-moderation; nonmember-moderation; administrivia;
 implicit-dest; max-recipients; max-size; news-moderation; no-subject;
 digests; suspicious-header
CC: Justin Richer <jricher@mit.edu>, "wimse@ietf.org" <wimse@ietf.org>
X-Mailman-Version: 3.3.9rc4
Precedence: list
Subject: =?utf-8?q?=5BWimse=5D_Re=3A_Authentication_Levels_for_Workloads?=
List-Id: WIMSE Workload Identity in Multi-Service Environment <wimse.ietf.org>
Archived-At: 
 <https://mailarchive.ietf.org/arch/msg/wimse/_vFQHvi3iXCRIbFKhfwFjPpArH0>
List-Archive: <https://mailarchive.ietf.org/arch/browse/wimse>
List-Help: <mailto:wimse-request@ietf.org?subject=help>
List-Owner: <mailto:wimse-owner@ietf.org>
List-Post: <mailto:wimse@ietf.org>
List-Subscribe: <mailto:wimse-join@ietf.org>
List-Unsubscribe: <mailto:wimse-leave@ietf.org>

--00000000000039046a061f8834e8
Content-Type: text/plain; charset="UTF-8"
Content-Transfer-Encoding: quoted-printable

On Mon, Jul 29, 2024 at 10:33=E2=80=AFAM Pieter Kasselman <
pieter.kasselman@microsoft.com> wrote:

> Thanks A.J.
>
>
>
> Can you say a little more on how you would benefit if such a draft exists=
?
>

First off, I apologize for the late reply.

Re the benefit: I have worked in the public sector in digital services in
the United States where "high assurance" requirements and practices obviate
the need for better clarity here. I appreciate the interest thus far (I
have looked at slides, not yet completed watching the WIMSE session on
YouTube) to compare and contrast to something *akin* to SP 800-63
authenticator levels for workloads. I think that framing helped me quickly
understand and I presume others (even if that comparison is not the only
basis or framing, it will be a starting point for many).

I had not even considered the significance of this gap as it existed in
those environments where authenticating workloads instead of users or the
user identities they proxy until this thread came up. So at least for me, a
standard, interoperable approach for this (especially so it is not just use
whatever the environment's predominant cloud service officers as a customer
mapping or foundational layer) would be helpful to me.

I hope that help explains my support for work in this area.


> Cheers
>
>
>
> Pieter
>
>
>
> *From:* A.J. Stein <ajstein.standards@gmail.com>
> *Sent:* Monday, July 29, 2024 3:25 PM
> *To:* Justin Richer <jricher@mit.edu>
> *Cc:* wimse@ietf.org
> *Subject:* [Wimse] Re: Authentication Levels for Workloads
>
>
>
> You don't often get email from ajstein.standards@gmail.com. Learn why
> this is important <https://aka.ms/LearnAboutSenderIdentification>
>
> On Mon, Jul 29, 2024 at 10:03=E2=80=AFAM Justin Richer <jricher@mit.edu> =
wrote:
>
> In the Vancouver meeting, there was a presentation from Ryan Hurst
> on Authentication Levels for Workloads. While this is not a current WG
> charter item, the energy in the room indicated that it is a topic of
> interest. As such, the chairs would like to encourage conversation on thi=
s
> topic. Please see the presentation slides [1] and recording [2] for more
> information.
>
>
>
> I had missed the WIMSE session and not reviewed the agenda. This
> presentation is informative to me based on the first few minutes, so than=
ks
> for bringing it up.I will now watch the full session later.
>
>
>
> I would also like to encourage the presenters to create an I-D to capture
> their thoughts on this topic to encourage further discussion.
>
>
>
> As one lurker and hardly active contributor, I would benefit from this I-=
D
> if they move forward with it.
>
>
>
> =E2=80=94 Justin and Pieter
>
>
>
> [1]
> https://datatracker.ietf.org/meeting/120/materials/minutes-120-wimse-2024=
07241630-00
>
> [2] https://www.youtube.com/watch?v=3D-BVTXj94wbw
>
> --
> Wimse mailing list -- wimse@ietf.org
> To unsubscribe send an email to wimse-leave@ietf.org
>
>

--00000000000039046a061f8834e8
Content-Type: text/html; charset="UTF-8"
Content-Transfer-Encoding: quoted-printable

<div dir=3D"ltr"><div dir=3D"ltr">On Mon, Jul 29, 2024 at 10:33=E2=80=AFAM =
Pieter Kasselman &lt;<a href=3D"mailto:pieter.kasselman@microsoft.com">piet=
er.kasselman@microsoft.com</a>&gt; wrote:</div><div class=3D"gmail_quote"><=
blockquote class=3D"gmail_quote" style=3D"margin:0px 0px 0px 0.8ex;border-l=
eft:1px solid rgb(204,204,204);padding-left:1ex"><div class=3D"msg-69967588=
37443557439">





<div lang=3D"EN-IE" style=3D"overflow-wrap: break-word;">
<div class=3D"m_-6996758837443557439WordSection1">
<p class=3D"MsoNormal"><span style=3D"font-size:11pt;font-family:&quot;Cali=
bri&quot;,sans-serif">Thanks A.J.<u></u><u></u></span></p>
<p class=3D"MsoNormal"><span style=3D"font-size:11pt;font-family:&quot;Cali=
bri&quot;,sans-serif"><u></u>=C2=A0<u></u></span></p>
<p class=3D"MsoNormal"><span style=3D"font-size:11pt;font-family:&quot;Cali=
bri&quot;,sans-serif">Can you say a little more on how you would benefit if=
 such a draft exists?</span></p></div></div></div></blockquote><div><br></d=
iv><div>First off, I apologize for the late reply.</div><div><br></div><div=
>Re the benefit: I have worked in the public sector in digital services in =
the United States where &quot;high assurance&quot; requirements and practic=
es obviate the need for better clarity here. I appreciate the interest thus=
 far (I have looked at slides, not yet completed watching the WIMSE session=
 on YouTube) to compare and contrast to something <i>akin</i> to SP 800-63 =
authenticator levels for workloads. I think that framing helped me quickly =
understand and I presume others (even if that comparison is not the only ba=
sis or framing, it will be a starting point for many).</div><div><br></div>=
<div>I had not even considered the significance of this gap as it existed i=
n those environments where authenticating workloads instead of users or the=
 user identities they proxy until this thread came up. So at least for me, =
a standard, interoperable approach for this (especially so it is not just u=
se whatever the environment&#39;s predominant cloud service officers as a c=
ustomer mapping or foundational layer) would be helpful to me.</div><div><b=
r></div><div>I hope that help explains my support for work in this area.<br=
></div><div>=C2=A0</div><blockquote class=3D"gmail_quote" style=3D"margin:0=
px 0px 0px 0.8ex;border-left:1px solid rgb(204,204,204);padding-left:1ex"><=
div class=3D"msg-6996758837443557439"><div lang=3D"EN-IE" style=3D"overflow=
-wrap: break-word;"><div class=3D"m_-6996758837443557439WordSection1"><p cl=
ass=3D"MsoNormal"><span style=3D"font-size:11pt;font-family:&quot;Calibri&q=
uot;,sans-serif"><u></u><u></u></span></p><p class=3D"MsoNormal"><span styl=
e=3D"font-size:11pt;font-family:&quot;Calibri&quot;,sans-serif">Cheers<u></=
u><u></u></span></p>
<p class=3D"MsoNormal"><span style=3D"font-size:11pt;font-family:&quot;Cali=
bri&quot;,sans-serif"><u></u>=C2=A0<u></u></span></p>
<p class=3D"MsoNormal"><span style=3D"font-size:11pt;font-family:&quot;Cali=
bri&quot;,sans-serif">Pieter<u></u><u></u></span></p>
<p class=3D"MsoNormal"><span style=3D"font-size:11pt;font-family:&quot;Cali=
bri&quot;,sans-serif"><u></u>=C2=A0<u></u></span></p>
<div>
<div style=3D"border-width:1pt medium medium;border-style:solid none none;b=
order-color:rgb(225,225,225) currentcolor currentcolor;padding:3pt 0cm 0cm"=
>
<p class=3D"MsoNormal"><b><span lang=3D"EN-US" style=3D"font-size:11pt;font=
-family:&quot;Calibri&quot;,sans-serif">From:</span></b><span lang=3D"EN-US=
" style=3D"font-size:11pt;font-family:&quot;Calibri&quot;,sans-serif"> A.J.=
 Stein &lt;<a href=3D"mailto:ajstein.standards@gmail.com" target=3D"_blank"=
>ajstein.standards@gmail.com</a>&gt;
<br>
<b>Sent:</b> Monday, July 29, 2024 3:25 PM<br>
<b>To:</b> Justin Richer &lt;<a href=3D"mailto:jricher@mit.edu" target=3D"_=
blank">jricher@mit.edu</a>&gt;<br>
<b>Cc:</b> <a href=3D"mailto:wimse@ietf.org" target=3D"_blank">wimse@ietf.o=
rg</a><br>
<b>Subject:</b> [Wimse] Re: Authentication Levels for Workloads<u></u><u></=
u></span></p>
</div>
</div>
<p class=3D"MsoNormal"><u></u>=C2=A0<u></u></p>
<table border=3D"0" cellspacing=3D"0" cellpadding=3D"0" align=3D"left" widt=
h=3D"100%" style=3D"width:100%">
<tbody>
<tr>
<td style=3D"background:rgb(166,166,166);padding:5.25pt 1.5pt"></td>
<td width=3D"100%" style=3D"width:100%;background:rgb(234,234,234);padding:=
5.25pt 3.75pt 5.25pt 11.25pt">
<div>
<p class=3D"MsoNormal">
<span style=3D"font-size:9pt;font-family:&quot;Segoe UI&quot;,sans-serif;co=
lor:rgb(33,33,33)">You don&#39;t often get email from
<a href=3D"mailto:ajstein.standards@gmail.com" target=3D"_blank">ajstein.st=
andards@gmail.com</a>. <a href=3D"https://aka.ms/LearnAboutSenderIdentifica=
tion" target=3D"_blank">
Learn why this is important</a><u></u><u></u></span></p>
</div>
</td>
<td width=3D"75" style=3D"width:56.25pt;background:rgb(234,234,234);padding=
:5.25pt 3.75pt">
</td>
</tr>
</tbody>
</table>
<div>
<div>
<div>
<p class=3D"MsoNormal">On Mon, Jul 29, 2024 at 10:03<span style=3D"font-fam=
ily:&quot;Arial&quot;,sans-serif">=E2=80=AF</span>AM Justin Richer &lt;<a h=
ref=3D"mailto:jricher@mit.edu" target=3D"_blank">jricher@mit.edu</a>&gt; wr=
ote:<u></u><u></u></p>
</div>
<div>
<blockquote style=3D"border-width:medium medium medium 1pt;border-style:non=
e none none solid;border-color:currentcolor currentcolor currentcolor rgb(2=
04,204,204);padding:0cm 0cm 0cm 6pt;margin-left:4.8pt;margin-right:0cm">
<div>
<p class=3D"MsoNormal">In the Vancouver meeting, there was a presentation f=
rom Ryan Hurst on=C2=A0Authentication Levels for Workloads. While this is n=
ot a current WG charter item, the energy in the room indicated that it is a=
 topic of interest. As such, the chairs
 would like to encourage conversation on this topic. Please see the present=
ation slides [1] and recording [2] for more information.<u></u><u></u></p>
</div>
</blockquote>
<div>
<p class=3D"MsoNormal"><u></u>=C2=A0<u></u></p>
</div>
<div>
<p class=3D"MsoNormal">I had missed the WIMSE session and not reviewed the =
agenda. This presentation is informative to me based on the first few minut=
es, so thanks for bringing it up.I will now watch the full session later.<u=
></u><u></u></p>
</div>
<div>
<p class=3D"MsoNormal">=C2=A0<u></u><u></u></p>
</div>
<blockquote style=3D"border-width:medium medium medium 1pt;border-style:non=
e none none solid;border-color:currentcolor currentcolor currentcolor rgb(2=
04,204,204);padding:0cm 0cm 0cm 6pt;margin-left:4.8pt;margin-right:0cm">
<div>
<div>
<p class=3D"MsoNormal">I would also like to encourage the presenters to cre=
ate an I-D to capture their thoughts on this topic to encourage further dis=
cussion.<u></u><u></u></p>
</div>
</div>
</blockquote>
<div>
<p class=3D"MsoNormal"><u></u>=C2=A0<u></u></p>
</div>
<div>
<p class=3D"MsoNormal">As one lurker and hardly active contributor, I would=
 benefit from this I-D if they move forward with it.<u></u><u></u></p>
</div>
<div>
<p class=3D"MsoNormal">=C2=A0<u></u><u></u></p>
</div>
<blockquote style=3D"border-width:medium medium medium 1pt;border-style:non=
e none none solid;border-color:currentcolor currentcolor currentcolor rgb(2=
04,204,204);padding:0cm 0cm 0cm 6pt;margin-left:4.8pt;margin-right:0cm">
<div>
<div>
<div>
<div>
<p class=3D"MsoNormal"><span style=3D"font-size:9pt;font-family:&quot;Helve=
tica&quot;,sans-serif;color:black">=E2=80=94 Justin and Pieter<u></u><u></u=
></span></p>
</div>
</div>
<p class=3D"MsoNormal"><u></u>=C2=A0<u></u></p>
</div>
<div>
<p class=3D"MsoNormal">[1]=C2=A0<a href=3D"https://datatracker.ietf.org/mee=
ting/120/materials/minutes-120-wimse-202407241630-00" target=3D"_blank">htt=
ps://datatracker.ietf.org/meeting/120/materials/minutes-120-wimse-202407241=
630-00</a><u></u><u></u></p>
</div>
<div>
<p class=3D"MsoNormal">[2]=C2=A0<a href=3D"https://www.youtube.com/watch?v=
=3D-BVTXj94wbw" target=3D"_blank">https://www.youtube.com/watch?v=3D-BVTXj9=
4wbw</a><u></u><u></u></p>
</div>
</div>
<p class=3D"MsoNormal">-- <br>
Wimse mailing list -- <a href=3D"mailto:wimse@ietf.org" target=3D"_blank">w=
imse@ietf.org</a><br>
To unsubscribe send an email to <a href=3D"mailto:wimse-leave@ietf.org" tar=
get=3D"_blank">
wimse-leave@ietf.org</a><u></u><u></u></p>
</blockquote>
</div>
</div>
</div>
</div>
</div>

</div></blockquote></div></div>

--00000000000039046a061f8834e8--

