
From nico@cryptonector.com  Sat Jun  2 16:55:46 2012
Return-Path: <nico@cryptonector.com>
X-Original-To: http-auth@ietfa.amsl.com
Delivered-To: http-auth@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id AB2A421F8542 for <http-auth@ietfa.amsl.com>; Sat,  2 Jun 2012 16:55:46 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.977
X-Spam-Level: 
X-Spam-Status: No, score=-1.977 tagged_above=-999 required=5 tests=[BAYES_00=-2.599, FM_FORGED_GMAIL=0.622]
Received: from mail.ietf.org ([12.22.58.30]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id j0+cZfrKWskG for <http-auth@ietfa.amsl.com>; Sat,  2 Jun 2012 16:55:46 -0700 (PDT)
Received: from homiemail-a36.g.dreamhost.com (caiajhbdcbbj.dreamhost.com [208.97.132.119]) by ietfa.amsl.com (Postfix) with ESMTP id 345D821F853E for <http-auth@ietf.org>; Sat,  2 Jun 2012 16:55:46 -0700 (PDT)
Received: from homiemail-a36.g.dreamhost.com (localhost [127.0.0.1]) by homiemail-a36.g.dreamhost.com (Postfix) with ESMTP id CCF8C778057 for <http-auth@ietf.org>; Sat,  2 Jun 2012 16:55:45 -0700 (PDT)
DomainKey-Signature: a=rsa-sha1; c=nofws; d=cryptonector.com; h=mime-version :in-reply-to:references:date:message-id:subject:from:to:cc: content-type; q=dns; s=cryptonector.com; b=CBwwrihBmH/xxJMXZdRr4 5ivoSGeGW6WcNCLIQchrUaO+ELygxCM0N9LuhTrmblxvPfuOOjy1gpAGZF2Wyped jqpi/2xkkJ7fZaEwPkgkd9LsNokUKVt8pmUPAxZFElZ52rAGl9k4i5rvDfFkjQY8 O+Gu70MEtVSYlqU7mOtJQ8=
DKIM-Signature: v=1; a=rsa-sha1; c=relaxed; d=cryptonector.com; h= mime-version:in-reply-to:references:date:message-id:subject:from :to:cc:content-type; s=cryptonector.com; bh=oVhmfnuR0bTcU/lnAX2E rME5sEg=; b=tTS9werX8DAoK1Mqv/cGh5Xb9SukCR9239UdTp/1NVO1xyou1Eun p0zeNIXIRgll5+4qAXw7NR4Pr/v+XL0E406iGw71HRfPbokiIF9JWrhnVeyJ/HVq T0AayP1Jd977iWFsUHvBtKJprTIMFf6SuLaPwGMVFfAg//+DtfM6f/g=
Received: from mail-pb0-f44.google.com (mail-pb0-f44.google.com [209.85.160.44]) (using TLSv1 with cipher RC4-MD5 (128/128 bits)) (No client certificate requested) (Authenticated sender: nico@cryptonector.com) by homiemail-a36.g.dreamhost.com (Postfix) with ESMTPSA id B37BA77801F for <http-auth@ietf.org>; Sat,  2 Jun 2012 16:55:45 -0700 (PDT)
Received: by pbcwy7 with SMTP id wy7so4405720pbc.31 for <http-auth@ietf.org>; Sat, 02 Jun 2012 16:55:45 -0700 (PDT)
MIME-Version: 1.0
Received: by 10.68.202.130 with SMTP id ki2mr25455653pbc.52.1338681345247; Sat, 02 Jun 2012 16:55:45 -0700 (PDT)
Received: by 10.68.15.134 with HTTP; Sat, 2 Jun 2012 16:55:45 -0700 (PDT)
In-Reply-To: <4F9A793E.6000704@cs.tcd.ie>
References: <14A09626-8397-4656-A042-FEFDDD017C9F@mnot.net> <4F9A793E.6000704@cs.tcd.ie>
Date: Sat, 2 Jun 2012 18:55:45 -0500
Message-ID: <CAK3OfOjgf3bgZjcU_zXY=h9V6FQm-zoNjPbnOM-LiaaNTfDK5w@mail.gmail.com>
From: Nico Williams <nico@cryptonector.com>
To: Stephen Farrell <stephen.farrell@cs.tcd.ie>
Content-Type: text/plain; charset=UTF-8
Cc: "http-auth@ietf.org" <http-auth@ietf.org>
Subject: Re: [http-auth] Fwd: Reminder: Call for Proposals - HTTP/2.0 and HTTP Authentication
X-BeenThere: http-auth@ietf.org
X-Mailman-Version: 2.1.12
Precedence: list
List-Id: HTTP authentication methods <http-auth.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/http-auth>, <mailto:http-auth-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/http-auth>
List-Post: <mailto:http-auth@ietf.org>
List-Help: <mailto:http-auth-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/http-auth>, <mailto:http-auth-request@ietf.org?subject=subscribe>
X-List-Received-Date: Sat, 02 Jun 2012 23:55:46 -0000

I've posted draft-williams-httpbis-auth-classification-00.txt.

It's not finished, but it has enough shape that I can expect some
comments.  Whether you think this is awful or better or worse than
awful, let me know so I know what else to do it before the deadline
(the 15th), up to and including dropping it, re-writing it, or merely
improving it or filling in the many blanks.

BTW, this I-D was written entirely using LyX, and formatted with
lyx2rfc (which converts to XML and then applies xml2rfc).

Nico
--

From y.oiwa@aist.go.jp  Mon Jun  4 07:28:18 2012
Return-Path: <y.oiwa@aist.go.jp>
X-Original-To: http-auth@ietfa.amsl.com
Delivered-To: http-auth@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 083C721F8881 for <http-auth@ietfa.amsl.com>; Mon,  4 Jun 2012 07:28:18 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -7.977
X-Spam-Level: 
X-Spam-Status: No, score=-7.977 tagged_above=-999 required=5 tests=[AWL=-2.000, BAYES_00=-2.599, FM_FORGED_GMAIL=0.622, RCVD_IN_DNSWL_MED=-4]
Received: from mail.ietf.org ([12.22.58.30]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id 0dthKxsrhF5e for <http-auth@ietfa.amsl.com>; Mon,  4 Jun 2012 07:28:17 -0700 (PDT)
Received: from na3sys010aog108.obsmtp.com (na3sys010aog108.obsmtp.com [74.125.245.84]) by ietfa.amsl.com (Postfix) with ESMTP id 9CC9621F887B for <http-auth@ietf.org>; Mon,  4 Jun 2012 07:28:16 -0700 (PDT)
Received: from mail-pz0-f51.google.com ([209.85.210.51]) (using TLSv1) by na3sys010aob108.postini.com ([74.125.244.12]) with SMTP ID DSNKT8zGAHtCbEXaKgAfRA2f7KGDIiafXAx3@postini.com; Mon, 04 Jun 2012 07:28:16 PDT
Received: by dajt11 with SMTP id t11so7111153daj.38 for <http-auth@ietf.org>; Mon, 04 Jun 2012 07:28:15 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=aist.go.jp; s=google; h=mime-version:from:date:message-id:subject:to:content-type :content-transfer-encoding; bh=v3GafOP6fL96VBXamPc/taM6wYq8e2ZbDV4GugWD4gI=; b=E7L0SY49vnRbvBbQblVFy+llr+0rY0/zC2l6qskQjWAHu+ZIOAfbVcmhEFVTkTlCz0 NqhVPERRCZVa7SvwsaQVvJTMPfDsQGTjUtcnBjxOtb4ixkQjo2E3lFnhBF0SbPYwToL3 6FCVK3Qczb6Vs2ztouxftTi+ip880GVEgnz0A=
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=20120113; h=mime-version:from:date:message-id:subject:to:content-type :content-transfer-encoding:x-gm-message-state; bh=v3GafOP6fL96VBXamPc/taM6wYq8e2ZbDV4GugWD4gI=; b=jHeHDiAeXonVycljHSGU79xK3joPtOBLkS/JndcHKhcmqvvdTEajJP0GRUpkj3VMA1 LDohSIcEuSghKK9NTNn2jtkjRhUEWBjrigVR6nYT1BATevvnyfUrp4q7I45Lrrd7KsZp LXEXVBPaHEFNnTk80KXJJdSCTRmAMlj7QG65oM0fongYF4KjGMysDuFDz9or/iXDLvpM m7tiGIXGU9y7wUv215KMieHAUMpvQ2bloGPVeDcE2Da252Qj2CiR/eauXfkmOt+kb/wp bXTpSMXv3EDu71x8Fpb43FRXalg/QfwZoP+ws3YGq5EOH+55scpPNw613HEx6vlVWPKy WNTw==
Received: by 10.68.227.67 with SMTP id ry3mr14110584pbc.158.1338820095459; Mon, 04 Jun 2012 07:28:15 -0700 (PDT)
MIME-Version: 1.0
Received: by 10.66.42.83 with HTTP; Mon, 4 Jun 2012 07:27:55 -0700 (PDT)
From: Yutaka OIWA <y.oiwa@aist.go.jp>
Date: Mon, 4 Jun 2012 23:27:55 +0900
Message-ID: <CAMeZVwuGYZqoZOH1hvc=-YWFKUizjMJmj+=c3ZkgswdYYP3pxw@mail.gmail.com>
To: HTTP Working Group <ietf-http-wg@w3.org>, "http-auth@ietf.org" <http-auth@ietf.org>
Content-Type: text/plain; charset=ISO-8859-1
Content-Transfer-Encoding: quoted-printable
X-Gm-Message-State: ALoCoQkO4tWwvYaRWZEKRBqFoSQjJd5bZfXO8UqmiOkXQqWCrzMSK7Yqgvxz52f44uFzHGtZ9Y34
Subject: [http-auth] [httpauth] Mutual authentication proposal
X-BeenThere: http-auth@ietf.org
X-Mailman-Version: 2.1.12
Precedence: list
List-Id: HTTP authentication methods <http-auth.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/http-auth>, <mailto:http-auth-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/http-auth>
List-Post: <mailto:http-auth@ietf.org>
List-Help: <mailto:http-auth-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/http-auth>, <mailto:http-auth-request@ietf.org?subject=subscribe>
X-List-Received-Date: Mon, 04 Jun 2012 14:28:18 -0000

Dear all,

with a few corrections from the May-21st draft,
I submitted the HTTP Mutual authentication draft as an httpbis proposal.

The proposal consists of two parts:

<http://www.ietf.org/id/draft-oiwa-httpbis-mutualauth-00.txt>
is the core proposal for HTTP Mutual authentication,
using RFC 2617 architecture.

<http://www.ietf.org/id/draft-oiwa-httpbis-auth-extension-00.txt>
is the important companion draft for generic extensions
which makes HTTP authentication useful again with
many Web applications.

The proposal is (both documents are) HTTP/1.1 compatible, and
as far as core HTTP request/response semantics are kept,
it should work with future HTTP/2.0, too.

I will set up wiki pages for these around tomorrow or so.
It will include information on available reference implementations,
some more introductions and so on.
I hope you will enjoy the proposed solution.

Following previous suggestions on http-auth, crypto primitive choices
are kept for future discussions.  One of primitive candidates,
which is now for an "example" or "reference" purpose,
is available as an "individual" draft at
<http://tools.ietf.org/html/draft-oiwa-http-mutualauth-algo-02>.
To implement the core proposal now, please refer this, too.


P. S.
I also incremented the individual draft revisions for book-keeping purpose.
(One of these depends on the revision numbers embedded to the protocol).
Contents of these are exactly the same as httpbis-proposed versions.

--=20
Yutaka OIWA, Ph.D. =A0 =A0 =A0 =A0 =A0 =A0 =A0Leader, Software Reliability =
Research Group
=A0 =A0 =A0 =A0 =A0 =A0 =A0 =A0 =A0 =A0 =A0 =A0 =A0 =A0 =A0Research Institu=
te for Secure Systems (RISEC)
=A0 =A0National Institute of Advanced Industrial Science and Technology (AI=
ST)
=A0 =A0 =A0 =A0 =A0 =A0 =A0 =A0 =A0 =A0 =A0Mail addresses: <y.oiwa@aist.go.=
jp>, <yutaka@oiwa.jp>
OpenPGP: id[440546B5] fp[7C9F 723A 7559 3246 229D =A03139 8677 9BD2 4405 46=
B5]

From y.oiwa@aist.go.jp  Mon Jun  4 22:28:19 2012
Return-Path: <y.oiwa@aist.go.jp>
X-Original-To: http-auth@ietfa.amsl.com
Delivered-To: http-auth@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 19DBC21F875D for <http-auth@ietfa.amsl.com>; Mon,  4 Jun 2012 22:28:19 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -7.31
X-Spam-Level: 
X-Spam-Status: No, score=-7.31 tagged_above=-999 required=5 tests=[AWL=-1.333,  BAYES_00=-2.599, FM_FORGED_GMAIL=0.622, RCVD_IN_DNSWL_MED=-4]
Received: from mail.ietf.org ([12.22.58.30]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id 3falNwYlPqEa for <http-auth@ietfa.amsl.com>; Mon,  4 Jun 2012 22:28:17 -0700 (PDT)
Received: from na3sys010aog112.obsmtp.com (na3sys010aog112.obsmtp.com [74.125.245.92]) by ietfa.amsl.com (Postfix) with ESMTP id 4572C21F8757 for <http-auth@ietf.org>; Mon,  4 Jun 2012 22:28:17 -0700 (PDT)
Received: from mail-gg0-f172.google.com ([209.85.161.172]) (using TLSv1) by na3sys010aob112.postini.com ([74.125.244.12]) with SMTP ID DSNKT82Y8CGXiIRvtbX6kcV1gDLIg+pto/HT@postini.com; Mon, 04 Jun 2012 22:28:17 PDT
Received: by ggnc4 with SMTP id c4so3791946ggn.3 for <http-auth@ietf.org>; Mon, 04 Jun 2012 22:28:16 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=aist.go.jp; s=google; h=mime-version:in-reply-to:references:from:date:message-id:subject:to :content-type:content-transfer-encoding; bh=iaRgV4UWr/X4+Lfqn22TQpxFf9kZWPnIBWmG5N7nD6E=; b=Gbyu0j+fP1JbwSmiWdKV5pUjH1qe5rlrzmzEs3+RTDvxNxzoIrPcH2IdnOSSgSHEVP vf+czlgnE8L+4WvVghtroqDpgqSjiIvE8YQokJm7xg8CbZEY/pwmHo/0djEFO5fOevMt 00tTdXak0ffJuKBpmuyR8DLNG3J8RDhTh4JZY=
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=20120113; h=mime-version:in-reply-to:references:from:date:message-id:subject:to :content-type:content-transfer-encoding:x-gm-message-state; bh=iaRgV4UWr/X4+Lfqn22TQpxFf9kZWPnIBWmG5N7nD6E=; b=knrvXvICTn0QRmoS7XZGw/RAVa5uNrNY2i6gg33uYoYG+4DVsrhHNtzWYxcLySRiO+ MELdGdmRL2bRWfjbuLNjmPM5vwZYK/rIpbVR1tXICugD00nwFhCUzaD5enh21Smu8hGl TKV34aWWRTPMiBCeuvRfxN1l7XrTTu0QWiyBazV3C8L65tSHQJoomLF9MjhcS5Bt9qO/ lseJ2p6gMXGwuBuxmZ3B6wCXxqrm6e7lC6PlJWcwysQ2p7FSlxb2c5tcJ3l5tI2I7XOA m6iX8huH4WjrIVCddN3Rw8hNw0qCdIem7ziWIQAE8hux6iQOvT7OysqpkQHC5q3lkpRe xFgA==
Received: by 10.50.169.33 with SMTP id ab1mr716510igc.73.1338874096127; Mon, 04 Jun 2012 22:28:16 -0700 (PDT)
MIME-Version: 1.0
Received: by 10.50.7.98 with HTTP; Mon, 4 Jun 2012 22:27:56 -0700 (PDT)
In-Reply-To: <CAMeZVwuGYZqoZOH1hvc=-YWFKUizjMJmj+=c3ZkgswdYYP3pxw@mail.gmail.com>
References: <CAMeZVwuGYZqoZOH1hvc=-YWFKUizjMJmj+=c3ZkgswdYYP3pxw@mail.gmail.com>
From: Yutaka OIWA <y.oiwa@aist.go.jp>
Date: Tue, 5 Jun 2012 14:27:56 +0900
Message-ID: <CAMeZVwvgsMdY_EMyODzTAbZrWxp=GQpj_y=mLOZoyOx24-XevQ@mail.gmail.com>
To: HTTP Working Group <ietf-http-wg@w3.org>, "http-auth@ietf.org" <http-auth@ietf.org>
Content-Type: text/plain; charset=ISO-8859-1
Content-Transfer-Encoding: quoted-printable
X-Gm-Message-State: ALoCoQnHrnk37cfm+PqvRtnyZ9t7xTc9syvnJmi/dlIPOgGN87kuaQHrSDNlEtaXxnNNhNk5LNIC
Subject: Re: [http-auth] [httpauth] Mutual authentication proposal
X-BeenThere: http-auth@ietf.org
X-Mailman-Version: 2.1.12
Precedence: list
List-Id: HTTP authentication methods <http-auth.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/http-auth>, <mailto:http-auth-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/http-auth>
List-Post: <mailto:http-auth@ietf.org>
List-Help: <mailto:http-auth-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/http-auth>, <mailto:http-auth-request@ietf.org?subject=subscribe>
X-List-Received-Date: Tue, 05 Jun 2012 05:28:19 -0000

Dear all,

I created Wiki pages for my proposals:

http://trac.tools.ietf.org/wg/httpbis/trac/wiki/HttpAuthProposals/MutualAut=
h
http://trac.tools.ietf.org/wg/httpbis/trac/wiki/HttpAuthProposals/AuthExten=
sion

I hope you will feel the information helpful.

Cheers,

Yutaka

2012/6/4 Yutaka OIWA <y.oiwa@aist.go.jp>:
> Dear all,
>
> with a few corrections from the May-21st draft,
> I submitted the HTTP Mutual authentication draft as an httpbis proposal.
>
> The proposal consists of two parts:
>
> <http://www.ietf.org/id/draft-oiwa-httpbis-mutualauth-00.txt>
> is the core proposal for HTTP Mutual authentication,
> using RFC 2617 architecture.
>
> <http://www.ietf.org/id/draft-oiwa-httpbis-auth-extension-00.txt>
> is the important companion draft for generic extensions
> which makes HTTP authentication useful again with
> many Web applications.
>
> The proposal is (both documents are) HTTP/1.1 compatible, and
> as far as core HTTP request/response semantics are kept,
> it should work with future HTTP/2.0, too.
>
> I will set up wiki pages for these around tomorrow or so.
> It will include information on available reference implementations,
> some more introductions and so on.
> I hope you will enjoy the proposed solution.
>
> Following previous suggestions on http-auth, crypto primitive choices
> are kept for future discussions. =A0One of primitive candidates,
> which is now for an "example" or "reference" purpose,
> is available as an "individual" draft at
> <http://tools.ietf.org/html/draft-oiwa-http-mutualauth-algo-02>.
> To implement the core proposal now, please refer this, too.
>
>
> P. S.
> I also incremented the individual draft revisions for book-keeping purpos=
e.
> (One of these depends on the revision numbers embedded to the protocol).
> Contents of these are exactly the same as httpbis-proposed versions.
>
> --
> Yutaka OIWA, Ph.D. =A0 =A0 =A0 =A0 =A0 =A0 =A0Leader, Software Reliabilit=
y Research Group
> =A0 =A0 =A0 =A0 =A0 =A0 =A0 =A0 =A0 =A0 =A0 =A0 =A0 =A0 =A0Research Insti=
tute for Secure Systems (RISEC)
> =A0 =A0National Institute of Advanced Industrial Science and Technology (=
AIST)
> =A0 =A0 =A0 =A0 =A0 =A0 =A0 =A0 =A0 =A0 =A0Mail addresses: <y.oiwa@aist.g=
o.jp>, <yutaka@oiwa.jp>
> OpenPGP: id[440546B5] fp[7C9F 723A 7559 3246 229D =A03139 8677 9BD2 4405 =
46B5]



--=20
Yutaka OIWA, Ph.D. =A0 =A0 =A0 =A0 =A0 =A0 =A0Leader, Software Reliability =
Research Group
=A0 =A0 =A0 =A0 =A0 =A0 =A0 =A0 =A0 =A0 =A0 =A0 =A0 =A0 =A0Research Institu=
te for Secure Systems (RISEC)
=A0 =A0National Institute of Advanced Industrial Science and Technology (AI=
ST)
=A0 =A0 =A0 =A0 =A0 =A0 =A0 =A0 =A0 =A0 =A0Mail addresses: <y.oiwa@aist.go.=
jp>, <yutaka@oiwa.jp>
OpenPGP: id[440546B5] fp[7C9F 723A 7559 3246 229D =A03139 8677 9BD2 4405 46=
B5]

From mnot@mnot.net  Fri Jun  8 00:12:23 2012
Return-Path: <mnot@mnot.net>
X-Original-To: http-auth@ietfa.amsl.com
Delivered-To: http-auth@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 6E5EB11E80A5 for <http-auth@ietfa.amsl.com>; Fri,  8 Jun 2012 00:12:23 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -103.867
X-Spam-Level: 
X-Spam-Status: No, score=-103.867 tagged_above=-999 required=5 tests=[AWL=-1.268, BAYES_00=-2.599, USER_IN_WHITELIST=-100]
Received: from mail.ietf.org ([12.22.58.30]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id jv1hZugXcN4D for <http-auth@ietfa.amsl.com>; Fri,  8 Jun 2012 00:12:22 -0700 (PDT)
Received: from mxout-07.mxes.net (mxout-07.mxes.net [216.86.168.182]) by ietfa.amsl.com (Postfix) with ESMTP id 333C021F865A for <http-auth@ietf.org>; Fri,  8 Jun 2012 00:12:21 -0700 (PDT)
Received: from mnot-mini.mnot.net (unknown [118.209.56.90]) (using TLSv1 with cipher AES128-SHA (128/128 bits)) (No client certificate requested) by smtp.mxes.net (Postfix) with ESMTPSA id 0833322E25B; Fri,  8 Jun 2012 03:12:14 -0400 (EDT)
From: Mark Nottingham <mnot@mnot.net>
Content-Type: text/plain; charset=us-ascii
Content-Transfer-Encoding: quoted-printable
Date: Fri, 8 Jun 2012 17:12:11 +1000
Message-Id: <E4731404-8A93-4810-92AE-D611C6D2B63D@mnot.net>
To: HTTP Working Group <ietf-http-wg@w3.org>
Mime-Version: 1.0 (Apple Message framework v1278)
X-Mailer: Apple Mail (2.1278)
Cc: http-auth@ietf.org
Subject: [http-auth] Reminder: Proposals for HTTP/2.0, Authentication Schemes Due
X-BeenThere: http-auth@ietf.org
X-Mailman-Version: 2.1.12
Precedence: list
List-Id: HTTP authentication methods <http-auth.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/http-auth>, <mailto:http-auth-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/http-auth>
List-Post: <mailto:http-auth@ietf.org>
List-Help: <mailto:http-auth-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/http-auth>, <mailto:http-auth-request@ietf.org?subject=subscribe>
X-List-Received-Date: Fri, 08 Jun 2012 07:12:23 -0000

As discussed in Paris, we'll start evaluating proposals we've received =
at the end of next week.

See our charter <http://datatracker.ietf.org/wg/httpbis/charter/> for =
details. We're collecting proposals here:

 <http://trac.tools.ietf.org/wg/httpbis/trac/wiki/Http2Proposals>
 <http://trac.tools.ietf.org/wg/httpbis/trac/wiki/HttpAuthProposals>

Once the 15th passes, we'll start discussing them in earnest, and =
gathering feedback from implementers and deployers to help us get to a =
new charter.

Regards,

--
Mark Nottingham   http://www.mnot.net/




From y.oiwa@aist.go.jp  Tue Jun 12 20:50:22 2012
Return-Path: <y.oiwa@aist.go.jp>
X-Original-To: http-auth@ietfa.amsl.com
Delivered-To: http-auth@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id E613B11E8098 for <http-auth@ietfa.amsl.com>; Tue, 12 Jun 2012 20:50:21 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -5.977
X-Spam-Level: 
X-Spam-Status: No, score=-5.977 tagged_above=-999 required=5 tests=[BAYES_00=-2.599, FM_FORGED_GMAIL=0.622, RCVD_IN_DNSWL_MED=-4]
Received: from mail.ietf.org ([12.22.58.30]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id 0bWpcMNl6KSf for <http-auth@ietfa.amsl.com>; Tue, 12 Jun 2012 20:50:21 -0700 (PDT)
Received: from na3sys010aog106.obsmtp.com (na3sys010aog106.obsmtp.com [74.125.245.80]) by ietfa.amsl.com (Postfix) with ESMTP id DD8DC11E808D for <http-auth@ietf.org>; Tue, 12 Jun 2012 20:50:20 -0700 (PDT)
Received: from mail-pz0-f44.google.com ([209.85.210.44]) (using TLSv1) by na3sys010aob106.postini.com ([74.125.244.12]) with SMTP ID DSNKT9gN/BcVCVa8v7P7BgKZAJ6uQ/ThilYL@postini.com; Tue, 12 Jun 2012 20:50:20 PDT
Received: by dacx6 with SMTP id x6so449877dac.17 for <http-auth@ietf.org>; Tue, 12 Jun 2012 20:50:19 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=aist.go.jp; s=google; h=mime-version:in-reply-to:references:from:date:message-id:subject:to :content-type:content-transfer-encoding; bh=MEC4uXzZQBLutmbzy3+eU4U/3AZX59Be7hIg3J4o+QI=; b=PxYALCTTuUoMhulHRTJ4l9JvVIp4B+VLIBOTog44Hi/5/Bvw2bLvc2nRKDrIiv9005 /tHbgpEVhrptNElvXFAquC1F+qJZDObdkjc3wIKkYF7QBqDoubQhTiBN1Qzu4/y/m8p5 447BLC/jnQ6yzuI9LKUU5jgWaMxT94JOLpQQI=
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=20120113; h=mime-version:in-reply-to:references:from:date:message-id:subject:to :content-type:content-transfer-encoding:x-gm-message-state; bh=MEC4uXzZQBLutmbzy3+eU4U/3AZX59Be7hIg3J4o+QI=; b=RXd41zyKHqKN64xwPGmReTCHnW9+S0UOEkiaqqWGFBoRSLNXjpcHya27PhjW9ZiJG2 iqfAzoJj95/wS6AT7Brd9JlpCn4DhnfwnFJ8+6fX9o3XVO5s/Ja9HxHp9N2s2gUvCHaf 81o6MmWurYpFsRi3AEfyndNJExOwXKsIDLHbLK4W7QFc+D83N9YcXhAmFyu8xIQ1E67d ZZtw8+G9FYAXNsh2ApOqVf//Wvo7bbYRRqb1/VoHH0m50uZRIn9Fn3DDtcyFrSt9pyJU 5vFA593zlGfoKkDxSMoHrdlLTlJ5+KQWQ107/seykclLCMJdPxKkTMSRzzjFhnrU0VuA lnoQ==
Received: by 10.68.225.201 with SMTP id rm9mr45879447pbc.71.1339559419522; Tue, 12 Jun 2012 20:50:19 -0700 (PDT)
MIME-Version: 1.0
Received: by 10.66.254.42 with HTTP; Tue, 12 Jun 2012 20:49:59 -0700 (PDT)
In-Reply-To: <CAMeZVwvgsMdY_EMyODzTAbZrWxp=GQpj_y=mLOZoyOx24-XevQ@mail.gmail.com>
References: <CAMeZVwuGYZqoZOH1hvc=-YWFKUizjMJmj+=c3ZkgswdYYP3pxw@mail.gmail.com> <CAMeZVwvgsMdY_EMyODzTAbZrWxp=GQpj_y=mLOZoyOx24-XevQ@mail.gmail.com>
From: Yutaka OIWA <y.oiwa@aist.go.jp>
Date: Wed, 13 Jun 2012 12:49:59 +0900
Message-ID: <CAMeZVwsUmBVDYduXh06gy-FzBiyyP=B=HRvWFYkaZ5xtxqMr9Q@mail.gmail.com>
To: HTTP Working Group <ietf-http-wg@w3.org>, "http-auth@ietf.org" <http-auth@ietf.org>
Content-Type: text/plain; charset=ISO-8859-1
Content-Transfer-Encoding: quoted-printable
X-Gm-Message-State: ALoCoQmYjhpSlrH75HVBClwX/H6d8b2UPinZKy79v1CdtkyKGNqlZIy3Z6vffkFvCioZ7KX9qXBf
Subject: Re: [http-auth] [httpauth] Mutual authentication proposal
X-BeenThere: http-auth@ietf.org
X-Mailman-Version: 2.1.12
Precedence: list
List-Id: HTTP authentication methods <http-auth.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/http-auth>, <mailto:http-auth-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/http-auth>
List-Post: <mailto:http-auth@ietf.org>
List-Help: <mailto:http-auth-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/http-auth>, <mailto:http-auth-request@ietf.org?subject=subscribe>
X-List-Received-Date: Wed, 13 Jun 2012 03:50:22 -0000

I put some document about some design decisions of
our protocol on the wiki.

It is available from
http://trac.tools.ietf.org/wg/httpbis/trac/wiki/HttpAuthProposals/MutualAut=
h/LayeringDesigns

Hope this will help you understanding how the things work.

2012/6/5 Yutaka OIWA <y.oiwa@aist.go.jp>:
> Dear all,
>
> I created Wiki pages for my proposals:
>
> http://trac.tools.ietf.org/wg/httpbis/trac/wiki/HttpAuthProposals/MutualA=
uth
> http://trac.tools.ietf.org/wg/httpbis/trac/wiki/HttpAuthProposals/AuthExt=
ension
>
> I hope you will feel the information helpful.
>
> Cheers,
>
> Yutaka
>
> 2012/6/4 Yutaka OIWA <y.oiwa@aist.go.jp>:
>> Dear all,
>>
>> with a few corrections from the May-21st draft,
>> I submitted the HTTP Mutual authentication draft as an httpbis proposal.
>>
>> The proposal consists of two parts:
>>
>> <http://www.ietf.org/id/draft-oiwa-httpbis-mutualauth-00.txt>
>> is the core proposal for HTTP Mutual authentication,
>> using RFC 2617 architecture.
>>
>> <http://www.ietf.org/id/draft-oiwa-httpbis-auth-extension-00.txt>
>> is the important companion draft for generic extensions
>> which makes HTTP authentication useful again with
>> many Web applications.
>>
>> The proposal is (both documents are) HTTP/1.1 compatible, and
>> as far as core HTTP request/response semantics are kept,
>> it should work with future HTTP/2.0, too.
>>
>> I will set up wiki pages for these around tomorrow or so.
>> It will include information on available reference implementations,
>> some more introductions and so on.
>> I hope you will enjoy the proposed solution.
>>
>> Following previous suggestions on http-auth, crypto primitive choices
>> are kept for future discussions. =A0One of primitive candidates,
>> which is now for an "example" or "reference" purpose,
>> is available as an "individual" draft at
>> <http://tools.ietf.org/html/draft-oiwa-http-mutualauth-algo-02>.
>> To implement the core proposal now, please refer this, too.
>>
>>
>> P. S.
>> I also incremented the individual draft revisions for book-keeping purpo=
se.
>> (One of these depends on the revision numbers embedded to the protocol).
>> Contents of these are exactly the same as httpbis-proposed versions.
>>
>> --
>> Yutaka OIWA, Ph.D. =A0 =A0 =A0 =A0 =A0 =A0 =A0Leader, Software Reliabili=
ty Research Group
>> =A0 =A0 =A0 =A0 =A0 =A0 =A0 =A0 =A0 =A0 =A0 =A0 =A0 =A0 =A0Research Inst=
itute for Secure Systems (RISEC)
>> =A0 =A0National Institute of Advanced Industrial Science and Technology =
(AIST)
>> =A0 =A0 =A0 =A0 =A0 =A0 =A0 =A0 =A0 =A0 =A0Mail addresses: <y.oiwa@aist.=
go.jp>, <yutaka@oiwa.jp>
>> OpenPGP: id[440546B5] fp[7C9F 723A 7559 3246 229D =A03139 8677 9BD2 4405=
 46B5]
>
>
>
> --
> Yutaka OIWA, Ph.D. =A0 =A0 =A0 =A0 =A0 =A0 =A0Leader, Software Reliabilit=
y Research Group
> =A0 =A0 =A0 =A0 =A0 =A0 =A0 =A0 =A0 =A0 =A0 =A0 =A0 =A0 =A0Research Insti=
tute for Secure Systems (RISEC)
> =A0 =A0National Institute of Advanced Industrial Science and Technology (=
AIST)
> =A0 =A0 =A0 =A0 =A0 =A0 =A0 =A0 =A0 =A0 =A0Mail addresses: <y.oiwa@aist.g=
o.jp>, <yutaka@oiwa.jp>
> OpenPGP: id[440546B5] fp[7C9F 723A 7559 3246 229D =A03139 8677 9BD2 4405 =
46B5]



--=20
Yutaka OIWA, Ph.D. =A0 =A0 =A0 =A0 =A0 =A0 =A0Leader, Software Reliability =
Research Group
=A0 =A0 =A0 =A0 =A0 =A0 =A0 =A0 =A0 =A0 =A0 =A0 =A0 =A0 =A0Research Institu=
te for Secure Systems (RISEC)
=A0 =A0National Institute of Advanced Industrial Science and Technology (AI=
ST)
=A0 =A0 =A0 =A0 =A0 =A0 =A0 =A0 =A0 =A0 =A0Mail addresses: <y.oiwa@aist.go.=
jp>, <yutaka@oiwa.jp>
OpenPGP: id[440546B5] fp[7C9F 723A 7559 3246 229D =A03139 8677 9BD2 4405 46=
B5]

From stephen.farrell@cs.tcd.ie  Wed Jun 13 08:05:53 2012
Return-Path: <stephen.farrell@cs.tcd.ie>
X-Original-To: http-auth@ietfa.amsl.com
Delivered-To: http-auth@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 1F34D21F8501 for <http-auth@ietfa.amsl.com>; Wed, 13 Jun 2012 08:05:53 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -102.572
X-Spam-Level: 
X-Spam-Status: No, score=-102.572 tagged_above=-999 required=5 tests=[AWL=0.027, BAYES_00=-2.599, USER_IN_WHITELIST=-100]
Received: from mail.ietf.org ([12.22.58.30]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id l0Y21Z1JITPn for <http-auth@ietfa.amsl.com>; Wed, 13 Jun 2012 08:05:51 -0700 (PDT)
Received: from scss.tcd.ie (hermes.scss.tcd.ie [IPv6:2001:770:10:200:889f:cdff:fe8d:ccd2]) by ietfa.amsl.com (Postfix) with ESMTP id D5BFD21F85D0 for <http-auth@ietf.org>; Wed, 13 Jun 2012 08:05:50 -0700 (PDT)
Received: from localhost (localhost [127.0.0.1]) by hermes.scss.tcd.ie (Postfix) with ESMTP id BBB9C1717FE for <http-auth@ietf.org>; Wed, 13 Jun 2012 16:05:49 +0100 (IST)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=cs.tcd.ie; h= content-transfer-encoding:content-type:in-reply-to:references :subject:mime-version:user-agent:from:date:message-id:received :received:x-virus-scanned; s=cs; t=1339599948; bh=k+ijnWtwZdcY3E Ror2kaYk1jD8lUN25KwZ9kCojWwl8=; b=hXcAm7gK6qEKen895rXYwhwyi3Bbg8 Bm7aJLS2d9egn90GMGfIE1daEpnIw8l7506c0w0Je1mvaEHdmVQAbhXKdAjkF44M 1I/r+ODoktT5eoBB+n+D91KsIdUdDv8hOTx5YQ9cmqGjXGYb9KjzfWzX5IeqAdA5 W7U84v7FcClH0cp91JBFSS9FvMirbwK7bMThP0cO2g3uUBehAZVjdhJth3tTnvEy c7F0HZ20Np0dXuzGlfNCGopNptttICim/yYWRfAoI3uSkmeM+rIHKrKGMgUY1RKG 2AhvC/5aw3366fLuRWuXcOkb9bJxkARlYNfOwL69mkI9n5boct+t1FBQ==
X-Virus-Scanned: Debian amavisd-new at scss.tcd.ie
Received: from scss.tcd.ie ([127.0.0.1]) by localhost (scss.tcd.ie [127.0.0.1]) (amavisd-new, port 10027) with ESMTP id RWfP8i214NRN for <http-auth@ietf.org>; Wed, 13 Jun 2012 16:05:48 +0100 (IST)
Received: from [IPv6:2001:770:10:203:353a:5c1f:6277:879a] (unknown [IPv6:2001:770:10:203:353a:5c1f:6277:879a]) by smtp.scss.tcd.ie (Postfix) with ESMTPSA id 843A41717F3 for <http-auth@ietf.org>; Wed, 13 Jun 2012 16:05:48 +0100 (IST)
Message-ID: <4FD8AC4C.2050403@cs.tcd.ie>
Date: Wed, 13 Jun 2012 16:05:48 +0100
From: Stephen Farrell <stephen.farrell@cs.tcd.ie>
User-Agent: Mozilla/5.0 (X11; Linux x86_64; rv:12.0) Gecko/20120430 Thunderbird/12.0.1
MIME-Version: 1.0
To: "http-auth@ietf.org" <http-auth@ietf.org>
References: <20120613150028.28062.59572.idtracker@ietfa.amsl.com>
In-Reply-To: <20120613150028.28062.59572.idtracker@ietfa.amsl.com>
X-Enigmail-Version: 1.4.2
X-Forwarded-Message-Id: <20120613150028.28062.59572.idtracker@ietfa.amsl.com>
Content-Type: text/plain; charset=ISO-8859-1
Content-Transfer-Encoding: 7bit
Subject: [http-auth] Fwd: New Version Notification for draft-farrell-httpbis-hoba-00.txt
X-BeenThere: http-auth@ietf.org
X-Mailman-Version: 2.1.12
Precedence: list
List-Id: HTTP authentication methods <http-auth.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/http-auth>, <mailto:http-auth-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/http-auth>
List-Post: <mailto:http-auth@ietf.org>
List-Help: <mailto:http-auth-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/http-auth>, <mailto:http-auth-request@ietf.org?subject=subscribe>
X-List-Received-Date: Wed, 13 Jun 2012 15:05:53 -0000

FYI. I guess discussion, if any, would be on the httpbis wg list.
Cheers,
S

-------- Original Message --------
Subject: New Version Notification for draft-farrell-httpbis-hoba-00.txt
Date: Wed, 13 Jun 2012 08:00:28 -0700
From: internet-drafts@ietf.org
To: stephen.farrell@cs.tcd.ie


A new version of I-D, draft-farrell-httpbis-hoba-00.txt
has been successfully submitted by Stephen Farrell and posted to the
IETF repository.

Filename:	 draft-farrell-httpbis-hoba
Revision:	 00
Title:		 HTTP Origin-Bound Authentication (HOBA)
Creation date:	 2012-06-13
WG ID:		 Individual Submission
Number of pages: 11
URL:
http://www.ietf.org/internet-drafts/draft-farrell-httpbis-hoba-00.txt
Status:          http://datatracker.ietf.org/doc/draft-farrell-httpbis-hoba
Htmlized:        http://tools.ietf.org/html/draft-farrell-httpbis-hoba-00


Abstract:
   This memo proposes a way of using origin-bound certificates for HTTP
   authentication, called HOBA.  HOBA is an HTTP authentication method
   with credentials that are not vulnerable to simple phishing attacks,
   and that does not require a server-side password database, both major
   potential positives, if deployed.  HOBA can be integrated with
   account management and other applications running over HTTP and
   supports portability, so a user can associate more than one device or
   origin-bound certificate with the same service.  This also provides a
   mechanism to handle state-loss, if one of a user's credentials is
   lost.  HOBA also provides a logout mechanism.





The IETF Secretariat
