[Wimse] Re: Request for Input: Best Current Practice for OAuth 2.0 Client Authentication in Workload Environments

"Flemming Andreasen (fandreas)" <fandreas@cisco.com> Mon, 29 July 2024 22:17 UTC

Return-Path: <fandreas@cisco.com>
X-Original-To: wimse@ietfa.amsl.com
Delivered-To: wimse@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 9DD1EC15107C for <wimse@ietfa.amsl.com>; Mon, 29 Jul 2024 15:17:26 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -9.741
X-Spam-Level:
X-Spam-Status: No, score=-9.741 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIMWL_WL_HIGH=-0.148, DKIMWL_WL_MED=-0.001, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, HTML_MESSAGE=0.001, RCVD_IN_DNSWL_NONE=-0.0001, RCVD_IN_MSPIKE_H3=0.001, RCVD_IN_MSPIKE_WL=0.001, RCVD_IN_ZEN_BLOCKED_OPENDNS=0.001, SPF_NONE=0.001, T_SCC_BODY_TEXT_LINE=-0.01, T_SPF_HELO_PERMERROR=0.01, URIBL_BLOCKED=0.001, URIBL_DBL_BLOCKED_OPENDNS=0.001, URIBL_ZEN_BLOCKED_OPENDNS=0.001, USER_IN_DEF_DKIM_WL=-7.5] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (1024-bit key) header.d=cisco.com
Received: from mail.ietf.org ([50.223.129.194]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id vIazjZmMaARQ for <wimse@ietfa.amsl.com>; Mon, 29 Jul 2024 15:17:22 -0700 (PDT)
Received: from rcdn-iport-4.cisco.com (rcdn-iport-4.cisco.com [173.37.86.75]) (using TLSv1.2 with cipher ECDHE-ECDSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 65867C151092 for <wimse@ietf.org>; Mon, 29 Jul 2024 15:17:22 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=cisco.com; i=@cisco.com; l=9785; q=dns/txt; s=iport; t=1722291442; x=1723501042; h=from:to:subject:date:message-id:references:in-reply-to: mime-version; bh=X9SOs6Mj7yAEB/7dVqS1r7nOfM14jJYyhQzrxBkkoR8=; b=H/lho+QPGqXL02ILt64E5meZDbQKQer27HSu5Le1QB2uRwUrmRxpXEKn M2prQugIzsQuk+KUgocEp6FQQRk+q2FuWqFUj3QQnt7Wy8yLV9lNMZp15 4/t5T+rJW4IzMZXavaQRzxB9wo8FDIxHNQSjUSEB6GQBOCRiBORdN7E1B A=;
X-CSE-ConnectionGUID: YsorroKhRHmpH204jMZLwA==
X-CSE-MsgGUID: UkPQ1aZ4RpCZk1EBc6Ni1Q==
X-IPAS-Result: A0DyAABaFKhmmJtdJa1RCQ4QAQELEgxlgR8LgUExUnoCgRyFHYNMA4Uthk+BdS2RSIV3hlWBfg8BAQENAQE7CQQBAYUGAhaJKAImNAkOAQIEAQEBAQMCAwEBAQEBAQEBAQUBAQUBAQECAQcFFAEBAQEBAQEBNwVJhXUNhl4CAQMSEQpcAgEIOwcCAgIvJQEBBAEUAQEegl4BghxIAwEQnzABgUACiih6gTKBAYNsQdtqBoFIiD0BKIExAgKEMIRHJxuBSUSBFSeCUjE+axoBgVsBAQOBMYQHgmkEihtBgUyCJoEkghYFBw+CD4EchE6DBnwmS401UnUiAyYzIQIRAVUTFwsJBYlMCoJ9BSEEgW4mgQsXdoIBdj8VgQgCglqBawxhhECDMmKBD4E+gV8BSYEXgV8wGyQLgjOBBRweFYEwST89HUACAQttPRQhBgMLGwaiPAQvAYQzIwMEUyJEbhYYB5c4izijXQqEFYwUlSoGDwQvhAWNAJhVZESDD4c3jWQijVmVGQIWNIUJAgQCBAUCDwEBBoFnOoFbcBU7gjMBNFEZD444Ah+IVoogvA+BMwIHAQoBAQMJimoBAQ
IronPort-PHdr: A9a23:Shv8+RfuWY2P0Yn/rgOuUog2lGM/gIqcDmcuAtIPgrZKdOGk55v9e RCZ7vR2h1iPVoLeuLpIiOvT5rjpQndIoY2Av3YLbIFWWlcbhN8XkQ0tDI/NCUDyIPPwKS1vN M9DT1RiuXq8NCBo
IronPort-Data: A9a23:p31S+6iJluSec2oNY3YtKyFJX161ahAKZh0ujC45NGQN5FlHY01je htvCDvSOfeDa2Sjet9zPIm+8xgP7ZTVmNUyHgI+pS9mH3hjpJueD7x1DKtf0wB+jyHnZBg6h ynLQoCYdKjYdleF+1HwdOGn9SQhvU2xbuKUIPbePSxsThNTRi4kiBZy88Y0mYcAbeKRW2thg vus5ZWOULOZ82QsaD5MtPjS8EkHUMna4Vv0gHRvPZing3eG/5UlJMp3Db28KXL+Xr5VEoaSL 87fzKu093/u5BwkDNWoiN7TKiXmlZaLYGBiIlIPM0STqkAqSh4ai87XB9JAAatjsAhlqvgqo Dl7WTNcfi9yVkHEsLx1vxC1iEiSN4UekFPMCSDXXcB+UyQqflO0q8iCAn3aMqUp4eFtG2Zt9 cY4LSgtNEjfhceE5K2SH7wEasQLdKEHPasFsX1miDreF/tjHdbIQr7B4plT2zJYasJmRKmFI ZFGL2s0Kk2dPnWjOX9PYH46tOmhgHXlfjRDgFmUvqEwpWPUyWSd1ZC3a4aLJYfVFZo9ckCwm 2H+xj3wME0gLPetymOo2HnyoO6WpHauMG4VPOblrqEx2gL7KnYoIAIXUEC2ifi0lkD4XMhQQ 3H44QI0pqQ0sUesVNS4A1uzoWWPuVgXXN84//AGBB+l+7HT+RyeJWg+bjtZSIZ+6M0Tdxg1/ wrc9z/2PgBHvLqQQHOb076bqzKuJCQYRVPugwdaEGPpBPG9/OkOYgLzczp1LEKiYjTI9dzY2 TuGqm01gK8eyJJN3KSg9leBiDWpznQocuLXzluJNo5GxlolDGJAW2BOwQOChRqnBN3CJmRtR FBex6CjABkmVPlhbhClTuQXB62O7P2YKjDailMHN8B+rW71oCb5INkKvm0WyKJV3iAsJGOBj Kj75FM52XOvFCHxBUOKS9vrUp1xnPKI+SrNCq+NMIYmjmdNmP+vp3w2OhXKgAgBYWAnkLo0P t+AYN2wAHMBQaVhx3zeegvu+eFD+8zK/kuKHcqT503+idK2PSfFIZ9bawHmRr5is8u5TPD9r ow32z2ikUsPCYUTo0D/rOYuELz9BSNnVMmr95MNKbTrz8gPMDhJNsI9CIgJIuRNt69UjezPu Hq6XydlJJDX3BUr9S3ihqhfVY7S
IronPort-HdrOrdr: A9a23:7v8iOKHe3/MiBYFlpLqFoZLXdLJyesId70hD6qkvc203TiXIra CTdaogtCMc0AxhJ03I+ertBEDyewKjyXcV2/hcAV7MZnichILFFvAH0WKm+UydJ8SczJ8T6U 4DSdkFNDSYNzET5qiKgnjcLz9j+qj7zEnCv5a5854Zd3ATV0gW1XYBNu/0KDwQeCB2QbACON 634M1BqzC8eXIRQPiaKxA+NdTrlpngrr6jRQQJKSIGxWC14A9A7oSULzGomjMlFx9fy7Yr9m bI1ybj4L+4jv29whjAk0fO8pV/grLau5p+Lf3JrvJQBiTniw6uaogkcaaFpioJrOam70tvuM XQoi0nI9945xrqDyGISFrWqkrdOQQVmjrfIGyj8D/eSAvCNXUH4v969MBkm93imgwdVZ9Hof t2Nimixutq5Fv77VTADp7zJl9Xfo7emwt4rQbV5EYvCbf3ItVq3P8i1VIQH5EaEC3g7oc7VO FoEcHH/f5TNUiXdnbDowBUsZeRt1kIb167q3I5y4So+ikTmGo8w1oTxcQZkHtF/JUhS4Nc7+ CBNqhzjrlBQsIfcKo4XY46MIaKI32IRQiJPHOZIFzhGq1CM3XRq4Tv6LFw4O2xYpQHwJY7hZ yEWlJFsmw5fV7oFKS1rdd22wGIRH/4USXmy8lY6ZQ8srrgRKDzOSnGU1wqm9vImYRoPiQaYY fFBHt7OY6WEYK1I/c64+TXYegmFUUj
X-Talos-CUID: 9a23:rReB8G82+Q7i9iONoNSVv38PHdo/dV7d9lfVO2/iUTprbY+xVnbFrQ==
X-Talos-MUID: 9a23:MeAVcgW7Q2QZOE7q/ALvvAg7PfU02byFOkNUvL8N5e+FbBUlbg==
X-IronPort-Anti-Spam-Filtered: true
Received: from rcdn-core-4.cisco.com ([173.37.93.155]) by rcdn-iport-4.cisco.com with ESMTP/TLS/ECDHE-RSA-AES256-GCM-SHA384; 29 Jul 2024 22:17:21 +0000
Received: from alln-opgw-4.cisco.com (alln-opgw-4.cisco.com [173.37.147.252]) by rcdn-core-4.cisco.com (8.15.2/8.15.2) with ESMTPS id 46TMHLlT008776 (version=TLSv1.2 cipher=DHE-RSA-AES256-GCM-SHA384 bits=256 verify=OK) for <wimse@ietf.org>; Mon, 29 Jul 2024 22:17:21 GMT
X-CSE-ConnectionGUID: qKcI1yz0RE2k8bS3Hxo6uw==
X-CSE-MsgGUID: HTYv2nR4Su6Xya5rU9Acbg==
Authentication-Results: alln-opgw-4.cisco.com; dkim=pass (signature verified) header.i=@cisco.com
X-IronPort-AV: E=Sophos;i="6.09,247,1716249600"; d="scan'208,217";a="35300054"
Received: from mail-bn7nam10lp2048.outbound.protection.outlook.com (HELO NAM10-BN7-obe.outbound.protection.outlook.com) ([104.47.70.48]) by alln-opgw-4.cisco.com with ESMTP/TLS/ECDHE-RSA-AES256-GCM-SHA384; 29 Jul 2024 22:17:20 +0000
ARC-Seal: i=1; a=rsa-sha256; s=arcselector10001; d=microsoft.com; cv=none; b=sgjffwrNgUYXgxrJoZQ9CHxDF6AEAiHIhvX+B85sgDUIl4tLwvDF/FHad+15IN2nOTavbk9GpTD0i1Ek5sIpXrn0SOyGWYdebN9U/PiAJAgp42y4/x1tnGFa8AhV03OlX4jflRuW/xv0eFVprDMDsoIWL3znRqXZU7qBjlyCmAgiZzk5ufEZ9xoH6bCSjhSjganxaeasUVSpkDG2Qikyad3Z1a5OJnx7bHTKqLsjICFTYifVvJ5PEXa1XowkHbSqjx8VvpL9nIERcWygqGQchbhchMLDeKuiU/kqupIIWZCtnSIqikI4DX6OoLMs5ZfTERo5Aujro1XHnKG3JzskeA==
ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=microsoft.com; s=arcselector10001; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-AntiSpam-MessageData-ChunkCount:X-MS-Exchange-AntiSpam-MessageData-0:X-MS-Exchange-AntiSpam-MessageData-1; bh=X9SOs6Mj7yAEB/7dVqS1r7nOfM14jJYyhQzrxBkkoR8=; b=ZO3nfCLxrNaqxQOIVPNbk/ZuGwRi4vtCMHEMNVreOTsb+Vt+gjvmaAa6iYW5sG03Fuu7+c+4naApnPrQs/r0+mhGAoB18sCHvLg4wDjJkfxsohvNP2rrRt8sm3vNCZLggmLsElhDBKQ58QOr+ykdAExmftgy4QzTkpRUvdN+XGSyaL46QkS9B6jRJHspiTRWlaBuJf6NY0HHWVXLl8rg4jyH84fXAEvhDjinyPHV4au7AJu2kxh9fBDJt56JXxb9xmpJEtBHU29b0xWKk8alBHLG9osld+TYdOvXUomP2F4xB2myLHQX5sjKOog97Q/Ft6rz9D0LM7Xr8bDd7ouV+g==
ARC-Authentication-Results: i=1; mx.microsoft.com 1; spf=pass smtp.mailfrom=cisco.com; dmarc=pass action=none header.from=cisco.com; dkim=pass header.d=cisco.com; arc=none
Received: from MN2PR11MB4760.namprd11.prod.outlook.com (2603:10b6:208:266::22) by CO1PR11MB5123.namprd11.prod.outlook.com (2603:10b6:303:94::13) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.20.7807.28; Mon, 29 Jul 2024 22:17:18 +0000
Received: from MN2PR11MB4760.namprd11.prod.outlook.com ([fe80::c0c3:62b9:7fc2:b66a]) by MN2PR11MB4760.namprd11.prod.outlook.com ([fe80::c0c3:62b9:7fc2:b66a%4]) with mapi id 15.20.7807.026; Mon, 29 Jul 2024 22:17:18 +0000
From: "Flemming Andreasen (fandreas)" <fandreas@cisco.com>
To: Pieter Kasselman <pieter.kasselman=40microsoft.com@dmarc.ietf.org>, "wimse@ietf.org" <wimse@ietf.org>, Justin Richer <jricher@mit.edu>
Thread-Topic: [Wimse] Request for Input: Best Current Practice for OAuth 2.0 Client Authentication in Workload Environments
Thread-Index: AdrhoMjopmD8yk6CTG2adWt4Qe20MQAZEn0A
Date: Mon, 29 Jul 2024 22:17:18 +0000
Message-ID: <7c7c2092-a806-4f28-a37b-f3556b9858a5@cisco.com>
References: <DBAPR83MB0437B6623ED287A218D1FE4F91B72@DBAPR83MB0437.EURPRD83.prod.outlook.com>
In-Reply-To: <DBAPR83MB0437B6623ED287A218D1FE4F91B72@DBAPR83MB0437.EURPRD83.prod.outlook.com>
Accept-Language: en-US
Content-Language: en-US
X-MS-Has-Attach:
X-MS-TNEF-Correlator:
user-agent: Mozilla Thunderbird
x-ms-publictraffictype: Email
x-ms-traffictypediagnostic: MN2PR11MB4760:EE_|CO1PR11MB5123:EE_
x-ms-office365-filtering-correlation-id: 1eb92eeb-3dba-4b09-e7e3-08dcb01c35bc
x-ms-exchange-senderadcheck: 1
x-ms-exchange-antispam-relay: 0
x-microsoft-antispam: BCL:0;ARA:13230040|376014|1800799024|366016|38070700018;
x-microsoft-antispam-message-info: /zgQE/XvSFEj28w6rGKMSwZhnM7P8IfJwdhRwVM5mvpb7xbA6fbMSrXWUaF7A4x8jI7tNPtM0QzAR09ByQQRtyrcLspRwnyzRn7Y0S57iXdsC8+DttMEcxQqVUi2+TWkRHm6UAYWmJwpTl9G2xfdzIlPGEoJDHv1GPCvVdnAEIM1qItjWwQpCBRd9h2/6+IX1U4d6DSy/R683fU9q9vVp2iNydj56dCyFqzrA+vXDq9rJgLacXY21342/k1TdX36iBq3divCQSkBbYyTX3r6JKRzU1RKbSuvR8zckQ4OEEKgPWkqYS55ta3WbpVaTpO7V1/GvfG0Ie7N+vg2GmMvs7qwqCo/NPoprBhkpyC94owvOLoHv2VZzvoV1isXw0NanJgt4uYYv2+NdhP01cUaExuHUxv4BrhQ6T8QswdpG9ywa7LtjhNPCyfduihcTOWRFottfNOXwMWUnY7uw51ex/qLPxT2uwrwFYJ9g6dJXHx+s9lcaQbeiA7dkpJtdCJOw5iySrmpDmt7oqLokgLTIC05926B+NA3c/NJ4TIWlXHOkzAGK87oS7kALSvQw6JOZ8HoqTkHMUsoR/2ahlDCbdxOTRAwHcWBGTNt/nuIvqj0Pknd26oBaO2IrxWukAb/lr4clATy0gzr1yGrQIAf37r6gERnt9sF0XPwBjYhm/WixP0hLyi7jmsZ4+ETgbqmHRTn6Dg9kAUA4sH57dCj1z72KjB5kSbMfsudnVkbB+ebm4jk5Lz9menxw2hoos7e56wkvj75YR1yTEAO4Gx5OAoeSTQQZuV1P12vBjwVZTTD4vlUCw2HWsB/T8NGi+SgKYuGPbxmTD7wtTJRAcclc11D9oMG09qOGzwOPc8EcCdW3jeZJCfiJ9Kmod0dCtW20x3+5I4FdujQvfa5UOCOQ4ogdeiOsES9LHXV8gWfa2bAXhifBfBi4C8WU3PegSDUJnapsPlUAGEZdsIHK4nT6jYPhuAoPuklly+xAzSsBxGdqr3INozju6GNuzNDcWNsu58yhgI7wLvsn37ftGvnvsiUwRYdP3U4OkOLNiooisBOhQE0LIsyIIJ30tjAXpFx70KiUf51FPfBqw1DtxmxKKZTGtGU89LuOOyWpQcMqlOx8sMXluYb8uFEuO4KZeqJpI5Ni4bLSm7D6JKKVsBAjQkJHmyCqPZY3FYF3V5cJd2V785v8ESA0zP14PkXpSg0Ml8XfqXiuExmcKXy8IgrbULFPiVzww5j/84/nIOifGjwL3jpV7qeB/t5XJAveEX4DbyY3kPHny29l/X/W3eCNfelq251ZejKOmGQJONLcOwokV3eWa2DnFXp6v0GSGR83MfA+y94y1v+Ag+WQgYsr20YqrJuBQS/jzWhvzWfFes=
x-forefront-antispam-report: CIP:255.255.255.255;CTRY:;LANG:en;SCL:1;SRV:;IPV:NLI;SFV:NSPM;H:MN2PR11MB4760.namprd11.prod.outlook.com;PTR:;CAT:NONE;SFS:(13230040)(376014)(1800799024)(366016)(38070700018);DIR:OUT;SFP:1101;
x-ms-exchange-antispam-messagedata-chunkcount: 1
x-ms-exchange-antispam-messagedata-0: QVolnR0jwaYplmlh2IutEk++L3U6nPHT5OQ1YMVqRHGDG2fOAi1+t+zMCc44zjDZZ5AC6gLI4ddQXrnZ+5xh4Nz7LRPA8IMzsmXruydLVD7jqH4O0RuWDKDOFoqr3uDIiCXzQvehzc4vPx8V25maV7Pd1XY/oU0OpA9HK9Cj/hJYfjdUmdkgd5a7qFr1Fatt+4ObvXHhDKYjeVs87C5nPgzf9la1lg+QQ51tlbZJmPahQ5DcglVq9XRowPoJ/+K6GR6c6Mbq6Z99VnEXLYODj671kgfpFoiEAax8u+fiLL5g5zCQqaUAc81SGMq0zb/Kgb4kGLliDEpnMrYe4wu/YHRhYRt1DRFzGUFqSFzoiYVxnym5grQcYQjwbWz3mXMII247KiKS6H3dBu1W3btfg7NGunYFS74J6P6esKukHn3hzmXDpLDxRwv1wmEeTgSlolLfLW9Wf05LkF/SAQj+bNgdP2Dzo5SVqcnAmLKRN6gchAO+e7pmQOGC59W2YQTQu8OJMTMh/MNY2AGqsue+OpxTLYVwisMVue5moXTqnVpCNmDG1aWncwOwIP2gUSDG3WecdfrIlcjdtSEaXxC+74QPg629q7DwcFlAbxisf1pLspbM+ASgdnwuBLKhFTTFcg7yJnVKGJiv1tyg/lHgkvwBFaTLyuWwMmP8Vf4glw5Z15XV+IP9LNgwU6TXNsoeRbB10VTBuSayrBLu/ZXpd7KXU7sn4vdxGnTU/zD4fNJ0DR8Q4guQZDhaCEBzWvrSDsgX/qL9jwLBcPsxkuVh3cy3G1/XaUfF3yCEYmiv8KSc0oUd0x+fLGxuAXjPSs0a/XWZ1fwD9lceD+FznnyAkElKjWSpKWIr6+HNx3xiio3BeeB+JcVA4TNRBfKFeMDAUAMKgKASxwukEB6FcBEaOp2DK68de4og782/ZlM5npmoqciyy2g5Iad/ycz7kRJCp2BNm4/RLoX3wGVMricKK+Mx/Ci/R62rFVd/VSjaWMHXoMFbdNwqXsSE6UdzKgP6AYxywYU6RyvZUR9iArzTOt2eo2yZWUynXMI/pSG2L2YeTioW98kck866fYSlCBpZZPJGojJokWbcCYAhRUg3h1mFM4GdxKANpua2d/BzYJKp09XxzS9urhI/DkNWVps7CAE1KA1z21l3QJxwG0Vd6URTs3PlRUAEGbbb6Cx9ExAPRae86l78CnP1H3gHRQM+GY1+AFE3qT9q1yYnT5jG4yJ31hQMysOiWZTtqFIflPVZA5jwXwLjrjEnWOyoFcxv6S/XyOdcg8u39z3kNdrRVZe9Kfj97/gDZDoqU3ObMZJbaSzQSnN3E5lxOO36orAEFY5eB4mecd+x67C4az0hSdEL4xfT4yW6KD8RLEq5IhVh1fohTGoZe+6mwvDi9rC4vVMWgp8WTudvcSWr+Fn/6buTOaHbJVVg+Fxmz3mvRnWqfJ8xbc8qhmCKTQmWwAIgLg4fICKaKGMVyCkATTARjLe2/ZCgV1u7vFzMxkOxDAVaS/gtevo5QVcDWIe4jb2cwQ/pGYB/jIOYGXtGuF9gZ5xMA0OmDW5Og0TtRdEO3eXSjlMsvgb3GDt9dEH3FoRE
Content-Type: multipart/alternative; boundary="_000_7c7c2092a8064f28a37bf3556b9858a5ciscocom_"
MIME-Version: 1.0
X-OriginatorOrg: cisco.com
X-MS-Exchange-CrossTenant-AuthAs: Internal
X-MS-Exchange-CrossTenant-AuthSource: MN2PR11MB4760.namprd11.prod.outlook.com
X-MS-Exchange-CrossTenant-Network-Message-Id: 1eb92eeb-3dba-4b09-e7e3-08dcb01c35bc
X-MS-Exchange-CrossTenant-originalarrivaltime: 29 Jul 2024 22:17:18.6715 (UTC)
X-MS-Exchange-CrossTenant-fromentityheader: Hosted
X-MS-Exchange-CrossTenant-id: 5ae1af62-9505-4097-a69a-c1553ef7840e
X-MS-Exchange-CrossTenant-mailboxtype: HOSTED
X-MS-Exchange-CrossTenant-userprincipalname: gbKMtgUJDzK3Bg8WaWU1ozVAaeA+5phUR3GJb8De7SO1YLlQI7XSX7/BfsoZpJUeefCzytFwUsu8t2zI29VgTA==
X-MS-Exchange-Transport-CrossTenantHeadersStamped: CO1PR11MB5123
X-Outbound-SMTP-Client: 173.37.147.252, alln-opgw-4.cisco.com
X-Outbound-Node: rcdn-core-4.cisco.com
Message-ID-Hash: Z2HEVJBXCIFHJGWRZVOVU65FZFGUHX7C
X-Message-ID-Hash: Z2HEVJBXCIFHJGWRZVOVU65FZFGUHX7C
X-MailFrom: fandreas@cisco.com
X-Mailman-Rule-Misses: dmarc-mitigation; no-senders; approved; emergency; loop; banned-address; member-moderation; nonmember-moderation; administrivia; implicit-dest; max-recipients; max-size; news-moderation; no-subject; digests; suspicious-header
X-Mailman-Version: 3.3.9rc4
Precedence: list
Subject: [Wimse] Re: Request for Input: Best Current Practice for OAuth 2.0 Client Authentication in Workload Environments
List-Id: WIMSE Workload Identity in Multi-Service Environment <wimse.ietf.org>
Archived-At: <https://mailarchive.ietf.org/arch/msg/wimse/tPPjYoOt-rjM2ZaPGVtyJpjArUk>
List-Archive: <https://mailarchive.ietf.org/arch/browse/wimse>
List-Help: <mailto:wimse-request@ietf.org?subject=help>
List-Owner: <mailto:wimse-owner@ietf.org>
List-Post: <mailto:wimse@ietf.org>
List-Subscribe: <mailto:wimse-join@ietf.org>
List-Unsubscribe: <mailto:wimse-leave@ietf.org>

Given the choices, I would go for option A (i.e. no specific recommendations), the reason being I don't think it makes a lot of sense for WIMSE to recommend one thing based purely on OAuth access tokens, when we may end up specifying something different using WIMSE tokens (or whatever we end up calling it). I do think pointing out potential issues with current mechanisms would be helpful though.

Thanks

-- Flemming


On 7/29/24 06:21, Pieter Kasselman wrote:
During the Working Group meeting in Vancouver there was discussion on the scope of the Working Group document titled Best Current Practice for OAuth 2.0 Client Authentication in Workload Environments [1], which was adopted in accordance with the following deliverable in the charter [2]:


  *   [I or BCP] Document and make recommendations based on operational experience to existing token distribution practices for workloads.

This is intended to respond to the following milestone [3]:


  *   Submit informational document describing considerations for filesystem-based JWT delivery in Kubernetes to the IESG

Please reply to the list to indicate which of the following options represent the appropriate scope for this document:


  1.  Document existing practices without specific recommendations on how to obtain, protect and use OAuth Access Tokens.
  2.  Document existing practices along with strong recommendations on how to obtain, protect and use OAuth Access Tokens.
  3.  Need more information (please state what more information you need).
  4.  No opinion (i.e., this isn’t a topic you care strongly about).

Please reply to the list by August 12th, 2024.

Thank you,

Pieter and Justin

[1] https://datatracker.ietf.org/doc/draft-ietf-wimse-workload-identity-bcp/
[2] https://datatracker.ietf.org/doc/charter-ietf-wimse/
[3] https://datatracker.ietf.org/wg/wimse/about/