
From y.oiwa@aist.go.jp  Mon Jan 23 03:29:21 2012
Return-Path: <y.oiwa@aist.go.jp>
X-Original-To: http-auth@ietfa.amsl.com
Delivered-To: http-auth@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id D683C21F86D8 for <http-auth@ietfa.amsl.com>; Mon, 23 Jan 2012 03:29:21 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -0.09
X-Spam-Level: 
X-Spam-Status: No, score=-0.09 tagged_above=-999 required=5 tests=[BAYES_00=-2.599, HELO_EQ_JP=1.244, HOST_EQ_JP=1.265]
Received: from mail.ietf.org ([12.22.58.30]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id jMgctH0WxkSb for <http-auth@ietfa.amsl.com>; Mon, 23 Jan 2012 03:29:21 -0800 (PST)
Received: from mx1.aist.go.jp (mx1.aist.go.jp [150.29.246.133]) by ietfa.amsl.com (Postfix) with ESMTP id BF18821F8659 for <http-auth@ietf.org>; Mon, 23 Jan 2012 03:29:19 -0800 (PST)
Received: from rqsmtp2.aist.go.jp (rqsmtp2.aist.go.jp [150.29.254.123]) by mx1.aist.go.jp  with ESMTP id q0NBTFnS017642; Mon, 23 Jan 2012 20:29:15 +0900 (JST) env-from (y.oiwa@aist.go.jp)
DKIM-Signature: v=1; a=rsa-sha256; c=simple/simple; d=aist.go.jp; s=aist; t=1327318156; bh=IVpihxpA8H+KmyalaYTXF3RyC/OdBMHPr//6ZlR50lQ=; h=Message-ID:Date:From; b=D5FNZUCmHS05pVX8qTwru7lYbJbFzapqwOLhVcxSg+jsa5pPBpFvEJqk748Joytkl wX4aN6fXyH+TVFzNNhlgK6nnMyO+JQOnlgs3Yghy+R+PpURCsDa++MQwe1sWc6rzuN utU+1BSyqGt0MfNJ+KpKS7e//fgjtxEMWMEf/TwI=
Received: from smtp4.aist.go.jp by rqsmtp2.aist.go.jp  with ESMTP id q0NBTFAA005046; Mon, 23 Jan 2012 20:29:15 +0900 (JST) env-from (y.oiwa@aist.go.jp)
Received: by smtp4.aist.go.jp  with ESMTP id q0NBTAnI002047; Mon, 23 Jan 2012 20:29:11 +0900 (JST) env-from (y.oiwa@aist.go.jp)
Message-ID: <4F1D4485.5060806@aist.go.jp>
Date: Mon, 23 Jan 2012 20:29:09 +0900
From: Yutaka OIWA <y.oiwa@aist.go.jp>
User-Agent: Mozilla/5.0 (Windows NT 6.1; rv:9.0) Gecko/20111222 Thunderbird/9.0.1
MIME-Version: 1.0
To: "http-auth@ietf.org" <http-auth@ietf.org>
X-Enigmail-Version: 1.3.4
Content-Type: text/plain; charset=ISO-2022-JP
Content-Transfer-Encoding: 7bit
Cc: Alexey Melnikov <alexey.melnikov@isode.com>, Mark Nottingham <mnot@mnot.net>, Thomas Roessler <tlr@w3.org>
Subject: [http-auth] HTTP-Auth activity in oncoming IETF Paris Meeting
X-BeenThere: http-auth@ietf.org
X-Mailman-Version: 2.1.12
Precedence: list
List-Id: HTTP authentication methods <http-auth.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/http-auth>, <mailto:http-auth-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/http-auth>
List-Post: <mailto:http-auth@ietf.org>
List-Help: <mailto:http-auth-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/http-auth>, <mailto:http-auth-request@ietf.org?subject=subscribe>
X-List-Received-Date: Mon, 23 Jan 2012 11:29:21 -0000

Dear HTTP-AUTH Members,

I would like to propose another http-auth meeting-up at IETF Paris.
Main topic might be face-to-face discussion on our problem-space
survey in IETF Sec-area Wiki

http://trac.tools.ietf.org/area/sec/trac/wiki/HttpAuthentication/ProblemSpace

so that we can update the problem statement I-D and go forward for possible
future chartering.  Suggestions about scheduling, format of meeting, topics or
anything other are really welcome.

I am thankful for several comments and updates for the Wiki contents, and
currently I am looking for people who can update the contents especially
regarding Negotiate and other authentication mechanisms which enable
bridging between HTTP and existing authentication frameworks such as
GSS, SASL or Kerberos.  Any volunteers or candidates?

Since Vancouver we have talked with several people and had presentation sessions
in both IIW and W3C TPAC in California.  I'd like to update our project status soon.

I'm looking forward to seeing you in Paris!

-- 
Yutaka OIWA, Ph.D.                                       Research Scientist
                            Research Center for Information Security (RCIS)
    National Institute of Advanced Industrial Science and Technology (AIST)
                      Mail addresses: <y.oiwa@aist.go.jp>, <yutaka@oiwa.jp>
OpenPGP: id[440546B5] fp[7C9F 723A 7559 3246 229D  3139 8677 9BD2 4405 46B5]

From ynir@checkpoint.com  Mon Jan 23 04:52:20 2012
Return-Path: <ynir@checkpoint.com>
X-Original-To: http-auth@ietfa.amsl.com
Delivered-To: http-auth@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 8257621F8726 for <http-auth@ietfa.amsl.com>; Mon, 23 Jan 2012 04:52:20 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -10.474
X-Spam-Level: 
X-Spam-Status: No, score=-10.474 tagged_above=-999 required=5 tests=[AWL=0.125, BAYES_00=-2.599, RCVD_IN_DNSWL_HI=-8]
Received: from mail.ietf.org ([12.22.58.30]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id Z-oDuehAGTcp for <http-auth@ietfa.amsl.com>; Mon, 23 Jan 2012 04:52:20 -0800 (PST)
Received: from michael.checkpoint.com (smtp.checkpoint.com [194.29.34.68]) by ietfa.amsl.com (Postfix) with ESMTP id 6ED3A21F84B6 for <http-auth@ietf.org>; Mon, 23 Jan 2012 04:52:19 -0800 (PST)
X-CheckPoint: {4F1D5509-0-1B221DC2-1FFFF}
Received: from il-ex01.ad.checkpoint.com (il-ex01.ad.checkpoint.com [194.29.34.26]) by michael.checkpoint.com (8.13.8/8.13.8) with ESMTP id q0NCq9Gi010226;  Mon, 23 Jan 2012 14:52:09 +0200
Received: from il-ex03.ad.checkpoint.com (194.29.34.71) by il-ex01.ad.checkpoint.com (194.29.34.26) with Microsoft SMTP Server (TLS) id 8.3.213.0; Mon, 23 Jan 2012 14:52:09 +0200
Received: from il-ex01.ad.checkpoint.com ([126.0.0.2]) by il-ex03.ad.checkpoint.com ([194.29.34.71]) with mapi; Mon, 23 Jan 2012 14:52:09 +0200
From: Yoav Nir <ynir@checkpoint.com>
To: "'Yutaka OIWA'" <y.oiwa@aist.go.jp>, "http-auth@ietf.org" <http-auth@ietf.org>
Date: Mon, 23 Jan 2012 14:52:08 +0200
Thread-Topic: [http-auth] HTTP-Auth activity in oncoming IETF Paris Meeting
Thread-Index: AczZwkdST/Es3qsHRren23SdruYZkQAAbNUw
Message-ID: <006FEB08D9C6444AB014105C9AEB133F017A59DE7E95@il-ex01.ad.checkpoint.com>
References: <4F1D4485.5060806@aist.go.jp>
In-Reply-To: <4F1D4485.5060806@aist.go.jp>
Accept-Language: en-US
Content-Language: en-US
X-MS-Has-Attach: 
X-MS-TNEF-Correlator: 
acceptlanguage: en-US
x-kse-antivirus-interceptor-info: scan successful
x-kse-antivirus-info: Clean
Content-Type: text/plain; charset="us-ascii"
Content-Transfer-Encoding: quoted-printable
MIME-Version: 1.0
X-KSE-AntiSpam-Interceptor-Info: protection disabled
Cc: Alexey Melnikov <alexey.melnikov@isode.com>, Mark Nottingham <mnot@mnot.net>, Thomas Roessler <tlr@w3.org>
Subject: Re: [http-auth] HTTP-Auth activity in oncoming IETF Paris Meeting
X-BeenThere: http-auth@ietf.org
X-Mailman-Version: 2.1.12
Precedence: list
List-Id: HTTP authentication methods <http-auth.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/http-auth>, <mailto:http-auth-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/http-auth>
List-Post: <mailto:http-auth@ietf.org>
List-Help: <mailto:http-auth-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/http-auth>, <mailto:http-auth-request@ietf.org?subject=subscribe>
X-List-Received-Date: Mon, 23 Jan 2012 12:52:20 -0000

Hi

I think a big obstacle to converging on a charter item for a new or existin=
g working group, is that there are so many possible solutions all over the =
map. We've heard proposals for the authentication in TLS, in HTTP, and in H=
TML (or more likely javascript)

If you would like this to lead to charterable work, I suggest you concentra=
te on one of these avenues (I think the HTTP), and have a good explanation =
why not the others. Then confine the discussion to that avenue only.

As I have said in QC, once there's a charter item in some group, you'll get=
 plenty of crypto suggestions. We got 4 competing proposals in IPsecME, so =
I suggest to keep the crypto out of the discussion for now. Just try to get=
 consensus that we need to work on an HTTP-based method for authentication.

Yoav

-----Original Message-----
From: http-auth-bounces@ietf.org [mailto:http-auth-bounces@ietf.org] On Beh=
alf Of Yutaka OIWA
Sent: 23 January 2012 13:29
To: http-auth@ietf.org
Cc: Alexey Melnikov; Mark Nottingham; Thomas Roessler
Subject: [http-auth] HTTP-Auth activity in oncoming IETF Paris Meeting

Dear HTTP-AUTH Members,

I would like to propose another http-auth meeting-up at IETF Paris.
Main topic might be face-to-face discussion on our problem-space survey in =
IETF Sec-area Wiki

http://trac.tools.ietf.org/area/sec/trac/wiki/HttpAuthentication/ProblemSpa=
ce

so that we can update the problem statement I-D and go forward for possible=
 future chartering.  Suggestions about scheduling, format of meeting, topic=
s or anything other are really welcome.

I am thankful for several comments and updates for the Wiki contents, and c=
urrently I am looking for people who can update the contents especially reg=
arding Negotiate and other authentication mechanisms which enable bridging =
between HTTP and existing authentication frameworks such as GSS, SASL or Ke=
rberos.  Any volunteers or candidates?

Since Vancouver we have talked with several people and had presentation ses=
sions in both IIW and W3C TPAC in California.  I'd like to update our proje=
ct status soon.

I'm looking forward to seeing you in Paris!

--=20
Yutaka OIWA, Ph.D.                                       Research Scientist
                            Research Center for Information Security (RCIS)
    National Institute of Advanced Industrial Science and Technology (AIST)
                      Mail addresses: <y.oiwa@aist.go.jp>, <yutaka@oiwa.jp>
OpenPGP: id[440546B5] fp[7C9F 723A 7559 3246 229D  3139 8677 9BD2 4405 46B5=
] _______________________________________________
http-auth mailing list
http-auth@ietf.org
https://www.ietf.org/mailman/listinfo/http-auth

Scanned by Check Point Total Security Gateway.

From julian.reschke@gmx.de  Mon Jan 23 05:01:16 2012
Return-Path: <julian.reschke@gmx.de>
X-Original-To: http-auth@ietfa.amsl.com
Delivered-To: http-auth@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 6C70121F8741 for <http-auth@ietfa.amsl.com>; Mon, 23 Jan 2012 05:01:16 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -103.684
X-Spam-Level: 
X-Spam-Status: No, score=-103.684 tagged_above=-999 required=5 tests=[AWL=-1.085, BAYES_00=-2.599, USER_IN_WHITELIST=-100]
Received: from mail.ietf.org ([12.22.58.30]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id D3dzubUyYKug for <http-auth@ietfa.amsl.com>; Mon, 23 Jan 2012 05:01:16 -0800 (PST)
Received: from mailout-de.gmx.net (mailout-de.gmx.net [213.165.64.23]) by ietfa.amsl.com (Postfix) with SMTP id 7C06B21F8738 for <http-auth@ietf.org>; Mon, 23 Jan 2012 05:01:15 -0800 (PST)
Received: (qmail invoked by alias); 23 Jan 2012 13:01:14 -0000
Received: from mail.greenbytes.de (EHLO [192.168.1.140]) [217.91.35.233] by mail.gmx.net (mp071) with SMTP; 23 Jan 2012 14:01:14 +0100
X-Authenticated: #1915285
X-Provags-ID: V01U2FsdGVkX1+hN/4wQfShIxMapf0ql2G5BCg1fSOJFeqiou1ywy lf1KMgEbqvuHel
Message-ID: <4F1D5A14.3040808@gmx.de>
Date: Mon, 23 Jan 2012 14:01:08 +0100
From: Julian Reschke <julian.reschke@gmx.de>
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; rv:9.0) Gecko/20111222 Thunderbird/9.0.1
MIME-Version: 1.0
To: Yoav Nir <ynir@checkpoint.com>
References: <4F1D4485.5060806@aist.go.jp> <006FEB08D9C6444AB014105C9AEB133F017A59DE7E95@il-ex01.ad.checkpoint.com>
In-Reply-To: <006FEB08D9C6444AB014105C9AEB133F017A59DE7E95@il-ex01.ad.checkpoint.com>
Content-Type: text/plain; charset=ISO-8859-1; format=flowed
Content-Transfer-Encoding: 7bit
X-Y-GMX-Trusted: 0
Cc: Mark Nottingham <mnot@mnot.net>, "http-auth@ietf.org" <http-auth@ietf.org>, Thomas Roessler <tlr@w3.org>, Alexey Melnikov <alexey.melnikov@isode.com>
Subject: Re: [http-auth] HTTP-Auth activity in oncoming IETF Paris Meeting
X-BeenThere: http-auth@ietf.org
X-Mailman-Version: 2.1.12
Precedence: list
List-Id: HTTP authentication methods <http-auth.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/http-auth>, <mailto:http-auth-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/http-auth>
List-Post: <mailto:http-auth@ietf.org>
List-Help: <mailto:http-auth-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/http-auth>, <mailto:http-auth-request@ietf.org?subject=subscribe>
X-List-Received-Date: Mon, 23 Jan 2012 13:01:16 -0000

On 2012-01-23 13:52, Yoav Nir wrote:
> Hi
>
> I think a big obstacle to converging on a charter item for a new or existing working group, is that there are so many possible solutions all over the map. We've heard proposals for the authentication in TLS, in HTTP, and in HTML (or more likely javascript)
>
> If you would like this to lead to charterable work, I suggest you concentrate on one of these avenues (I think the HTTP), and have a good explanation why not the others. Then confine the discussion to that avenue only.
>
> As I have said in QC, once there's a charter item in some group, you'll get plenty of crypto suggestions. We got 4 competing proposals in IPsecME, so I suggest to keep the crypto out of the discussion for now. Just try to get consensus that we need to work on an HTTP-based method for authentication.
>
> Yoav

+1

Also: maybe concentrate on what's broken first?

- no way to logout (need a Javascript API -> W3C Webapps WG?)

- fix implementations (parsing WWW-Authenticate)

- maintain a test suide (W3C Test IG?)

- fix I18N for Basic auth

- fix UI issue (better support for HTML-form-based logon to HTTP auth)

...and so on...


From hhalpin@w3.org  Mon Jan 23 06:23:20 2012
Return-Path: <hhalpin@w3.org>
X-Original-To: http-auth@ietfa.amsl.com
Delivered-To: http-auth@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id D13AB21F86BA for <http-auth@ietfa.amsl.com>; Mon, 23 Jan 2012 06:23:20 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -10.599
X-Spam-Level: 
X-Spam-Status: No, score=-10.599 tagged_above=-999 required=5 tests=[BAYES_00=-2.599, RCVD_IN_DNSWL_HI=-8]
Received: from mail.ietf.org ([12.22.58.30]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id fny8VdFqOSI7 for <http-auth@ietfa.amsl.com>; Mon, 23 Jan 2012 06:23:20 -0800 (PST)
Received: from jay.w3.org (ssh.w3.org [128.30.52.60]) by ietfa.amsl.com (Postfix) with ESMTP id 4A68A21F852F for <http-auth@ietf.org>; Mon, 23 Jan 2012 06:23:19 -0800 (PST)
Received: from seattle239.riseup.net ([198.252.153.239] helo=[172.27.0.23]) by jay.w3.org with esmtpsa (TLS1.0:DHE_RSA_AES_256_CBC_SHA1:32) (Exim 4.69) (envelope-from <hhalpin@w3.org>) id 1RpKnm-0000aG-4l for http-auth@ietf.org; Mon, 23 Jan 2012 09:23:18 -0500
Message-ID: <4F1D6D7D.603@w3.org>
Date: Mon, 23 Jan 2012 15:23:58 +0100
From: Harry Halpin <hhalpin@w3.org>
User-Agent: Mozilla/5.0 (X11; U; Linux i686; en-US; rv:1.9.2.23) Gecko/20110922 Lightning/1.0b2 Thunderbird/3.1.15
MIME-Version: 1.0
To: http-auth@ietf.org
References: <4F1D4485.5060806@aist.go.jp>	<006FEB08D9C6444AB014105C9AEB133F017A59DE7E95@il-ex01.ad.checkpoint.com> <4F1D5A14.3040808@gmx.de>
In-Reply-To: <4F1D5A14.3040808@gmx.de>
Content-Type: text/plain; charset=ISO-8859-1; format=flowed
Content-Transfer-Encoding: 7bit
Subject: Re: [http-auth] HTTP-Auth activity in oncoming IETF Paris Meeting
X-BeenThere: http-auth@ietf.org
X-Mailman-Version: 2.1.12
Precedence: list
List-Id: HTTP authentication methods <http-auth.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/http-auth>, <mailto:http-auth-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/http-auth>
List-Post: <mailto:http-auth@ietf.org>
List-Help: <mailto:http-auth-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/http-auth>, <mailto:http-auth-request@ietf.org?subject=subscribe>
X-List-Received-Date: Mon, 23 Jan 2012 14:23:20 -0000

On 01/23/2012 02:01 PM, Julian Reschke wrote:
> On 2012-01-23 13:52, Yoav Nir wrote:
>> Hi
>>
>> I think a big obstacle to converging on a charter item for a new or 
>> existing working group, is that there are so many possible solutions 
>> all over the map. We've heard proposals for the authentication in 
>> TLS, in HTTP, and in HTML (or more likely javascript)
>>
>> If you would like this to lead to charterable work, I suggest you 
>> concentrate on one of these avenues (I think the HTTP), and have a 
>> good explanation why not the others. Then confine the discussion to 
>> that avenue only.
>>
>> As I have said in QC, once there's a charter item in some group, 
>> you'll get plenty of crypto suggestions. We got 4 competing proposals 
>> in IPsecME, so I suggest to keep the crypto out of the discussion for 
>> now. Just try to get consensus that we need to work on an HTTP-based 
>> method for authentication.
>>
>> Yoav
>
> +1
>
> Also: maybe concentrate on what's broken first?
>
> - no way to logout (need a Javascript API -> W3C Webapps WG?)

This is going to happen in the Web Cryptography Working Group. The 
charter is finished, W3C WG to begin after patent commitments to charter 
are finalized (expecting mid-February):

http://www.w3.org/2011/11/webcryptography-charter.html

>
> - fix implementations (parsing WWW-Authenticate)
>
> - maintain a test suide (W3C Test IG?)
>

The interest group is for sharing test suite design, a test suite should 
still likely happen under the IETF if the IETF is up for it.

> - fix I18N for Basic auth
>
> - fix UI issue (better support for HTML-form-based logon to HTTP auth)

As UI is one of the areas that browsers still compete on, standardizing 
UI will simply not happen.

>
> ...and so on...
>
> _______________________________________________
> http-auth mailing list
> http-auth@ietf.org
> https://www.ietf.org/mailman/listinfo/http-auth


From julian.reschke@gmx.de  Mon Jan 23 06:39:53 2012
Return-Path: <julian.reschke@gmx.de>
X-Original-To: http-auth@ietfa.amsl.com
Delivered-To: http-auth@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id E8F6221F8714 for <http-auth@ietfa.amsl.com>; Mon, 23 Jan 2012 06:39:53 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -103.645
X-Spam-Level: 
X-Spam-Status: No, score=-103.645 tagged_above=-999 required=5 tests=[AWL=-1.046, BAYES_00=-2.599, USER_IN_WHITELIST=-100]
Received: from mail.ietf.org ([12.22.58.30]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id uKQ-NsImoUGg for <http-auth@ietfa.amsl.com>; Mon, 23 Jan 2012 06:39:53 -0800 (PST)
Received: from mailout-de.gmx.net (mailout-de.gmx.net [213.165.64.23]) by ietfa.amsl.com (Postfix) with SMTP id ED1BB21F8709 for <http-auth@ietf.org>; Mon, 23 Jan 2012 06:39:52 -0800 (PST)
Received: (qmail invoked by alias); 23 Jan 2012 14:39:51 -0000
Received: from mail.greenbytes.de (EHLO [192.168.1.140]) [217.91.35.233] by mail.gmx.net (mp005) with SMTP; 23 Jan 2012 15:39:51 +0100
X-Authenticated: #1915285
X-Provags-ID: V01U2FsdGVkX1/UYS95wpfU/c19D7UGP6qmku4rCs2F4DGtoIYz/U j4ShthvYm1pN/s
Message-ID: <4F1D7134.80207@gmx.de>
Date: Mon, 23 Jan 2012 15:39:48 +0100
From: Julian Reschke <julian.reschke@gmx.de>
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; rv:9.0) Gecko/20111222 Thunderbird/9.0.1
MIME-Version: 1.0
To: Harry Halpin <hhalpin@w3.org>
References: <4F1D4485.5060806@aist.go.jp>	<006FEB08D9C6444AB014105C9AEB133F017A59DE7E95@il-ex01.ad.checkpoint.com> <4F1D5A14.3040808@gmx.de> <4F1D6D7D.603@w3.org>
In-Reply-To: <4F1D6D7D.603@w3.org>
Content-Type: text/plain; charset=ISO-8859-1; format=flowed
Content-Transfer-Encoding: 7bit
X-Y-GMX-Trusted: 0
Cc: http-auth@ietf.org
Subject: Re: [http-auth] HTTP-Auth activity in oncoming IETF Paris Meeting
X-BeenThere: http-auth@ietf.org
X-Mailman-Version: 2.1.12
Precedence: list
List-Id: HTTP authentication methods <http-auth.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/http-auth>, <mailto:http-auth-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/http-auth>
List-Post: <mailto:http-auth@ietf.org>
List-Help: <mailto:http-auth-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/http-auth>, <mailto:http-auth-request@ietf.org?subject=subscribe>
X-List-Received-Date: Mon, 23 Jan 2012 14:39:54 -0000

On 2012-01-23 15:23, Harry Halpin wrote:
> ...
>> Also: maybe concentrate on what's broken first?
>>
>> - no way to logout (need a Javascript API -> W3C Webapps WG?)
>
> This is going to happen in the Web Cryptography Working Group. The
> charter is finished, W3C WG to begin after patent commitments to charter
> are finalized (expecting mid-February):
>
> http://www.w3.org/2011/11/webcryptography-charter.html

That would be cool.

>> - fix implementations (parsing WWW-Authenticate)
>>
>> - maintain a test suide (W3C Test IG?)
>>
>
> The interest group is for sharing test suite design, a test suite should
> still likely happen under the IETF if the IETF is up for it.

The IETF so far isn't good in hosting tests; if the W3C had the 
infrastructure earlier (because of HTML testing) it might make sense to 
use that.

>> - fix I18N for Basic auth
>>
>> - fix UI issue (better support for HTML-form-based logon to HTTP auth)
>
> As UI is one of the areas that browsers still compete on, standardizing
> UI will simply not happen.

I was referring to what some people call HTML-form based HTTP 
authentication, which works by sending an HTML login form with a 403 
status, and then use JS + XHR to actually perform HTTP auth based on the 
entered credentials. It appears this "works" in Firefox and Internet 
Explorer, so it might make sense to find out what needs to be done to 
make it work better (as in other browsers, and with a proper 401 status 
code).

Best regards, Julian

From ynir@checkpoint.com  Mon Jan 23 06:51:08 2012
Return-Path: <ynir@checkpoint.com>
X-Original-To: http-auth@ietfa.amsl.com
Delivered-To: http-auth@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 33E5021F873A for <http-auth@ietfa.amsl.com>; Mon, 23 Jan 2012 06:51:08 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -10.479
X-Spam-Level: 
X-Spam-Status: No, score=-10.479 tagged_above=-999 required=5 tests=[AWL=0.120, BAYES_00=-2.599, RCVD_IN_DNSWL_HI=-8]
Received: from mail.ietf.org ([12.22.58.30]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id QaihRk4fryC5 for <http-auth@ietfa.amsl.com>; Mon, 23 Jan 2012 06:51:07 -0800 (PST)
Received: from michael.checkpoint.com (smtp.checkpoint.com [194.29.34.68]) by ietfa.amsl.com (Postfix) with ESMTP id EFE5121F8734 for <http-auth@ietf.org>; Mon, 23 Jan 2012 06:51:02 -0800 (PST)
X-CheckPoint: {4F1D70DC-0-1B221DC2-1FFFF}
Received: from il-ex01.ad.checkpoint.com (il-ex01.ad.checkpoint.com [194.29.34.26]) by michael.checkpoint.com (8.13.8/8.13.8) with ESMTP id q0NEoxw6013506;  Mon, 23 Jan 2012 16:51:01 +0200
Received: from il-ex03.ad.checkpoint.com (194.29.34.71) by il-ex01.ad.checkpoint.com (194.29.34.26) with Microsoft SMTP Server (TLS) id 8.3.213.0; Mon, 23 Jan 2012 16:50:59 +0200
Received: from il-ex01.ad.checkpoint.com ([126.0.0.2]) by il-ex03.ad.checkpoint.com ([194.29.34.71]) with mapi; Mon, 23 Jan 2012 16:50:58 +0200
From: Yoav Nir <ynir@checkpoint.com>
To: Harry Halpin <hhalpin@w3.org>
Date: Mon, 23 Jan 2012 16:50:55 +0200
Thread-Topic: [http-auth] HTTP-Auth activity in oncoming IETF Paris Meeting
Thread-Index: AczZ3mqjDXIYtVG6QES+38pmvM+oag==
Message-ID: <B8E9F483-659A-4C89-8115-2496C3236FD9@checkpoint.com>
References: <4F1D4485.5060806@aist.go.jp> <006FEB08D9C6444AB014105C9AEB133F017A59DE7E95@il-ex01.ad.checkpoint.com> <4F1D5A14.3040808@gmx.de> <4F1D6D7D.603@w3.org>
In-Reply-To: <4F1D6D7D.603@w3.org>
Accept-Language: en-US
Content-Language: en-US
X-MS-Has-Attach: 
X-MS-TNEF-Correlator: 
acceptlanguage: en-US
x-kse-antivirus-interceptor-info: scan successful
x-kse-antivirus-info: Clean
Content-Type: text/plain; charset="us-ascii"
Content-Transfer-Encoding: quoted-printable
MIME-Version: 1.0
X-KSE-AntiSpam-Interceptor-Info: protection disabled
Cc: "http-auth@ietf.org" <http-auth@ietf.org>
Subject: Re: [http-auth] HTTP-Auth activity in oncoming IETF Paris Meeting
X-BeenThere: http-auth@ietf.org
X-Mailman-Version: 2.1.12
Precedence: list
List-Id: HTTP authentication methods <http-auth.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/http-auth>, <mailto:http-auth-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/http-auth>
List-Post: <mailto:http-auth@ietf.org>
List-Help: <mailto:http-auth-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/http-auth>, <mailto:http-auth-request@ietf.org?subject=subscribe>
X-List-Received-Date: Mon, 23 Jan 2012 14:51:08 -0000

On Jan 23, 2012, at 4:23 PM, Harry Halpin wrote:
>=20
>> - fix I18N for Basic auth

Do we really want to touch basic auth?

>>=20
>> - fix UI issue (better support for HTML-form-based logon to HTTP auth)
>=20
> As UI is one of the areas that browsers still compete on, standardizing=20
> UI will simply not happen.

While we can't standardize UI (besides, it is bound to look different on a =
desktop screen than on a phone), but we can standardize UI requirements. Sp=
ecifically, we can require that the authentication dialog will be something=
 that cannot be achieved with regular HTML5/Flash/other canvas technologies=
.=

From julian.reschke@gmx.de  Mon Jan 23 07:07:25 2012
Return-Path: <julian.reschke@gmx.de>
X-Original-To: http-auth@ietfa.amsl.com
Delivered-To: http-auth@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 9A1EF21F86C6 for <http-auth@ietfa.amsl.com>; Mon, 23 Jan 2012 07:07:25 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -103.609
X-Spam-Level: 
X-Spam-Status: No, score=-103.609 tagged_above=-999 required=5 tests=[AWL=-1.010, BAYES_00=-2.599, USER_IN_WHITELIST=-100]
Received: from mail.ietf.org ([12.22.58.30]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id UiiTxrennSpJ for <http-auth@ietfa.amsl.com>; Mon, 23 Jan 2012 07:07:25 -0800 (PST)
Received: from mailout-de.gmx.net (mailout-de.gmx.net [213.165.64.23]) by ietfa.amsl.com (Postfix) with SMTP id A6F0C21F86C1 for <http-auth@ietf.org>; Mon, 23 Jan 2012 07:07:24 -0800 (PST)
Received: (qmail invoked by alias); 23 Jan 2012 15:07:23 -0000
Received: from mail.greenbytes.de (EHLO [192.168.1.140]) [217.91.35.233] by mail.gmx.net (mp057) with SMTP; 23 Jan 2012 16:07:23 +0100
X-Authenticated: #1915285
X-Provags-ID: V01U2FsdGVkX186lUQ0xlc6KeN6VBOquSrBaV8tLBSqVCaB/dTQmi 6pIpmIUtGnm+m8
Message-ID: <4F1D77A1.4090401@gmx.de>
Date: Mon, 23 Jan 2012 16:07:13 +0100
From: Julian Reschke <julian.reschke@gmx.de>
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; rv:9.0) Gecko/20111222 Thunderbird/9.0.1
MIME-Version: 1.0
To: Yoav Nir <ynir@checkpoint.com>
References: <4F1D4485.5060806@aist.go.jp> <006FEB08D9C6444AB014105C9AEB133F017A59DE7E95@il-ex01.ad.checkpoint.com> <4F1D5A14.3040808@gmx.de> <4F1D6D7D.603@w3.org> <B8E9F483-659A-4C89-8115-2496C3236FD9@checkpoint.com>
In-Reply-To: <B8E9F483-659A-4C89-8115-2496C3236FD9@checkpoint.com>
Content-Type: text/plain; charset=ISO-8859-1; format=flowed
Content-Transfer-Encoding: 7bit
X-Y-GMX-Trusted: 0
Cc: "http-auth@ietf.org" <http-auth@ietf.org>
Subject: Re: [http-auth] HTTP-Auth activity in oncoming IETF Paris Meeting
X-BeenThere: http-auth@ietf.org
X-Mailman-Version: 2.1.12
Precedence: list
List-Id: HTTP authentication methods <http-auth.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/http-auth>, <mailto:http-auth-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/http-auth>
List-Post: <mailto:http-auth@ietf.org>
List-Help: <mailto:http-auth-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/http-auth>, <mailto:http-auth-request@ietf.org?subject=subscribe>
X-List-Received-Date: Mon, 23 Jan 2012 15:07:25 -0000

On 2012-01-23 15:50, Yoav Nir wrote:
>
> On Jan 23, 2012, at 4:23 PM, Harry Halpin wrote:
>>
>>> - fix I18N for Basic auth
>
> Do we really want to touch basic auth?

It's in use. It suffers from I18N problem. I don't see a simple 
replacement. Why not fix it?

> ...

Best regards, Julian

From tim-research@sentinelchicken.org  Mon Jan 23 08:18:24 2012
Return-Path: <tim-research@sentinelchicken.org>
X-Original-To: http-auth@ietfa.amsl.com
Delivered-To: http-auth@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id D62CA21F87D1 for <http-auth@ietfa.amsl.com>; Mon, 23 Jan 2012 08:18:24 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.265
X-Spam-Level: 
X-Spam-Status: No, score=-2.265 tagged_above=-999 required=5 tests=[BAYES_00=-2.599, IP_NOT_FRIENDLY=0.334]
Received: from mail.ietf.org ([12.22.58.30]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id XO4OySStA3S9 for <http-auth@ietfa.amsl.com>; Mon, 23 Jan 2012 08:18:24 -0800 (PST)
Received: from sentinelchicken.org (mail.sentinelchicken.org [69.168.48.72]) by ietfa.amsl.com (Postfix) with ESMTP id 2517321F84A5 for <http-auth@ietf.org>; Mon, 23 Jan 2012 08:18:23 -0800 (PST)
Received: (qmail 23592 invoked from network); 23 Jan 2012 16:18:22 -0000
Received: from unknown (HELO pascal.sentinelchicken.org) (10.81.64.2) by feynman.sentinelchicken.org with ESMTPS (DHE-RSA-AES256-SHA encrypted); 23 Jan 2012 16:18:22 -0000
Received: (qmail 3327 invoked from network); 23 Jan 2012 16:21:00 -0000
Received: from shannon.sentinelchicken.org (10.81.64.4) by pascal.sentinelchicken.org with SMTP; 23 Jan 2012 16:21:00 -0000
Received: (nullmailer pid 16415 invoked by uid 1000); Mon, 23 Jan 2012 16:18:21 -0000
Date: Mon, 23 Jan 2012 08:18:21 -0800
From: Tim <tim-research@sentinelchicken.org>
To: Yoav Nir <ynir@checkpoint.com>
Message-ID: <20120123161821.GS1689@sentinelchicken.org>
References: <4F1D4485.5060806@aist.go.jp> <006FEB08D9C6444AB014105C9AEB133F017A59DE7E95@il-ex01.ad.checkpoint.com>
MIME-Version: 1.0
Content-Type: text/plain; charset=us-ascii
Content-Disposition: inline
In-Reply-To: <006FEB08D9C6444AB014105C9AEB133F017A59DE7E95@il-ex01.ad.checkpoint.com>
User-Agent: Mutt/1.5.21 (2010-09-15)
Cc: Mark Nottingham <mnot@mnot.net>, "http-auth@ietf.org" <http-auth@ietf.org>, Thomas Roessler <tlr@w3.org>, Alexey Melnikov <alexey.melnikov@isode.com>
Subject: Re: [http-auth] HTTP-Auth activity in oncoming IETF Paris Meeting
X-BeenThere: http-auth@ietf.org
X-Mailman-Version: 2.1.12
Precedence: list
List-Id: HTTP authentication methods <http-auth.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/http-auth>, <mailto:http-auth-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/http-auth>
List-Post: <mailto:http-auth@ietf.org>
List-Help: <mailto:http-auth-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/http-auth>, <mailto:http-auth-request@ietf.org?subject=subscribe>
X-List-Received-Date: Mon, 23 Jan 2012 16:18:24 -0000

I too agree that focusing the discussion a little is in order, and
that improved/new HTTP authentication protocols make sense.

However, I would caution that just because the focus may be on HTTP
authentication, that doesn't mean some effort shouldn't be put into
integration with other layers and standards.  That is, browser
interaction with HTTP authentication continues to be pathetic.  Also,
a lot of value can be derived from improving the way XMLHttpRequest
uses HTTP authentication.

cheers,
tim


On Mon, Jan 23, 2012 at 02:52:08PM +0200, Yoav Nir wrote:
> Hi
> 
> I think a big obstacle to converging on a charter item for a new or existing working group, is that there are so many possible solutions all over the map. We've heard proposals for the authentication in TLS, in HTTP, and in HTML (or more likely javascript)
> 
> If you would like this to lead to charterable work, I suggest you concentrate on one of these avenues (I think the HTTP), and have a good explanation why not the others. Then confine the discussion to that avenue only.
> 
> As I have said in QC, once there's a charter item in some group, you'll get plenty of crypto suggestions. We got 4 competing proposals in IPsecME, so I suggest to keep the crypto out of the discussion for now. Just try to get consensus that we need to work on an HTTP-based method for authentication.
> 
> Yoav
> 
> -----Original Message-----
> From: http-auth-bounces@ietf.org [mailto:http-auth-bounces@ietf.org] On Behalf Of Yutaka OIWA
> Sent: 23 January 2012 13:29
> To: http-auth@ietf.org
> Cc: Alexey Melnikov; Mark Nottingham; Thomas Roessler
> Subject: [http-auth] HTTP-Auth activity in oncoming IETF Paris Meeting
> 
> Dear HTTP-AUTH Members,
> 
> I would like to propose another http-auth meeting-up at IETF Paris.
> Main topic might be face-to-face discussion on our problem-space survey in IETF Sec-area Wiki
> 
> http://trac.tools.ietf.org/area/sec/trac/wiki/HttpAuthentication/ProblemSpace
> 
> so that we can update the problem statement I-D and go forward for possible future chartering.  Suggestions about scheduling, format of meeting, topics or anything other are really welcome.
> 
> I am thankful for several comments and updates for the Wiki contents, and currently I am looking for people who can update the contents especially regarding Negotiate and other authentication mechanisms which enable bridging between HTTP and existing authentication frameworks such as GSS, SASL or Kerberos.  Any volunteers or candidates?
> 
> Since Vancouver we have talked with several people and had presentation sessions in both IIW and W3C TPAC in California.  I'd like to update our project status soon.
> 
> I'm looking forward to seeing you in Paris!
> 
> -- 
> Yutaka OIWA, Ph.D.                                       Research Scientist
>                             Research Center for Information Security (RCIS)
>     National Institute of Advanced Industrial Science and Technology (AIST)
>                       Mail addresses: <y.oiwa@aist.go.jp>, <yutaka@oiwa.jp>
> OpenPGP: id[440546B5] fp[7C9F 723A 7559 3246 229D  3139 8677 9BD2 4405 46B5] _______________________________________________
> http-auth mailing list
> http-auth@ietf.org
> https://www.ietf.org/mailman/listinfo/http-auth
> 
> Scanned by Check Point Total Security Gateway.
> _______________________________________________
> http-auth mailing list
> http-auth@ietf.org
> https://www.ietf.org/mailman/listinfo/http-auth

From tim-research@sentinelchicken.org  Mon Jan 23 08:23:09 2012
Return-Path: <tim-research@sentinelchicken.org>
X-Original-To: http-auth@ietfa.amsl.com
Delivered-To: http-auth@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id E84C721F8729 for <http-auth@ietfa.amsl.com>; Mon, 23 Jan 2012 08:23:09 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.265
X-Spam-Level: 
X-Spam-Status: No, score=-2.265 tagged_above=-999 required=5 tests=[BAYES_00=-2.599, IP_NOT_FRIENDLY=0.334]
Received: from mail.ietf.org ([12.22.58.30]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id NdjJzv7Ruo7G for <http-auth@ietfa.amsl.com>; Mon, 23 Jan 2012 08:23:09 -0800 (PST)
Received: from sentinelchicken.org (mail.sentinelchicken.org [69.168.48.72]) by ietfa.amsl.com (Postfix) with ESMTP id 4605021F871C for <http-auth@ietf.org>; Mon, 23 Jan 2012 08:23:09 -0800 (PST)
Received: (qmail 23616 invoked from network); 23 Jan 2012 16:23:09 -0000
Received: from unknown (HELO pascal.sentinelchicken.org) (10.81.64.2) by feynman.sentinelchicken.org with ESMTPS (DHE-RSA-AES256-SHA encrypted); 23 Jan 2012 16:23:09 -0000
Received: (qmail 3343 invoked from network); 23 Jan 2012 16:25:47 -0000
Received: from shannon.sentinelchicken.org (10.81.64.4) by pascal.sentinelchicken.org with SMTP; 23 Jan 2012 16:25:47 -0000
Received: (nullmailer pid 16503 invoked by uid 1000); Mon, 23 Jan 2012 16:23:08 -0000
Date: Mon, 23 Jan 2012 08:23:08 -0800
From: Tim <tim-research@sentinelchicken.org>
To: Julian Reschke <julian.reschke@gmx.de>
Message-ID: <20120123162308.GT1689@sentinelchicken.org>
References: <4F1D4485.5060806@aist.go.jp> <006FEB08D9C6444AB014105C9AEB133F017A59DE7E95@il-ex01.ad.checkpoint.com> <4F1D5A14.3040808@gmx.de>
MIME-Version: 1.0
Content-Type: text/plain; charset=us-ascii
Content-Disposition: inline
In-Reply-To: <4F1D5A14.3040808@gmx.de>
User-Agent: Mutt/1.5.21 (2010-09-15)
Cc: Alexey Melnikov <alexey.melnikov@isode.com>, Mark Nottingham <mnot@mnot.net>, "http-auth@ietf.org" <http-auth@ietf.org>, Thomas Roessler <tlr@w3.org>
Subject: Re: [http-auth] HTTP-Auth activity in oncoming IETF Paris Meeting
X-BeenThere: http-auth@ietf.org
X-Mailman-Version: 2.1.12
Precedence: list
List-Id: HTTP authentication methods <http-auth.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/http-auth>, <mailto:http-auth-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/http-auth>
List-Post: <mailto:http-auth@ietf.org>
List-Help: <mailto:http-auth-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/http-auth>, <mailto:http-auth-request@ietf.org?subject=subscribe>
X-List-Received-Date: Mon, 23 Jan 2012 16:23:10 -0000

> Also: maybe concentrate on what's broken first?

That seems like that might be a good way to narrow the focus to
achievable goals.  That doesn't mean we should necessarily stick with
existing HTTP auth protocols, but at least defining the WG scope as
trying to address existing HTTP auth shortcomings.


> - no way to logout (need a Javascript API -> W3C Webapps WG?)

YES!


> - fix UI issue (better support for HTML-form-based logon to HTTP auth)

Well, we essentially already have this through XMLHttpRequest.  What
we could use is improvements to the XMLHttpRequest interface so more
advanced HTTP authentication protocols could be used, but for
username/password pairs, the current XMLHttpRequest spec works well.

Yes, I know XMLHttpRequest is JavaScript, not HTML, but it fills the
need for a GUI-based login for users.  HTTP authentication already
handles the need for non-GUI/scripted logins.

tim

From julian.reschke@gmx.de  Mon Jan 23 08:32:53 2012
Return-Path: <julian.reschke@gmx.de>
X-Original-To: http-auth@ietfa.amsl.com
Delivered-To: http-auth@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 0B1AF21F8540 for <http-auth@ietfa.amsl.com>; Mon, 23 Jan 2012 08:32:53 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -103.515
X-Spam-Level: 
X-Spam-Status: No, score=-103.515 tagged_above=-999 required=5 tests=[AWL=-0.916, BAYES_00=-2.599, USER_IN_WHITELIST=-100]
Received: from mail.ietf.org ([12.22.58.30]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id y7+cp9RDYFPM for <http-auth@ietfa.amsl.com>; Mon, 23 Jan 2012 08:32:52 -0800 (PST)
Received: from mailout-de.gmx.net (mailout-de.gmx.net [213.165.64.23]) by ietfa.amsl.com (Postfix) with SMTP id 9F92021F8466 for <http-auth@ietf.org>; Mon, 23 Jan 2012 08:32:51 -0800 (PST)
Received: (qmail invoked by alias); 23 Jan 2012 16:32:50 -0000
Received: from mail.greenbytes.de (EHLO [192.168.1.140]) [217.91.35.233] by mail.gmx.net (mp029) with SMTP; 23 Jan 2012 17:32:50 +0100
X-Authenticated: #1915285
X-Provags-ID: V01U2FsdGVkX19onw5duaRof3FvhkHFcOdxR11AzwERckuo1QVfIS n7fmJo8tOgXwrY
Message-ID: <4F1D8BAD.7000603@gmx.de>
Date: Mon, 23 Jan 2012 17:32:45 +0100
From: Julian Reschke <julian.reschke@gmx.de>
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; rv:9.0) Gecko/20111222 Thunderbird/9.0.1
MIME-Version: 1.0
To: Tim <tim-research@sentinelchicken.org>
References: <4F1D4485.5060806@aist.go.jp> <006FEB08D9C6444AB014105C9AEB133F017A59DE7E95@il-ex01.ad.checkpoint.com> <4F1D5A14.3040808@gmx.de> <20120123162308.GT1689@sentinelchicken.org>
In-Reply-To: <20120123162308.GT1689@sentinelchicken.org>
Content-Type: text/plain; charset=ISO-8859-1; format=flowed
Content-Transfer-Encoding: 7bit
X-Y-GMX-Trusted: 0
Cc: Alexey Melnikov <alexey.melnikov@isode.com>, Mark Nottingham <mnot@mnot.net>, "http-auth@ietf.org" <http-auth@ietf.org>, Thomas Roessler <tlr@w3.org>
Subject: Re: [http-auth] HTTP-Auth activity in oncoming IETF Paris Meeting
X-BeenThere: http-auth@ietf.org
X-Mailman-Version: 2.1.12
Precedence: list
List-Id: HTTP authentication methods <http-auth.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/http-auth>, <mailto:http-auth-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/http-auth>
List-Post: <mailto:http-auth@ietf.org>
List-Help: <mailto:http-auth-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/http-auth>, <mailto:http-auth-request@ietf.org?subject=subscribe>
X-List-Received-Date: Mon, 23 Jan 2012 16:32:53 -0000

On 2012-01-23 17:23, Tim wrote:
>
>> Also: maybe concentrate on what's broken first?
>
> That seems like that might be a good way to narrow the focus to
> achievable goals.  That doesn't mean we should necessarily stick with
> existing HTTP auth protocols, but at least defining the WG scope as
> trying to address existing HTTP auth shortcomings.
>
>
>> - no way to logout (need a Javascript API ->  W3C Webapps WG?)
>
> YES!
>
>
>> - fix UI issue (better support for HTML-form-based logon to HTTP auth)
>
> Well, we essentially already have this through XMLHttpRequest.  What
> we could use is improvements to the XMLHttpRequest interface so more
> advanced HTTP authentication protocols could be used, but for
> username/password pairs, the current XMLHttpRequest spec works well.
>
> Yes, I know XMLHttpRequest is JavaScript, not HTML, but it fills the
> need for a GUI-based login for users.  HTTP authentication already
> handles the need for non-GUI/scripted logins.

But unless I'm missing something, it requires using a non-401 response 
to initiate the login. That's cheating, because the server needs to 
special-case clients that can use the form from others.

One way to address this might be an auth-param that allows the recipient 
to display the response body despite it being sent with 401 with a known 
auth scheme.

Best regards, Julian

From tim-research@sentinelchicken.org  Mon Jan 23 08:40:26 2012
Return-Path: <tim-research@sentinelchicken.org>
X-Original-To: http-auth@ietfa.amsl.com
Delivered-To: http-auth@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id C04E621F86A4 for <http-auth@ietfa.amsl.com>; Mon, 23 Jan 2012 08:40:26 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.265
X-Spam-Level: 
X-Spam-Status: No, score=-2.265 tagged_above=-999 required=5 tests=[BAYES_00=-2.599, IP_NOT_FRIENDLY=0.334]
Received: from mail.ietf.org ([12.22.58.30]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id jTfNHhKxhnTh for <http-auth@ietfa.amsl.com>; Mon, 23 Jan 2012 08:40:26 -0800 (PST)
Received: from sentinelchicken.org (mail.sentinelchicken.org [69.168.48.72]) by ietfa.amsl.com (Postfix) with ESMTP id 2D02621F8686 for <http-auth@ietf.org>; Mon, 23 Jan 2012 08:40:26 -0800 (PST)
Received: (qmail 24767 invoked from network); 23 Jan 2012 16:40:26 -0000
Received: from unknown (HELO pascal.sentinelchicken.org) (10.81.64.2) by feynman.sentinelchicken.org with ESMTPS (DHE-RSA-AES256-SHA encrypted); 23 Jan 2012 16:40:26 -0000
Received: (qmail 6690 invoked from network); 23 Jan 2012 16:43:04 -0000
Received: from shannon.sentinelchicken.org (10.81.64.4) by pascal.sentinelchicken.org with SMTP; 23 Jan 2012 16:43:04 -0000
Received: (nullmailer pid 16657 invoked by uid 1000); Mon, 23 Jan 2012 16:40:25 -0000
Date: Mon, 23 Jan 2012 08:40:25 -0800
From: Tim <tim-research@sentinelchicken.org>
To: Julian Reschke <julian.reschke@gmx.de>
Message-ID: <20120123164025.GU1689@sentinelchicken.org>
References: <4F1D4485.5060806@aist.go.jp> <006FEB08D9C6444AB014105C9AEB133F017A59DE7E95@il-ex01.ad.checkpoint.com> <4F1D5A14.3040808@gmx.de> <20120123162308.GT1689@sentinelchicken.org> <4F1D8BAD.7000603@gmx.de>
MIME-Version: 1.0
Content-Type: text/plain; charset=us-ascii
Content-Disposition: inline
In-Reply-To: <4F1D8BAD.7000603@gmx.de>
User-Agent: Mutt/1.5.21 (2010-09-15)
Cc: Alexey Melnikov <alexey.melnikov@isode.com>, Mark Nottingham <mnot@mnot.net>, "http-auth@ietf.org" <http-auth@ietf.org>, Thomas Roessler <tlr@w3.org>
Subject: Re: [http-auth] HTTP-Auth activity in oncoming IETF Paris Meeting
X-BeenThere: http-auth@ietf.org
X-Mailman-Version: 2.1.12
Precedence: list
List-Id: HTTP authentication methods <http-auth.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/http-auth>, <mailto:http-auth-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/http-auth>
List-Post: <mailto:http-auth@ietf.org>
List-Help: <mailto:http-auth-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/http-auth>, <mailto:http-auth-request@ietf.org?subject=subscribe>
X-List-Received-Date: Mon, 23 Jan 2012 16:40:26 -0000

> >>- fix UI issue (better support for HTML-form-based logon to HTTP auth)
> >
> >Well, we essentially already have this through XMLHttpRequest.  What
> >we could use is improvements to the XMLHttpRequest interface so more
> >advanced HTTP authentication protocols could be used, but for
> >username/password pairs, the current XMLHttpRequest spec works well.
> >
> >Yes, I know XMLHttpRequest is JavaScript, not HTML, but it fills the
> >need for a GUI-based login for users.  HTTP authentication already
> >handles the need for non-GUI/scripted logins.
> 
> But unless I'm missing something, it requires using a non-401
> response to initiate the login. That's cheating, because the server
> needs to special-case clients that can use the form from others.

Actually, if my memory serves correctly, the only reason this is
necessary is because browsers don't follow the W3C XMLHttpRequest
spec.  They prompt users with a dialog box upon receiving an XHR 401
response whereas the spec explicitly states that they shouldn't do
this under certain conditions.  So it's just an implementation issue
(across the board).


> One way to address this might be an auth-param that allows the
> recipient to display the response body despite it being sent with
> 401 with a known auth scheme.

Yeah, fortunately this shouldn't be necessary if browsers just
followed the XMLHttpRequest spec.


Good thing to point out though,
tim

From julian.reschke@gmx.de  Mon Jan 23 08:50:20 2012
Return-Path: <julian.reschke@gmx.de>
X-Original-To: http-auth@ietfa.amsl.com
Delivered-To: http-auth@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id CF03721F8710 for <http-auth@ietfa.amsl.com>; Mon, 23 Jan 2012 08:50:20 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -103.487
X-Spam-Level: 
X-Spam-Status: No, score=-103.487 tagged_above=-999 required=5 tests=[AWL=-0.888, BAYES_00=-2.599, USER_IN_WHITELIST=-100]
Received: from mail.ietf.org ([12.22.58.30]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id VlszNe817Euk for <http-auth@ietfa.amsl.com>; Mon, 23 Jan 2012 08:50:20 -0800 (PST)
Received: from mailout-de.gmx.net (mailout-de.gmx.net [213.165.64.23]) by ietfa.amsl.com (Postfix) with SMTP id DB8F421F86F8 for <http-auth@ietf.org>; Mon, 23 Jan 2012 08:50:19 -0800 (PST)
Received: (qmail invoked by alias); 23 Jan 2012 16:50:18 -0000
Received: from mail.greenbytes.de (EHLO [192.168.1.140]) [217.91.35.233] by mail.gmx.net (mp059) with SMTP; 23 Jan 2012 17:50:18 +0100
X-Authenticated: #1915285
X-Provags-ID: V01U2FsdGVkX18lPhUasSklgjER3lUEXFKSEG05/ANpprOr0QfOwk VxL6Y8kcPI+Rjo
Message-ID: <4F1D8FC7.4070602@gmx.de>
Date: Mon, 23 Jan 2012 17:50:15 +0100
From: Julian Reschke <julian.reschke@gmx.de>
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; rv:9.0) Gecko/20111222 Thunderbird/9.0.1
MIME-Version: 1.0
To: Tim <tim-research@sentinelchicken.org>
References: <4F1D4485.5060806@aist.go.jp> <006FEB08D9C6444AB014105C9AEB133F017A59DE7E95@il-ex01.ad.checkpoint.com> <4F1D5A14.3040808@gmx.de> <20120123162308.GT1689@sentinelchicken.org> <4F1D8BAD.7000603@gmx.de> <20120123164025.GU1689@sentinelchicken.org>
In-Reply-To: <20120123164025.GU1689@sentinelchicken.org>
Content-Type: text/plain; charset=ISO-8859-1; format=flowed
Content-Transfer-Encoding: 7bit
X-Y-GMX-Trusted: 0
Cc: Alexey Melnikov <alexey.melnikov@isode.com>, Mark Nottingham <mnot@mnot.net>, "http-auth@ietf.org" <http-auth@ietf.org>, Thomas Roessler <tlr@w3.org>
Subject: Re: [http-auth] HTTP-Auth activity in oncoming IETF Paris Meeting
X-BeenThere: http-auth@ietf.org
X-Mailman-Version: 2.1.12
Precedence: list
List-Id: HTTP authentication methods <http-auth.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/http-auth>, <mailto:http-auth-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/http-auth>
List-Post: <mailto:http-auth@ietf.org>
List-Help: <mailto:http-auth-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/http-auth>, <mailto:http-auth-request@ietf.org?subject=subscribe>
X-List-Received-Date: Mon, 23 Jan 2012 16:50:21 -0000

On 2012-01-23 17:40, Tim wrote:
> ...
> Actually, if my memory serves correctly, the only reason this is
> necessary is because browsers don't follow the W3C XMLHttpRequest
> spec.  They prompt users with a dialog box upon receiving an XHR 401
> response whereas the spec explicitly states that they shouldn't do
> this under certain conditions.  So it's just an implementation issue
> (across the board).
> ...

Not sure. The whole point here is that you can open a browser with a URI 
requiring auth, and the right thing happens. In this case, the request 
that needs authentication is not an XHR request.

>> One way to address this might be an auth-param that allows the
>> recipient to display the response body despite it being sent with
>> 401 with a known auth scheme.
>
> Yeah, fortunately this shouldn't be necessary if browsers just
> followed the XMLHttpRequest spec.

...not sure (see above). This shows it needs to be written down :-).

From tim-research@sentinelchicken.org  Mon Jan 23 09:17:59 2012
Return-Path: <tim-research@sentinelchicken.org>
X-Original-To: http-auth@ietfa.amsl.com
Delivered-To: http-auth@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 8FE2A21F85F6 for <http-auth@ietfa.amsl.com>; Mon, 23 Jan 2012 09:17:59 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.265
X-Spam-Level: 
X-Spam-Status: No, score=-2.265 tagged_above=-999 required=5 tests=[BAYES_00=-2.599, IP_NOT_FRIENDLY=0.334]
Received: from mail.ietf.org ([12.22.58.30]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id lwFAUMVh54Jm for <http-auth@ietfa.amsl.com>; Mon, 23 Jan 2012 09:17:59 -0800 (PST)
Received: from sentinelchicken.org (mail.sentinelchicken.org [69.168.48.72]) by ietfa.amsl.com (Postfix) with ESMTP id DBE2F21F85B9 for <http-auth@ietf.org>; Mon, 23 Jan 2012 09:17:58 -0800 (PST)
Received: (qmail 25284 invoked from network); 23 Jan 2012 17:17:58 -0000
Received: from unknown (HELO pascal.sentinelchicken.org) (10.81.64.2) by feynman.sentinelchicken.org with ESMTPS (DHE-RSA-AES256-SHA encrypted); 23 Jan 2012 17:17:58 -0000
Received: (qmail 8119 invoked from network); 23 Jan 2012 17:20:36 -0000
Received: from shannon.sentinelchicken.org (10.81.64.4) by pascal.sentinelchicken.org with SMTP; 23 Jan 2012 17:20:36 -0000
Received: (nullmailer pid 16941 invoked by uid 1000); Mon, 23 Jan 2012 17:17:57 -0000
Date: Mon, 23 Jan 2012 09:17:57 -0800
From: Tim <tim-research@sentinelchicken.org>
To: Julian Reschke <julian.reschke@gmx.de>
Message-ID: <20120123171757.GV1689@sentinelchicken.org>
References: <4F1D4485.5060806@aist.go.jp> <006FEB08D9C6444AB014105C9AEB133F017A59DE7E95@il-ex01.ad.checkpoint.com> <4F1D5A14.3040808@gmx.de> <20120123162308.GT1689@sentinelchicken.org> <4F1D8BAD.7000603@gmx.de> <20120123164025.GU1689@sentinelchicken.org> <4F1D8FC7.4070602@gmx.de>
MIME-Version: 1.0
Content-Type: text/plain; charset=us-ascii
Content-Disposition: inline
In-Reply-To: <4F1D8FC7.4070602@gmx.de>
User-Agent: Mutt/1.5.21 (2010-09-15)
Cc: Alexey Melnikov <alexey.melnikov@isode.com>, Mark Nottingham <mnot@mnot.net>, "http-auth@ietf.org" <http-auth@ietf.org>, Thomas Roessler <tlr@w3.org>
Subject: Re: [http-auth] HTTP-Auth activity in oncoming IETF Paris Meeting
X-BeenThere: http-auth@ietf.org
X-Mailman-Version: 2.1.12
Precedence: list
List-Id: HTTP authentication methods <http-auth.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/http-auth>, <mailto:http-auth-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/http-auth>
List-Post: <mailto:http-auth@ietf.org>
List-Help: <mailto:http-auth-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/http-auth>, <mailto:http-auth-request@ietf.org?subject=subscribe>
X-List-Received-Date: Mon, 23 Jan 2012 17:17:59 -0000

> Not sure. The whole point here is that you can open a browser with a
> URI requiring auth, and the right thing happens. In this case, the
> request that needs authentication is not an XHR request.

Ok, to put a finer point on it, the following website login setup
should be possible right now without any nonstandard response codes
and without changes to any specs:

/login.html   - plain HTML page with JavaScript
/authenticate - dynamic page which performs HTTP authentication

The login.html page includes a normal login form.  Upon submitting it,
JavaScript uses XMLHttpRequests to set up the user's HTTP auth session
by sending requests to /authenticate.  For clients that don't support
JavaScript, a simple HTML link which points to /authenticate can be
provided.  

I suppose if you were clever, you could provide an /index.html page
which detects whether or not JavaScript is supported and redirects
users to the appropriate page, maybe using a combination of META
redirect timeouts and JavaScript.



Now, if you want to have *true* integration with forms, we certainly
could pressure browser makers to:

A.  Not pop-up an annoying modal dialog when a 401 is received.
Instead, provide a login prompt in the "chrome" next to the URL bar.

B. Display the page content of a 401 at the same time that the chrome
password prompt appears.

I've spent quite a bit of time searching the HTTP RFCs to locate
anything that forbids this behavior and haven't found anything.  It is
currently just an implementation choice that browsers aren't
displaying the 401 body.

This change would allow /login.html and /authenticate to be merged
into a single page.  Sites that don't want two password prompts to
appear on the same page (chrome+401 body) could continue to use the
split page approach that works right now.


> ...not sure (see above). This shows it needs to be written down :-).

I'm thinking this latter change is what you are referring to, yes?  I
agree it is worth defining these behaviors in more detail and at least
setting down in words what would be a better approach.  I think
improvements to XMLHttpRequest will be important too, to allow for
more advanced HTTP auth protocols in the future.

Thanks,
tim

From julian.reschke@gmx.de  Mon Jan 23 09:35:41 2012
Return-Path: <julian.reschke@gmx.de>
X-Original-To: http-auth@ietfa.amsl.com
Delivered-To: http-auth@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 0804221F85D7 for <http-auth@ietfa.amsl.com>; Mon, 23 Jan 2012 09:35:41 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -103.461
X-Spam-Level: 
X-Spam-Status: No, score=-103.461 tagged_above=-999 required=5 tests=[AWL=-0.862, BAYES_00=-2.599, USER_IN_WHITELIST=-100]
Received: from mail.ietf.org ([12.22.58.30]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id m894bADxFo9X for <http-auth@ietfa.amsl.com>; Mon, 23 Jan 2012 09:35:40 -0800 (PST)
Received: from mailout-de.gmx.net (mailout-de.gmx.net [213.165.64.23]) by ietfa.amsl.com (Postfix) with SMTP id D05E721F84A2 for <http-auth@ietf.org>; Mon, 23 Jan 2012 09:35:39 -0800 (PST)
Received: (qmail invoked by alias); 23 Jan 2012 17:35:38 -0000
Received: from mail.greenbytes.de (EHLO [192.168.1.140]) [217.91.35.233] by mail.gmx.net (mp067) with SMTP; 23 Jan 2012 18:35:38 +0100
X-Authenticated: #1915285
X-Provags-ID: V01U2FsdGVkX18a4jNK0SwauhMqYJtuz71uq0Vy27hmk6mcg2BfbD OFnRtV/fTykDk9
Message-ID: <4F1D9A66.6070303@gmx.de>
Date: Mon, 23 Jan 2012 18:35:34 +0100
From: Julian Reschke <julian.reschke@gmx.de>
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; rv:9.0) Gecko/20111222 Thunderbird/9.0.1
MIME-Version: 1.0
To: Tim <tim-research@sentinelchicken.org>
References: <4F1D4485.5060806@aist.go.jp> <006FEB08D9C6444AB014105C9AEB133F017A59DE7E95@il-ex01.ad.checkpoint.com> <4F1D5A14.3040808@gmx.de> <20120123162308.GT1689@sentinelchicken.org> <4F1D8BAD.7000603@gmx.de> <20120123164025.GU1689@sentinelchicken.org> <4F1D8FC7.4070602@gmx.de> <20120123171757.GV1689@sentinelchicken.org>
In-Reply-To: <20120123171757.GV1689@sentinelchicken.org>
Content-Type: text/plain; charset=ISO-8859-1; format=flowed
Content-Transfer-Encoding: 7bit
X-Y-GMX-Trusted: 0
Cc: Alexey Melnikov <alexey.melnikov@isode.com>, Mark Nottingham <mnot@mnot.net>, "http-auth@ietf.org" <http-auth@ietf.org>, Thomas Roessler <tlr@w3.org>
Subject: Re: [http-auth] HTTP-Auth activity in oncoming IETF Paris Meeting
X-BeenThere: http-auth@ietf.org
X-Mailman-Version: 2.1.12
Precedence: list
List-Id: HTTP authentication methods <http-auth.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/http-auth>, <mailto:http-auth-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/http-auth>
List-Post: <mailto:http-auth@ietf.org>
List-Help: <mailto:http-auth-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/http-auth>, <mailto:http-auth-request@ietf.org?subject=subscribe>
X-List-Received-Date: Mon, 23 Jan 2012 17:35:41 -0000

On 2012-01-23 18:17, Tim wrote:
>> Not sure. The whole point here is that you can open a browser with a
>> URI requiring auth, and the right thing happens. In this case, the
>> request that needs authentication is not an XHR request.
>
> Ok, to put a finer point on it, the following website login setup
> should be possible right now without any nonstandard response codes
> and without changes to any specs:
>
> /login.html   - plain HTML page with JavaScript
> /authenticate - dynamic page which performs HTTP authentication
>
> The login.html page includes a normal login form.  Upon submitting it,
> JavaScript uses XMLHttpRequests to set up the user's HTTP auth session
> by sending requests to /authenticate.  For clients that don't support
> JavaScript, a simple HTML link which points to /authenticate can be
> provided.
>
> I suppose if you were clever, you could provide an /index.html page
> which detects whether or not JavaScript is supported and redirects
> users to the appropriate page, maybe using a combination of META
> redirect timeouts and JavaScript.

Yes, and people are doing that (using UA sniffing).

Optimally, we wouldn't need sniffing, and also server login.html with a 
status of 401.

> Now, if you want to have *true* integration with forms, we certainly
> could pressure browser makers to:
>
> A.  Not pop-up an annoying modal dialog when a 401 is received.
> Instead, provide a login prompt in the "chrome" next to the URL bar.
>
> B. Display the page content of a 401 at the same time that the chrome
> password prompt appears.
>
> I've spent quite a bit of time searching the HTTP RFCs to locate
> anything that forbids this behavior and haven't found anything.  It is
> currently just an implementation choice that browsers aren't
> displaying the 401 body.

Displaying both a login field somewhere *and* the response body (which 
usually isn't helpful) probably would be confusing.

The browsers may need an indicator that tells them that the response 
body really is worth displaying.

> This change would allow /login.html and /authenticate to be merged
> into a single page.  Sites that don't want two password prompts to
> appear on the same page (chrome+401 body) could continue to use the
> split page approach that works right now.
>
>
>> ...not sure (see above). This shows it needs to be written down :-).
>
> I'm thinking this latter change is what you are referring to, yes?  I
> agree it is worth defining these behaviors in more detail and at least
> setting down in words what would be a better approach.  I think
> improvements to XMLHttpRequest will be important too, to allow for
> more advanced HTTP auth protocols in the future.

As far as I can tell, XHR-based login doesn't work with Safari and Opera 
(<http://www.peej.co.uk/articles/http-auth-with-html-forms.html>); it 
would be worthwhile to investigate this (bug or just an implementation 
detail?) and to see whether the situation can be improved.

Best regards, Julian


From tim-research@sentinelchicken.org  Mon Jan 23 09:54:05 2012
Return-Path: <tim-research@sentinelchicken.org>
X-Original-To: http-auth@ietfa.amsl.com
Delivered-To: http-auth@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 08B1C21F86A0 for <http-auth@ietfa.amsl.com>; Mon, 23 Jan 2012 09:54:05 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -3.265
X-Spam-Level: 
X-Spam-Status: No, score=-3.265 tagged_above=-999 required=5 tests=[AWL=1.000,  BAYES_00=-2.599, GB_I_LETTER=-2, IP_NOT_FRIENDLY=0.334]
Received: from mail.ietf.org ([12.22.58.30]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id lDTS3+QYKJXo for <http-auth@ietfa.amsl.com>; Mon, 23 Jan 2012 09:54:03 -0800 (PST)
Received: from sentinelchicken.org (mail.sentinelchicken.org [69.168.48.72]) by ietfa.amsl.com (Postfix) with ESMTP id 8FB8E21F8467 for <http-auth@ietf.org>; Mon, 23 Jan 2012 09:54:03 -0800 (PST)
Received: (qmail 25511 invoked from network); 23 Jan 2012 17:54:01 -0000
Received: from unknown (HELO pascal.sentinelchicken.org) (10.81.64.2) by feynman.sentinelchicken.org with ESMTPS (DHE-RSA-AES256-SHA encrypted); 23 Jan 2012 17:54:01 -0000
Received: (qmail 9470 invoked from network); 23 Jan 2012 17:56:39 -0000
Received: from shannon.sentinelchicken.org (10.81.64.4) by pascal.sentinelchicken.org with SMTP; 23 Jan 2012 17:56:39 -0000
Received: (nullmailer pid 17353 invoked by uid 1000); Mon, 23 Jan 2012 17:54:00 -0000
Date: Mon, 23 Jan 2012 09:54:00 -0800
From: Tim <tim-research@sentinelchicken.org>
To: Julian Reschke <julian.reschke@gmx.de>
Message-ID: <20120123175400.GW1689@sentinelchicken.org>
References: <4F1D4485.5060806@aist.go.jp> <006FEB08D9C6444AB014105C9AEB133F017A59DE7E95@il-ex01.ad.checkpoint.com> <4F1D5A14.3040808@gmx.de> <20120123162308.GT1689@sentinelchicken.org> <4F1D8BAD.7000603@gmx.de> <20120123164025.GU1689@sentinelchicken.org> <4F1D8FC7.4070602@gmx.de> <20120123171757.GV1689@sentinelchicken.org> <4F1D9A66.6070303@gmx.de>
MIME-Version: 1.0
Content-Type: text/plain; charset=us-ascii
Content-Disposition: inline
In-Reply-To: <4F1D9A66.6070303@gmx.de>
User-Agent: Mutt/1.5.21 (2010-09-15)
Cc: Alexey Melnikov <alexey.melnikov@isode.com>, Mark Nottingham <mnot@mnot.net>, "http-auth@ietf.org" <http-auth@ietf.org>, Thomas Roessler <tlr@w3.org>
Subject: Re: [http-auth] HTTP-Auth activity in oncoming IETF Paris Meeting
X-BeenThere: http-auth@ietf.org
X-Mailman-Version: 2.1.12
Precedence: list
List-Id: HTTP authentication methods <http-auth.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/http-auth>, <mailto:http-auth-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/http-auth>
List-Post: <mailto:http-auth@ietf.org>
List-Help: <mailto:http-auth-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/http-auth>, <mailto:http-auth-request@ietf.org?subject=subscribe>
X-List-Received-Date: Mon, 23 Jan 2012 17:54:05 -0000

> Displaying both a login field somewhere *and* the response body
> (which usually isn't helpful) probably would be confusing.
> 
> The browsers may need an indicator that tells them that the response
> body really is worth displaying.

That certainly doesn't hurt to have.

> As far as I can tell, XHR-based login doesn't work with Safari and
> Opera
> (<http://www.peej.co.uk/articles/http-auth-with-html-forms.html>);
> it would be worthwhile to investigate this (bug or just an
> implementation detail?) and to see whether the situation can be
> improved.

In my investigation a couple of years ago, I was able to get Safari
working fine, but not Opera.  (I believe I used the peej.co.uk article
as a reference, as it looks familiar.)  All of the browsers would be a lot
easier to deal with if they followed the XHR spec to the letter, but
some deviate more than others.  Check out the source comments in my
proof of concept implementation:
  http://vsecurity.com/download/tools/fbha-poc_0.1.zip

I did try to contact developers for the top 5 browsers after I did
this investigation, but it is very difficult to get meaningful
dialog going with many of them.  If we have a more comprehensive HTTP
auth story as to why browser makers should follow existing specs, then
maybe it would be easier to get traction. It would be interesting to
test the various scenarios on recent versions of browsers, now that
some time has passed.

tim

From hannes.tschofenig@gmx.net  Mon Jan 23 10:12:55 2012
Return-Path: <hannes.tschofenig@gmx.net>
X-Original-To: http-auth@ietfa.amsl.com
Delivered-To: http-auth@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 9B38121F86E8 for <http-auth@ietfa.amsl.com>; Mon, 23 Jan 2012 10:12:55 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -102.546
X-Spam-Level: 
X-Spam-Status: No, score=-102.546 tagged_above=-999 required=5 tests=[AWL=0.053, BAYES_00=-2.599, USER_IN_WHITELIST=-100]
Received: from mail.ietf.org ([12.22.58.30]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id M3KepXi3GnQT for <http-auth@ietfa.amsl.com>; Mon, 23 Jan 2012 10:12:54 -0800 (PST)
Received: from mailout-de.gmx.net (mailout-de.gmx.net [213.165.64.23]) by ietfa.amsl.com (Postfix) with SMTP id 1F62321F86DA for <http-auth@ietf.org>; Mon, 23 Jan 2012 10:12:53 -0800 (PST)
Received: (qmail invoked by alias); 23 Jan 2012 18:12:51 -0000
Received: from a88-115-216-191.elisa-laajakaista.fi (EHLO [192.168.100.106]) [88.115.216.191] by mail.gmx.net (mp007) with SMTP; 23 Jan 2012 19:12:51 +0100
X-Authenticated: #29516787
X-Provags-ID: V01U2FsdGVkX1/dNlV2njPdghb9zhCrZsuPXk+i+MT3wu87ebmvBI gO5rTWUkd1RWdV
Mime-Version: 1.0 (Apple Message framework v1084)
Content-Type: text/plain; charset=us-ascii
From: Hannes Tschofenig <hannes.tschofenig@gmx.net>
In-Reply-To: <4F1D4485.5060806@aist.go.jp>
Date: Mon, 23 Jan 2012 20:12:49 +0200
Content-Transfer-Encoding: quoted-printable
Message-Id: <BF7F2CBF-E7FB-46F2-92B5-F56595F0A5AE@gmx.net>
References: <4F1D4485.5060806@aist.go.jp>
To: Yutaka OIWA <y.oiwa@aist.go.jp>
X-Mailer: Apple Mail (2.1084)
X-Y-GMX-Trusted: 0
Cc: "http-auth@ietf.org" <http-auth@ietf.org>, Mark Nottingham <mnot@mnot.net>, Thomas Roessler <tlr@w3.org>, Alexey Melnikov <alexey.melnikov@isode.com>
Subject: Re: [http-auth] HTTP-Auth activity in oncoming IETF Paris Meeting
X-BeenThere: http-auth@ietf.org
X-Mailman-Version: 2.1.12
Precedence: list
List-Id: HTTP authentication methods <http-auth.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/http-auth>, <mailto:http-auth-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/http-auth>
List-Post: <mailto:http-auth@ietf.org>
List-Help: <mailto:http-auth-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/http-auth>, <mailto:http-auth-request@ietf.org?subject=subscribe>
X-List-Received-Date: Mon, 23 Jan 2012 18:12:55 -0000

Hi Yutaka,=20

you may want to take a look at this document:
http://tools.ietf.org/html/draft-tschofenig-secure-the-web-00

Ciao
Hannes

On Jan 23, 2012, at 1:29 PM, Yutaka OIWA wrote:

> Dear HTTP-AUTH Members,
>=20
> I would like to propose another http-auth meeting-up at IETF Paris.
> Main topic might be face-to-face discussion on our problem-space
> survey in IETF Sec-area Wiki
>=20
> =
http://trac.tools.ietf.org/area/sec/trac/wiki/HttpAuthentication/ProblemSp=
ace
>=20
> so that we can update the problem statement I-D and go forward for =
possible
> future chartering.  Suggestions about scheduling, format of meeting, =
topics or
> anything other are really welcome.
>=20
> I am thankful for several comments and updates for the Wiki contents, =
and
> currently I am looking for people who can update the contents =
especially
> regarding Negotiate and other authentication mechanisms which enable
> bridging between HTTP and existing authentication frameworks such as
> GSS, SASL or Kerberos.  Any volunteers or candidates?
>=20
> Since Vancouver we have talked with several people and had =
presentation sessions
> in both IIW and W3C TPAC in California.  I'd like to update our =
project status soon.
>=20
> I'm looking forward to seeing you in Paris!
>=20
> --=20
> Yutaka OIWA, Ph.D.                                       Research =
Scientist
>                            Research Center for Information Security =
(RCIS)
>    National Institute of Advanced Industrial Science and Technology =
(AIST)
>                      Mail addresses: <y.oiwa@aist.go.jp>, =
<yutaka@oiwa.jp>
> OpenPGP: id[440546B5] fp[7C9F 723A 7559 3246 229D  3139 8677 9BD2 4405 =
46B5]
> _______________________________________________
> http-auth mailing list
> http-auth@ietf.org
> https://www.ietf.org/mailman/listinfo/http-auth


From hotz@jpl.nasa.gov  Mon Jan 23 18:01:38 2012
Return-Path: <hotz@jpl.nasa.gov>
X-Original-To: http-auth@ietfa.amsl.com
Delivered-To: http-auth@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 9DF8721F85E7 for <http-auth@ietfa.amsl.com>; Mon, 23 Jan 2012 18:01:38 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -6.599
X-Spam-Level: 
X-Spam-Status: No, score=-6.599 tagged_above=-999 required=5 tests=[BAYES_00=-2.599, RCVD_IN_DNSWL_MED=-4]
Received: from mail.ietf.org ([12.22.58.30]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id fhn3uXhxNBqo for <http-auth@ietfa.amsl.com>; Mon, 23 Jan 2012 18:01:38 -0800 (PST)
Received: from mail.jpl.nasa.gov (smtp.jpl.nasa.gov [128.149.139.105]) by ietfa.amsl.com (Postfix) with ESMTP id AD84421F85E6 for <http-auth@ietf.org>; Mon, 23 Jan 2012 18:01:33 -0800 (PST)
Received: from laphotz.jpl.nasa.gov (laphotz.jpl.nasa.gov [128.149.133.44]) (authenticated (0 bits)) by smtp.jpl.nasa.gov (Switch-3.4.3/Switch-3.4.3) with ESMTP id q0O21VXp029803 (using TLSv1/SSLv3 with cipher AES128-SHA (128 bits) verified NO) for <http-auth@ietf.org>; Mon, 23 Jan 2012 18:01:33 -0800
Content-Type: text/plain; charset=us-ascii
Mime-Version: 1.0 (Apple Message framework v1084)
From: "Henry B. Hotz" <hotz@jpl.nasa.gov>
In-Reply-To: <4F1D5A14.3040808@gmx.de>
Date: Mon, 23 Jan 2012 18:01:31 -0800
Content-Transfer-Encoding: quoted-printable
Message-Id: <F527EB5A-D780-43B8-A5AE-B0664F05F965@jpl.nasa.gov>
References: <4F1D4485.5060806@aist.go.jp> <006FEB08D9C6444AB014105C9AEB133F017A59DE7E95@il-ex01.ad.checkpoint.com> <4F1D5A14.3040808@gmx.de>
To: http-auth@ietf.org
X-Mailer: Apple Mail (2.1084)
X-Source-IP: laphotz.jpl.nasa.gov [128.149.133.44]
X-Source-Sender: hotz@jpl.nasa.gov
X-AUTH: Authorized
Subject: Re: [http-auth] HTTP-Auth activity in oncoming IETF Paris Meeting
X-BeenThere: http-auth@ietf.org
X-Mailman-Version: 2.1.12
Precedence: list
List-Id: HTTP authentication methods <http-auth.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/http-auth>, <mailto:http-auth-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/http-auth>
List-Post: <mailto:http-auth@ietf.org>
List-Help: <mailto:http-auth-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/http-auth>, <mailto:http-auth-request@ietf.org?subject=subscribe>
X-List-Received-Date: Tue, 24 Jan 2012 02:01:38 -0000

IIRC there was some consensus that real security was not possible unless =
it interacted with browser chrome.  (Any html form is inherently =
spoofable, since an evil MITM web site just issues html that looks the =
same to the user.)

Will there be representation from the major browser vendors present?

------------------------------------------------------
The opinions expressed in this message are mine,
not those of Caltech, JPL, NASA, or the US Government.
Henry.B.Hotz@jpl.nasa.gov, or hbhotz@oxy.edu


From julian.reschke@gmx.de  Thu Jan 26 00:29:50 2012
Return-Path: <julian.reschke@gmx.de>
X-Original-To: http-auth@ietfa.amsl.com
Delivered-To: http-auth@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id E0CA521F8607 for <http-auth@ietfa.amsl.com>; Thu, 26 Jan 2012 00:29:50 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -103.57
X-Spam-Level: 
X-Spam-Status: No, score=-103.57 tagged_above=-999 required=5 tests=[AWL=-0.971, BAYES_00=-2.599, USER_IN_WHITELIST=-100]
Received: from mail.ietf.org ([12.22.58.30]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id bw6U+Vaw71p5 for <http-auth@ietfa.amsl.com>; Thu, 26 Jan 2012 00:29:50 -0800 (PST)
Received: from mailout-de.gmx.net (mailout-de.gmx.net [213.165.64.22]) by ietfa.amsl.com (Postfix) with SMTP id A02C721F8602 for <http-auth@ietf.org>; Thu, 26 Jan 2012 00:29:49 -0800 (PST)
Received: (qmail invoked by alias); 26 Jan 2012 08:29:47 -0000
Received: from p5DCC27CC.dip.t-dialin.net (EHLO [192.168.178.36]) [93.204.39.204] by mail.gmx.net (mp022) with SMTP; 26 Jan 2012 09:29:47 +0100
X-Authenticated: #1915285
X-Provags-ID: V01U2FsdGVkX1/zEGFMVhPzsL9jH/JTG3tOAPn5Q/9hpD2dzXK9s0 03Q8PEPYzgHnc0
Message-ID: <4F210EF8.7030306@gmx.de>
Date: Thu, 26 Jan 2012 09:29:44 +0100
From: Julian Reschke <julian.reschke@gmx.de>
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; rv:9.0) Gecko/20111222 Thunderbird/9.0.1
MIME-Version: 1.0
To: "http-auth@ietf.org" <http-auth@ietf.org>
References: <lbe1i7159ov4dp24v0v9kl7e0co8jk3m0d@hive.bjoern.hoehrmann.de>
In-Reply-To: <lbe1i7159ov4dp24v0v9kl7e0co8jk3m0d@hive.bjoern.hoehrmann.de>
X-Forwarded-Message-Id: <lbe1i7159ov4dp24v0v9kl7e0co8jk3m0d@hive.bjoern.hoehrmann.de>
Content-Type: text/plain; charset=ISO-8859-1; format=flowed
Content-Transfer-Encoding: 8bit
X-Y-GMX-Trusted: 0
Subject: [http-auth] Fwd: Re: Fwd: I-D Action: draft-reschke-basicauth-enc-03.txt
X-BeenThere: http-auth@ietf.org
X-Mailman-Version: 2.1.12
Precedence: list
List-Id: HTTP authentication methods <http-auth.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/http-auth>, <mailto:http-auth-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/http-auth>
List-Post: <mailto:http-auth@ietf.org>
List-Help: <mailto:http-auth-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/http-auth>, <mailto:http-auth-request@ietf.org?subject=subscribe>
X-List-Received-Date: Thu, 26 Jan 2012 08:29:51 -0000

FYI - please send comments to *ietf-http-wg@w3.org*

-------- Original Message --------
Subject: Re: Fwd: I-D Action: draft-reschke-basicauth-enc-03.txt
Resent-Date: Thu, 26 Jan 2012 02:30:40 +0000
Resent-From: ietf-http-wg@w3.org
Date: Thu, 26 Jan 2012 03:30:08 +0100
From: Bjoern Hoehrmann <derhoermi@gmx.net>
To: Julian Reschke <julian.reschke@gmx.de>
CC: HTTP Working Group <ietf-http-wg@w3.org>, 
ietf-http-auth@osafoundation.org

* Julian Reschke wrote:
>FYI: this is a minor update (adding a note about XHR sometimes using a
>different encoding default). At this point there's nothing left to do
>here except for waiting for feedback; hopefully from implementers.
>Should I try to get it published as is?

A note to ietf-http-auth@osafoundation.org might be a good idea, at
least in 2006 the list discussed encoding issues like the document
addresses. In fact, let me just try copying it there (and if E-Mail
had a Followup-to header like we had with Netnews, I would not have
to worry about silly crosspost responses...)

>A New Internet-Draft is available from the on-line Internet-Drafts
>directories.
>
>	Title           : An Encoding Parameter for HTTP Basic Authentication
>	Author(s)       : Julian F. Reschke
>	Filename        : draft-reschke-basicauth-enc-03.txt
>	Pages           : 9
>	Date            : 2012-01-25
>
>    The "Basic" authentication scheme defined in RFC 2617 does not
>    properly define how to treat non-ASCII characters.  This has lead to
>    a situation where user agent implementations disagree, and servers
>    make different assumptions based on the locales they are running in.
>    There is little interoperability for characters in the ISO-8859-1
>    character set, and even less interoperability for any characters
>    beyond that.
>
>    This document defines a backwards-compatible extension to "Basic",
>    specifying the server's character encoding expectation, using a new
>    authentication scheme parameter.
>
>
>A URL for this Internet-Draft is:
>http://www.ietf.org/internet-drafts/draft-reschke-basicauth-enc-03.txt

regards,
-- 
Björn Höhrmann · mailto:bjoern@hoehrmann.de · http://bjoern.hoehrmann.de
Am Badedeich 7 · Telefon: +49(0)160/4415681 · http://www.bjoernsworld.de
25899 Dagebüll · PGP Pub. KeyID: 0xA4357E78 · http://www.websitedev.de/



From julian.reschke@gmx.de  Sun Jan 29 07:44:27 2012
Return-Path: <julian.reschke@gmx.de>
X-Original-To: http-auth@ietfa.amsl.com
Delivered-To: http-auth@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id CB7A221F84DA for <http-auth@ietfa.amsl.com>; Sun, 29 Jan 2012 07:44:27 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -104.149
X-Spam-Level: 
X-Spam-Status: No, score=-104.149 tagged_above=-999 required=5 tests=[AWL=-1.550, BAYES_00=-2.599, USER_IN_WHITELIST=-100]
Received: from mail.ietf.org ([12.22.58.30]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id DtnQMGmGURBY for <http-auth@ietfa.amsl.com>; Sun, 29 Jan 2012 07:44:27 -0800 (PST)
Received: from mailout-de.gmx.net (mailout-de.gmx.net [213.165.64.22]) by ietfa.amsl.com (Postfix) with SMTP id 3A52921F84D7 for <http-auth@ietf.org>; Sun, 29 Jan 2012 07:44:27 -0800 (PST)
Received: (qmail invoked by alias); 29 Jan 2012 15:44:23 -0000
Received: from p3EE276D7.dip.t-dialin.net (EHLO [192.168.178.36]) [62.226.118.215] by mail.gmx.net (mp024) with SMTP; 29 Jan 2012 16:44:23 +0100
X-Authenticated: #1915285
X-Provags-ID: V01U2FsdGVkX19OgQoVYoZOBSdRnXMBkZu+caEn5fEqL9JS+7RPg7 /vNyAOZEn2jadH
Message-ID: <4F25694E.1050101@gmx.de>
Date: Sun, 29 Jan 2012 16:44:14 +0100
From: Julian Reschke <julian.reschke@gmx.de>
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; rv:9.0) Gecko/20111222 Thunderbird/9.0.1
MIME-Version: 1.0
To: "http-auth@ietf.org" <http-auth@ietf.org>
References: <4F2567DA.3060608@gmx.de>
In-Reply-To: <4F2567DA.3060608@gmx.de>
X-Forwarded-Message-Id: <4F2567DA.3060608@gmx.de>
Content-Type: text/plain; charset=ISO-8859-1; format=flowed
Content-Transfer-Encoding: 7bit
X-Y-GMX-Trusted: 0
Subject: [http-auth] Fwd: Informal Last Call for draft-reschke-basicauth-enc-04, was: Fwd: I-D Action: draft-reschke-basicauth-enc-04.txt
X-BeenThere: http-auth@ietf.org
X-Mailman-Version: 2.1.12
Precedence: list
List-Id: HTTP authentication methods <http-auth.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/http-auth>, <mailto:http-auth-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/http-auth>
List-Post: <mailto:http-auth@ietf.org>
List-Help: <mailto:http-auth-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/http-auth>, <mailto:http-auth-request@ietf.org?subject=subscribe>
X-List-Received-Date: Sun, 29 Jan 2012 15:44:27 -0000

(FYI)

-------- Original Message --------
Subject: Informal Last Call for draft-reschke-basicauth-enc-04, was: 
Fwd: I-D Action: draft-reschke-basicauth-enc-04.txt
Date: Sun, 29 Jan 2012 16:38:02 +0100
From: Julian Reschke <julian.reschke@gmx.de>
To: HTTP Working Group <ietf-http-wg@w3.org>

Hi there,

I just submitted a new revision of d draft-reschke-basicauth-enc - see
below (HTML version at
<http://greenbytes.de/tech/webdav/draft-reschke-basicauth-enc-04.html>;
this version also includes new hooks for providing feedback; please try!).

At this point, I'd like to solicit additional feedback before I proceed;
in particular: should this potentially be an Applications Area WG
deliverable?

With respect to intended status: in theory, this is a candidate for
Experimental. However, Basic Authentication (as defined in RFC 2617)
doesn't have a registry for extension parameters, so the cleanest
approach appears to say "Updates 2617", which IMHO requires a standards
track document.

Best regards, Julian


-------- Original Message --------
Subject: I-D Action: draft-reschke-basicauth-enc-04.txt
Date: Sun, 29 Jan 2012 07:28:40 -0800
From: internet-drafts@ietf.org
Reply-To: internet-drafts@ietf.org
To: i-d-announce@ietf.org


A New Internet-Draft is available from the on-line Internet-Drafts
directories.

	Title           : An Encoding Parameter for HTTP Basic Authentication
	Author(s)       : Julian F. Reschke
	Filename        : draft-reschke-basicauth-enc-04.txt
	Pages           : 9
	Date            : 2012-01-29

    The "Basic" authentication scheme defined in RFC 2617 does not
    properly define how to treat non-ASCII characters.  This has lead to
    a situation where user agent implementations disagree, and servers
    make different assumptions based on the locales they are running in.
    There is little interoperability for characters in the ISO-8859-1
    character set, and even less interoperability for any characters
    beyond that.

    This document defines a backwards-compatible extension to "Basic",
    specifying the server's character encoding expectation, using a new
    authentication scheme parameter.


A URL for this Internet-Draft is:
http://www.ietf.org/internet-drafts/draft-reschke-basicauth-enc-04.txt

Internet-Drafts are also available by anonymous FTP at:
ftp://ftp.ietf.org/internet-drafts/

This Internet-Draft can be retrieved at:
ftp://ftp.ietf.org/internet-drafts/draft-reschke-basicauth-enc-04.txt

_______________________________________________
I-D-Announce mailing list
I-D-Announce@ietf.org
https://www.ietf.org/mailman/listinfo/i-d-announce
Internet-Draft directories: http://www.ietf.org/shadow.html
or ftp://ftp.ietf.org/ietf/1shadow-sites.txt


From julian.reschke@gmx.de  Sun Jan 29 07:39:52 2012
Return-Path: <julian.reschke@gmx.de>
X-Original-To: http-auth@ietfa.amsl.com
Delivered-To: http-auth@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 63E4C21F8570 for <http-auth@ietfa.amsl.com>; Sun, 29 Jan 2012 07:39:52 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -104.172
X-Spam-Level: 
X-Spam-Status: No, score=-104.172 tagged_above=-999 required=5 tests=[AWL=-1.573, BAYES_00=-2.599, USER_IN_WHITELIST=-100]
Received: from mail.ietf.org ([12.22.58.30]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id QWH0-sQwPgcA for <http-auth@ietfa.amsl.com>; Sun, 29 Jan 2012 07:39:51 -0800 (PST)
Received: from mailout-de.gmx.net (mailout-de.gmx.net [213.165.64.23]) by ietfa.amsl.com (Postfix) with SMTP id DC2ED21F8540 for <http-auth@ietf.org>; Sun, 29 Jan 2012 07:39:50 -0800 (PST)
Received: (qmail invoked by alias); 29 Jan 2012 15:39:49 -0000
Received: from p3EE276D7.dip.t-dialin.net (EHLO [192.168.178.36]) [62.226.118.215] by mail.gmx.net (mp069) with SMTP; 29 Jan 2012 16:39:49 +0100
X-Authenticated: #1915285
X-Provags-ID: V01U2FsdGVkX1+6XgIxqIy6fionB4feiUpmu7P33xkcUCERSU+zV4 EvuoDyWAJQtVBg
Message-ID: <4F256840.4070403@gmx.de>
Date: Sun, 29 Jan 2012 16:39:44 +0100
From: Julian Reschke <julian.reschke@gmx.de>
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; rv:9.0) Gecko/20111222 Thunderbird/9.0.1
MIME-Version: 1.0
To: Julian Reschke <julian.reschke@gmx.de>
References: <4F2567DA.3060608@gmx.de>
In-Reply-To: <4F2567DA.3060608@gmx.de>
X-Forwarded-Message-Id: <4F2567DA.3060608@gmx.de>
Content-Type: text/plain; charset=ISO-8859-1; format=flowed
Content-Transfer-Encoding: 7bit
X-Y-GMX-Trusted: 0
X-Mailman-Approved-At: Sun, 29 Jan 2012 18:20:45 -0800
Subject: [http-auth] Fwd: Informal Last Call for draft-reschke-basicauth-enc-04, was: Fwd: I-D Action: draft-reschke-basicauth-enc-04.txt
X-BeenThere: http-auth@ietf.org
X-Mailman-Version: 2.1.12
Precedence: list
List-Id: HTTP authentication methods <http-auth.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/http-auth>, <mailto:http-auth-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/http-auth>
List-Post: <mailto:http-auth@ietf.org>
List-Help: <mailto:http-auth-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/http-auth>, <mailto:http-auth-request@ietf.org?subject=subscribe>
X-List-Received-Date: Sun, 29 Jan 2012 15:39:52 -0000

(FYI)

-------- Original Message --------
Subject: Informal Last Call for draft-reschke-basicauth-enc-04, was: 
Fwd: I-D Action: draft-reschke-basicauth-enc-04.txt
Date: Sun, 29 Jan 2012 16:38:02 +0100
From: Julian Reschke <julian.reschke@gmx.de>
To: HTTP Working Group <ietf-http-wg@w3.org>

Hi there,

I just submitted a new revision of d draft-reschke-basicauth-enc - see
below (HTML version at
<http://greenbytes.de/tech/webdav/draft-reschke-basicauth-enc-04.html>;
this version also includes new hooks for providing feedback; please try!).

At this point, I'd like to solicit additional feedback before I proceed;
in particular: should this potentially be an Applications Area WG
deliverable?

With respect to intended status: in theory, this is a candidate for
Experimental. However, Basic Authentication (as defined in RFC 2617)
doesn't have a registry for extension parameters, so the cleanest
approach appears to say "Updates 2617", which IMHO requires a standards
track document.

Best regards, Julian


-------- Original Message --------
Subject: I-D Action: draft-reschke-basicauth-enc-04.txt
Date: Sun, 29 Jan 2012 07:28:40 -0800
From: internet-drafts@ietf.org
Reply-To: internet-drafts@ietf.org
To: i-d-announce@ietf.org


A New Internet-Draft is available from the on-line Internet-Drafts
directories.

	Title           : An Encoding Parameter for HTTP Basic Authentication
	Author(s)       : Julian F. Reschke
	Filename        : draft-reschke-basicauth-enc-04.txt
	Pages           : 9
	Date            : 2012-01-29

    The "Basic" authentication scheme defined in RFC 2617 does not
    properly define how to treat non-ASCII characters.  This has lead to
    a situation where user agent implementations disagree, and servers
    make different assumptions based on the locales they are running in.
    There is little interoperability for characters in the ISO-8859-1
    character set, and even less interoperability for any characters
    beyond that.

    This document defines a backwards-compatible extension to "Basic",
    specifying the server's character encoding expectation, using a new
    authentication scheme parameter.


A URL for this Internet-Draft is:
http://www.ietf.org/internet-drafts/draft-reschke-basicauth-enc-04.txt

Internet-Drafts are also available by anonymous FTP at:
ftp://ftp.ietf.org/internet-drafts/

This Internet-Draft can be retrieved at:
ftp://ftp.ietf.org/internet-drafts/draft-reschke-basicauth-enc-04.txt

_______________________________________________
I-D-Announce mailing list
I-D-Announce@ietf.org
https://www.ietf.org/mailman/listinfo/i-d-announce
Internet-Draft directories: http://www.ietf.org/shadow.html
or ftp://ftp.ietf.org/ietf/1shadow-sites.txt

