
From nobody Fri Mar  3 01:16:48 2017
Return-Path: <John.Woodworth@CenturyLink.com>
X-Original-To: http-auth@ietfa.amsl.com
Delivered-To: http-auth@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id E54C71294B9 for <http-auth@ietfa.amsl.com>; Fri,  3 Mar 2017 01:16:46 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.901
X-Spam-Level: 
X-Spam-Status: No, score=-1.901 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, RCVD_IN_DNSWL_NONE=-0.0001, RP_MATCHES_RCVD=-0.001, SPF_PASS=-0.001, URIBL_BLOCKED=0.001] autolearn=ham autolearn_force=no
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id sbyIjpJaqGfv for <http-auth@ietfa.amsl.com>; Fri,  3 Mar 2017 01:16:45 -0800 (PST)
Received: from lxomp52w.centurylink.com (lxomp52w.centurylink.com [155.70.50.76]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 8447112942F for <http-auth@ietf.org>; Fri,  3 Mar 2017 01:16:45 -0800 (PST)
Received: from lxdenvmpc030.qintra.com (lxdenvmpc030.qintra.com [10.1.51.30]) by lxomp52w.centurylink.com (8.14.8/8.14.8) with ESMTP id v239Ghkh037452 (version=TLSv1/SSLv3 cipher=DHE-RSA-AES256-SHA bits=256 verify=NO); Fri, 3 Mar 2017 03:16:43 -0600
Received: from lxdenvmpc030.qintra.com (unknown [127.0.0.1]) by IMSA (Postfix) with ESMTP id 83FF01E0062; Fri,  3 Mar 2017 02:16:38 -0700 (MST)
Received: from lxdnp31k.corp.intranet (unknown [151.119.92.134]) by lxdenvmpc030.qintra.com (Postfix) with ESMTP id 5E12E1E004E; Fri,  3 Mar 2017 02:16:38 -0700 (MST)
Received: from lxdnp31k.corp.intranet (localhost [127.0.0.1]) by lxdnp31k.corp.intranet (8.14.8/8.14.8) with ESMTP id v239GcP5032509; Fri, 3 Mar 2017 02:16:38 -0700
Received: from vodcwhubex502.ctl.intranet (vodcwhubex502.ctl.intranet [151.117.206.28]) by lxdnp31k.corp.intranet (8.14.8/8.14.8) with ESMTP id v239GbZA032500 (version=TLSv1/SSLv3 cipher=AES128-SHA bits=128 verify=FAIL); Fri, 3 Mar 2017 02:16:38 -0700
Received: from PODCWMBXEX501.ctl.intranet ([169.254.1.220]) by vodcwhubex502.ctl.intranet ([151.117.206.28]) with mapi id 14.03.0294.000; Fri, 3 Mar 2017 03:16:37 -0600
From: "Woodworth, John R" <John.Woodworth@CenturyLink.com>
To: "http-auth@ietf.org" <http-auth@ietf.org>
Thread-Topic: New Version Notification for draft-woodworth-json-http-auth-00.txt
Thread-Index: AQHSk/274hOGmOJRSkapVznP/gi4aqGC1A8w
Date: Fri, 3 Mar 2017 09:16:36 +0000
Message-ID: <A05B583C828C614EBAD1DA920D92866BD06ED074@PODCWMBXEX501.ctl.intranet>
References: <148853210107.10146.992834374988004676.idtracker@ietfa.amsl.com>
In-Reply-To: <148853210107.10146.992834374988004676.idtracker@ietfa.amsl.com>
Accept-Language: en-US
Content-Language: en-US
X-MS-Has-Attach: 
X-MS-TNEF-Correlator: 
x-originating-ip: [151.117.206.8]
Content-Type: text/plain; charset="utf-8"
Content-Transfer-Encoding: base64
MIME-Version: 1.0
X-TM-AS-MML: disable
X-CFilter-Loop: Reflected
Archived-At: <https://mailarchive.ietf.org/arch/msg/http-auth/rnEElFCnTD9JAoj_9r7Vm3zMWAs>
Cc: "Ballew, Dean" <Dean.Ballew@CenturyLink.com>
Subject: [http-auth] FW: New Version Notification for draft-woodworth-json-http-auth-00.txt
X-BeenThere: http-auth@ietf.org
X-Mailman-Version: 2.1.17
Precedence: list
List-Id: HTTP authentication methods <http-auth.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/http-auth>, <mailto:http-auth-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/http-auth/>
List-Post: <mailto:http-auth@ietf.org>
List-Help: <mailto:http-auth-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/http-auth>, <mailto:http-auth-request@ietf.org?subject=subscribe>
X-List-Received-Date: Fri, 03 Mar 2017 09:16:47 -0000

QWxsLA0KDQpJIHVuZGVyc3RhbmQgdGhpcyBpcyBsYXRlIHRvIHRoZSBwYXJ0eSBidXQgd2FzIGhv
cGluZyBzb21lIG9mIHlvdSBtYXkgaGF2ZSB0aW1lIHRvIHJldmlldyBvdXIgbmV3IGRyYWZ0LiAg
V2Ugd2VsY29tZSBhbnkgcXVlc3Rpb25zLCBjb21tZW50cyBhbmQgYXNzaXN0YW5jZSBmcm9tIHRo
ZSBncm91cC4NCg0KDQpUaGFua3MsDQpKb2huDQotLS0tLU9yaWdpbmFsIE1lc3NhZ2UtLS0tLQ0K
RnJvbTogaW50ZXJuZXQtZHJhZnRzQGlldGYub3JnIFttYWlsdG86aW50ZXJuZXQtZHJhZnRzQGll
dGYub3JnXQ0KDQoNCkEgbmV3IHZlcnNpb24gb2YgSS1ELCBkcmFmdC13b29kd29ydGgtanNvbi1o
dHRwLWF1dGgtMDAudHh0DQpoYXMgYmVlbiBzdWNjZXNzZnVsbHkgc3VibWl0dGVkIGJ5IEpvaG4g
V29vZHdvcnRoIGFuZCBwb3N0ZWQgdG8gdGhlIElFVEYgcmVwb3NpdG9yeS4NCg0KTmFtZTogICAg
ICAgICAgIGRyYWZ0LXdvb2R3b3J0aC1qc29uLWh0dHAtYXV0aA0KUmV2aXNpb246ICAgICAgIDAw
DQpUaXRsZTogICAgICAgICAgSFRUUCBBdXRoZW50aWNhdGlvbiAtIHxKU09OfCBTY2hlbWUNCkRv
Y3VtZW50IGRhdGU6ICAyMDE3LTAyLTI4DQpHcm91cDogICAgICAgICAgSW5kaXZpZHVhbCBTdWJt
aXNzaW9uDQpQYWdlczogICAgICAgICAgMTcNClVSTDogICAgICAgICAgICBodHRwczovL3d3dy5p
ZXRmLm9yZy9pbnRlcm5ldC1kcmFmdHMvZHJhZnQtd29vZHdvcnRoLWpzb24taHR0cC1hdXRoLTAw
LnR4dA0KU3RhdHVzOiAgICAgICAgIGh0dHBzOi8vZGF0YXRyYWNrZXIuaWV0Zi5vcmcvZG9jL2Ry
YWZ0LXdvb2R3b3J0aC1qc29uLWh0dHAtYXV0aC8NCkh0bWxpemVkOiAgICAgICBodHRwczovL3Rv
b2xzLmlldGYub3JnL2h0bWwvZHJhZnQtd29vZHdvcnRoLWpzb24taHR0cC1hdXRoLTAwDQoNCg0K
QWJzdHJhY3Q6DQogICBUaGUgfEpTT058IGF1dGhlbnRpY2F0aW9uIHNjaGVtZSBwcm92aWRlcyBh
IG1lY2hhbmlzbSBmb3IgZXhjaGFuZ2luZw0KICAgYXV0aGVudGljYXRpb24gY2hhbGxlbmdlcyBh
bmQgY3JlZGVudGlhbHMgYXMgb2JqZWN0cyBpbiB0aGUgZm9ybSBvZg0KICAgSmF2YVNjcmlwdCBP
YmplY3QgTm90YXRpb24gKEpTT04pLiAgVGhpcyBzY2hlbWUgb2ZmZXJzIGEgc2VjdXJlDQogICBt
ZWNoYW5pc20gb2YgcHJvdmlkaW5nIGF1dGhlbnRpY2F0ZWQgYWNjZXNzIHRvIGEgc2V0IG9mIHBy
b3RlY3RlZA0KICAgSFRUUCByZXNvdXJjZXMgd2hpY2ggbWF5IGJlIGhhbmRsZWQgYnkgc2NyaXB0
aW5nIHV0aWxpdHkgZnJhbWV3b3JrIGFzDQogICBpbiBYTUxIdHRwUmVxdWVzdCBjYWxscyAoQUpB
WCkgb3IgZGlyZWN0bHkgYnkgdGhlIGNsaWVudCdzIHVzZXINCiAgIGFnZW50LiAgVGhpcyBjaGFp
bmluZyBmZWF0dXJlIGlzIHVuaXF1ZSB0byB0aGlzIHNjaGVtZS4NCg0KDQoNCg0KUGxlYXNlIG5v
dGUgdGhhdCBpdCBtYXkgdGFrZSBhIGNvdXBsZSBvZiBtaW51dGVzIGZyb20gdGhlIHRpbWUgb2Yg
c3VibWlzc2lvbiB1bnRpbCB0aGUgaHRtbGl6ZWQgdmVyc2lvbiBhbmQgZGlmZiBhcmUgYXZhaWxh
YmxlIGF0IHRvb2xzLmlldGYub3JnLg0KDQpUaGUgSUVURiBTZWNyZXRhcmlhdA0KDQotLSBUSEVT
RSBBUkUgVEhFIERST0lEUyBUTyBXSE9NIEkgUkVGRVI6DQpUaGlzIGNvbW11bmljYXRpb24gaXMg
dGhlIHByb3BlcnR5IG9mIENlbnR1cnlMaW5rIGFuZCBtYXkgY29udGFpbiBjb25maWRlbnRpYWwg
b3IgcHJpdmlsZWdlZCBpbmZvcm1hdGlvbi4gVW5hdXRob3JpemVkIHVzZSBvZiB0aGlzIGNvbW11
bmljYXRpb24gaXMgc3RyaWN0bHkgcHJvaGliaXRlZCBhbmQgbWF5IGJlIHVubGF3ZnVsLiBJZiB5
b3UgaGF2ZSByZWNlaXZlZCB0aGlzIGNvbW11bmljYXRpb24gaW4gZXJyb3IsIHBsZWFzZSBpbW1l
ZGlhdGVseSBub3RpZnkgdGhlIHNlbmRlciBieSByZXBseSBlLW1haWwgYW5kIGRlc3Ryb3kgYWxs
IGNvcGllcyBvZiB0aGUgY29tbXVuaWNhdGlvbiBhbmQgYW55IGF0dGFjaG1lbnRzLg0K


From nobody Sun Mar  5 03:03:07 2017
Return-Path: <julian.reschke@gmx.de>
X-Original-To: http-auth@ietfa.amsl.com
Delivered-To: http-auth@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 15526129411 for <http-auth@ietfa.amsl.com>; Sun,  5 Mar 2017 03:03:06 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.601
X-Spam-Level: 
X-Spam-Status: No, score=-2.601 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, FREEMAIL_FROM=0.001, RCVD_IN_DNSWL_LOW=-0.7, RCVD_IN_MSPIKE_H2=-0.001, SPF_PASS=-0.001] autolearn=ham autolearn_force=no
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id FCAExODBbHCS for <http-auth@ietfa.amsl.com>; Sun,  5 Mar 2017 03:03:05 -0800 (PST)
Received: from mout.gmx.net (mout.gmx.net [212.227.17.21]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id BC7591293E3 for <http-auth@ietf.org>; Sun,  5 Mar 2017 03:03:04 -0800 (PST)
Received: from [192.168.178.20] ([93.217.119.101]) by mail.gmx.com (mrgmx103 [212.227.17.168]) with ESMTPSA (Nemesis) id 0M6ioC-1cPMes2xzo-00wWIs; Sun, 05 Mar 2017 12:02:58 +0100
To: "Woodworth, John R" <John.Woodworth@CenturyLink.com>, "http-auth@ietf.org" <http-auth@ietf.org>
References: <148853210107.10146.992834374988004676.idtracker@ietfa.amsl.com> <A05B583C828C614EBAD1DA920D92866BD06ED074@PODCWMBXEX501.ctl.intranet>
From: Julian Reschke <julian.reschke@gmx.de>
Message-ID: <52705e55-3924-3a9d-dfe6-73e4d33cb06c@gmx.de>
Date: Sun, 5 Mar 2017 12:02:58 +0100
User-Agent: Mozilla/5.0 (Windows NT 10.0; WOW64; rv:45.0) Gecko/20100101 Thunderbird/45.7.1
MIME-Version: 1.0
In-Reply-To: <A05B583C828C614EBAD1DA920D92866BD06ED074@PODCWMBXEX501.ctl.intranet>
Content-Type: text/plain; charset=windows-1252; format=flowed
Content-Transfer-Encoding: 7bit
X-Provags-ID: V03:K0:BC6/79JsbThsZWgBS1zXT5CbS4NuhwoUUdwOVunEcwRPmDJJBg9 NFXcvZ7k6Q2dD5fSSwMwfNR8C7cbu5MEZcz+XBdWr+C/g/+scqn2mY+RW4AGiYoCNsg05Uf TpsPNvks+iwMUgHo/sghdJgwXnOXv9S6ZJFHyuN1wdYyr+JLCQLIuoQ05rIFlTj07cqi3uh DRt6/6M0upHjGAQR26nMw==
X-UI-Out-Filterresults: notjunk:1;V01:K0:Lsc85JNgsqA=:vfxBsz+oplBBdYpwsQ+RFr /N8BWzL5C0ROeFbki1b8aFZtkKuEheH4zWiv9fKsaswat432u4BbZwoHtn9KVgb+tNamPfsHQ EMQ1ROeZqU01T6rwP7y45RFmFsFuHhJddk1LzJDpBoojA0NShnMiLl8hm8IDEHzvcDHypKXE2 W0Ol0YCtI9D0fvGWgttLt7NzzXj6cjqsD31gOzlInmbaomFG5QqRRZEhq0uiKXGrcQiWcB4vN Sb1gaS01myw8fiO+GdhoeZVn4GJvGhsMKlZP/5U37tIQv6NHuBxDRz1Z9oXnGL0lfgcR8CXX6 68jwyZWMWFs46PXI1pGK7r+gteoktojixwplBZNFKxv4ehrFyscmUJKstenATyv0ziFuWpLNx VSz4uiXJQx99X6qHdwwbdASp6s7bYNnTARXvfk+0d3je8QdsKdeGGxa41iYmo7kM1xar3+yTS gPQLjyRxcHC2/Ytl0Qwwp5AqviNChltddVSMvTEdSS18+TPJWKuwt58Lr6JFwmkdPK20qO6D8 kFQNnRKh9ROtFKwO0YY2KgkW0sjb7RXwXnkr+DVm5omWa1qg9e27wXI1Joev3WUfty7hJ/2Ej WLOMWSZYNahjsuC3Qghjvn6JD6QjMAlS+sKNAd1GjRCSXazfxVKXgI486iuXmwleJiGGFzR5z NuwObdQGRImaIm2tq2/35sKl5D0X6Bkir0iHcv8s1fRF7Tj9zeMVjJ0kAolSkYklq/KM4rXKs 5mjlswjTVqbs5OCQ166PX9hzQnrb9JHqmas1oq9kajLXki59Pip6zmTtXjH7XHc70igcKldiX YY5I0Z+
Archived-At: <https://mailarchive.ietf.org/arch/msg/http-auth/nH3URp2lPnufW14IIW9-eoLqEJY>
Cc: "Ballew, Dean" <Dean.Ballew@CenturyLink.com>
Subject: Re: [http-auth] FW: New Version Notification for draft-woodworth-json-http-auth-00.txt
X-BeenThere: http-auth@ietf.org
X-Mailman-Version: 2.1.17
Precedence: list
List-Id: HTTP authentication methods <http-auth.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/http-auth>, <mailto:http-auth-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/http-auth/>
List-Post: <mailto:http-auth@ietf.org>
List-Help: <mailto:http-auth-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/http-auth>, <mailto:http-auth-request@ietf.org?subject=subscribe>
X-List-Received-Date: Sun, 05 Mar 2017 11:03:06 -0000

On 2017-03-03 10:16, Woodworth, John R wrote:
> All,
>
> I understand this is late to the party but was hoping some of you may have time to review our new draft.  We welcome any questions, comments and assistance from the group.
> ...

Hi there,


a few formal nits:

- please don't put "httpauth" on the front page if the draft isn't a 
Working Group draft - that said, *do* add a note to the front page with 
instructions where to send feedback (this list is fine for that)

- you IPR statement looks weird:

> This document may contain material from IETF Documents or IETF
> Contributions published or made publicly available before November
> 10, 2008.

- registering a whole set of auth schemes isn't going to fly; please 
also consider removing the somewhat weird pipe characters from the 
scheme name...

Best regards, Julian


From nobody Sun Mar  5 13:10:57 2017
Return-Path: <John.Woodworth@CenturyLink.com>
X-Original-To: http-auth@ietfa.amsl.com
Delivered-To: http-auth@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 7231012949B for <http-auth@ietfa.amsl.com>; Sun,  5 Mar 2017 13:10:56 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.902
X-Spam-Level: 
X-Spam-Status: No, score=-1.902 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, RCVD_IN_DNSWL_NONE=-0.0001, RP_MATCHES_RCVD=-0.001, SPF_PASS=-0.001] autolearn=ham autolearn_force=no
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id J2pixVGvhr3I for <http-auth@ietfa.amsl.com>; Sun,  5 Mar 2017 13:10:55 -0800 (PST)
Received: from lxdnp29m.centurylink.com (lxdnp29m.centurylink.com [155.70.32.52]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id A7611129488 for <http-auth@ietf.org>; Sun,  5 Mar 2017 13:10:55 -0800 (PST)
Received: from lxomavmpc030.qintra.com (lxomavmpc030.qintra.com [151.117.207.30]) by lxdnp29m.centurylink.com (8.14.8/8.14.8) with ESMTP id v25LAotO023808 (version=TLSv1/SSLv3 cipher=DHE-RSA-AES256-SHA bits=256 verify=NO); Sun, 5 Mar 2017 14:10:51 -0700
Received: from lxomavmpc030.qintra.com (unknown [127.0.0.1]) by IMSA (Postfix) with ESMTP id 9D7731E0049; Sun,  5 Mar 2017 15:10:45 -0600 (CST)
Received: from lxdnp31k.corp.intranet (unknown [151.117.18.14]) by lxomavmpc030.qintra.com (Postfix) with ESMTP id 769621E0032; Sun,  5 Mar 2017 15:10:45 -0600 (CST)
Received: from lxdnp31k.corp.intranet (localhost [127.0.0.1]) by lxdnp31k.corp.intranet (8.14.8/8.14.8) with ESMTP id v25LAjE1052593; Sun, 5 Mar 2017 14:10:45 -0700
Received: from vodcwhubex502.ctl.intranet (vodcwhubex502.ctl.intranet [151.117.206.28]) by lxdnp31k.corp.intranet (8.14.8/8.14.8) with ESMTP id v25LAfWC052574 (version=TLSv1/SSLv3 cipher=AES128-SHA bits=128 verify=FAIL); Sun, 5 Mar 2017 14:10:45 -0700
Received: from PODCWMBXEX501.ctl.intranet ([169.254.1.220]) by vodcwhubex502.ctl.intranet ([151.117.206.28]) with mapi id 14.03.0294.000; Sun, 5 Mar 2017 15:10:43 -0600
From: "Woodworth, John R" <John.Woodworth@CenturyLink.com>
To: "'Julian Reschke'" <julian.reschke@gmx.de>, "http-auth@ietf.org" <http-auth@ietf.org>
Thread-Topic: [http-auth] FW: New Version Notification for draft-woodworth-json-http-auth-00.txt
Thread-Index: AQHSk/274hOGmOJRSkapVznP/gi4aqGC1A8wgAOoowCAADw5UA==
Date: Sun, 5 Mar 2017 21:10:42 +0000
Message-ID: <A05B583C828C614EBAD1DA920D92866BD06ED4B6@PODCWMBXEX501.ctl.intranet>
References: <148853210107.10146.992834374988004676.idtracker@ietfa.amsl.com> <A05B583C828C614EBAD1DA920D92866BD06ED074@PODCWMBXEX501.ctl.intranet> <52705e55-3924-3a9d-dfe6-73e4d33cb06c@gmx.de>
In-Reply-To: <52705e55-3924-3a9d-dfe6-73e4d33cb06c@gmx.de>
Accept-Language: en-US
Content-Language: en-US
X-MS-Has-Attach: 
X-MS-TNEF-Correlator: 
x-originating-ip: [151.117.206.8]
Content-Type: text/plain; charset="us-ascii"
Content-Transfer-Encoding: quoted-printable
MIME-Version: 1.0
X-TM-AS-MML: disable
X-CFilter-Loop: Reflected
Archived-At: <https://mailarchive.ietf.org/arch/msg/http-auth/lpFLAsN9YN3_uYWb-GYinlKbhJE>
Cc: "Ballew, Dean" <Dean.Ballew@CenturyLink.com>
Subject: Re: [http-auth] FW: New Version Notification for draft-woodworth-json-http-auth-00.txt
X-BeenThere: http-auth@ietf.org
X-Mailman-Version: 2.1.17
Precedence: list
List-Id: HTTP authentication methods <http-auth.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/http-auth>, <mailto:http-auth-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/http-auth/>
List-Post: <mailto:http-auth@ietf.org>
List-Help: <mailto:http-auth-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/http-auth>, <mailto:http-auth-request@ietf.org?subject=subscribe>
X-List-Received-Date: Sun, 05 Mar 2017 21:10:56 -0000

> -----Original Message-----
> From: Julian Reschke [mailto:julian.reschke@gmx.de]
>
> On 2017-03-03 10:16, Woodworth, John R wrote:
> > All,
> >
> > I understand this is late to the party but was hoping some of you
> > may have time to review our new draft.  We welcome any questions,
> > comments and assistance from the group.
> > ...
>
> Hi there,
>
>
> a few formal nits:
>
> - please don't put "httpauth" on the front page if the draft isn't
> a Working Group draft - that said, *do* add a note to the front page
> with instructions where to send feedback (this list is fine for that)
>

Hi Julian,

First, thank you for looking at our draft and your comments, we are
very excited to have feedback so quickly.

We understand listing the intended WG is premature and it will be
removed as suggested.

> - you IPR statement looks weird:
>
> > This document may contain material from IETF Documents or IETF
> > Contributions published or made publicly available before November 10,
> > 2008.

Again, thank you.

This is an oversight and was mistakenly left in from another draft we
are working on.  It will be removed in our next release.

>
> - registering a whole set of auth schemes isn't going to fly; please
> also consider removing the somewhat weird pipe characters from
> the scheme name...
>

This draft is currently experimental but intended to be somewhat of
an umbrella for a "class" of schemes.  We understand this may be
different than currently available schemes but it is something which
makes ours different.  Any advice you have for registering a scheme
"class" would be appreciated.

The pipe is rather critical to the draft as it is used as an
"indicator" for intent.  As I understand it, it is a legal character
and was chosen for another project we are working on as others were
unavailable to the scheme name.  We are rather happy with the way
it is currently working in our implementation and felt it would be
a good idea to share our solution with an even larger community.

It (the pipe) is used to indicate our scheme "class" and allow for
scripts in the browser to offer authentication ahead of the built-in
logic offered by the browser.  For example, if one tries to implement
the "Basic" scheme in a script providing a pretty themed page, it
will undoubtedly be rudely intercepted by the browser via an ugly
login popup without any scripting or theming capabilities.  Our
draft hopes to offer an alternate path.

We debated taking it (the pipe) out of some of the titles and
references but the protocol chaining feature we are introducing
relies on it in order to properly function.


Thanks again,
John

> Best regards, Julian
>

-- THESE ARE THE DROIDS TO WHOM I REFER:
This communication is the property of CenturyLink and may contain confident=
ial or privileged information. Unauthorized use of this communication is st=
rictly prohibited and may be unlawful. If you have received this communicat=
ion in error, please immediately notify the sender by reply e-mail and dest=
roy all copies of the communication and any attachments.


From nobody Sun Mar  5 18:44:59 2017
Return-Path: <James.H.Manger@team.telstra.com>
X-Original-To: http-auth@ietfa.amsl.com
Delivered-To: http-auth@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 9946B12955F for <http-auth@ietfa.amsl.com>; Sun,  5 Mar 2017 18:44:58 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.62
X-Spam-Level: 
X-Spam-Status: No, score=-2.62 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, RCVD_IN_DNSWL_LOW=-0.7, RCVD_IN_MSPIKE_H3=-0.01, RCVD_IN_MSPIKE_WL=-0.01] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (1024-bit key) header.d=teamtelstra.onmicrosoft.com
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id 6_7z8JIjamvY for <http-auth@ietfa.amsl.com>; Sun,  5 Mar 2017 18:44:55 -0800 (PST)
Received: from ipxano.tcif.telstra.com.au (ipxano.tcif.telstra.com.au [203.35.82.200]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 374DD12943B for <http-auth@ietf.org>; Sun,  5 Mar 2017 18:44:54 -0800 (PST)
X-IronPort-AV: E=Sophos;i="5.35,251,1483966800"; d="scan'208";a="140398708"
Received: from unknown (HELO ipcbni.tcif.telstra.com.au) ([10.97.216.204]) by ipoani.tcif.telstra.com.au with ESMTP; 06 Mar 2017 13:44:51 +1100
X-IronPort-AV: E=McAfee;i="5800,7501,8458"; a="315987459"
Received: from wsmsg3706.srv.dir.telstra.com ([172.49.40.80]) by ipcbni.tcif.telstra.com.au with ESMTP; 06 Mar 2017 13:44:51 +1100
Received: from wsapp5872.srv.dir.telstra.com (10.75.11.108) by wsmsg3706.srv.dir.telstra.com (172.49.40.80) with Microsoft SMTP Server (TLS) id 8.3.485.1; Mon, 6 Mar 2017 13:44:50 +1100
Received: from wsapp5584.srv.dir.telstra.com (10.75.131.20) by wsapp5872.srv.dir.telstra.com (10.75.11.108) with Microsoft SMTP Server (TLS) id 15.0.1236.3; Mon, 6 Mar 2017 13:44:00 +1100
Received: from AUS01-SY3-obe.outbound.protection.outlook.com (10.172.229.126) by wsapp5584.srv.dir.telstra.com (10.75.131.20) with Microsoft SMTP Server (TLS) id 15.0.1236.3 via Frontend Transport; Mon, 6 Mar 2017 13:44:00 +1100
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=teamtelstra.onmicrosoft.com; s=selector1-team-telstra-com; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version; bh=Px39bsKZPtzciAPToXbmWYlYAClpvjZk8iL/BbNqBCY=; b=lkb+ufEi5+C+WtHqoui7DZGKtuHzsdDqPVkPepN33BJyMIKHkudEMK64omJxupNX1pgdNaPwARqpKGfYgmzWbs3vxqaO3XPf+5acwclgBPUendUp7gbAGScuVPf5omrvHcg05UN2LUlZ3JmOG3HfvFZk8kVNG97SVlcJJtIzt5k=
Received: from SYXPR01MB1615.ausprd01.prod.outlook.com (10.175.209.15) by SYXPR01MB1615.ausprd01.prod.outlook.com (10.175.209.15) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_CBC_SHA384_P384) id 15.1.947.12; Mon, 6 Mar 2017 02:44:00 +0000
Received: from SYXPR01MB1615.ausprd01.prod.outlook.com ([10.175.209.15]) by SYXPR01MB1615.ausprd01.prod.outlook.com ([10.175.209.15]) with mapi id 15.01.0947.018; Mon, 6 Mar 2017 02:44:00 +0000
From: "Manger, James" <James.H.Manger@team.telstra.com>
To: "Woodworth, John R" <John.Woodworth@CenturyLink.com>, "http-auth@ietf.org" <http-auth@ietf.org>
Thread-Topic: [http-auth] FW: New Version Notification for draft-woodworth-json-http-auth-00.txt
Thread-Index: AdKWIe47Nsjve9cLQxGv18uJXOQWaA==
Date: Mon, 6 Mar 2017 02:44:00 +0000
Message-ID: <SYXPR01MB1615649D5B909D36B080A8D9E52C0@SYXPR01MB1615.ausprd01.prod.outlook.com>
Accept-Language: en-AU, en-US
Content-Language: en-US
X-MS-Has-Attach: 
X-MS-TNEF-Correlator: 
authentication-results: CenturyLink.com; dkim=none (message not signed) header.d=none;CenturyLink.com; dmarc=none action=none header.from=team.telstra.com;
x-originating-ip: [203.35.9.18]
x-ms-office365-filtering-correlation-id: 54c87e40-16c4-4a7d-36db-08d4643aa4df
x-microsoft-antispam: UriScan:;BCL:0;PCL:0;RULEID:(22001);SRVR:SYXPR01MB1615;
x-microsoft-exchange-diagnostics: 1; SYXPR01MB1615; 7:VA633BKTFPnSA4Vo9ih+ttCZrzuVH01qdIfc4pOTtNyiO8mzWBcjxw0y64il3ixFec5KckMaWoCaPcoZvqeZcTz0eALfoKrMoeoQN//uonxnlPMydFfc+bpg6rr73lJJHsfE+CfnrGIp7NWH74d7gj0RlxVuZi9VSsaEw/Sbi7A0Le80bsvEwJ64bmowx8tlJqCFFI1Ke221vexP/BBpu0YweAJ2T1acKTicDkz4TSqPKHgBs2eNlIa/4d9Stc/CDDOUkgxzSCxrAe0jnl5lmyujTxAS0OtNDI51miqt9RCUtsplaIzFqpesjmJ4UIovmvUkL+GGSllytbqICF7TKA==
x-microsoft-antispam-prvs: <SYXPR01MB1615F9B14585F4DC215A9368E52C0@SYXPR01MB1615.ausprd01.prod.outlook.com>
x-exchange-antispam-report-test: UriScan:(158342451672863)(120809045254105);
x-exchange-antispam-report-cfa-test: BCL:0; PCL:0; RULEID:(6040375)(2401047)(8121501046)(5005006)(10201501046)(3002001)(6041248)(20161123558025)(20161123564025)(20161123562025)(20161123560025)(20161123555025)(6072148); SRVR:SYXPR01MB1615; BCL:0; PCL:0; RULEID:; SRVR:SYXPR01MB1615; 
x-forefront-prvs: 0238AEEDB0
x-forefront-antispam-report: SFV:NSPM; SFS:(10019020)(6009001)(7916002)(39450400003)(15594002)(377424004)(13464003)(377454003)(4326008)(5660300001)(38730400002)(3280700002)(305945005)(50986999)(86362001)(54356999)(66066001)(3660700001)(2900100001)(8676002)(81166006)(74316002)(53546006)(189998001)(8936002)(7696004)(2906002)(15650500001)(77096006)(6506006)(33656002)(7736002)(42882006)(2501003)(5890100001)(551544002)(53936002)(6436002)(55016002)(99286003)(9686003)(6306002)(230783001)(102836003)(92566002)(25786008)(3846002)(6116002)(122556002); DIR:OUT; SFP:1102; SCL:1; SRVR:SYXPR01MB1615; H:SYXPR01MB1615.ausprd01.prod.outlook.com; FPR:; SPF:None; MLV:sfv; LANG:en; 
spamdiagnosticoutput: 1:99
spamdiagnosticmetadata: NSPM
Content-Type: text/plain; charset="iso-8859-1"
Content-Transfer-Encoding: quoted-printable
MIME-Version: 1.0
X-MS-Exchange-CrossTenant-originalarrivaltime: 06 Mar 2017 02:44:00.1961 (UTC)
X-MS-Exchange-CrossTenant-fromentityheader: Hosted
X-MS-Exchange-CrossTenant-id: 49dfc6a3-5fb7-49f4-adea-c54e725bb854
X-MS-Exchange-Transport-CrossTenantHeadersStamped: SYXPR01MB1615
X-OriginatorOrg: team.telstra.com
Archived-At: <https://mailarchive.ietf.org/arch/msg/http-auth/Upl6EnrzF-q2PPK-sPKJtqs7qG4>
Cc: "Ballew, Dean" <Dean.Ballew@CenturyLink.com>
Subject: Re: [http-auth] FW: New Version Notification for draft-woodworth-json-http-auth-00.txt
X-BeenThere: http-auth@ietf.org
X-Mailman-Version: 2.1.17
Precedence: list
List-Id: HTTP authentication methods <http-auth.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/http-auth>, <mailto:http-auth-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/http-auth/>
List-Post: <mailto:http-auth@ietf.org>
List-Help: <mailto:http-auth-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/http-auth>, <mailto:http-auth-request@ietf.org?subject=subscribe>
X-List-Received-Date: Mon, 06 Mar 2017 02:44:58 -0000

The "password" variant sends the same info as BASIC, just with a different =
syntax. It is hard to see the point. Surely a normal BASIC header could be =
passed to client-side scripting just as easily as a re-formatted version?

The "challenge" variant looks like it is trying to mimic the DIGEST scheme,=
 with a different syntax, and with the crypto applied slightly differently.=
 The crypto changes look more dangerous than helpful. DIGEST at least separ=
ated the concepts of a Hash from a MAC (Keyed Digest), even if the latter u=
sed the former in too simple a way. In DIGEST the password is hashed with t=
he username and realm to form a secret key, but not in "challenge". A new s=
pec today should use a proper MAC algorithm, such as HMAC.

Quirks from DIGEST seem to be repeated in "challenge", such as separate "no=
nce" and "opaque" members despite both being: chosen by the server; opaque =
to the client; hashed into the response; and returned to the server.

The highly recommended "nonce" construction looks poor. A 36-char random UU=
ID just to provide uniqueness within the 10=B5s window of the time componen=
t (eg 1488442706.13154) is overkill. Hashing a concatenation of nonce parts=
 and a secret is the sort of ad hoc crypto that should be avoided. Use a pr=
oper MAC algorithm instead.

JSON has arrays so why not use an array for the "algorithms" member, instea=
d of a comma-separated string with a rule to ignore whitespace?

The mix of base64, lowercase-hex, and UUID encoding; plus commas, slashes, =
hyphens, and colons as separators is a bit messy.

Suggesting window.AuthHandler() as a place to host handlers (without specif=
ying actual APIs) sounds like it will ruin this place for use once somethin=
g interoperable is actually defined.

Your pretty JSON format with commas at the start of the next line (instead =
of the end of the previous line) is a cute convention.
      {
         "type"     : "password"
        ,"username" : "MyUser"
        ,"password" : "MyPassword"
      }
=20
--
James Manger


-----Original Message-----
From: http-auth [mailto:http-auth-bounces@ietf.org] On Behalf Of Woodworth,=
 John R
Sent: Friday, 3 March 2017 8:17 PM
To: http-auth@ietf.org
Cc: Ballew, Dean <Dean.Ballew@CenturyLink.com>
Subject: [http-auth] FW: New Version Notification for draft-woodworth-json-=
http-auth-00.txt

All,

I understand this is late to the party but was hoping some of you may have =
time to review our new draft.  We welcome any questions, comments and assis=
tance from the group.


Thanks,
John
-----Original Message-----
From: internet-drafts@ietf.org [mailto:internet-drafts@ietf.org]


A new version of I-D, draft-woodworth-json-http-auth-00.txt
has been successfully submitted by John Woodworth and posted to the IETF re=
pository.

Name:           draft-woodworth-json-http-auth
Revision:       00
Title:          HTTP Authentication - |JSON| Scheme
Document date:  2017-02-28
Group:          Individual Submission
Pages:          17
URL:            https://www.ietf.org/internet-drafts/draft-woodworth-json-h=
ttp-auth-00.txt
Status:         https://datatracker.ietf.org/doc/draft-woodworth-json-http-=
auth/
Htmlized:       https://tools.ietf.org/html/draft-woodworth-json-http-auth-=
00


Abstract:
   The |JSON| authentication scheme provides a mechanism for exchanging
   authentication challenges and credentials as objects in the form of
   JavaScript Object Notation (JSON).  This scheme offers a secure
   mechanism of providing authenticated access to a set of protected
   HTTP resources which may be handled by scripting utility framework as
   in XMLHttpRequest calls (AJAX) or directly by the client's user
   agent.  This chaining feature is unique to this scheme.




Please note that it may take a couple of minutes from the time of submissio=
n until the htmlized version and diff are available at tools.ietf.org.

The IETF Secretariat

-- THESE ARE THE DROIDS TO WHOM I REFER:
This communication is the property of CenturyLink and may contain confident=
ial or privileged information. Unauthorized use of this communication is st=
rictly prohibited and may be unlawful. If you have received this communicat=
ion in error, please immediately notify the sender by reply e-mail and dest=
roy all copies of the communication and any attachments.
_______________________________________________
http-auth mailing list
http-auth@ietf.org
https://www.ietf.org/mailman/listinfo/http-auth


From nobody Sun Mar  5 22:50:07 2017
Return-Path: <John.Woodworth@CenturyLink.com>
X-Original-To: http-auth@ietfa.amsl.com
Delivered-To: http-auth@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 18A8212711D for <http-auth@ietfa.amsl.com>; Sun,  5 Mar 2017 22:50:07 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.902
X-Spam-Level: 
X-Spam-Status: No, score=-1.902 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, RCVD_IN_DNSWL_NONE=-0.0001, RP_MATCHES_RCVD=-0.001, SPF_PASS=-0.001] autolearn=ham autolearn_force=no
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id d2ZhVxbXJTrt for <http-auth@ietfa.amsl.com>; Sun,  5 Mar 2017 22:50:06 -0800 (PST)
Received: from lxomp52w.centurylink.com (lxomp52w.centurylink.com [155.70.50.76]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 0D43F127A90 for <http-auth@ietf.org>; Sun,  5 Mar 2017 22:50:05 -0800 (PST)
Received: from lxomavmpc030.qintra.com (lxomavmpc030.qintra.com [151.117.207.30]) by lxomp52w.centurylink.com (8.14.8/8.14.8) with ESMTP id v266o4b7055880 (version=TLSv1/SSLv3 cipher=DHE-RSA-AES256-SHA bits=256 verify=NO); Mon, 6 Mar 2017 00:50:04 -0600
Received: from lxomavmpc030.qintra.com (unknown [127.0.0.1]) by IMSA (Postfix) with ESMTP id 5AC421E0049; Mon,  6 Mar 2017 00:49:59 -0600 (CST)
Received: from lxomp06u.corp.intranet (unknown [151.117.18.14]) by lxomavmpc030.qintra.com (Postfix) with ESMTP id 3DD0D1E0032; Mon,  6 Mar 2017 00:49:59 -0600 (CST)
Received: from lxomp06u.corp.intranet (localhost [127.0.0.1]) by lxomp06u.corp.intranet (8.14.8/8.14.8) with ESMTP id v266nxtJ006927; Mon, 6 Mar 2017 00:49:59 -0600
Received: from vodcwhubex501.ctl.intranet (vodcwhubex501.ctl.intranet [151.117.206.27]) by lxomp06u.corp.intranet (8.14.8/8.14.8) with ESMTP id v266nwWH006924 (version=TLSv1/SSLv3 cipher=AES128-SHA bits=128 verify=FAIL); Mon, 6 Mar 2017 00:49:58 -0600
Received: from PODCWMBXEX501.ctl.intranet ([169.254.1.220]) by vodcwhubex501.ctl.intranet ([151.117.206.27]) with mapi id 14.03.0294.000; Mon, 6 Mar 2017 00:49:58 -0600
From: "Woodworth, John R" <John.Woodworth@CenturyLink.com>
To: "'Manger, James'" <James.H.Manger@team.telstra.com>, "http-auth@ietf.org" <http-auth@ietf.org>
Thread-Topic: [http-auth] FW: New Version Notification for draft-woodworth-json-http-auth-00.txt
Thread-Index: AdKWIe474hOGmOJRSkapVznP/gi4agAEvilQ
Date: Mon, 6 Mar 2017 06:49:57 +0000
Message-ID: <A05B583C828C614EBAD1DA920D92866BD06ED513@PODCWMBXEX501.ctl.intranet>
References: <SYXPR01MB1615649D5B909D36B080A8D9E52C0@SYXPR01MB1615.ausprd01.prod.outlook.com>
In-Reply-To: <SYXPR01MB1615649D5B909D36B080A8D9E52C0@SYXPR01MB1615.ausprd01.prod.outlook.com>
Accept-Language: en-US
Content-Language: en-US
X-MS-Has-Attach: 
X-MS-TNEF-Correlator: 
x-originating-ip: [151.117.206.8]
Content-Type: text/plain; charset="iso-8859-1"
Content-Transfer-Encoding: quoted-printable
MIME-Version: 1.0
X-TM-AS-MML: disable
X-CFilter-Loop: Reflected
Archived-At: <https://mailarchive.ietf.org/arch/msg/http-auth/rneLGQuamH83AIe_jFAWpZZ5KB4>
Cc: "Ballew, Dean" <Dean.Ballew@CenturyLink.com>
Subject: Re: [http-auth] FW: New Version Notification for draft-woodworth-json-http-auth-00.txt
X-BeenThere: http-auth@ietf.org
X-Mailman-Version: 2.1.17
Precedence: list
List-Id: HTTP authentication methods <http-auth.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/http-auth>, <mailto:http-auth-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/http-auth/>
List-Post: <mailto:http-auth@ietf.org>
List-Help: <mailto:http-auth-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/http-auth>, <mailto:http-auth-request@ietf.org?subject=subscribe>
X-List-Received-Date: Mon, 06 Mar 2017 06:50:07 -0000

-----Original Message-----
From: Manger, James [mailto:James.H.Manger@team.telstra.com]


Hi James,

First, thank you for the detailed feedback it is very much
appreciated.  It's actually eerie how your comments mirror
our own internal discussions on many points.

>
> The "password" variant sends the same info as BASIC, just with a
> different syntax. It is hard to see the point. Surely a normal
> BASIC header could be passed to client-side scripting just as
> easily as a re-formatted version?
>
> The "challenge" variant looks like it is trying to mimic the
> DIGEST scheme, with a different syntax, and with the crypto
> applied slightly differently. The crypto changes look more
> dangerous than helpful. DIGEST at least separated the concepts
> of a Hash from a MAC (Keyed Digest), even if the latter used
> the former in too simple a way. In DIGEST the password is hashed
> with the username and realm to form a secret key, but not in
> "challenge". A new spec today should use a proper MAC algorithm,
> such as HMAC.
>

Both of these similarities are actually intentional.  One of our
goals is to get a "usable framework" which is both JSON based and
can be easily extended.  Our rational for including something
basic-ish and digest-ish was that a framework not having comparable
features was dead out of the gate.  Early versions actually used
"basic" and "digest" types and borrowed even more heavily from each.
It was decided to avoid being *too* close in an attempt to cut down
on confusion.  Perhaps we should make this point obvious in the
introduction?

>
> Quirks from DIGEST seem to be repeated in "challenge", such as
> separate "nonce" and "opaque" members despite both being: chosen
> by the server; opaque to the client; hashed into the response;
> and returned to the server.
>

The opaque value is not strictly necessary for the authentication
portion and is expected to be _additional_ easily validated data the
server can use to simplify its session management.

To keep implementation requirements down for the server, our thought
was if the nonce (and other session data) could be self validated, a
table would not _need_ to be kept.  With no table, no shared memory
or other complications would need to be done among the multiple
threads and/ or multiple servers.  This opens itself to something
as simple as a CGI script.

>
> The highly recommended "nonce" construction looks poor. A 36-char
> random UUID just to provide uniqueness within the 10=B5s window of
> the time component (eg 1488442706.13154) is overkill.
>

Funny, this was added to avoid the whole "this is cryptographically
too weak" discussion :) .

>
> Hashing a
> concatenation of nonce parts and a secret is the sort of ad hoc
> crypto that should be avoided. Use a proper MAC algorithm instead.
>

We are definitely open to something like HMAC, our target here was
again to keep implementation effort minimal.  Thankfully, we have
really good MIT compatible libraries for the project which spawned
this draft so I guess it's reasonable to assume this is not an
issue.  We just wanted to get additional input from this group
before moving in that direction.

>
> JSON has arrays so why not use an array for the "algorithms"
> member, instead of a comma-separated string with a rule to ignore
> whitespace?
>

No strong reason.  Our rational was to keep the object from
becoming too much of a nested mess but we are in agreement here.

>
> The mix of base64, lowercase-hex, and UUID encoding; plus commas,
> slashes, hyphens, and colons as separators is a bit messy.
>

I guess the nonce could just as easily be a sub-object.

Somehow, this was expected to allow a developer to run some really
simple cli tools to manually dissect, inspect and verify all the
parts of the process.

As you may have noticed, 'simplicity in implementation' is a common
theme.  It sounds like crypto comes easily to you but I have found
it to be a difficult topic for many developers.  Keeping simple
components which can each be easily checked via readily available
tools like 'sha256sum' and 'jq' is an attempt to simplify the
process.

This, in my mind at least should make for fewer conceptual
problems and fewer problems makes for less buggy implementations.

Having said that, I am always open to being wrong.

>
> Suggesting window.AuthHandler() as a place to host handlers
> (without specifying actual APIs) sounds like it will ruin this
> place for use once something interoperable is actually defined.
>

This is true.  As silly as it may sound, we were hoping to keep
the page-count down to around 10.  We have another draft which
is roughly 35 pages and it is difficult to get that much of
someone's time for feedback.  We are currently sitting at around
15 and every minor detail seems to add 5 pages.

That said, we will expand on this topic in hopes we miss shooting
either foot.

>
> Your pretty JSON format with commas at the start of the next line
> (instead of the end of the previous line) is a cute convention.
>

Thanks.  I wish I could take credit for it but I found this little
gem as part of a code-style requirements doc for contributing to
some JavaScript project a while back and have been searching for
it again to give proper attribution.

It is by far the one JS tip that's saved me the most frustration
as trailing commas are simply death waiting to happen };{> .


Thanks,
John

>
>       {
>          "type"     : "password"
>         ,"username" : "MyUser"
>         ,"password" : "MyPassword"
>       }
>
> --
> James Manger
>

-- THESE ARE THE DROIDS TO WHOM I REFER:
This communication is the property of CenturyLink and may contain confident=
ial or privileged information. Unauthorized use of this communication is st=
rictly prohibited and may be unlawful. If you have received this communicat=
ion in error, please immediately notify the sender by reply e-mail and dest=
roy all copies of the communication and any attachments.


From nobody Sun Mar  5 22:56:22 2017
Return-Path: <julian.reschke@gmx.de>
X-Original-To: http-auth@ietfa.amsl.com
Delivered-To: http-auth@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id E951A1293E4 for <http-auth@ietfa.amsl.com>; Sun,  5 Mar 2017 22:56:20 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.601
X-Spam-Level: 
X-Spam-Status: No, score=-2.601 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, FREEMAIL_FROM=0.001, RCVD_IN_DNSWL_LOW=-0.7, RCVD_IN_MSPIKE_H2=-0.001, SPF_PASS=-0.001] autolearn=ham autolearn_force=no
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id wNuyqmCgLObC for <http-auth@ietfa.amsl.com>; Sun,  5 Mar 2017 22:56:20 -0800 (PST)
Received: from mout.gmx.net (mout.gmx.net [212.227.17.22]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 81A5E127A90 for <http-auth@ietf.org>; Sun,  5 Mar 2017 22:56:19 -0800 (PST)
Received: from [192.168.178.20] ([93.217.79.102]) by mail.gmx.com (mrgmx103 [212.227.17.168]) with ESMTPSA (Nemesis) id 0LgI0W-1bxTnK0yma-00ngze; Mon, 06 Mar 2017 07:56:10 +0100
To: "Woodworth, John R" <John.Woodworth@CenturyLink.com>, "http-auth@ietf.org" <http-auth@ietf.org>
References: <148853210107.10146.992834374988004676.idtracker@ietfa.amsl.com> <A05B583C828C614EBAD1DA920D92866BD06ED074@PODCWMBXEX501.ctl.intranet> <52705e55-3924-3a9d-dfe6-73e4d33cb06c@gmx.de> <A05B583C828C614EBAD1DA920D92866BD06ED4B6@PODCWMBXEX501.ctl.intranet>
From: Julian Reschke <julian.reschke@gmx.de>
Message-ID: <156a9955-24a2-0a61-6752-f82b955128ae@gmx.de>
Date: Mon, 6 Mar 2017 07:56:09 +0100
User-Agent: Mozilla/5.0 (Windows NT 10.0; WOW64; rv:45.0) Gecko/20100101 Thunderbird/45.7.1
MIME-Version: 1.0
In-Reply-To: <A05B583C828C614EBAD1DA920D92866BD06ED4B6@PODCWMBXEX501.ctl.intranet>
Content-Type: text/plain; charset=windows-1252; format=flowed
Content-Transfer-Encoding: 7bit
X-Provags-ID: V03:K0:FLjmEc6FksOcny9ftA1Iu+jwvqRcuXgWYSX11keKsUS3cobKdsi g7bNr3E1fxIdrbs78fcC3QUhhmQs3ghNq8Ijjg9ZmX1ATGBq4KavNgIvWcIRpfLN929gV1K 6O9iZ1m3Inqwp+Y3jSELWRAEFEf38efwKsx0xtwUQzTHNCCuiV36NWv5lW+TPEtyt+c3Pju Tf5deg34LXQ5ZmnF9csKQ==
X-UI-Out-Filterresults: notjunk:1;V01:K0:/zduqT1Ksi4=:XN0gadwHdHYptPg36SFeRY /0IS1Ijpkdw/OYKJUW2xybpTkoFPGk08y0j7QzJTaTPNMsHkGshVrj6+QkACyI2c8LyH76SVL yzB7gUMIOEi5kmY73P5khE2Fp0ZP8DgJwCaYxk69JwWZEelU5NY0MrEXE3WSPqzZGRxOpJSz4 tpuHKyHApkMo7cMaIdH1nyr1V/R0UlCiDhlip228j5JeYHkxC3OskLG2fEyO+3pAZ5mYEjnf+ I+KGpds1v1wbeVhS420R2oTqvQ71kD2ExjIFR7QnGilWKKE/CqThXGED4y6qhGn8yxR8JXxkx 1kxeTXwIYoea1Z2tPgilEmWef3rJ1iVjmWqOHdJflxI44HV92aqUobxwDask/IWa8MnMa/VEm ETdCu95W3Ipj8YwlystXJKrX6F7vrQqCq4xibuCUIjrvyOEWkRykKBzmApNu1tBsW/9T7XA76 esF0YRDqVLwrLQKpwFiX0lP5tj63A5Gx7YUv/Dwe2gPLupqnJICHDSYNlqXxUQKiA7S+SD8o8 iMwWXLNTpDS2W+s9Z8ZdEUAHqSbN6hlbDXTlbG9qr5QlW6M0u5+Eb7N1L8B5nLT/YbpB5HW1s 2aTGt9P013cbWOT1aosNrt5CJDRtCx09xHfVADkSVgopt72Ax69SXOv7z9JbqWKqwncnwc7nR GJwZwP3By+LxwdBz3jzF1wUXS19FpXv5Qd9nYK/Y+tzTfmIAYLID/rFBbRS7oIIATx2mjAsMv Y+MBrb+tGvZeYsxb3CCKa+GUv01GqYYgdnlOD4XmHY+GIkgs5tdkgKBXwY7sjDGstt6kGEdtC jhTu/7cgeQqN7gQK3SMc/kd7SEpvxrCIGjUNuqcHd8+ItHj098/faXoBk+ePNPZGG3nwUOhZ9 NKsbn+ZlZRiYXbVdRhZjd83lhVTju/EeAn4yl563qdvPJuIONlTrWodax4urRwmvSkXk3GOBw TrETh1J/MBOhKXPGuQsprtYjfd0vp+sVb2GN7bZut3axONYrxq3yOhRKCv3VrcSNyaXBMjvpO mQz9boGyCrAkQgPOaWdoNZo=
Archived-At: <https://mailarchive.ietf.org/arch/msg/http-auth/ymXjSZ-PBPtcImCLXdSzKWfq1qQ>
Cc: "Ballew, Dean" <Dean.Ballew@CenturyLink.com>
Subject: Re: [http-auth] FW: New Version Notification for draft-woodworth-json-http-auth-00.txt
X-BeenThere: http-auth@ietf.org
X-Mailman-Version: 2.1.17
Precedence: list
List-Id: HTTP authentication methods <http-auth.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/http-auth>, <mailto:http-auth-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/http-auth/>
List-Post: <mailto:http-auth@ietf.org>
List-Help: <mailto:http-auth-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/http-auth>, <mailto:http-auth-request@ietf.org?subject=subscribe>
X-List-Received-Date: Mon, 06 Mar 2017 06:56:21 -0000

On 2017-03-05 22:10, Woodworth, John R wrote:
> ...
> Hi Julian,
>
> First, thank you for looking at our draft and your comments, we are
> very excited to have feedback so quickly.
>
> We understand listing the intended WG is premature and it will be
> removed as suggested.

FWIW, there is no httpauth WG anymore. So a new or different WG would be 
needed.

> ...
>> - registering a whole set of auth schemes isn't going to fly; please
>> also consider removing the somewhat weird pipe characters from
>> the scheme name...
>>
>
> This draft is currently experimental but intended to be somewhat of
> an umbrella for a "class" of schemes.  We understand this may be
> different than currently available schemes but it is something which
> makes ours different.  Any advice you have for registering a scheme
> "class" would be appreciated.
> ...

There is currently no way to register a class of schemes, it's somewhat 
contrary to the concept of the registry. I would recommend to find a way 
where no registration of classes is needed.

 > ...

Best regards, Julian


From nobody Mon Mar  6 07:47:50 2017
Return-Path: <John.Woodworth@CenturyLink.com>
X-Original-To: http-auth@ietfa.amsl.com
Delivered-To: http-auth@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id DF992129534 for <http-auth@ietfa.amsl.com>; Mon,  6 Mar 2017 07:47:48 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.402
X-Spam-Level: 
X-Spam-Status: No, score=-1.402 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, RCVD_IN_DNSWL_NONE=-0.0001, RCVD_IN_SORBS_SPAM=0.5, RP_MATCHES_RCVD=-0.001, SPF_PASS=-0.001] autolearn=no autolearn_force=no
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id yUnbQJorHO2B for <http-auth@ietfa.amsl.com>; Mon,  6 Mar 2017 07:47:47 -0800 (PST)
Received: from lxdnp29m.centurylink.com (lxdnp29m.centurylink.com [155.70.32.52]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 970251293DC for <http-auth@ietf.org>; Mon,  6 Mar 2017 07:47:47 -0800 (PST)
Received: from lxomavmpc030.qintra.com (lxomavmpc030.qintra.com [151.117.207.30]) by lxdnp29m.centurylink.com (8.14.8/8.14.8) with ESMTP id v26Flbi5027801 (version=TLSv1/SSLv3 cipher=DHE-RSA-AES256-SHA bits=256 verify=NO); Mon, 6 Mar 2017 08:47:37 -0700
Received: from lxomavmpc030.qintra.com (unknown [127.0.0.1]) by IMSA (Postfix) with ESMTP id D3BFA1E0073; Mon,  6 Mar 2017 09:47:31 -0600 (CST)
Received: from lxdnp31k.corp.intranet (unknown [151.117.18.14]) by lxomavmpc030.qintra.com (Postfix) with ESMTP id A88CC1E008F; Mon,  6 Mar 2017 09:47:31 -0600 (CST)
Received: from lxdnp31k.corp.intranet (localhost [127.0.0.1]) by lxdnp31k.corp.intranet (8.14.8/8.14.8) with ESMTP id v26FlVV6004053; Mon, 6 Mar 2017 08:47:31 -0700
Received: from vodcwhubex501.ctl.intranet (vodcwhubex501.ctl.intranet [151.117.206.27]) by lxdnp31k.corp.intranet (8.14.8/8.14.8) with ESMTP id v26FlVxp004044 (version=TLSv1/SSLv3 cipher=AES128-SHA bits=128 verify=FAIL); Mon, 6 Mar 2017 08:47:31 -0700
Received: from PODCWMBXEX501.ctl.intranet ([169.254.1.220]) by vodcwhubex501.ctl.intranet ([151.117.206.27]) with mapi id 14.03.0294.000; Mon, 6 Mar 2017 09:47:30 -0600
From: "Woodworth, John R" <John.Woodworth@CenturyLink.com>
To: "'Julian Reschke'" <julian.reschke@gmx.de>, "http-auth@ietf.org" <http-auth@ietf.org>
Thread-Topic: [http-auth] FW: New Version Notification for draft-woodworth-json-http-auth-00.txt
Thread-Index: AQHSk/274hOGmOJRSkapVznP/gi4aqGC1A8wgAOoowCAADw5UIABESaAgAAuQaA=
Date: Mon, 6 Mar 2017 15:47:30 +0000
Message-ID: <A05B583C828C614EBAD1DA920D92866BD06ED603@PODCWMBXEX501.ctl.intranet>
References: <148853210107.10146.992834374988004676.idtracker@ietfa.amsl.com> <A05B583C828C614EBAD1DA920D92866BD06ED074@PODCWMBXEX501.ctl.intranet> <52705e55-3924-3a9d-dfe6-73e4d33cb06c@gmx.de> <A05B583C828C614EBAD1DA920D92866BD06ED4B6@PODCWMBXEX501.ctl.intranet> <156a9955-24a2-0a61-6752-f82b955128ae@gmx.de>
In-Reply-To: <156a9955-24a2-0a61-6752-f82b955128ae@gmx.de>
Accept-Language: en-US
Content-Language: en-US
X-MS-Has-Attach: 
X-MS-TNEF-Correlator: 
x-originating-ip: [151.117.206.8]
Content-Type: text/plain; charset="us-ascii"
Content-Transfer-Encoding: quoted-printable
MIME-Version: 1.0
X-TM-AS-MML: disable
X-CFilter-Loop: Reflected
Archived-At: <https://mailarchive.ietf.org/arch/msg/http-auth/oClWJMnrpYrgn4sU09YdYJ0mn3Y>
Cc: "Ballew, Dean" <Dean.Ballew@CenturyLink.com>
Subject: Re: [http-auth] FW: New Version Notification for draft-woodworth-json-http-auth-00.txt
X-BeenThere: http-auth@ietf.org
X-Mailman-Version: 2.1.17
Precedence: list
List-Id: HTTP authentication methods <http-auth.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/http-auth>, <mailto:http-auth-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/http-auth/>
List-Post: <mailto:http-auth@ietf.org>
List-Help: <mailto:http-auth-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/http-auth>, <mailto:http-auth-request@ietf.org?subject=subscribe>
X-List-Received-Date: Mon, 06 Mar 2017 15:47:49 -0000

>
> -----Original Message-----
> From: Julian Reschke [mailto:julian.reschke@gmx.de]
>

Hi Julian,

>
> FWIW, there is no httpauth WG anymore. So a new or different WG
> would be needed.
>

Understood.

> > ...
>
> There is currently no way to register a class of schemes, it's
> somewhat contrary to the concept of the registry. I would recommend
> to find a way where no registration of classes is needed.
>

We do love a challenge :)


Thanks again,
John

>  > ...
>
> Best regards, Julian
>

-- THESE ARE THE DROIDS TO WHOM I REFER:
This communication is the property of CenturyLink and may contain confident=
ial or privileged information. Unauthorized use of this communication is st=
rictly prohibited and may be unlawful. If you have received this communicat=
ion in error, please immediately notify the sender by reply e-mail and dest=
roy all copies of the communication and any attachments.

