
From ynir@checkpoint.com  Mon Feb 28 01:02:46 2011
Return-Path: <ynir@checkpoint.com>
X-Original-To: http-auth@core3.amsl.com
Delivered-To: http-auth@core3.amsl.com
Received: from localhost (localhost [127.0.0.1]) by core3.amsl.com (Postfix) with ESMTP id 82A713A6AE2 for <http-auth@core3.amsl.com>; Mon, 28 Feb 2011 01:02:46 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -10.567
X-Spam-Level: 
X-Spam-Status: No, score=-10.567 tagged_above=-999 required=5 tests=[AWL=0.032, BAYES_00=-2.599, RCVD_IN_DNSWL_HI=-8]
Received: from mail.ietf.org ([64.170.98.32]) by localhost (core3.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id SQLBqN1ieBMA for <http-auth@core3.amsl.com>; Mon, 28 Feb 2011 01:02:45 -0800 (PST)
Received: from michael.checkpoint.com (smtp.checkpoint.com [194.29.34.68]) by core3.amsl.com (Postfix) with ESMTP id 4FADD3A6AE6 for <http-auth@ietf.org>; Mon, 28 Feb 2011 01:02:45 -0800 (PST)
Received: from il-ex01.ad.checkpoint.com (il-ex01.ad.checkpoint.com [194.29.34.26]) by michael.checkpoint.com (8.13.8/8.13.8) with ESMTP id p1S93irJ001447 for <http-auth@ietf.org>; Mon, 28 Feb 2011 11:03:44 +0200
X-CheckPoint: {4D6B6509-D-1B221DC2-FFFF}
Received: from il-ex01.ad.checkpoint.com ([126.0.0.2]) by il-ex01.ad.checkpoint.com ([126.0.0.2]) with mapi; Mon, 28 Feb 2011 11:03:44 +0200
From: Yoav Nir <ynir@checkpoint.com>
To: "http-auth@ietf.org" <http-auth@ietf.org>
Date: Mon, 28 Feb 2011 11:03:46 +0200
Thread-Topic: [http-auth] HTTP Auth Next BOF at IETF Prague deadline Monday/Possible W3C Workshop?
Thread-Index: AcvXJmabJJT9aFqKRReobOAEt/NQ7w==
Message-ID: <7DA01D9C-A6A1-4EE0-9825-1DEA50A724CF@checkpoint.com>
References: <1c2bbcf25744cc1b9a8627f2a9bd66a3.squirrel@webmail-mit.w3.org> <4D4670CF.7060301@aist.go.jp> <abc33601a820ad6566c33b8f81129f17.squirrel@webmail-mit.w3.org> <4D46F497.2000005@stpeter.im>
In-Reply-To: <4D46F497.2000005@stpeter.im>
Accept-Language: en-US
Content-Language: en-US
X-MS-Has-Attach: 
X-MS-TNEF-Correlator: 
acceptlanguage: en-US
Content-Type: text/plain; charset="us-ascii"
Content-Transfer-Encoding: quoted-printable
MIME-Version: 1.0
Subject: Re: [http-auth] HTTP Auth Next BOF at IETF Prague deadline Monday/Possible W3C Workshop?
X-BeenThere: http-auth@ietf.org
X-Mailman-Version: 2.1.9
Precedence: list
List-Id: HTTP authentication methods <http-auth.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/listinfo/http-auth>, <mailto:http-auth-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/http-auth>
List-Post: <mailto:http-auth@ietf.org>
List-Help: <mailto:http-auth-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/http-auth>, <mailto:http-auth-request@ietf.org?subject=subscribe>
X-List-Received-Date: Mon, 28 Feb 2011 09:02:46 -0000

On Jan 31, 2011, at 7:42 PM, Peter Saint-Andre wrote:
>=20
> I think that a "bar bof" / informal side meeting at the Prague IETF
> meeting makes the most sense, followed by focused discussions on this
> list and then a WG-forming BoF at IETF 81 (if we think that's needed).
>=20
> I say that because I don't think we're quite ready to form a working
> group, but we have important technical topics to discuss. We could hold
> a non-WG-forming BoF ("exploratory BoF") but an informal side meeting
> might be less pressured and therefore more productive -- in my
> experience it's best to hold a BoF when you have a strong proposal about
> forming a WG.

Hi.

I'm still making my travel plans, so has anyone thought of when to hold suc=
h a "bar bof" / side meeting ?  The "known bar bof" at the meeting main pag=
e is still not a link.

Thanks

Yoav



From y.oiwa@aist.go.jp  Mon Feb 28 17:05:37 2011
Return-Path: <y.oiwa@aist.go.jp>
X-Original-To: http-auth@core3.amsl.com
Delivered-To: http-auth@core3.amsl.com
Received: from localhost (localhost [127.0.0.1]) by core3.amsl.com (Postfix) with ESMTP id 5ED833A6D41 for <http-auth@core3.amsl.com>; Mon, 28 Feb 2011 17:05:36 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -0.09
X-Spam-Level: 
X-Spam-Status: No, score=-0.09 tagged_above=-999 required=5 tests=[BAYES_00=-2.599, HELO_EQ_JP=1.244, HOST_EQ_JP=1.265]
Received: from mail.ietf.org ([64.170.98.32]) by localhost (core3.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id SSTWfql4Wy9K for <http-auth@core3.amsl.com>; Mon, 28 Feb 2011 17:05:35 -0800 (PST)
Received: from mx1.aist.go.jp (mx1.aist.go.jp [150.29.246.133]) by core3.amsl.com (Postfix) with ESMTP id BEF5D3A6D44 for <http-auth@ietf.org>; Mon, 28 Feb 2011 17:05:34 -0800 (PST)
Received: from rqsmtp1.aist.go.jp (rqsmtp1.aist.go.jp [150.29.254.115]) by mx1.aist.go.jp  with ESMTP id p2116T3n029781; Tue, 1 Mar 2011 10:06:29 +0900 (JST) env-from (y.oiwa@aist.go.jp)
DKIM-Signature: v=1; a=rsa-sha256; c=simple/simple; d=aist.go.jp; s=aist; t=1298941590; bh=2nJ7nwS74A008+pw5eVLuvPKSNaB/ezL82E3/y0QZS4=; h=Message-ID:Date:From; b=hwZsQiH/vCUAnHe1RkK3v2ZLHptVdm6+2wO7LT6FhbCcrMhKL8bf8YmsjkaAulPtt p+c60l+Xvu3kKBoQ4Ze13f7xS9OZBnqZm1Ayawvor0nQ8pVzrdSdF1LTdDI8/LL+CF UGH6jNG44siv9esv62yMmusU3/i5D6dgh5ydqlIc=
Received: from smtp1.aist.go.jp by rqsmtp1.aist.go.jp  with ESMTP id p2116T5g005528; Tue, 1 Mar 2011 10:06:29 +0900 (JST) env-from (y.oiwa@aist.go.jp)
Received: by smtp1.aist.go.jp  with ESMTP id p2116QHU011042; Tue, 1 Mar 2011 10:06:28 +0900 (JST) env-from (y.oiwa@aist.go.jp)
Message-ID: <4D6C4691.5000604@aist.go.jp>
Date: Tue, 01 Mar 2011 10:06:25 +0900
From: Yutaka OIWA <y.oiwa@aist.go.jp>
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en; rv:1.9.2.13) Gecko/20101207 Thunderbird/3.1.7
MIME-Version: 1.0
To: Yoav Nir <ynir@checkpoint.com>
References: <1c2bbcf25744cc1b9a8627f2a9bd66a3.squirrel@webmail-mit.w3.org>	<4D4670CF.7060301@aist.go.jp>	<abc33601a820ad6566c33b8f81129f17.squirrel@webmail-mit.w3.org>	<4D46F497.2000005@stpeter.im> <7DA01D9C-A6A1-4EE0-9825-1DEA50A724CF@checkpoint.com>
In-Reply-To: <7DA01D9C-A6A1-4EE0-9825-1DEA50A724CF@checkpoint.com>
X-Enigmail-Version: 1.1.1
Content-Type: text/plain; charset=ISO-8859-1
Content-Transfer-Encoding: 7bit
Cc: "http-auth@ietf.org" <http-auth@ietf.org>
Subject: Re: [http-auth] HTTP Auth Next BOF at IETF Prague deadline Monday/Possible W3C Workshop?
X-BeenThere: http-auth@ietf.org
X-Mailman-Version: 2.1.9
Precedence: list
List-Id: HTTP authentication methods <http-auth.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/listinfo/http-auth>, <mailto:http-auth-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/http-auth>
List-Post: <mailto:http-auth@ietf.org>
List-Help: <mailto:http-auth-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/http-auth>, <mailto:http-auth-request@ietf.org?subject=subscribe>
X-List-Received-Date: Tue, 01 Mar 2011 01:05:37 -0000

Dear Yoav,

Now the draft WG timetable is available, and this time in Prague, there seems to
be a slightly different scheduling schema (e.g. a plenary in Monday, some
apparea efforts e.g. httpbis in Thursday).
For the first impression, IMO Tuesday or Thursday evening seems to be
a good place.
If no other opinions, we will check the timetable wholly and propose a candidate
in a few days.

In addition, comments for the discussion item list which I posted before are
really *needed* and will be greatly welcomed. >all

On 2011/02/28 18:03, Yoav Nir wrote:
> 
> On Jan 31, 2011, at 7:42 PM, Peter Saint-Andre wrote:
>>
>> I think that a "bar bof" / informal side meeting at the Prague IETF
>> meeting makes the most sense, followed by focused discussions on this
>> list and then a WG-forming BoF at IETF 81 (if we think that's needed).
>>
>> I say that because I don't think we're quite ready to form a working
>> group, but we have important technical topics to discuss. We could hold
>> a non-WG-forming BoF ("exploratory BoF") but an informal side meeting
>> might be less pressured and therefore more productive -- in my
>> experience it's best to hold a BoF when you have a strong proposal about
>> forming a WG.
> 
> Hi.
> 
> I'm still making my travel plans, so has anyone thought of when to hold such a "bar bof" / side meeting ?  The "known bar bof" at the meeting main page is still not a link.
> 
> Thanks
> 
> Yoav
> 
> 
> _______________________________________________
> http-auth mailing list
> http-auth@ietf.org
> https://www.ietf.org/mailman/listinfo/http-auth


From ynir@checkpoint.com  Mon Feb 28 23:05:21 2011
Return-Path: <ynir@checkpoint.com>
X-Original-To: http-auth@core3.amsl.com
Delivered-To: http-auth@core3.amsl.com
Received: from localhost (localhost [127.0.0.1]) by core3.amsl.com (Postfix) with ESMTP id 4727B3A68B3 for <http-auth@core3.amsl.com>; Mon, 28 Feb 2011 23:05:21 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -10.568
X-Spam-Level: 
X-Spam-Status: No, score=-10.568 tagged_above=-999 required=5 tests=[AWL=0.031, BAYES_00=-2.599, RCVD_IN_DNSWL_HI=-8]
Received: from mail.ietf.org ([64.170.98.32]) by localhost (core3.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id aVfP3uQRsnYR for <http-auth@core3.amsl.com>; Mon, 28 Feb 2011 23:05:17 -0800 (PST)
Received: from michael.checkpoint.com (smtp.checkpoint.com [194.29.34.68]) by core3.amsl.com (Postfix) with ESMTP id 0AFB93A6A97 for <http-auth@ietf.org>; Mon, 28 Feb 2011 23:05:10 -0800 (PST)
Received: from il-ex01.ad.checkpoint.com (il-ex01.ad.checkpoint.com [194.29.34.26]) by michael.checkpoint.com (8.13.8/8.13.8) with ESMTP id p21767Nv018372;  Tue, 1 Mar 2011 09:06:07 +0200
X-CheckPoint: {4D6C9AF4-0-1B221DC2-FFFF}
Received: from il-ex03.ad.checkpoint.com (194.29.34.71) by il-ex01.ad.checkpoint.com (194.29.34.26) with Microsoft SMTP Server (TLS) id 8.2.255.0; Tue, 1 Mar 2011 09:06:07 +0200
Received: from il-ex01.ad.checkpoint.com ([126.0.0.2]) by il-ex03.ad.checkpoint.com ([194.29.34.71]) with mapi; Tue, 1 Mar 2011 09:06:07 +0200
From: Yoav Nir <ynir@checkpoint.com>
To: Yutaka OIWA <y.oiwa@aist.go.jp>
Date: Tue, 1 Mar 2011 09:06:05 +0200
Thread-Topic: [http-auth] HTTP Auth Next BOF at IETF Prague deadline Monday/Possible W3C Workshop?
Thread-Index: AcvX3yKeQYKDfDSlTfCJHSFH1u3CzA==
Message-ID: <570D362C-2095-4872-ADAD-77BAC05F5C45@checkpoint.com>
References: <1c2bbcf25744cc1b9a8627f2a9bd66a3.squirrel@webmail-mit.w3.org> <4D4670CF.7060301@aist.go.jp> <abc33601a820ad6566c33b8f81129f17.squirrel@webmail-mit.w3.org> <4D46F497.2000005@stpeter.im> <7DA01D9C-A6A1-4EE0-9825-1DEA50A724CF@checkpoint.com> <4D6C4691.5000604@aist.go.jp>
In-Reply-To: <4D6C4691.5000604@aist.go.jp>
Accept-Language: en-US
Content-Language: en-US
X-MS-Has-Attach: 
X-MS-TNEF-Correlator: 
acceptlanguage: en-US
Content-Type: text/plain; charset="us-ascii"
Content-Transfer-Encoding: quoted-printable
MIME-Version: 1.0
Cc: "http-auth@ietf.org" <http-auth@ietf.org>
Subject: Re: [http-auth] HTTP Auth Next BOF at IETF Prague deadline Monday/Possible W3C Workshop?
X-BeenThere: http-auth@ietf.org
X-Mailman-Version: 2.1.9
Precedence: list
List-Id: HTTP authentication methods <http-auth.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/listinfo/http-auth>, <mailto:http-auth-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/http-auth>
List-Post: <mailto:http-auth@ietf.org>
List-Help: <mailto:http-auth-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/http-auth>, <mailto:http-auth-request@ietf.org?subject=subscribe>
X-List-Received-Date: Tue, 01 Mar 2011 07:05:21 -0000

On Mar 1, 2011, at 3:06 AM, Yutaka OIWA wrote:

> In addition, comments for the discussion item list which I posted before =
are
> really *needed* and will be greatly welcomed. >all
>=20

I think everyone who has responded agrees that something should be done. Ba=
sic or digest auth, with the only alternative being a webform is not good e=
nough.

Someone (I think it was Marsh Ray) think that doing proper authentication i=
n HTTP doesn't do much unless you also use data authentication, such as in =
TLS. I tend to agree, since simple HTTP is vulnerable to a MitM attack. I d=
on't know if this is the general feeling of the (not yet) group.


The question is whether it is worthwhile to propose an authentication mecha=
nism for HTTP itself, or to move it to TLS. Moving it to TLS has the advant=
age of binding the authenticated identity to the key, and adding APIs for t=
he HTTP application to get the authenticated identity is trivial - it is al=
ready done for user certificate authentication. I'm sure there will be othe=
rs who disagree.

I have a draft for putting authentication in TLS ( http://tools.ietf.org/ht=
ml/draft-nir-tls-eap ), but there are other ways as well.

I think we also need to discuss the UI issue. Signing in with a webform is =
equivalent (as far as security is concerned) with basic authentication, and=
 yet you don't see any websites using basic authentication. Regardless of h=
ow secure and wonderful we can make the protocol, I'd like to hear from peo=
ple who understand web design what would convince the web designers to use =
the new mechanism rather than web forms.

Yoav

