Re: [Wish] Authentication for resource url

Juliusz Chroboczek <jch@irif.fr> Thu, 16 September 2021 18:44 UTC

Return-Path: <jch@irif.fr>
X-Original-To: wish@ietfa.amsl.com
Delivered-To: wish@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 658013A33BE for <wish@ietfa.amsl.com>; Thu, 16 Sep 2021 11:44:37 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.9
X-Spam-Level:
X-Spam-Status: No, score=-1.9 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, SPF_HELO_NONE=0.001, SPF_PASS=-0.001] autolearn=ham autolearn_force=no
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id nQZBuzL78kUH for <wish@ietfa.amsl.com>; Thu, 16 Sep 2021 11:44:33 -0700 (PDT)
Received: from korolev.univ-paris7.fr (korolev.univ-paris7.fr [IPv6:2001:660:3301:8000::1:2]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id B245A3A33BC for <wish@ietf.org>; Thu, 16 Sep 2021 11:44:31 -0700 (PDT)
Received: from mailhub.math.univ-paris-diderot.fr (mailhub.math.univ-paris-diderot.fr [81.194.30.253]) by korolev.univ-paris7.fr (8.14.4/8.14.4/relay1/82085) with ESMTP id 18GIiSpM024968; Thu, 16 Sep 2021 20:44:28 +0200
Received: from mailhub.math.univ-paris-diderot.fr (localhost [127.0.0.1]) by mailhub.math.univ-paris-diderot.fr (Postfix) with ESMTP id 51D0320F3F; Thu, 16 Sep 2021 20:44:34 +0200 (CEST)
X-Virus-Scanned: amavisd-new at math.univ-paris-diderot.fr
Received: from mailhub.math.univ-paris-diderot.fr ([127.0.0.1]) by mailhub.math.univ-paris-diderot.fr (mailhub.math.univ-paris-diderot.fr [127.0.0.1]) (amavisd-new, port 10023) with ESMTP id R4wasF-9qylZ; Thu, 16 Sep 2021 20:44:32 +0200 (CEST)
Received: from pirx.irif.fr (unknown [78.194.40.74]) (Authenticated sender: jch) by mailhub.math.univ-paris-diderot.fr (Postfix) with ESMTPSA id 84F2120F3D; Thu, 16 Sep 2021 20:44:32 +0200 (CEST)
Date: Thu, 16 Sep 2021 20:44:26 +0200
Message-ID: <87tuikbbsl.wl-jch@irif.fr>
From: Juliusz Chroboczek <jch@irif.fr>
To: Matt Ward <mattward@mux.com>
Cc: WISH List <wish@ietf.org>
In-Reply-To: <CAABnt0PzPJiMxUj+yNr29YB8VfS41501B0c4gDZaqzLxh-u=Hw@mail.gmail.com>
References: <CA+ag07bjtS1Ucw1BZ5qQ_jJFfXbfQ3-hzDgxfkV1APhV1JZMnQ@mail.gmail.com> <CAABnt0M2Vg-9=SwX=O1mFbyYTS4b7ewmevW2qzMf17fsagoc2Q@mail.gmail.com> <CA+ag07aJKFy2s_UD0L-PaGHNwA9XH6Khz+0tReOMMcweJ0Q0hQ@mail.gmail.com> <CAABnt0MSUuxYK1CvOQUmC-a4b_U9m7YQ+vhXfjaaDxFZE+_JOQ@mail.gmail.com> <CA+ag07bb5WfoUJRkQt37nYtkmtEi=Kpp44ihVNGRd=OytakADg@mail.gmail.com> <CAABnt0PXKPejtywBDizx_Og0d0qPp6qa6cXXsCjBrbTQHN9pKg@mail.gmail.com> <CAMyc9bXUXR5nrxoQsQwDqE46sHWN_8vicG_c53ZruRbC0gfeMw@mail.gmail.com> <877dfk9fil.wl-jch@irif.fr> <CA+ag07ZxJF95xd7y_ToRRNJmbRboRR56t=mnW+nGYFqpAkH61g@mail.gmail.com> <8735q72yo4.wl-jch@irif.fr> <CA+ag07Z6_Nd2VvWG4HyuXK=E3u2xn8a2a_xVCEWk3_yyfQSp3A@mail.gmail.com> <87r1dr89mr.wl-jch@irif.fr> <a12adb1d-da65-8290-7d91-d911aa0aa6cc@nostrum.com> <87ee9qyyum.wl-jch@irif.fr> <87bl4uyxr4.wl-jch@irif.fr> <20210915121851.67088a25@lminiero> <HE1PR07MB4441791F1620CB6B6B9C5D8893DB9@HE1PR07MB4441.eurprd07.prod.outlook.com> <87y27xd6tl.wl-jch@irif.fr> <bd8bab3f-2bc9-1827-0184-2b5d1a5fb68e@nostrum.com> <CAABnt0MKd-MH1L4V=hVuhYJHHHv-nco98-0pTDzVhS04Wk2o2w@mail.gmail.com> <CA+ag07bzhoFfX4vMxPOtXvNK+f=zirCbDHa13Ucctx0oiMD88Q@mail.gmail.com> <CAABnt0PzPJiMxUj+yNr29YB8VfS41501B0c4gDZaqzLxh-u=Hw@mail.gmail.com>
User-Agent: Wanderlust/2.15.9 (Almost Unreal) Emacs/27.1 Mule/6.0
MIME-Version: 1.0 (generated by SEMI-EPG 1.14.7 - "Harue")
Content-Type: text/plain; charset=US-ASCII
X-Greylist: Sender IP whitelisted, not delayed by milter-greylist-4.2.7 (korolev.univ-paris7.fr [194.254.61.138]); Thu, 16 Sep 2021 20:44:28 +0200 (CEST)
X-Miltered: at korolev with ID 6143908C.000 by Joe's j-chkmail (http : // j-chkmail dot ensmp dot fr)!
X-j-chkmail-Enveloppe: 6143908C.000 from mailhub.math.univ-paris-diderot.fr/mailhub.math.univ-paris-diderot.fr/null/mailhub.math.univ-paris-diderot.fr/<jch@irif.fr>
X-j-chkmail-Score: MSGID : 6143908C.000 on korolev.univ-paris7.fr : j-chkmail score : . : R=. U=. O=. B=0.000 -> S=0.000
X-j-chkmail-Status: Ham
Archived-At: <https://mailarchive.ietf.org/arch/msg/wish/PbLvZWUVeWugTvMjH8BV5FjbHuQ>
Subject: Re: [Wish] Authentication for resource url
X-BeenThere: wish@ietf.org
X-Mailman-Version: 2.1.29
Precedence: list
List-Id: WebRTC Ingest Signaling over HTTPS <wish.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/wish>, <mailto:wish-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/wish/>
List-Post: <mailto:wish@ietf.org>
List-Help: <mailto:wish-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/wish>, <mailto:wish-request@ietf.org?subject=subscribe>
X-List-Received-Date: Thu, 16 Sep 2021 18:44:38 -0000

> Why must it be mandated?

It's fairly standard at IETF, as far as I'm aware.

The IETF insists that every protocol have a "mandatory to implement" (MTI)
security mechanism that ensures interoperability.  MTI does not means that
the mechanism needs to be enabled by default, just that it can be easily
enabled by the user if required.  (I expect most clients to be unauthentified
by default.)

The debate we're having is not about what mechanisms we'll be allowed to
implement -- it's highly unlikely that an angry Sergio will suddenly
appear in my office and try to prevent me from implementing HTTP Basic.
The debate is about what mechanism should be MTI according to the spec,
since that is the mechanism that's most likely to be implemented in
a uniform manner by third-party clients.

-- Juliusz