
From nobody Sun Jun 18 18:28:00 2017
Return-Path: <ve7jtb@ve7jtb.com>
X-Original-To: unbearable@ietfa.amsl.com
Delivered-To: unbearable@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 4DC4F126CC4 for <unbearable@ietfa.amsl.com>; Sun, 18 Jun 2017 18:27:58 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.599
X-Spam-Level: 
X-Spam-Status: No, score=-2.599 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, HTML_MESSAGE=0.001, RCVD_IN_DNSWL_LOW=-0.7, SPF_PASS=-0.001, URIBL_BLOCKED=0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (2048-bit key) header.d=ve7jtb-com.20150623.gappssmtp.com
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id C8QQ-HLY7bmI for <unbearable@ietfa.amsl.com>; Sun, 18 Jun 2017 18:27:55 -0700 (PDT)
Received: from mail-it0-x233.google.com (mail-it0-x233.google.com [IPv6:2607:f8b0:4001:c0b::233]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 05574126B6D for <unbearable@ietf.org>; Sun, 18 Jun 2017 18:27:54 -0700 (PDT)
Received: by mail-it0-x233.google.com with SMTP id m47so49290380iti.0 for <unbearable@ietf.org>; Sun, 18 Jun 2017 18:27:54 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=ve7jtb-com.20150623.gappssmtp.com; s=20150623; h=from:mime-version:subject:message-id:date:cc:to; bh=08Et0uola7nPYVu1HM6zHfx1RlQR/s7wKJTbmI1pJ6I=; b=aFyS3sWrF/dC19VsLBz9Ybze+PH3i/n0mrhgfvGZYwq9DPKdiuICTDDmjLNrC9AFag RwxW1YyE/A5+siiJA2+5Cj9Y0RouU0YVbnnG/ZIhCQt34zpuRG3VcEsxFYs8dpYA7g2U NolmwmxunF2rO0c+9NyOXr/XHHSRyYK9LtKKZkWJSssltLPw5+0CAWbrkRvGQtGCa3UO O26tppERyjQGd+BjjLmYY7ICymFeBszzB2LPsT9pW/JrQ8pGBrOXPG+G/X6sh+wv5AGN 6WAvXg3JoH4cXI6mFbsPJBH4bZWzMCdrUqkROl7jUh5A2ADPkZCor1MLRuGSQ2YLdy5c /Rfg==
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20161025; h=x-gm-message-state:from:mime-version:subject:message-id:date:cc:to; bh=08Et0uola7nPYVu1HM6zHfx1RlQR/s7wKJTbmI1pJ6I=; b=GI2Sr1ghaGpkfpfSpzBzNbVw7VF6Jq5kNzncetlWKJsDDuNh4PZEINCAnJEER/UFwg xCHoNEWV5QxcBeehkmoQ9nBgy8PvroL8Di3zy40ayJC6nnIhbRSQ94nYuqIbKraYt+G8 JmGtC0pdVQXrwpNAZcO78Tkq+iI+2zdMlzjEr03AI5JshiFIYit15cshAi8QDv7ekCM8 t48xQnZY1GYLP1Vrm5fj9+82HhKxTElCkeI3mK80Cd6W1v00/Ys4/ayFsFJa1XpYcCVj Nh1yRCuQlYDylCSvr21AbE6Ej/0UTM7USxFM8M1gipP/TZ/LjUwBZXy0sptUjlrimDWZ Rj8Q==
X-Gm-Message-State: AKS2vOxksHtnCk+MXCe/JLETM35j7kenj+/Xn4A2dP71rHSWpyfxYjaP tntomK/vN1iIn1fYdXJGhA==
X-Received: by 10.36.211.69 with SMTP id n66mr19866846itg.36.1497835674004; Sun, 18 Jun 2017 18:27:54 -0700 (PDT)
Received: from jbradley-r.lan ([208.59.64.21]) by smtp.gmail.com with ESMTPSA id h76sm3117003ith.24.2017.06.18.18.27.50 (version=TLS1_2 cipher=ECDHE-RSA-AES128-GCM-SHA256 bits=128/128); Sun, 18 Jun 2017 18:27:51 -0700 (PDT)
From: John Bradley <ve7jtb@ve7jtb.com>
Mime-Version: 1.0 (Mac OS X Mail 10.3 \(3273\))
Message-Id: <EE89D9AF-F52B-48ED-8046-F441A67818A4@ve7jtb.com>
Date: Sun, 18 Jun 2017 20:27:47 -0500
Cc: draft-ietf-tokbind-negotiation@ietf.org
To: IETF TokBind WG <unbearable@ietf.org>
X-Mailer: Apple Mail (2.3273)
Content-Type: multipart/signed; protocol="application/pkcs7-signature"; micalg=sha-256; boundary="001a1149a9644d08c70552460b57"
Archived-At: <https://mailarchive.ietf.org/arch/msg/unbearable/DXNMY4VFW0QE_6_giKykVN9b_lA>
Subject: [Unbearable] IPR for draft-ietf-tokbind-negotiation
X-BeenThere: unbearable@ietf.org
X-Mailman-Version: 2.1.22
Precedence: list
List-Id: "\"This list is for discussion of proposals for doing better than bearer tokens \(e.g. HTTP cookies, OAuth tokens etc.\) for web applications. The specific goal is chartering a WG focused on preventing security token export and replay attacks.\"" <unbearable.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/unbearable>, <mailto:unbearable-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/unbearable/>
List-Post: <mailto:unbearable@ietf.org>
List-Help: <mailto:unbearable-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/unbearable>, <mailto:unbearable-request@ietf.org?subject=subscribe>
X-List-Received-Date: Mon, 19 Jun 2017 01:27:58 -0000

--001a1149a9644d08c70552460b57
Content-Type: multipart/alternative;
 boundary="Apple-Mail=_48CDB961-D32D-40ED-A970-58F55E98DFE3"


--Apple-Mail=_48CDB961-D32D-40ED-A970-58F55E98DFE3
Content-Transfer-Encoding: quoted-printable
Content-Type: text/plain;
	charset=us-ascii


I am working on the shepherd writeup for the Transport Layer Security =
(TLS) Extension for Token Binding Protocol Negotiation document:
https://tools.ietf.org/html/draft-ietf-tokbind-negotiation-08

One item in the template requires me to indicate whether each document
author has confirmed that any and all appropriate IPR disclosures
required for full conformance with the provisions of BCP 78 and BCP 79
have already been filed.

Could each of you please confirm?

   Magnus Nystroem
   Microsoft Corp.
   USA

   Email: mnystrom@microsoft.com


   Dirk Balfanz
   Google Inc.
   USA

   Email: balfanz@google.com


   Adam Langley
   Google Inc.
   USA

   Email: agl@google.com




--Apple-Mail=_48CDB961-D32D-40ED-A970-58F55E98DFE3
Content-Transfer-Encoding: quoted-printable
Content-Type: text/html;
	charset=us-ascii

<html><head><meta http-equiv=3D"Content-Type" content=3D"text/html =
charset=3Dus-ascii"></head><body style=3D"word-wrap: break-word; =
-webkit-nbsp-mode: space; -webkit-line-break: after-white-space;" =
class=3D""><span class=3D""><br class=3D""></span><span =
class=3D"">I&nbsp;am working on the shepherd writeup for =
the&nbsp;Transport Layer Security (TLS) Extension for Token =
Binding&nbsp;Protocol&nbsp;Negotiation&nbsp;document:<br class=3D""><a =
href=3D"https://tools.ietf.org/html/draft-ietf-tokbind-negotiation-08" =
class=3D"">https://tools.ietf.org/html/draft-ietf-tokbind-negotiation-08</=
a><br class=3D""><br class=3D"">One item in the template requires me to =
indicate whether each document<br class=3D"">author has confirmed that =
any and all appropriate IPR disclosures<br class=3D"">required for full =
conformance with the provisions of BCP 78 and BCP 79<br class=3D"">have =
already been filed.<br class=3D""><br class=3D"">Could each of you =
please confirm?<br class=3D""><br class=3D""><div class=3D""><pre =
class=3D"newpage" style=3D"font-size: 13.3333px; margin-top: 0px; =
margin-bottom: 0px; break-before: page; font-variant-ligatures: normal; =
orphans: 2; widows: 2;">   Magnus Nystroem
   Microsoft Corp.
   USA

   Email: mnystrom@microsoft.com


   Dirk Balfanz
   Google Inc.
   USA

   Email: balfanz@google.com


   Adam Langley
   Google Inc.
   USA

   Email: agl@google.com



</pre></div></span></body></html>=

--Apple-Mail=_48CDB961-D32D-40ED-A970-58F55E98DFE3--

--001a1149a9644d08c70552460b57
Content-Type: application/pkcs7-signature; name="smime.p7s"
Content-Transfer-Encoding: base64
Content-Disposition: attachment; filename="smime.p7s"
Content-Description: S/MIME Cryptographic Signature

MIIRGwYJKoZIhvcNAQcCoIIRDDCCEQgCAQExDzANBglghkgBZQMEAgEFADALBgkqhkiG9w0BBwGg
gg4rMIIErzCCA5egAwIBAgIRAOAjyxUSg1OJrWFuelRnayEwDQYJKoZIhvcNAQELBQAwbzELMAkG
A1UEBhMCU0UxFDASBgNVBAoTC0FkZFRydXN0IEFCMSYwJAYDVQQLEx1BZGRUcnVzdCBFeHRlcm5h
bCBUVFAgTmV0d29yazEiMCAGA1UEAxMZQWRkVHJ1c3QgRXh0ZXJuYWwgQ0EgUm9vdDAeFw0xNDEy
MjIwMDAwMDBaFw0yMDA1MzAxMDQ4MzhaMIGbMQswCQYDVQQGEwJHQjEbMBkGA1UECBMSR3JlYXRl
ciBNYW5jaGVzdGVyMRAwDgYDVQQHEwdTYWxmb3JkMRowGAYDVQQKExFDT01PRE8gQ0EgTGltaXRl
ZDFBMD8GA1UEAxM4Q09NT0RPIFNIQS0yNTYgQ2xpZW50IEF1dGhlbnRpY2F0aW9uIGFuZCBTZWN1
cmUgRW1haWwgQ0EwggEiMA0GCSqGSIb3DQEBAQUAA4IBDwAwggEKAoIBAQCJsQ3aelMZTnBSHbxW
pgYmt7hJ4JbnUavx8FoTSRWjtIwbYLx6UUKneYykIt8XYU6R1XYjChTTSgJ/th0JgG6lBD3ZursW
/qGHqS5DUkMWfK8yUMimT1rpCNjPkyWce4joMGTmpPhWgP0qJBQzF5msROVpi6NGBkvCM9TpQJ8G
sLGsk0C5tQiTOpwqU6MQ2z0gYTxVA47ZTnYlAiEp+qN8cXZP7uFfgen7VIDbw3s1UreE3iI9LDAt
MX9ZvVI3sDNpLUPr+tal8Zd3Z1GM2e4n67ylBzh2jKSpOP/fjPUDrEm+yvdzmToPMquclToTPQ5G
Old0YVC+xkA/y+Tin6IhAgMBAAGjggEXMIIBEzAfBgNVHSMEGDAWgBStvZh6NLQm9/rEJlTvA73g
JMtUGjAdBgNVHQ4EFgQUkmFrguGioKpP7GfxwqP3tIAAwewwDgYDVR0PAQH/BAQDAgGGMBIGA1Ud
EwEB/wQIMAYBAf8CAQAwHQYDVR0lBBYwFAYIKwYBBQUHAwIGCCsGAQUFBwMEMBEGA1UdIAQKMAgw
BgYEVR0gADBEBgNVHR8EPTA7MDmgN6A1hjNodHRwOi8vY3JsLnVzZXJ0cnVzdC5jb20vQWRkVHJ1
c3RFeHRlcm5hbENBUm9vdC5jcmwwNQYIKwYBBQUHAQEEKTAnMCUGCCsGAQUFBzABhhlodHRwOi8v
b2NzcC51c2VydHJ1c3QuY29tMA0GCSqGSIb3DQEBCwUAA4IBAQAbKm6sVcE6q4jF2O3NVfOqa2Er
wAkQI5kPxWZqb7H1tLV3Xg8CYQDffQX+ErOkgIAA/PsdW2pyAgpBvAW6wVjVJsLq1U2E+/6CmM9Y
G+MiY5xS+LsFNqt9WKXeqztj5drVc+/s4Pt74qP/8EIjnMq2jU0+5EsYA7KoLdTYu0JLkGmFENum
NzToe+ABEKWcyjrHn0+ING6KZdAairup3MrKNtH0/MJkKTWv1rGncRHSA0Oxjz6a7J4yU/R2ksqG
NAe5LMrmHErYmQ3BhuKQkvtaQmojIRDpZcf11bt+6oyFIAJi6tE6ByxZxZkz8jiJ5bbpFnofeRT2
ShAaJvp8ivubMIIENjCCAx6gAwIBAgIBATANBgkqhkiG9w0BAQUFADBvMQswCQYDVQQGEwJTRTEU
MBIGA1UEChMLQWRkVHJ1c3QgQUIxJjAkBgNVBAsTHUFkZFRydXN0IEV4dGVybmFsIFRUUCBOZXR3
b3JrMSIwIAYDVQQDExlBZGRUcnVzdCBFeHRlcm5hbCBDQSBSb290MB4XDTAwMDUzMDEwNDgzOFoX
DTIwMDUzMDEwNDgzOFowbzELMAkGA1UEBhMCU0UxFDASBgNVBAoTC0FkZFRydXN0IEFCMSYwJAYD
VQQLEx1BZGRUcnVzdCBFeHRlcm5hbCBUVFAgTmV0d29yazEiMCAGA1UEAxMZQWRkVHJ1c3QgRXh0
ZXJuYWwgQ0EgUm9vdDCCASIwDQYJKoZIhvcNAQEBBQADggEPADCCAQoCggEBALf3GjPm8gAELTng
TlvtH7xsD821+iO2zt6bETOXpClMfZOfvUq8k+0DGuOPz+VtUFrWlymUWoCwSXrbLpX9uMq/Nzgt
Hj6RQa1wVsfwTz/oMp50ysiQVOnGXw94nZpAPA6sYapeFI+eh6FqUNzXmk6vBbOmcZSccbNQYArH
E504B4YCqOmoaSYYkKtMsE8jqzpPhNjfzp/haW+710LXa0Tkx63ubUFfclpxCDezeWWkWaCUN/cA
Lw3CknLa0Dhy2xSoRcRdKn23tNbE7qzNE0S3ySvdQwAl+mG5aWpYIxG3pzOPVnVZ9c0p10a3Citl
ttNCbxWyuHv77+ldU9U0WicCAwEAAaOB3DCB2TAdBgNVHQ4EFgQUrb2YejS0Jvf6xCZU7wO94CTL
VBowCwYDVR0PBAQDAgEGMA8GA1UdEwEB/wQFMAMBAf8wgZkGA1UdIwSBkTCBjoAUrb2YejS0Jvf6
xCZU7wO94CTLVBqhc6RxMG8xCzAJBgNVBAYTAlNFMRQwEgYDVQQKEwtBZGRUcnVzdCBBQjEmMCQG
A1UECxMdQWRkVHJ1c3QgRXh0ZXJuYWwgVFRQIE5ldHdvcmsxIjAgBgNVBAMTGUFkZFRydXN0IEV4
dGVybmFsIENBIFJvb3SCAQEwDQYJKoZIhvcNAQEFBQADggEBALCb4IUlwtYj4g+WBpKdQZic2YR5
gdkeWxQHIzZlj7DYd7usQWxHYINRsPkyPef89iYTx4AWpb9a/IfPeHmJIZriTAcKhjW88t5RxNKW
t9x+Tu5w/Rw56wwCURQtjr0W4MHfRnXnJK3s9EK0hZNwEGe6nQY1ShjTK3rMUUKhemPR5ruhxSvC
Nr4TDea9Y355e6cJDUCrat2PisP29owaQgVR1EX1n6diIWgVIEM8med8vSTYqZEXc4g/VhsxOBi0
cQ+azcgOno4uG+GMmIPLHzHxREzGBHNJdmAPx/i9F4BrLunMTA5amnkPIAou1Z5jJh5VkpTYghda
e9C8x49OhgQwggU6MIIEIqADAgECAhEA2TLMtWuXNcB2cbqZ/VgVujANBgkqhkiG9w0BAQsFADCB
mzELMAkGA1UEBhMCR0IxGzAZBgNVBAgTEkdyZWF0ZXIgTWFuY2hlc3RlcjEQMA4GA1UEBxMHU2Fs
Zm9yZDEaMBgGA1UEChMRQ09NT0RPIENBIExpbWl0ZWQxQTA/BgNVBAMTOENPTU9ETyBTSEEtMjU2
IENsaWVudCBBdXRoZW50aWNhdGlvbiBhbmQgU2VjdXJlIEVtYWlsIENBMB4XDTE3MDEwOTAwMDAw
MFoXDTE4MDEwOTIzNTk1OVowIjEgMB4GCSqGSIb3DQEJARYRdmU3anRiQHZlN2p0Yi5jb20wggEi
MA0GCSqGSIb3DQEBAQUAA4IBDwAwggEKAoIBAQDW2rqobOFQ/XmzH3DG2UK1Dt6jtc+OFZ71KQoB
o8IZa/V94Ey12BPjBcoj+cjHNVsLd2QiUpMcf5sZFMX1cmvpR7TiUISgVcHe8zgiUUvN5Jn5tPDM
Kb4E34TtDEG2X5FyY35AwCl8NV/loj2D5KLid9BLdVTJjfqokjLQ/4qCQjWBjfTpIdAdr3lXfg5f
a5UPyIkphEIplM8/yGfX0W/PBl804XAL0gesLrfEMdgG58UCN1wJMgH4uRKmKU/U2Ap4W9hTpioN
M722U8x7N6P1v6MqTAWCUaskdOp+ktNxFGxOlCE7BEo/EIaWbEt5RHwDePctScDLsi56+VI3TysR
AgMBAAGjggHvMIIB6zAfBgNVHSMEGDAWgBSSYWuC4aKgqk/sZ/HCo/e0gADB7DAdBgNVHQ4EFgQU
Yg3SsFWhMro4Abonbn1IX4JKj5QwDgYDVR0PAQH/BAQDAgWgMAwGA1UdEwEB/wQCMAAwIAYDVR0l
BBkwFwYIKwYBBQUHAwQGCysGAQQBsjEBAwUCMBEGCWCGSAGG+EIBAQQEAwIFIDBGBgNVHSAEPzA9
MDsGDCsGAQQBsjEBAgEBATArMCkGCCsGAQUFBwIBFh1odHRwczovL3NlY3VyZS5jb21vZG8ubmV0
L0NQUzBdBgNVHR8EVjBUMFKgUKBOhkxodHRwOi8vY3JsLmNvbW9kb2NhLmNvbS9DT01PRE9TSEEy
NTZDbGllbnRBdXRoZW50aWNhdGlvbmFuZFNlY3VyZUVtYWlsQ0EuY3JsMIGQBggrBgEFBQcBAQSB
gzCBgDBYBggrBgEFBQcwAoZMaHR0cDovL2NydC5jb21vZG9jYS5jb20vQ09NT0RPU0hBMjU2Q2xp
ZW50QXV0aGVudGljYXRpb25hbmRTZWN1cmVFbWFpbENBLmNydDAkBggrBgEFBQcwAYYYaHR0cDov
L29jc3AuY29tb2RvY2EuY29tMBwGA1UdEQQVMBOBEXZlN2p0YkB2ZTdqdGIuY29tMA0GCSqGSIb3
DQEBCwUAA4IBAQCC26y+6/+SJoRQWepca+rB9eSSwaCAb8nNqA+00ZiOHb+6UbbV1xa7Z8wDIuEL
5UKbNtQ2NDArvzF9YI0xNafoV1AEmP/3+ljxQHSEI0U1p2h401sOx+nSjcwtTzACso1lw+I0oJYM
JFITOIfZy8HgFpCipBrQAp9jMJ+KSKDX3xu/hzPosfdnXp7sV1KAjkFrAtR3AnQYfJ5W8QrsmC4N
BbiAKoYWUSdklqn3v1neTG/+oOhcw7hcGZo+YmPyF9Cdy0gBtwSHPt8hluhg2TlzmqYfi0dVL/mU
jCBNUY/BFH+MBqKF7sOIRMv8ALWceVaM/NEcBciKs4eR99A4cw9ZMYICtDCCArACAQEwgbEwgZsx
CzAJBgNVBAYTAkdCMRswGQYDVQQIExJHcmVhdGVyIE1hbmNoZXN0ZXIxEDAOBgNVBAcTB1NhbGZv
cmQxGjAYBgNVBAoTEUNPTU9ETyBDQSBMaW1pdGVkMUEwPwYDVQQDEzhDT01PRE8gU0hBLTI1NiBD
bGllbnQgQXV0aGVudGljYXRpb24gYW5kIFNlY3VyZSBFbWFpbCBDQQIRANkyzLVrlzXAdnG6mf1Y
FbowDQYJYIZIAWUDBAIBBQCggdQwLwYJKoZIhvcNAQkEMSIEIFOKrb/bxMrBuroccJjB2ibhxFYd
Jz2cWA+qoO2Bn2utMBgGCSqGSIb3DQEJAzELBgkqhkiG9w0BBwEwHAYJKoZIhvcNAQkFMQ8XDTE3
MDYxOTAxMjc1NFowaQYJKoZIhvcNAQkPMVwwWjALBglghkgBZQMEASowCwYJYIZIAWUDBAEWMAsG
CWCGSAFlAwQBAjAKBggqhkiG9w0DBzALBgkqhkiG9w0BAQowCwYJKoZIhvcNAQEHMAsGCWCGSAFl
AwQCATANBgkqhkiG9w0BAQEFAASCAQARP762e1NXnO8wb+sHCrUGRlwsYPY3vSEx4zATsMUhDPXe
8/nOkTUVTS9Ay4l4FIgftRvBzFumEsq36/GE2wZWpgF+tAhd4gT5w/5OAfKSSAJ5PDfP5yhUfYom
+OKsmO+BFgQDmZqtp7V5cYlIApoqqVoUPtyAjTAgtwwlvRuFGVIVuk1CsLwDkqrJrMGoTnmObF0g
9p9UIU+ddV0pqI8RSMJeHkkt8DwjQBB9cKeTPjyzeIpjzOnkdbN2vVnWcTqdVPoxto5QTbkJq4wP
jFNCMkrS/zzBk9s2pIrOIJ1ywPXXxyWBlUJW3jlfXw69UiA8RqxG8obt52v8/HyZJa1v
--001a1149a9644d08c70552460b57--


From nobody Sun Jun 18 18:28:06 2017
Return-Path: <ve7jtb@ve7jtb.com>
X-Original-To: unbearable@ietfa.amsl.com
Delivered-To: unbearable@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 8381A129A96 for <unbearable@ietfa.amsl.com>; Sun, 18 Jun 2017 18:28:00 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.6
X-Spam-Level: 
X-Spam-Status: No, score=-2.6 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, RCVD_IN_DNSWL_LOW=-0.7, SPF_PASS=-0.001, URIBL_BLOCKED=0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (2048-bit key) header.d=ve7jtb-com.20150623.gappssmtp.com
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id zEluct_IxUzd for <unbearable@ietfa.amsl.com>; Sun, 18 Jun 2017 18:27:58 -0700 (PDT)
Received: from mail-io0-x22c.google.com (mail-io0-x22c.google.com [IPv6:2607:f8b0:4001:c06::22c]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id C45B71200C5 for <unbearable@ietf.org>; Sun, 18 Jun 2017 18:27:57 -0700 (PDT)
Received: by mail-io0-x22c.google.com with SMTP id k93so55122076ioi.2 for <unbearable@ietf.org>; Sun, 18 Jun 2017 18:27:57 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=ve7jtb-com.20150623.gappssmtp.com; s=20150623; h=from:mime-version:subject:message-id:date:cc:to; bh=K2Y9j+W2Gi9AR9mtkTkRFDswnSq96Rb/8eXlZV35RBI=; b=jEKdR+wqwVAaWJlubRFaySU60zHmMUC8W68ye7ay5mCly4tfmRdSJLLlJAnxXzV6H2 R0hbJoAVo95gPf7yIges/Vt8n2goy+1ZoS2x4t7LyXLgfPwy5wdW7ra+T3p/ZtqnrsbZ r78i49XEXrqFWLxBqgqohVZXWx+LYH0SvpPOdqsvLfY/ZT7dIElbhtAN30TN7inLYHim tXKjeSAcbG1WysHqykhkCKF8qeIk38V9UxY5k7zwL6ft38RdB5AVYCXQIfc88W0wwRE6 D5em7Mzm+hXir2Bqv2II6i9c8siF3srZ1CvDdn/eUJ8w1gckENHtYVB9rwvFQb8k7yIp yvxg==
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20161025; h=x-gm-message-state:from:mime-version:subject:message-id:date:cc:to; bh=K2Y9j+W2Gi9AR9mtkTkRFDswnSq96Rb/8eXlZV35RBI=; b=B4PxDpdnzb9HqbmYtcJeZofdl1neoaaZ3ePtaltmiTj1KK8mC6sv3V0akNemOmJCb/ 7mWtC1Hsy1/FoShMrtZVZGzKO9nQu7H0MQkO18yWuCrTHG5Ys7npjWJqgUk1vSquqSDE R6PtMlswm6sAxZAdEVUueIi6IFkJpWdrkrG7rSCpipa9MSw/ls15y1SvFA/RDCvLHh9Y P9h8GL8LpmYfouc00Rke+EjsvPKv5EvwjoemiBQF87C7L5ZaAyos+K/9dCtfwundE4IB RdxhgOlyfvGQIBvBOfKC8+Cl3/etlWN8BpvHoCHwLEha/eHNH9Ime6jcUbx89tOBE2ue FtHQ==
X-Gm-Message-State: AKS2vOwFmAQlfUlL07MsyFMzTWUqfeSBO699+SNMiy07x1V5jqrV4R+C UMckQuVqrlQpWIFd06fpHw==
X-Received: by 10.107.35.83 with SMTP id j80mr18708935ioj.72.1497835676879; Sun, 18 Jun 2017 18:27:56 -0700 (PDT)
Received: from jbradley-r.lan ([208.59.64.21]) by smtp.gmail.com with ESMTPSA id h76sm3117003ith.24.2017.06.18.18.27.54 (version=TLS1_2 cipher=ECDHE-RSA-AES128-GCM-SHA256 bits=128/128); Sun, 18 Jun 2017 18:27:55 -0700 (PDT)
From: John Bradley <ve7jtb@ve7jtb.com>
Mime-Version: 1.0 (Mac OS X Mail 10.3 \(3273\))
Message-Id: <C7D885CC-9B96-4AA4-9EA0-6087084000B3@ve7jtb.com>
Date: Sun, 18 Jun 2017 20:27:49 -0500
Cc: draft-ietf-tokbind-protocol@ietf.org
To: IETF TokBind WG <unbearable@ietf.org>
X-Mailer: Apple Mail (2.3273)
Content-Type: multipart/signed; protocol="application/pkcs7-signature"; micalg=sha-256; boundary="001a1140c936786dc10552460ba6"
Archived-At: <https://mailarchive.ietf.org/arch/msg/unbearable/nPP41fHylSk0bhsu2FQ2aSHXD9s>
Subject: [Unbearable] IPR for draft-ietf-tokbind-protocol
X-BeenThere: unbearable@ietf.org
X-Mailman-Version: 2.1.22
Precedence: list
List-Id: "\"This list is for discussion of proposals for doing better than bearer tokens \(e.g. HTTP cookies, OAuth tokens etc.\) for web applications. The specific goal is chartering a WG focused on preventing security token export and replay attacks.\"" <unbearable.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/unbearable>, <mailto:unbearable-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/unbearable/>
List-Post: <mailto:unbearable@ietf.org>
List-Help: <mailto:unbearable-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/unbearable>, <mailto:unbearable-request@ietf.org?subject=subscribe>
X-List-Received-Date: Mon, 19 Jun 2017 01:28:00 -0000

--001a1140c936786dc10552460ba6
Content-Type: text/plain; charset=us-ascii
Content-Transfer-Encoding: quoted-printable

I am working on the shepherd writeup for the The Token Binding Protocol =
Version 1.0 document:
https://tools.ietf.org/html/draft-ietf-tokbind-protocol-14

One item in the template requires me to indicate whether each document
author has confirmed that any and all appropriate IPR disclosures
required for full conformance with the provisions of BCP 78 and BCP 79
have already been filed.

Could each of you please confirm?

   Andrei Popov (editor)
   Microsoft Corp.
   USA

   Email: andreipo@microsoft.com


   Magnus Nystroem
   Microsoft Corp.
   USA

   Email: mnystrom@microsoft.com


   Dirk Balfanz
   Google Inc.
   USA

   Email: balfanz@google.com


   Adam Langley
   Google Inc.
   USA

   Email: agl@google.com


   Jeff Hodges
   PayPal
   USA

   Email: Jeff.Hodges@paypal.com





--001a1140c936786dc10552460ba6
Content-Type: application/pkcs7-signature; name="smime.p7s"
Content-Transfer-Encoding: base64
Content-Disposition: attachment; filename="smime.p7s"
Content-Description: S/MIME Cryptographic Signature

MIIRGwYJKoZIhvcNAQcCoIIRDDCCEQgCAQExDzANBglghkgBZQMEAgEFADALBgkqhkiG9w0BBwGg
gg4rMIIErzCCA5egAwIBAgIRAOAjyxUSg1OJrWFuelRnayEwDQYJKoZIhvcNAQELBQAwbzELMAkG
A1UEBhMCU0UxFDASBgNVBAoTC0FkZFRydXN0IEFCMSYwJAYDVQQLEx1BZGRUcnVzdCBFeHRlcm5h
bCBUVFAgTmV0d29yazEiMCAGA1UEAxMZQWRkVHJ1c3QgRXh0ZXJuYWwgQ0EgUm9vdDAeFw0xNDEy
MjIwMDAwMDBaFw0yMDA1MzAxMDQ4MzhaMIGbMQswCQYDVQQGEwJHQjEbMBkGA1UECBMSR3JlYXRl
ciBNYW5jaGVzdGVyMRAwDgYDVQQHEwdTYWxmb3JkMRowGAYDVQQKExFDT01PRE8gQ0EgTGltaXRl
ZDFBMD8GA1UEAxM4Q09NT0RPIFNIQS0yNTYgQ2xpZW50IEF1dGhlbnRpY2F0aW9uIGFuZCBTZWN1
cmUgRW1haWwgQ0EwggEiMA0GCSqGSIb3DQEBAQUAA4IBDwAwggEKAoIBAQCJsQ3aelMZTnBSHbxW
pgYmt7hJ4JbnUavx8FoTSRWjtIwbYLx6UUKneYykIt8XYU6R1XYjChTTSgJ/th0JgG6lBD3ZursW
/qGHqS5DUkMWfK8yUMimT1rpCNjPkyWce4joMGTmpPhWgP0qJBQzF5msROVpi6NGBkvCM9TpQJ8G
sLGsk0C5tQiTOpwqU6MQ2z0gYTxVA47ZTnYlAiEp+qN8cXZP7uFfgen7VIDbw3s1UreE3iI9LDAt
MX9ZvVI3sDNpLUPr+tal8Zd3Z1GM2e4n67ylBzh2jKSpOP/fjPUDrEm+yvdzmToPMquclToTPQ5G
Old0YVC+xkA/y+Tin6IhAgMBAAGjggEXMIIBEzAfBgNVHSMEGDAWgBStvZh6NLQm9/rEJlTvA73g
JMtUGjAdBgNVHQ4EFgQUkmFrguGioKpP7GfxwqP3tIAAwewwDgYDVR0PAQH/BAQDAgGGMBIGA1Ud
EwEB/wQIMAYBAf8CAQAwHQYDVR0lBBYwFAYIKwYBBQUHAwIGCCsGAQUFBwMEMBEGA1UdIAQKMAgw
BgYEVR0gADBEBgNVHR8EPTA7MDmgN6A1hjNodHRwOi8vY3JsLnVzZXJ0cnVzdC5jb20vQWRkVHJ1
c3RFeHRlcm5hbENBUm9vdC5jcmwwNQYIKwYBBQUHAQEEKTAnMCUGCCsGAQUFBzABhhlodHRwOi8v
b2NzcC51c2VydHJ1c3QuY29tMA0GCSqGSIb3DQEBCwUAA4IBAQAbKm6sVcE6q4jF2O3NVfOqa2Er
wAkQI5kPxWZqb7H1tLV3Xg8CYQDffQX+ErOkgIAA/PsdW2pyAgpBvAW6wVjVJsLq1U2E+/6CmM9Y
G+MiY5xS+LsFNqt9WKXeqztj5drVc+/s4Pt74qP/8EIjnMq2jU0+5EsYA7KoLdTYu0JLkGmFENum
NzToe+ABEKWcyjrHn0+ING6KZdAairup3MrKNtH0/MJkKTWv1rGncRHSA0Oxjz6a7J4yU/R2ksqG
NAe5LMrmHErYmQ3BhuKQkvtaQmojIRDpZcf11bt+6oyFIAJi6tE6ByxZxZkz8jiJ5bbpFnofeRT2
ShAaJvp8ivubMIIENjCCAx6gAwIBAgIBATANBgkqhkiG9w0BAQUFADBvMQswCQYDVQQGEwJTRTEU
MBIGA1UEChMLQWRkVHJ1c3QgQUIxJjAkBgNVBAsTHUFkZFRydXN0IEV4dGVybmFsIFRUUCBOZXR3
b3JrMSIwIAYDVQQDExlBZGRUcnVzdCBFeHRlcm5hbCBDQSBSb290MB4XDTAwMDUzMDEwNDgzOFoX
DTIwMDUzMDEwNDgzOFowbzELMAkGA1UEBhMCU0UxFDASBgNVBAoTC0FkZFRydXN0IEFCMSYwJAYD
VQQLEx1BZGRUcnVzdCBFeHRlcm5hbCBUVFAgTmV0d29yazEiMCAGA1UEAxMZQWRkVHJ1c3QgRXh0
ZXJuYWwgQ0EgUm9vdDCCASIwDQYJKoZIhvcNAQEBBQADggEPADCCAQoCggEBALf3GjPm8gAELTng
TlvtH7xsD821+iO2zt6bETOXpClMfZOfvUq8k+0DGuOPz+VtUFrWlymUWoCwSXrbLpX9uMq/Nzgt
Hj6RQa1wVsfwTz/oMp50ysiQVOnGXw94nZpAPA6sYapeFI+eh6FqUNzXmk6vBbOmcZSccbNQYArH
E504B4YCqOmoaSYYkKtMsE8jqzpPhNjfzp/haW+710LXa0Tkx63ubUFfclpxCDezeWWkWaCUN/cA
Lw3CknLa0Dhy2xSoRcRdKn23tNbE7qzNE0S3ySvdQwAl+mG5aWpYIxG3pzOPVnVZ9c0p10a3Citl
ttNCbxWyuHv77+ldU9U0WicCAwEAAaOB3DCB2TAdBgNVHQ4EFgQUrb2YejS0Jvf6xCZU7wO94CTL
VBowCwYDVR0PBAQDAgEGMA8GA1UdEwEB/wQFMAMBAf8wgZkGA1UdIwSBkTCBjoAUrb2YejS0Jvf6
xCZU7wO94CTLVBqhc6RxMG8xCzAJBgNVBAYTAlNFMRQwEgYDVQQKEwtBZGRUcnVzdCBBQjEmMCQG
A1UECxMdQWRkVHJ1c3QgRXh0ZXJuYWwgVFRQIE5ldHdvcmsxIjAgBgNVBAMTGUFkZFRydXN0IEV4
dGVybmFsIENBIFJvb3SCAQEwDQYJKoZIhvcNAQEFBQADggEBALCb4IUlwtYj4g+WBpKdQZic2YR5
gdkeWxQHIzZlj7DYd7usQWxHYINRsPkyPef89iYTx4AWpb9a/IfPeHmJIZriTAcKhjW88t5RxNKW
t9x+Tu5w/Rw56wwCURQtjr0W4MHfRnXnJK3s9EK0hZNwEGe6nQY1ShjTK3rMUUKhemPR5ruhxSvC
Nr4TDea9Y355e6cJDUCrat2PisP29owaQgVR1EX1n6diIWgVIEM8med8vSTYqZEXc4g/VhsxOBi0
cQ+azcgOno4uG+GMmIPLHzHxREzGBHNJdmAPx/i9F4BrLunMTA5amnkPIAou1Z5jJh5VkpTYghda
e9C8x49OhgQwggU6MIIEIqADAgECAhEA2TLMtWuXNcB2cbqZ/VgVujANBgkqhkiG9w0BAQsFADCB
mzELMAkGA1UEBhMCR0IxGzAZBgNVBAgTEkdyZWF0ZXIgTWFuY2hlc3RlcjEQMA4GA1UEBxMHU2Fs
Zm9yZDEaMBgGA1UEChMRQ09NT0RPIENBIExpbWl0ZWQxQTA/BgNVBAMTOENPTU9ETyBTSEEtMjU2
IENsaWVudCBBdXRoZW50aWNhdGlvbiBhbmQgU2VjdXJlIEVtYWlsIENBMB4XDTE3MDEwOTAwMDAw
MFoXDTE4MDEwOTIzNTk1OVowIjEgMB4GCSqGSIb3DQEJARYRdmU3anRiQHZlN2p0Yi5jb20wggEi
MA0GCSqGSIb3DQEBAQUAA4IBDwAwggEKAoIBAQDW2rqobOFQ/XmzH3DG2UK1Dt6jtc+OFZ71KQoB
o8IZa/V94Ey12BPjBcoj+cjHNVsLd2QiUpMcf5sZFMX1cmvpR7TiUISgVcHe8zgiUUvN5Jn5tPDM
Kb4E34TtDEG2X5FyY35AwCl8NV/loj2D5KLid9BLdVTJjfqokjLQ/4qCQjWBjfTpIdAdr3lXfg5f
a5UPyIkphEIplM8/yGfX0W/PBl804XAL0gesLrfEMdgG58UCN1wJMgH4uRKmKU/U2Ap4W9hTpioN
M722U8x7N6P1v6MqTAWCUaskdOp+ktNxFGxOlCE7BEo/EIaWbEt5RHwDePctScDLsi56+VI3TysR
AgMBAAGjggHvMIIB6zAfBgNVHSMEGDAWgBSSYWuC4aKgqk/sZ/HCo/e0gADB7DAdBgNVHQ4EFgQU
Yg3SsFWhMro4Abonbn1IX4JKj5QwDgYDVR0PAQH/BAQDAgWgMAwGA1UdEwEB/wQCMAAwIAYDVR0l
BBkwFwYIKwYBBQUHAwQGCysGAQQBsjEBAwUCMBEGCWCGSAGG+EIBAQQEAwIFIDBGBgNVHSAEPzA9
MDsGDCsGAQQBsjEBAgEBATArMCkGCCsGAQUFBwIBFh1odHRwczovL3NlY3VyZS5jb21vZG8ubmV0
L0NQUzBdBgNVHR8EVjBUMFKgUKBOhkxodHRwOi8vY3JsLmNvbW9kb2NhLmNvbS9DT01PRE9TSEEy
NTZDbGllbnRBdXRoZW50aWNhdGlvbmFuZFNlY3VyZUVtYWlsQ0EuY3JsMIGQBggrBgEFBQcBAQSB
gzCBgDBYBggrBgEFBQcwAoZMaHR0cDovL2NydC5jb21vZG9jYS5jb20vQ09NT0RPU0hBMjU2Q2xp
ZW50QXV0aGVudGljYXRpb25hbmRTZWN1cmVFbWFpbENBLmNydDAkBggrBgEFBQcwAYYYaHR0cDov
L29jc3AuY29tb2RvY2EuY29tMBwGA1UdEQQVMBOBEXZlN2p0YkB2ZTdqdGIuY29tMA0GCSqGSIb3
DQEBCwUAA4IBAQCC26y+6/+SJoRQWepca+rB9eSSwaCAb8nNqA+00ZiOHb+6UbbV1xa7Z8wDIuEL
5UKbNtQ2NDArvzF9YI0xNafoV1AEmP/3+ljxQHSEI0U1p2h401sOx+nSjcwtTzACso1lw+I0oJYM
JFITOIfZy8HgFpCipBrQAp9jMJ+KSKDX3xu/hzPosfdnXp7sV1KAjkFrAtR3AnQYfJ5W8QrsmC4N
BbiAKoYWUSdklqn3v1neTG/+oOhcw7hcGZo+YmPyF9Cdy0gBtwSHPt8hluhg2TlzmqYfi0dVL/mU
jCBNUY/BFH+MBqKF7sOIRMv8ALWceVaM/NEcBciKs4eR99A4cw9ZMYICtDCCArACAQEwgbEwgZsx
CzAJBgNVBAYTAkdCMRswGQYDVQQIExJHcmVhdGVyIE1hbmNoZXN0ZXIxEDAOBgNVBAcTB1NhbGZv
cmQxGjAYBgNVBAoTEUNPTU9ETyBDQSBMaW1pdGVkMUEwPwYDVQQDEzhDT01PRE8gU0hBLTI1NiBD
bGllbnQgQXV0aGVudGljYXRpb24gYW5kIFNlY3VyZSBFbWFpbCBDQQIRANkyzLVrlzXAdnG6mf1Y
FbowDQYJYIZIAWUDBAIBBQCggdQwLwYJKoZIhvcNAQkEMSIEIGB8NFgbhQnJ2HJw2AP8aSsDsiWf
Ye8JgVAL2pONWQyyMBgGCSqGSIb3DQEJAzELBgkqhkiG9w0BBwEwHAYJKoZIhvcNAQkFMQ8XDTE3
MDYxOTAxMjc1N1owaQYJKoZIhvcNAQkPMVwwWjALBglghkgBZQMEASowCwYJYIZIAWUDBAEWMAsG
CWCGSAFlAwQBAjAKBggqhkiG9w0DBzALBgkqhkiG9w0BAQowCwYJKoZIhvcNAQEHMAsGCWCGSAFl
AwQCATANBgkqhkiG9w0BAQEFAASCAQCAqy1jbI3Y0ha2JalE1boEekKo5Fh01xqYmSObvHVhFXbC
4dz2CU70B8LljAwojD46YD4xDNAeEBNOOe+qjScGexJctpcJgs9Uzk0ciq3O63KaGvHyWlQFILJt
tkrdoDyO3Ln4k+EJR/9SA+xUgSVvhba8lFN+a2YICAQyld7TpDOfRpRr5/mXpTSs0F8qk48kL119
hiHUt3p30MriCoeJKHXcnB6VXxH0TzJ0gzFEwSVyISmyL98wppBSdxAlR1DjdQ50u3qDpvLJtf62
mP2/7iD4PiuBBBvgC1Ds+LILvbifZEbzoQr1vubwE6tKGuGmccXd2DPkceyUetQo0kbe
--001a1140c936786dc10552460ba6--


From nobody Sun Jun 18 18:28:13 2017
Return-Path: <ve7jtb@ve7jtb.com>
X-Original-To: unbearable@ietfa.amsl.com
Delivered-To: unbearable@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 5DC55129A96 for <unbearable@ietfa.amsl.com>; Sun, 18 Jun 2017 18:28:02 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.899
X-Spam-Level: 
X-Spam-Status: No, score=-1.899 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, HTML_MESSAGE=0.001, SPF_PASS=-0.001, URIBL_BLOCKED=0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (2048-bit key) header.d=ve7jtb-com.20150623.gappssmtp.com
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id W-NBlnE1GL8y for <unbearable@ietfa.amsl.com>; Sun, 18 Jun 2017 18:28:00 -0700 (PDT)
Received: from mail-io0-x230.google.com (mail-io0-x230.google.com [IPv6:2607:f8b0:4001:c06::230]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 9C9E4126B6D for <unbearable@ietf.org>; Sun, 18 Jun 2017 18:27:59 -0700 (PDT)
Received: by mail-io0-x230.google.com with SMTP id k93so55122297ioi.2 for <unbearable@ietf.org>; Sun, 18 Jun 2017 18:27:59 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=ve7jtb-com.20150623.gappssmtp.com; s=20150623; h=from:mime-version:subject:message-id:date:cc:to; bh=rGgUYaZNl3vy2SUi3fSdEAfGwyj4TL1pjy1de90lBqs=; b=qjmCwdfXE6YlwcOVR2M+Ik7hOAw8q77XBNMjh/LnAflnHInTMcl5AEpYiatM2Zs+47 OFHhN+9LazPWJD8Kpn+Io7Yr+71exZk9zZIqbrSNK5lp0QUVSNnbQuWYu1OUWhTx4lDw 0SuuLctKvzsdjzgF2q08vBF7b8y6zNd8IBOqb2np4Da6O36K5HQtudY5nWF1FMkesyqD A3RnalyLLs0Jr07hJqRdXPQw7DCjwZrsmylMGn+w8wU+cLjuxbK+8epxT0bXnX2x4wJ8 vDbjOhTbm8UPhzVpqRmseLbTQZGhETeZjMs20uWD667LogRVaec4Vc+WMZrn67NRsbtb jA6Q==
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20161025; h=x-gm-message-state:from:mime-version:subject:message-id:date:cc:to; bh=rGgUYaZNl3vy2SUi3fSdEAfGwyj4TL1pjy1de90lBqs=; b=FpRryF1BdpgABiZZ3P0vkX5I9ido/KR+tcIhuY1H65gVnsmyQWHv+MrN2Of+wP70St 6AeEmrNI1m1Oug6ko4reoIf+x6goggEnX3MbVRwMUtzfxwSznSTCj45dbXTMfmRFL+Fx /M07u0eXiZfaQFusKtqz3QIPoK8ynBY0G+++//5ZC676Yw2xTeO9B/8U/66Sh5kZK6xc rqmCwxO6mjwtZHNk7x8vkc+NCRRx1mI86fSd2Utw0HD6NwgxDy7sPj81iogBSnX1ilEP KbuWp9gxZS/QagVlX9KKEj73w4YZalA/RdbO6iasJrd8zNZ4t3NE1MzdouEnslnx9PeY bCVg==
X-Gm-Message-State: AKS2vOyK3sIHLGY5oTRCYV2Tz5pZ2LD8BnIJrt642gxaOh/PXuCtZQ5c utUIqsBIO1bwLGsrECQ85g==
X-Received: by 10.107.130.17 with SMTP id e17mr20230335iod.155.1497835678678;  Sun, 18 Jun 2017 18:27:58 -0700 (PDT)
Received: from jbradley-r.lan ([208.59.64.21]) by smtp.gmail.com with ESMTPSA id h76sm3117003ith.24.2017.06.18.18.27.57 (version=TLS1_2 cipher=ECDHE-RSA-AES128-GCM-SHA256 bits=128/128); Sun, 18 Jun 2017 18:27:58 -0700 (PDT)
From: John Bradley <ve7jtb@ve7jtb.com>
Mime-Version: 1.0 (Mac OS X Mail 10.3 \(3273\))
Message-Id: <634F056D-5B5F-4570-AE30-9F3F6F6AE3A5@ve7jtb.com>
Date: Sun, 18 Jun 2017 20:27:52 -0500
Cc: draft-ietf-tokbind-https@ietf.org
To: IETF TokBind WG <unbearable@ietf.org>
X-Mailer: Apple Mail (2.3273)
Content-Type: multipart/signed; protocol="application/pkcs7-signature"; micalg=sha-256; boundary="001a113fc1e8939ba80552460b3b"
Archived-At: <https://mailarchive.ietf.org/arch/msg/unbearable/bHIpaeHMU_waEloTtZEgAkFiye4>
Subject: [Unbearable] IPR for draft-ietf-tokbind-https
X-BeenThere: unbearable@ietf.org
X-Mailman-Version: 2.1.22
Precedence: list
List-Id: "\"This list is for discussion of proposals for doing better than bearer tokens \(e.g. HTTP cookies, OAuth tokens etc.\) for web applications. The specific goal is chartering a WG focused on preventing security token export and replay attacks.\"" <unbearable.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/unbearable>, <mailto:unbearable-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/unbearable/>
List-Post: <mailto:unbearable@ietf.org>
List-Help: <mailto:unbearable-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/unbearable>, <mailto:unbearable-request@ietf.org?subject=subscribe>
X-List-Received-Date: Mon, 19 Jun 2017 01:28:02 -0000

--001a113fc1e8939ba80552460b3b
Content-Type: multipart/alternative;
 boundary="Apple-Mail=_74FFC089-8BF1-4FDF-B72F-76E315790AB6"


--Apple-Mail=_74FFC089-8BF1-4FDF-B72F-76E315790AB6
Content-Transfer-Encoding: quoted-printable
Content-Type: text/plain;
	charset=us-ascii


I am working on the shepherd writeup for the Token Binding over HTTP =
document:
https://tools.ietf.org/html/draft-ietf-tokbind-https-09 =
<https://tools.ietf.org/html/draft-ietf-tokbind-https-09>

One item in the template requires me to indicate whether each document
author has confirmed that any and all appropriate IPR disclosures
required for full conformance with the provisions of BCP 78 and BCP 79
have already been filed.

Could each of you please confirm?

   Magnus Nystroem
   Microsoft Corp.
   USA

   Email: mnystrom@microsoft.com


   Dirk Balfanz (editor)
   Google Inc.
   USA

   Email: balfanz@google.com


   Adam Langley
   Google Inc.
   USA

   Email: agl@google.com


   Jeff Hodges
   PayPal
   USA

   Email: Jeff.Hodges@paypal.com


--Apple-Mail=_74FFC089-8BF1-4FDF-B72F-76E315790AB6
Content-Transfer-Encoding: quoted-printable
Content-Type: text/html;
	charset=us-ascii

<html><head><meta http-equiv=3D"Content-Type" content=3D"text/html =
charset=3Dus-ascii"></head><body style=3D"word-wrap: break-word; =
-webkit-nbsp-mode: space; -webkit-line-break: after-white-space;" =
class=3D""><span class=3D""><br class=3D""></span><span =
style=3D"font-family: Verdana, Arial, 'Bitstream Vera Sans', Helvetica, =
sans-serif; font-size: 13px; font-variant-ligatures: normal; orphans: 2; =
widows: 2; background-color: rgb(255, 255, 255);" class=3D""><div =
class=3D""><span class=3D"">I am working on the shepherd writeup for =
the&nbsp;Token Binding over HTTP&nbsp;document:<br class=3D""></span><a =
href=3D"https://tools.ietf.org/html/draft-ietf-tokbind-https-09" =
class=3D"">https://tools.ietf.org/html/draft-ietf-tokbind-https-09</a><spa=
n class=3D""><br class=3D""><br class=3D"">One item in the template =
requires me to indicate whether each document<br class=3D"">author has =
confirmed that any and all appropriate IPR disclosures<br =
class=3D"">required for full conformance with the provisions of BCP 78 =
and BCP 79<br class=3D"">have already been filed.<br class=3D""><br =
class=3D"">Could each of you please confirm?<br =
class=3D""></span></div></span><div class=3D""><br class=3D""></div><div =
class=3D""><span style=3D"font-family: Verdana, Arial, 'Bitstream Vera =
Sans', Helvetica, sans-serif; font-size: 13px; font-variant-ligatures: =
normal; orphans: 2; widows: 2; background-color: rgb(255, 255, 255);" =
class=3D""><pre class=3D"newpage" style=3D"font-size: 13.3333px; =
margin-top: 0px; margin-bottom: 0px; break-before: page; =
font-variant-ligatures: normal;">   Magnus Nystroem
   Microsoft Corp.
   USA

   Email: <a href=3D"mailto:mnystrom@microsoft.com" =
class=3D"">mnystrom@microsoft.com</a>


   Dirk Balfanz (editor)
   Google Inc.
   USA

   Email: <a href=3D"mailto:balfanz@google.com" =
class=3D"">balfanz@google.com</a>


   Adam Langley
   Google Inc.
   USA

   Email: <a href=3D"mailto:agl@google.com" class=3D"">agl@google.com</a>


   Jeff Hodges
   PayPal
   USA

   Email: <a href=3D"mailto:Jeff.Hodges@paypal.com" =
class=3D"">Jeff.Hodges@paypal.com</a>
</pre><div class=3D""><br class=3D""></div></span></div></body></html>=

--Apple-Mail=_74FFC089-8BF1-4FDF-B72F-76E315790AB6--

--001a113fc1e8939ba80552460b3b
Content-Type: application/pkcs7-signature; name="smime.p7s"
Content-Transfer-Encoding: base64
Content-Disposition: attachment; filename="smime.p7s"
Content-Description: S/MIME Cryptographic Signature

MIIRGwYJKoZIhvcNAQcCoIIRDDCCEQgCAQExDzANBglghkgBZQMEAgEFADALBgkqhkiG9w0BBwGg
gg4rMIIErzCCA5egAwIBAgIRAOAjyxUSg1OJrWFuelRnayEwDQYJKoZIhvcNAQELBQAwbzELMAkG
A1UEBhMCU0UxFDASBgNVBAoTC0FkZFRydXN0IEFCMSYwJAYDVQQLEx1BZGRUcnVzdCBFeHRlcm5h
bCBUVFAgTmV0d29yazEiMCAGA1UEAxMZQWRkVHJ1c3QgRXh0ZXJuYWwgQ0EgUm9vdDAeFw0xNDEy
MjIwMDAwMDBaFw0yMDA1MzAxMDQ4MzhaMIGbMQswCQYDVQQGEwJHQjEbMBkGA1UECBMSR3JlYXRl
ciBNYW5jaGVzdGVyMRAwDgYDVQQHEwdTYWxmb3JkMRowGAYDVQQKExFDT01PRE8gQ0EgTGltaXRl
ZDFBMD8GA1UEAxM4Q09NT0RPIFNIQS0yNTYgQ2xpZW50IEF1dGhlbnRpY2F0aW9uIGFuZCBTZWN1
cmUgRW1haWwgQ0EwggEiMA0GCSqGSIb3DQEBAQUAA4IBDwAwggEKAoIBAQCJsQ3aelMZTnBSHbxW
pgYmt7hJ4JbnUavx8FoTSRWjtIwbYLx6UUKneYykIt8XYU6R1XYjChTTSgJ/th0JgG6lBD3ZursW
/qGHqS5DUkMWfK8yUMimT1rpCNjPkyWce4joMGTmpPhWgP0qJBQzF5msROVpi6NGBkvCM9TpQJ8G
sLGsk0C5tQiTOpwqU6MQ2z0gYTxVA47ZTnYlAiEp+qN8cXZP7uFfgen7VIDbw3s1UreE3iI9LDAt
MX9ZvVI3sDNpLUPr+tal8Zd3Z1GM2e4n67ylBzh2jKSpOP/fjPUDrEm+yvdzmToPMquclToTPQ5G
Old0YVC+xkA/y+Tin6IhAgMBAAGjggEXMIIBEzAfBgNVHSMEGDAWgBStvZh6NLQm9/rEJlTvA73g
JMtUGjAdBgNVHQ4EFgQUkmFrguGioKpP7GfxwqP3tIAAwewwDgYDVR0PAQH/BAQDAgGGMBIGA1Ud
EwEB/wQIMAYBAf8CAQAwHQYDVR0lBBYwFAYIKwYBBQUHAwIGCCsGAQUFBwMEMBEGA1UdIAQKMAgw
BgYEVR0gADBEBgNVHR8EPTA7MDmgN6A1hjNodHRwOi8vY3JsLnVzZXJ0cnVzdC5jb20vQWRkVHJ1
c3RFeHRlcm5hbENBUm9vdC5jcmwwNQYIKwYBBQUHAQEEKTAnMCUGCCsGAQUFBzABhhlodHRwOi8v
b2NzcC51c2VydHJ1c3QuY29tMA0GCSqGSIb3DQEBCwUAA4IBAQAbKm6sVcE6q4jF2O3NVfOqa2Er
wAkQI5kPxWZqb7H1tLV3Xg8CYQDffQX+ErOkgIAA/PsdW2pyAgpBvAW6wVjVJsLq1U2E+/6CmM9Y
G+MiY5xS+LsFNqt9WKXeqztj5drVc+/s4Pt74qP/8EIjnMq2jU0+5EsYA7KoLdTYu0JLkGmFENum
NzToe+ABEKWcyjrHn0+ING6KZdAairup3MrKNtH0/MJkKTWv1rGncRHSA0Oxjz6a7J4yU/R2ksqG
NAe5LMrmHErYmQ3BhuKQkvtaQmojIRDpZcf11bt+6oyFIAJi6tE6ByxZxZkz8jiJ5bbpFnofeRT2
ShAaJvp8ivubMIIENjCCAx6gAwIBAgIBATANBgkqhkiG9w0BAQUFADBvMQswCQYDVQQGEwJTRTEU
MBIGA1UEChMLQWRkVHJ1c3QgQUIxJjAkBgNVBAsTHUFkZFRydXN0IEV4dGVybmFsIFRUUCBOZXR3
b3JrMSIwIAYDVQQDExlBZGRUcnVzdCBFeHRlcm5hbCBDQSBSb290MB4XDTAwMDUzMDEwNDgzOFoX
DTIwMDUzMDEwNDgzOFowbzELMAkGA1UEBhMCU0UxFDASBgNVBAoTC0FkZFRydXN0IEFCMSYwJAYD
VQQLEx1BZGRUcnVzdCBFeHRlcm5hbCBUVFAgTmV0d29yazEiMCAGA1UEAxMZQWRkVHJ1c3QgRXh0
ZXJuYWwgQ0EgUm9vdDCCASIwDQYJKoZIhvcNAQEBBQADggEPADCCAQoCggEBALf3GjPm8gAELTng
TlvtH7xsD821+iO2zt6bETOXpClMfZOfvUq8k+0DGuOPz+VtUFrWlymUWoCwSXrbLpX9uMq/Nzgt
Hj6RQa1wVsfwTz/oMp50ysiQVOnGXw94nZpAPA6sYapeFI+eh6FqUNzXmk6vBbOmcZSccbNQYArH
E504B4YCqOmoaSYYkKtMsE8jqzpPhNjfzp/haW+710LXa0Tkx63ubUFfclpxCDezeWWkWaCUN/cA
Lw3CknLa0Dhy2xSoRcRdKn23tNbE7qzNE0S3ySvdQwAl+mG5aWpYIxG3pzOPVnVZ9c0p10a3Citl
ttNCbxWyuHv77+ldU9U0WicCAwEAAaOB3DCB2TAdBgNVHQ4EFgQUrb2YejS0Jvf6xCZU7wO94CTL
VBowCwYDVR0PBAQDAgEGMA8GA1UdEwEB/wQFMAMBAf8wgZkGA1UdIwSBkTCBjoAUrb2YejS0Jvf6
xCZU7wO94CTLVBqhc6RxMG8xCzAJBgNVBAYTAlNFMRQwEgYDVQQKEwtBZGRUcnVzdCBBQjEmMCQG
A1UECxMdQWRkVHJ1c3QgRXh0ZXJuYWwgVFRQIE5ldHdvcmsxIjAgBgNVBAMTGUFkZFRydXN0IEV4
dGVybmFsIENBIFJvb3SCAQEwDQYJKoZIhvcNAQEFBQADggEBALCb4IUlwtYj4g+WBpKdQZic2YR5
gdkeWxQHIzZlj7DYd7usQWxHYINRsPkyPef89iYTx4AWpb9a/IfPeHmJIZriTAcKhjW88t5RxNKW
t9x+Tu5w/Rw56wwCURQtjr0W4MHfRnXnJK3s9EK0hZNwEGe6nQY1ShjTK3rMUUKhemPR5ruhxSvC
Nr4TDea9Y355e6cJDUCrat2PisP29owaQgVR1EX1n6diIWgVIEM8med8vSTYqZEXc4g/VhsxOBi0
cQ+azcgOno4uG+GMmIPLHzHxREzGBHNJdmAPx/i9F4BrLunMTA5amnkPIAou1Z5jJh5VkpTYghda
e9C8x49OhgQwggU6MIIEIqADAgECAhEA2TLMtWuXNcB2cbqZ/VgVujANBgkqhkiG9w0BAQsFADCB
mzELMAkGA1UEBhMCR0IxGzAZBgNVBAgTEkdyZWF0ZXIgTWFuY2hlc3RlcjEQMA4GA1UEBxMHU2Fs
Zm9yZDEaMBgGA1UEChMRQ09NT0RPIENBIExpbWl0ZWQxQTA/BgNVBAMTOENPTU9ETyBTSEEtMjU2
IENsaWVudCBBdXRoZW50aWNhdGlvbiBhbmQgU2VjdXJlIEVtYWlsIENBMB4XDTE3MDEwOTAwMDAw
MFoXDTE4MDEwOTIzNTk1OVowIjEgMB4GCSqGSIb3DQEJARYRdmU3anRiQHZlN2p0Yi5jb20wggEi
MA0GCSqGSIb3DQEBAQUAA4IBDwAwggEKAoIBAQDW2rqobOFQ/XmzH3DG2UK1Dt6jtc+OFZ71KQoB
o8IZa/V94Ey12BPjBcoj+cjHNVsLd2QiUpMcf5sZFMX1cmvpR7TiUISgVcHe8zgiUUvN5Jn5tPDM
Kb4E34TtDEG2X5FyY35AwCl8NV/loj2D5KLid9BLdVTJjfqokjLQ/4qCQjWBjfTpIdAdr3lXfg5f
a5UPyIkphEIplM8/yGfX0W/PBl804XAL0gesLrfEMdgG58UCN1wJMgH4uRKmKU/U2Ap4W9hTpioN
M722U8x7N6P1v6MqTAWCUaskdOp+ktNxFGxOlCE7BEo/EIaWbEt5RHwDePctScDLsi56+VI3TysR
AgMBAAGjggHvMIIB6zAfBgNVHSMEGDAWgBSSYWuC4aKgqk/sZ/HCo/e0gADB7DAdBgNVHQ4EFgQU
Yg3SsFWhMro4Abonbn1IX4JKj5QwDgYDVR0PAQH/BAQDAgWgMAwGA1UdEwEB/wQCMAAwIAYDVR0l
BBkwFwYIKwYBBQUHAwQGCysGAQQBsjEBAwUCMBEGCWCGSAGG+EIBAQQEAwIFIDBGBgNVHSAEPzA9
MDsGDCsGAQQBsjEBAgEBATArMCkGCCsGAQUFBwIBFh1odHRwczovL3NlY3VyZS5jb21vZG8ubmV0
L0NQUzBdBgNVHR8EVjBUMFKgUKBOhkxodHRwOi8vY3JsLmNvbW9kb2NhLmNvbS9DT01PRE9TSEEy
NTZDbGllbnRBdXRoZW50aWNhdGlvbmFuZFNlY3VyZUVtYWlsQ0EuY3JsMIGQBggrBgEFBQcBAQSB
gzCBgDBYBggrBgEFBQcwAoZMaHR0cDovL2NydC5jb21vZG9jYS5jb20vQ09NT0RPU0hBMjU2Q2xp
ZW50QXV0aGVudGljYXRpb25hbmRTZWN1cmVFbWFpbENBLmNydDAkBggrBgEFBQcwAYYYaHR0cDov
L29jc3AuY29tb2RvY2EuY29tMBwGA1UdEQQVMBOBEXZlN2p0YkB2ZTdqdGIuY29tMA0GCSqGSIb3
DQEBCwUAA4IBAQCC26y+6/+SJoRQWepca+rB9eSSwaCAb8nNqA+00ZiOHb+6UbbV1xa7Z8wDIuEL
5UKbNtQ2NDArvzF9YI0xNafoV1AEmP/3+ljxQHSEI0U1p2h401sOx+nSjcwtTzACso1lw+I0oJYM
JFITOIfZy8HgFpCipBrQAp9jMJ+KSKDX3xu/hzPosfdnXp7sV1KAjkFrAtR3AnQYfJ5W8QrsmC4N
BbiAKoYWUSdklqn3v1neTG/+oOhcw7hcGZo+YmPyF9Cdy0gBtwSHPt8hluhg2TlzmqYfi0dVL/mU
jCBNUY/BFH+MBqKF7sOIRMv8ALWceVaM/NEcBciKs4eR99A4cw9ZMYICtDCCArACAQEwgbEwgZsx
CzAJBgNVBAYTAkdCMRswGQYDVQQIExJHcmVhdGVyIE1hbmNoZXN0ZXIxEDAOBgNVBAcTB1NhbGZv
cmQxGjAYBgNVBAoTEUNPTU9ETyBDQSBMaW1pdGVkMUEwPwYDVQQDEzhDT01PRE8gU0hBLTI1NiBD
bGllbnQgQXV0aGVudGljYXRpb24gYW5kIFNlY3VyZSBFbWFpbCBDQQIRANkyzLVrlzXAdnG6mf1Y
FbowDQYJYIZIAWUDBAIBBQCggdQwLwYJKoZIhvcNAQkEMSIEINbBLB5JS7tTx5Ckn1wxf7ZOO9KM
Mvk3mq/oxzN+VnKNMBgGCSqGSIb3DQEJAzELBgkqhkiG9w0BBwEwHAYJKoZIhvcNAQkFMQ8XDTE3
MDYxOTAxMjc1OFowaQYJKoZIhvcNAQkPMVwwWjALBglghkgBZQMEASowCwYJYIZIAWUDBAEWMAsG
CWCGSAFlAwQBAjAKBggqhkiG9w0DBzALBgkqhkiG9w0BAQowCwYJKoZIhvcNAQEHMAsGCWCGSAFl
AwQCATANBgkqhkiG9w0BAQEFAASCAQCWtAEFVfLVK7gpLJGWgKl2h2wrWJKyBVNuDltU+bFNZGD3
lhpdGs1eu/o/LJY8nux/aSTd4tOOeerI/EnU7Mou3zTPCQHqhvgWPpwUWA/SZjX1vHZdbzeg51P0
1lhru7RkSFULtEVXrn5w6bjAFanukq/04bCemhT+iv6Bk3f7niQW/MDmguYRqV4mEj9HvZrKthvB
JrJ4jmDe79rdbsJ8bsUgr/Hh4fN07w7CmTVdfaxHDCq+tHV49A3n1IEexkog0PDa4U8ugyPDmf8/
LA5ixQ6vqekGQBpBkvU5qwuwlbDRvwOCgQtaYby/fKAdC3JHccZxa53QSi691fCLCR5G
--001a113fc1e8939ba80552460b3b--


From nobody Mon Jun 19 09:53:55 2017
Return-Path: <Andrei.Popov@microsoft.com>
X-Original-To: unbearable@ietfa.amsl.com
Delivered-To: unbearable@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id AB31812947C; Mon, 19 Jun 2017 09:53:53 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.02
X-Spam-Level: 
X-Spam-Status: No, score=-2.02 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, HTML_MESSAGE=0.001, RCVD_IN_DNSWL_NONE=-0.0001, RCVD_IN_MSPIKE_H4=-0.01, RCVD_IN_MSPIKE_WL=-0.01, SPF_HELO_PASS=-0.001, SPF_PASS=-0.001, URIBL_BLOCKED=0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (1024-bit key) header.d=microsoft.com
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id 4InECA4cHGSD; Mon, 19 Jun 2017 09:53:51 -0700 (PDT)
Received: from NAM02-CY1-obe.outbound.protection.outlook.com (mail-cys01nam02on0108.outbound.protection.outlook.com [104.47.37.108]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 9F9E513166A; Mon, 19 Jun 2017 09:50:29 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=microsoft.com; s=selector1; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version; bh=mN9+IytCLeEA9hnRnpO9wOR4N6B5OBlxPeYTdMcIWmM=; b=Up+PJV75a8tcdVoaz4DwCqVJB3+I7GPddcYBktzw7KelW3glZgyczlVV9XjC8wvypzS5jSuIosIml07kBvrn2tSKrOqLxNAnNjIH0Tfe+IMkDKbJXE7KgrKPioM3z8EbMrLUWnCezD9m+Pmm43Hzml1UJU4V+uOs/UcV7KFdB/s=
Received: from DM2PR21MB0091.namprd21.prod.outlook.com (10.161.141.14) by DM2PR21MB0042.namprd21.prod.outlook.com (10.161.140.20) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_128_CBC_SHA256_P256) id 15.1.1199.3; Mon, 19 Jun 2017 16:50:28 +0000
Received: from DM2PR21MB0091.namprd21.prod.outlook.com ([fe80::2d6d:96d3:f164:d70f]) by DM2PR21MB0091.namprd21.prod.outlook.com ([fe80::2d6d:96d3:f164:d70f%15]) with mapi id 15.01.1199.007; Mon, 19 Jun 2017 16:50:28 +0000
From: Andrei Popov <Andrei.Popov@microsoft.com>
To: John Bradley <ve7jtb@ve7jtb.com>, IETF TokBind WG <unbearable@ietf.org>
CC: "draft-ietf-tokbind-negotiation@ietf.org" <draft-ietf-tokbind-negotiation@ietf.org>
Thread-Topic: IPR for draft-ietf-tokbind-negotiation
Thread-Index: AQHS6JtKYMMRC1gvTkC4ey1EaicpUKIsZHbQ
Date: Mon, 19 Jun 2017 16:50:27 +0000
Message-ID: <DM2PR21MB0091485AB9D0EB25296C2CBB8CC40@DM2PR21MB0091.namprd21.prod.outlook.com>
References: <EE89D9AF-F52B-48ED-8046-F441A67818A4@ve7jtb.com>
In-Reply-To: <EE89D9AF-F52B-48ED-8046-F441A67818A4@ve7jtb.com>
Accept-Language: en-US
Content-Language: en-US
X-MS-Has-Attach: 
X-MS-TNEF-Correlator: 
authentication-results: ve7jtb.com; dkim=none (message not signed) header.d=none;ve7jtb.com; dmarc=none action=none header.from=microsoft.com;
x-originating-ip: [2001:4898:80e8:d::4ca]
x-ms-publictraffictype: Email
x-microsoft-exchange-diagnostics: 1; DM2PR21MB0042; 7:Y51p9OO7lIu0rnr7E2VjVDeDxQA3X5hpOdz/Wiv9IBV2qwNnCWLS9YYRMHGqQQUdAUtIy0SrwprUHjqlaNPH6v4ZqyYacBXmQAUxY2ht8rlYiuB3RFknXfvnfcZGDOokXMg6tHKsb1m/mjP7+PsdjMxMSNsE/dX/d9QeZnJxKBBaGVB3SJemhBiyKJM9jPUYYdUCbvUx5QEOYD+RzMfKwjRG91mEaOlsT2OgnMx7NfAwMY7EizrU4CjkoiBfzXJR1MVakZJDgD5CzE0Babj/oz35gixlzrICrstw4ZXfSSCnHKjzY10s8hfVDK4rgrufP0RDQ/VB/zEkxfPcERQtRE7lLyGXGPymLg4mpVRLbgNo3a7bApgM8vBsT9EW/fBrG7qHxwGCuY4+6fBT8fveWtZALUmIhLsM58E7N/Q2SrvCXZonoXjo+JMP7Cd3YRlokrl1bnxF5kuaekl/XvTOk0TYHBLEXs2L5/wLOa9jSlDbBoYNSZw3QbiWLj9lzVN2pkak/kCU7d/rCyvFSOw17vXs8Ds6sZiZOftGAEuMG4MwYrk13IgXaism+UIyELWdKoTyCpJ7AzTht6EC3mHTTe5qxgys+vWPjfkqWLoit1oOxvpM6J+GMfK1NZ6n4D1C00XP0qBhvb/iM4gbGpU3zRCIVjnz2Qk8n/adYCexkozRDrtuGb3GpFujcRBMZmmdjN9sx9/Xmu2NZsOwG2mtGXvhFp44J0D+d/GZN+eXJsNJ0q1YwXp4sIrmmdGHK4dc09MGlSQYoFYYF+mpzEGk/+e+VnmO90ugyGuXYGWx6ZQv0upaSRKRgZao4qNS44Zl
x-ms-office365-filtering-correlation-id: 61159065-3e41-4297-6e44-08d4b7334a22
x-ms-office365-filtering-ht: Tenant
x-microsoft-antispam: UriScan:; BCL:0; PCL:0; RULEID:(300000500041)(300135000095)(300000501041)(300135300095)(22001)(300000502041)(300135100095)(2017030254075)(300000503041)(300135400095)(48565401081)(201703131423075)(201703031133081)(201702281549075)(300000504041)(300135200095)(300000505041)(300135600095)(300000506037)(300135500095); SRVR:DM2PR21MB0042; 
x-ms-traffictypediagnostic: DM2PR21MB0042:
x-microsoft-antispam-prvs: <DM2PR21MB0042310AE857294536B08A4B8CC40@DM2PR21MB0042.namprd21.prod.outlook.com>
x-exchange-antispam-report-test: UriScan:(192374486261705)(211936372134217)(21748063052155); 
x-exchange-antispam-report-cfa-test: BCL:0; PCL:0; RULEID:(100000700101)(100105000095)(100000701101)(100105300095)(100000702101)(100105100095)(61425038)(6040450)(601004)(2401047)(5005006)(8121501046)(3002001)(10201501046)(100000703101)(100105400095)(93006095)(93001095)(6055026)(61426038)(61427038)(6041248)(20161123558100)(20161123555025)(20161123564025)(201703131423075)(201702281528075)(201703061421075)(201703061406153)(20161123560025)(20161123562025)(6072148)(100000704101)(100105200095)(100000705101)(100105500095); SRVR:DM2PR21MB0042; BCL:0; PCL:0; RULEID:(100000800101)(100110000095)(100000801101)(100110300095)(100000802101)(100110100095)(100000803101)(100110400095)(100000804101)(100110200095)(100000805101)(100110500095); SRVR:DM2PR21MB0042; 
x-forefront-prvs: 0343AC1D30
x-forefront-antispam-report: SFV:NSPM; SFS:(10019020)(39450400003)(39840400002)(39860400002)(39400400002)(39410400002)(39850400002)(377454003)(252514010)(2906002)(99286003)(76176999)(5250100002)(6506006)(55016002)(6436002)(606005)(50986999)(6306002)(74316002)(53936002)(478600001)(966005)(189998001)(8936002)(38730400002)(236005)(19609705001)(10290500003)(10090500001)(72206003)(9686003)(2950100002)(81166006)(8676002)(54356999)(54896002)(6246003)(229853002)(8990500004)(33656002)(5660300001)(25786009)(6116002)(5005710100001)(3660700001)(53546009)(14454004)(3280700002)(2900100001)(230783001)(7906003)(7736002)(86362001)(790700001)(86612001)(7696004)(102836003); DIR:OUT; SFP:1102; SCL:1; SRVR:DM2PR21MB0042; H:DM2PR21MB0091.namprd21.prod.outlook.com; FPR:; SPF:None; MLV:sfv; LANG:en; 
spamdiagnosticoutput: 1:99
spamdiagnosticmetadata: NSPM
Content-Type: multipart/alternative; boundary="_000_DM2PR21MB0091485AB9D0EB25296C2CBB8CC40DM2PR21MB0091namp_"
MIME-Version: 1.0
X-OriginatorOrg: microsoft.com
X-MS-Exchange-CrossTenant-originalarrivaltime: 19 Jun 2017 16:50:27.9661 (UTC)
X-MS-Exchange-CrossTenant-fromentityheader: Hosted
X-MS-Exchange-CrossTenant-id: 72f988bf-86f1-41af-91ab-2d7cd011db47
X-MS-Exchange-Transport-CrossTenantHeadersStamped: DM2PR21MB0042
Archived-At: <https://mailarchive.ietf.org/arch/msg/unbearable/m4tDDn5jgZRUV1ODjKloTv7oQkA>
Subject: Re: [Unbearable] IPR for draft-ietf-tokbind-negotiation
X-BeenThere: unbearable@ietf.org
X-Mailman-Version: 2.1.22
Precedence: list
List-Id: "\"This list is for discussion of proposals for doing better than bearer tokens \(e.g. HTTP cookies, OAuth tokens etc.\) for web applications. The specific goal is chartering a WG focused on preventing security token export and replay attacks.\"" <unbearable.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/unbearable>, <mailto:unbearable-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/unbearable/>
List-Post: <mailto:unbearable@ietf.org>
List-Help: <mailto:unbearable-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/unbearable>, <mailto:unbearable-request@ietf.org?subject=subscribe>
X-List-Received-Date: Mon, 19 Jun 2017 16:53:54 -0000

--_000_DM2PR21MB0091485AB9D0EB25296C2CBB8CC40DM2PR21MB0091namp_
Content-Type: text/plain; charset="us-ascii"
Content-Transfer-Encoding: quoted-printable

I am not aware of any IPR pertaining to TBNEGO.

Cheers,

Andrei

From: John Bradley [mailto:ve7jtb@ve7jtb.com]
Sent: Sunday, June 18, 2017 6:28 PM
To: IETF TokBind WG <unbearable@ietf.org>
Cc: draft-ietf-tokbind-negotiation@ietf.org
Subject: IPR for draft-ietf-tokbind-negotiation


I am working on the shepherd writeup for the Transport Layer Security (TLS)=
 Extension for Token Binding Protocol Negotiation document:
https://tools.ietf.org/html/draft-ietf-tokbind-negotiation-08

One item in the template requires me to indicate whether each document
author has confirmed that any and all appropriate IPR disclosures
required for full conformance with the provisions of BCP 78 and BCP 79
have already been filed.

Could each of you please confirm?

   Magnus Nystroem

   Microsoft Corp.

   USA



   Email: mnystrom@microsoft.com<mailto:mnystrom@microsoft.com>





   Dirk Balfanz

   Google Inc.

   USA



   Email: balfanz@google.com<mailto:balfanz@google.com>





   Adam Langley

   Google Inc.

   USA



   Email: agl@google.com<mailto:agl@google.com>







--_000_DM2PR21MB0091485AB9D0EB25296C2CBB8CC40DM2PR21MB0091namp_
Content-Type: text/html; charset="us-ascii"
Content-Transfer-Encoding: quoted-printable

<html xmlns:v=3D"urn:schemas-microsoft-com:vml" xmlns:o=3D"urn:schemas-micr=
osoft-com:office:office" xmlns:w=3D"urn:schemas-microsoft-com:office:word" =
xmlns:m=3D"http://schemas.microsoft.com/office/2004/12/omml" xmlns=3D"http:=
//www.w3.org/TR/REC-html40">
<head>
<meta http-equiv=3D"Content-Type" content=3D"text/html; charset=3Dus-ascii"=
>
<meta name=3D"Generator" content=3D"Microsoft Word 15 (filtered medium)">
<style><!--
/* Font Definitions */
@font-face
	{font-family:"Cambria Math";
	panose-1:2 4 5 3 5 4 6 3 2 4;}
@font-face
	{font-family:Calibri;
	panose-1:2 15 5 2 2 2 4 3 2 4;}
@font-face
	{font-family:Consolas;
	panose-1:2 11 6 9 2 2 4 3 2 4;}
/* Style Definitions */
p.MsoNormal, li.MsoNormal, div.MsoNormal
	{margin:0in;
	margin-bottom:.0001pt;
	font-size:11.0pt;
	font-family:"Calibri",sans-serif;}
a:link, span.MsoHyperlink
	{mso-style-priority:99;
	color:blue;
	text-decoration:underline;}
a:visited, span.MsoHyperlinkFollowed
	{mso-style-priority:99;
	color:purple;
	text-decoration:underline;}
pre
	{mso-style-priority:99;
	mso-style-link:"HTML Preformatted Char";
	margin:0in;
	margin-bottom:.0001pt;
	font-size:10.0pt;
	font-family:"Courier New";}
p.msonormal0, li.msonormal0, div.msonormal0
	{mso-style-name:msonormal;
	mso-margin-top-alt:auto;
	margin-right:0in;
	mso-margin-bottom-alt:auto;
	margin-left:0in;
	font-size:11.0pt;
	font-family:"Calibri",sans-serif;}
span.HTMLPreformattedChar
	{mso-style-name:"HTML Preformatted Char";
	mso-style-priority:99;
	mso-style-link:"HTML Preformatted";
	font-family:Consolas;}
span.EmailStyle21
	{mso-style-type:personal-reply;
	font-family:"Calibri",sans-serif;
	color:windowtext;}
.MsoChpDefault
	{mso-style-type:export-only;
	font-size:10.0pt;}
@page WordSection1
	{size:8.5in 11.0in;
	margin:1.0in 1.0in 1.0in 1.0in;}
div.WordSection1
	{page:WordSection1;}
--></style><!--[if gte mso 9]><xml>
<o:shapedefaults v:ext=3D"edit" spidmax=3D"1026" />
</xml><![endif]--><!--[if gte mso 9]><xml>
<o:shapelayout v:ext=3D"edit">
<o:idmap v:ext=3D"edit" data=3D"1" />
</o:shapelayout></xml><![endif]-->
</head>
<body lang=3D"EN-US" link=3D"blue" vlink=3D"purple">
<div class=3D"WordSection1">
<p class=3D"MsoNormal">I am not aware of any IPR pertaining to TBNEGO.<o:p>=
</o:p></p>
<p class=3D"MsoNormal"><o:p>&nbsp;</o:p></p>
<p class=3D"MsoNormal">Cheers,<o:p></o:p></p>
<p class=3D"MsoNormal"><o:p>&nbsp;</o:p></p>
<p class=3D"MsoNormal">Andrei<o:p></o:p></p>
<p class=3D"MsoNormal"><o:p>&nbsp;</o:p></p>
<div>
<div style=3D"border:none;border-top:solid #E1E1E1 1.0pt;padding:3.0pt 0in =
0in 0in">
<p class=3D"MsoNormal"><b>From:</b> John Bradley [mailto:ve7jtb@ve7jtb.com]=
 <br>
<b>Sent:</b> Sunday, June 18, 2017 6:28 PM<br>
<b>To:</b> IETF TokBind WG &lt;unbearable@ietf.org&gt;<br>
<b>Cc:</b> draft-ietf-tokbind-negotiation@ietf.org<br>
<b>Subject:</b> IPR for draft-ietf-tokbind-negotiation<o:p></o:p></p>
</div>
</div>
<p class=3D"MsoNormal"><o:p>&nbsp;</o:p></p>
<p class=3D"MsoNormal" style=3D"margin-bottom:12.0pt"><br>
I&nbsp;am working on the shepherd writeup for the&nbsp;Transport Layer Secu=
rity (TLS) Extension for Token Binding&nbsp;Protocol&nbsp;Negotiation&nbsp;=
document:<br>
<a href=3D"https://tools.ietf.org/html/draft-ietf-tokbind-negotiation-08">h=
ttps://tools.ietf.org/html/draft-ietf-tokbind-negotiation-08</a><br>
<br>
One item in the template requires me to indicate whether each document<br>
author has confirmed that any and all appropriate IPR disclosures<br>
required for full conformance with the provisions of BCP 78 and BCP 79<br>
have already been filed.<br>
<br>
Could each of you please confirm?<o:p></o:p></p>
<div>
<pre style=3D"break-before: page;font-variant-ligatures: normal;orphans: 2;=
widows: 2">&nbsp;&nbsp; Magnus Nystroem<o:p></o:p></pre>
<pre>&nbsp;&nbsp; Microsoft Corp.<o:p></o:p></pre>
<pre>&nbsp;&nbsp; USA<o:p></o:p></pre>
<pre><o:p>&nbsp;</o:p></pre>
<pre>&nbsp;&nbsp; Email: <a href=3D"mailto:mnystrom@microsoft.com">mnystrom=
@microsoft.com</a><o:p></o:p></pre>
<pre><o:p>&nbsp;</o:p></pre>
<pre><o:p>&nbsp;</o:p></pre>
<pre>&nbsp;&nbsp; Dirk Balfanz<o:p></o:p></pre>
<pre>&nbsp;&nbsp; Google Inc.<o:p></o:p></pre>
<pre>&nbsp;&nbsp; USA<o:p></o:p></pre>
<pre><o:p>&nbsp;</o:p></pre>
<pre>&nbsp;&nbsp; Email: <a href=3D"mailto:balfanz@google.com">balfanz@goog=
le.com</a><o:p></o:p></pre>
<pre><o:p>&nbsp;</o:p></pre>
<pre><o:p>&nbsp;</o:p></pre>
<pre>&nbsp;&nbsp; Adam Langley<o:p></o:p></pre>
<pre>&nbsp;&nbsp; Google Inc.<o:p></o:p></pre>
<pre>&nbsp;&nbsp; USA<o:p></o:p></pre>
<pre><o:p>&nbsp;</o:p></pre>
<pre>&nbsp;&nbsp; Email: <a href=3D"mailto:agl@google.com">agl@google.com</=
a><o:p></o:p></pre>
<pre><o:p>&nbsp;</o:p></pre>
<pre><o:p>&nbsp;</o:p></pre>
<pre><o:p>&nbsp;</o:p></pre>
</div>
</div>
</body>
</html>

--_000_DM2PR21MB0091485AB9D0EB25296C2CBB8CC40DM2PR21MB0091namp_--


From nobody Mon Jun 19 09:54:13 2017
Return-Path: <Andrei.Popov@microsoft.com>
X-Original-To: unbearable@ietfa.amsl.com
Delivered-To: unbearable@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 71E9D131632; Mon, 19 Jun 2017 09:54:11 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.021
X-Spam-Level: 
X-Spam-Status: No, score=-2.021 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, RCVD_IN_DNSWL_NONE=-0.0001, RCVD_IN_MSPIKE_H4=-0.01, RCVD_IN_MSPIKE_WL=-0.01, SPF_HELO_PASS=-0.001, SPF_PASS=-0.001, URIBL_BLOCKED=0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (1024-bit key) header.d=microsoft.com
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id PPQ48jVJ_yGk; Mon, 19 Jun 2017 09:54:09 -0700 (PDT)
Received: from NAM01-BN3-obe.outbound.protection.outlook.com (mail-bn3nam01on0125.outbound.protection.outlook.com [104.47.33.125]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 1D99F1316BF; Mon, 19 Jun 2017 09:50:49 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=microsoft.com; s=selector1; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version; bh=LnPrgd1Fl8N4jBfskdR/u6Qj/wv8OTJotIwVPN1020c=; b=MxvSCG587pkvKHb50xKmgiw1Okna5AVC2ZdIlpuAAV9VIhVme0NOMzEFKSGVxiK5xQi0SZz3oHGsufODl269PGp8R6E0O5Nr7pTEwMhv8Cq3MmPSkXu0ZCDKgw6pEHBjNySPVp/6VqbEp7AkvBxXno/lTx2rMmWflJ/iN/KdxfY=
Received: from DM2PR21MB0091.namprd21.prod.outlook.com (10.161.141.14) by DM2PR21MB0041.namprd21.prod.outlook.com (10.161.140.19) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_128_CBC_SHA256_P256) id 15.1.1199.3; Mon, 19 Jun 2017 16:50:47 +0000
Received: from DM2PR21MB0091.namprd21.prod.outlook.com ([fe80::2d6d:96d3:f164:d70f]) by DM2PR21MB0091.namprd21.prod.outlook.com ([fe80::2d6d:96d3:f164:d70f%15]) with mapi id 15.01.1199.007; Mon, 19 Jun 2017 16:50:47 +0000
From: Andrei Popov <Andrei.Popov@microsoft.com>
To: John Bradley <ve7jtb@ve7jtb.com>, IETF TokBind WG <unbearable@ietf.org>
CC: "draft-ietf-tokbind-protocol@ietf.org" <draft-ietf-tokbind-protocol@ietf.org>
Thread-Topic: IPR for draft-ietf-tokbind-protocol
Thread-Index: AQHS6JtM517oilF11E2qrR54s+xhIqIsZxjQ
Date: Mon, 19 Jun 2017 16:50:47 +0000
Message-ID: <DM2PR21MB0091680D1C3E2D3EBE2E29598CC40@DM2PR21MB0091.namprd21.prod.outlook.com>
References: <C7D885CC-9B96-4AA4-9EA0-6087084000B3@ve7jtb.com>
In-Reply-To: <C7D885CC-9B96-4AA4-9EA0-6087084000B3@ve7jtb.com>
Accept-Language: en-US
Content-Language: en-US
X-MS-Has-Attach: 
X-MS-TNEF-Correlator: 
authentication-results: ve7jtb.com; dkim=none (message not signed) header.d=none;ve7jtb.com; dmarc=none action=none header.from=microsoft.com;
x-originating-ip: [2001:4898:80e8:d::4ca]
x-ms-publictraffictype: Email
x-microsoft-exchange-diagnostics: 1; DM2PR21MB0041; 7:rHdXlAoiSMefsFGZwzm9JLFnmFUjtD9bXos/kQhB9V9kIgkGS95c3pl7gaisRMLf/BvTeYbEbst5X0XG8Uc2YZ/l1nLtHF/kd0KRgJ8tsTKEfcZmxHGAZtp2ISnXCbSQ1XsEoYmfOnyBUu1woE4UzqHNWyAsSN1e/4BUyEILqYa5q5g1pLUwEmetkFhnFt6qyfnTBrMq2gEJ5iq9rSQjZU0wsdrg36tzO3QIuFTJBoXv80w6F0Mc/mCiPSkNz+pgZF6C2PSpTfR872o7tdv9/gbUfj/ixpoJYP1sgpXkkv7Bb9803m/tIA9HPx5vINB64SbGKdDculcwzfMK0WiWW+Ko8iavCibwDf1P/F/Z+gz2bVkeA31gzTHk6uG2TuMb6BQuVl2s4eeMEV+pVLm8j2Qhoh0vE+b3AjCF49zICTkZx+ccndguDiT1zzCLaprzugn/5ryPZjK07Fr6tHPFnrOT0tKeGMrr47Qwi+DJHOvza6DW7jCiZNd8BgmCJbZv/0B7f1NMIa+RRbcWuZN+BJCSi4wKaIWc7LGh9lMPJmGSxh1oeloFDmgZ8SssOCfzqdpOTzqIVv0bWsKVdS5qP2IZUA7Xt6aelD9pypzocp6JIB/OA5bhLyAGpyJJSE+3fpxqRjQzYIuv5gUbNDbXDHd5/PEXX/EJqQPlAeTluMfqYe1Hmv1NhdHoziem/CJiTcym/D8brezDBx3PyZ9RqVrDmn0vmHzrz2IkMaAJy4Gj3qG5fvEtMLkIftxrFQ+yEXVokQBl/51vLnLSvdfZp7KvoGn2t2U5dAMXBY44qX4h4k2Mgs+LHwTNLj8oEyAT
x-ms-office365-filtering-correlation-id: 796e0835-6387-48f1-96a9-08d4b73355bf
x-ms-office365-filtering-ht: Tenant
x-microsoft-antispam: UriScan:; BCL:0; PCL:0; RULEID:(300000500041)(300135000095)(300000501041)(300135300095)(22001)(300000502041)(300135100095)(2017030254075)(300000503041)(300135400095)(48565401081)(201703131423075)(201703031133081)(300000504041)(300135200095)(300000505041)(300135600095)(300000506037)(300135500095); SRVR:DM2PR21MB0041; 
x-ms-traffictypediagnostic: DM2PR21MB0041:
x-microsoft-antispam-prvs: <DM2PR21MB004199CBF63AC6537435EDE98CC40@DM2PR21MB0041.namprd21.prod.outlook.com>
x-exchange-antispam-report-test: UriScan:(252895345309445)(211936372134217);
x-exchange-antispam-report-cfa-test: BCL:0; PCL:0; RULEID:(100000700101)(100105000095)(100000701101)(100105300095)(100000702101)(100105100095)(61425038)(6040450)(601004)(2401047)(8121501046)(5005006)(93006095)(93001095)(3002001)(100000703101)(100105400095)(10201501046)(6055026)(61426038)(61427038)(6041248)(20161123562025)(20161123555025)(20161123564025)(201703131423075)(201702281528075)(201703061421075)(201703061406153)(20161123560025)(20161123558100)(6072148)(100000704101)(100105200095)(100000705101)(100105500095); SRVR:DM2PR21MB0041; BCL:0; PCL:0; RULEID:(100000800101)(100110000095)(100000801101)(100110300095)(100000802101)(100110100095)(100000803101)(100110400095)(100000804101)(100110200095)(100000805101)(100110500095); SRVR:DM2PR21MB0041; 
x-forefront-prvs: 0343AC1D30
x-forefront-antispam-report: SFV:NSPM; SFS:(10019020)(6009001)(39860400002)(39450400003)(39840400002)(39400400002)(39410400002)(39850400002)(377454003)(252514010)(13464003)(5660300001)(2900100001)(189998001)(9686003)(102836003)(76176999)(7696004)(230783001)(50986999)(5250100002)(7736002)(6116002)(2950100002)(14454004)(305945005)(54356999)(74316002)(8936002)(6306002)(81166006)(6246003)(10090500001)(2906002)(478600001)(6506006)(33656002)(229853002)(8990500004)(38730400002)(25786009)(53546009)(6436002)(86362001)(99286003)(55016002)(3280700002)(8676002)(966005)(5005710100001)(86612001)(10290500003)(72206003)(53936002)(3660700001); DIR:OUT; SFP:1102; SCL:1; SRVR:DM2PR21MB0041; H:DM2PR21MB0091.namprd21.prod.outlook.com; FPR:; SPF:None; MLV:sfv; LANG:en; 
spamdiagnosticoutput: 1:99
spamdiagnosticmetadata: NSPM
Content-Type: text/plain; charset="us-ascii"
Content-Transfer-Encoding: quoted-printable
MIME-Version: 1.0
X-OriginatorOrg: microsoft.com
X-MS-Exchange-CrossTenant-originalarrivaltime: 19 Jun 2017 16:50:47.4666 (UTC)
X-MS-Exchange-CrossTenant-fromentityheader: Hosted
X-MS-Exchange-CrossTenant-id: 72f988bf-86f1-41af-91ab-2d7cd011db47
X-MS-Exchange-Transport-CrossTenantHeadersStamped: DM2PR21MB0041
Archived-At: <https://mailarchive.ietf.org/arch/msg/unbearable/Z_E1_h7hMV1mmvjax2USpuzeGho>
Subject: Re: [Unbearable] IPR for draft-ietf-tokbind-protocol
X-BeenThere: unbearable@ietf.org
X-Mailman-Version: 2.1.22
Precedence: list
List-Id: "\"This list is for discussion of proposals for doing better than bearer tokens \(e.g. HTTP cookies, OAuth tokens etc.\) for web applications. The specific goal is chartering a WG focused on preventing security token export and replay attacks.\"" <unbearable.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/unbearable>, <mailto:unbearable-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/unbearable/>
List-Post: <mailto:unbearable@ietf.org>
List-Help: <mailto:unbearable-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/unbearable>, <mailto:unbearable-request@ietf.org?subject=subscribe>
X-List-Received-Date: Mon, 19 Jun 2017 16:54:11 -0000

I am not aware of any IPR pertaining to TBPROTO.

Cheers,

Andrei

-----Original Message-----
From: John Bradley [mailto:ve7jtb@ve7jtb.com]=20
Sent: Sunday, June 18, 2017 6:28 PM
To: IETF TokBind WG <unbearable@ietf.org>
Cc: draft-ietf-tokbind-protocol@ietf.org
Subject: IPR for draft-ietf-tokbind-protocol

I am working on the shepherd writeup for the The Token Binding Protocol Ver=
sion 1.0 document:
https://tools.ietf.org/html/draft-ietf-tokbind-protocol-14

One item in the template requires me to indicate whether each document
author has confirmed that any and all appropriate IPR disclosures
required for full conformance with the provisions of BCP 78 and BCP 79
have already been filed.

Could each of you please confirm?

   Andrei Popov (editor)
   Microsoft Corp.
   USA

   Email: andreipo@microsoft.com


   Magnus Nystroem
   Microsoft Corp.
   USA

   Email: mnystrom@microsoft.com


   Dirk Balfanz
   Google Inc.
   USA

   Email: balfanz@google.com


   Adam Langley
   Google Inc.
   USA

   Email: agl@google.com


   Jeff Hodges
   PayPal
   USA

   Email: Jeff.Hodges@paypal.com





From nobody Mon Jun 19 09:54:36 2017
Return-Path: <Andrei.Popov@microsoft.com>
X-Original-To: unbearable@ietfa.amsl.com
Delivered-To: unbearable@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id C53B613166B; Mon, 19 Jun 2017 09:54:33 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.02
X-Spam-Level: 
X-Spam-Status: No, score=-2.02 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, HTML_MESSAGE=0.001, RCVD_IN_DNSWL_NONE=-0.0001, RCVD_IN_MSPIKE_H3=-0.01, RCVD_IN_MSPIKE_WL=-0.01, SPF_HELO_PASS=-0.001, SPF_PASS=-0.001, URIBL_BLOCKED=0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (1024-bit key) header.d=microsoft.com
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id wgFyJR_q8Urr; Mon, 19 Jun 2017 09:54:31 -0700 (PDT)
Received: from NAM03-BY2-obe.outbound.protection.outlook.com (mail-by2nam03on0112.outbound.protection.outlook.com [104.47.42.112]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 80FEE1316FB; Mon, 19 Jun 2017 09:51:02 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=microsoft.com; s=selector1; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version; bh=QMZlePGxVspWpEBbFIxtaxSEy82XorxWkXdvpzhpq0c=; b=m83ROvqa9SO02D+N6jxmwWU+gl/vwjWdMiZhcsHyDOHvQnVRb1L88R5XtGfXe/DDnZwm4YgKxtImdg3Bxi44IM4fDHhLw6jHDRiFqkDDZFgcxtBPHtSNX+uHiia+TMJpQvg38TrfsbxsC8XxawDGHx7Eji3Mu3sK/1fZPbDkt9g=
Received: from DM2PR21MB0091.namprd21.prod.outlook.com (10.161.141.14) by DM2PR21MB0042.namprd21.prod.outlook.com (10.161.140.20) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_128_CBC_SHA256_P256) id 15.1.1199.3; Mon, 19 Jun 2017 16:51:01 +0000
Received: from DM2PR21MB0091.namprd21.prod.outlook.com ([fe80::2d6d:96d3:f164:d70f]) by DM2PR21MB0091.namprd21.prod.outlook.com ([fe80::2d6d:96d3:f164:d70f%15]) with mapi id 15.01.1199.007; Mon, 19 Jun 2017 16:51:01 +0000
From: Andrei Popov <Andrei.Popov@microsoft.com>
To: John Bradley <ve7jtb@ve7jtb.com>, IETF TokBind WG <unbearable@ietf.org>
CC: "draft-ietf-tokbind-https@ietf.org" <draft-ietf-tokbind-https@ietf.org>
Thread-Topic: IPR for draft-ietf-tokbind-https
Thread-Index: AQHS6JtMKbqY6ld4NE69sfaKZYjUjaIsZzDw
Date: Mon, 19 Jun 2017 16:51:01 +0000
Message-ID: <DM2PR21MB0091E96712B26FDD088E8A708CC40@DM2PR21MB0091.namprd21.prod.outlook.com>
References: <634F056D-5B5F-4570-AE30-9F3F6F6AE3A5@ve7jtb.com>
In-Reply-To: <634F056D-5B5F-4570-AE30-9F3F6F6AE3A5@ve7jtb.com>
Accept-Language: en-US
Content-Language: en-US
X-MS-Has-Attach: 
X-MS-TNEF-Correlator: 
authentication-results: ve7jtb.com; dkim=none (message not signed) header.d=none;ve7jtb.com; dmarc=none action=none header.from=microsoft.com;
x-originating-ip: [2001:4898:80e8:d::4ca]
x-ms-publictraffictype: Email
x-microsoft-exchange-diagnostics: 1; DM2PR21MB0042; 7:OtiENBiV65gVFIi0LYA1dBLjVJ5j0gXNszN7aCepB6gF2ux6i5BuK+Gk9HMRXwyJjgI4+OmQR0lwjgnKP6mh86oQSBnU6pcHN7ynEWRLbhM/eeYHqI7+YBExvpj4EvrwHHbmgQNFkprXdJ02cyncHtX+uyBZ/wnENk1fnBXHcb9Ala3V43YCvOjLnY0A04ASckhD5JRJuitD0vO8Q1fplhwJ6nRunsEAi5HmZ2xjFxJJY9mpRvYTGFLc3IbLOJwKnoXaDTFtU8+R7GChYC4ivCTH+aM+5thEjzY/YfULyF8MtmQ/ywiOkdy9Hh+rCL3Tt+HZnR7GImVgszti8q04jh8J6WnBbJdHHLLtj2ctcOCfdQCXNF1hHiFLyLpztoKCy3EDRJEn3YfVlD4qS20QSrHWcImFmSnWD++KohT0X7WpjJgE5ZDH3TQ8mnVsCgzSF2otZlUB4x91QsTASpfO6+xcxFaRE81n4EUYNCqj/h8Dlyp+CARQPyjfF7iGbmOpxiyjLD0yw0vH60pZEpYGhxpbdO85i49m3oGBftV07NJvrL4CFJ/kg/eIsy6WS8I1rGsIuykKjaGm+wS7RDxfHDOC/U9EJtPjJuvaObATzY9kH6vgCG0RAWEUn2+aYWK2wEKgMgtqKRKPoeuDlV0pk2A9w0iYelsOrp0f/zjjdcJ+rGSQMNDydFToqdZywAR3U7fur2TFZjvECi2d33LNgRKayMaE/P1HGFvyGuBhrVoGg5/Pem0ME011maylx6omrQUGVjUeDy4E8gwbAru2ac4wOQngGUGUbyXTMCzT3uBiAGrnmtY57SSKQQfMubzz
x-ms-office365-filtering-correlation-id: 2c8946db-97b8-4efd-5684-08d4b7335e0e
x-ms-office365-filtering-ht: Tenant
x-microsoft-antispam: UriScan:; BCL:0; PCL:0; RULEID:(300000500041)(300135000095)(300000501041)(300135300095)(22001)(300000502041)(300135100095)(2017030254075)(300000503041)(300135400095)(48565401081)(201703131423075)(201703031133081)(201702281549075)(300000504041)(300135200095)(300000505041)(300135600095)(300000506037)(300135500095); SRVR:DM2PR21MB0042; 
x-ms-traffictypediagnostic: DM2PR21MB0042:
x-microsoft-antispam-prvs: <DM2PR21MB00426930C157ECD1A9E1E1F18CC40@DM2PR21MB0042.namprd21.prod.outlook.com>
x-exchange-antispam-report-test: UriScan:(252895345309445)(211936372134217)(21748063052155); 
x-exchange-antispam-report-cfa-test: BCL:0; PCL:0; RULEID:(100000700101)(100105000095)(100000701101)(100105300095)(100000702101)(100105100095)(61425038)(6040450)(601004)(2401047)(5005006)(8121501046)(3002001)(10201501046)(100000703101)(100105400095)(93006095)(93001095)(6055026)(61426038)(61427038)(6041248)(20161123558100)(20161123555025)(20161123564025)(201703131423075)(201702281528075)(201703061421075)(201703061406153)(20161123560025)(20161123562025)(6072148)(100000704101)(100105200095)(100000705101)(100105500095); SRVR:DM2PR21MB0042; BCL:0; PCL:0; RULEID:(100000800101)(100110000095)(100000801101)(100110300095)(100000802101)(100110100095)(100000803101)(100110400095)(100000804101)(100110200095)(100000805101)(100110500095); SRVR:DM2PR21MB0042; 
x-forefront-prvs: 0343AC1D30
x-forefront-antispam-report: SFV:NSPM; SFS:(10019020)(979002)(39450400003)(39840400002)(39860400002)(39400400002)(39410400002)(39850400002)(377454003)(252514010)(2906002)(99286003)(76176999)(5250100002)(6506006)(55016002)(6436002)(606005)(50986999)(6306002)(74316002)(53936002)(478600001)(966005)(189998001)(8936002)(38730400002)(236005)(19609705001)(10290500003)(10090500001)(72206003)(9686003)(2950100002)(81156014)(81166006)(8676002)(54356999)(54896002)(6246003)(229853002)(8990500004)(33656002)(5660300001)(25786009)(6116002)(5005710100001)(3660700001)(53546009)(14454004)(3280700002)(2900100001)(4326008)(230783001)(7906003)(7736002)(86362001)(790700001)(86612001)(7696004)(102836003)(969003)(989001)(999001)(1009001)(1019001); DIR:OUT; SFP:1102; SCL:1; SRVR:DM2PR21MB0042; H:DM2PR21MB0091.namprd21.prod.outlook.com; FPR:; SPF:None; MLV:ovrnspm; PTR:InfoNoRecords; LANG:en; 
spamdiagnosticoutput: 1:99
spamdiagnosticmetadata: NSPM
Content-Type: multipart/alternative; boundary="_000_DM2PR21MB0091E96712B26FDD088E8A708CC40DM2PR21MB0091namp_"
MIME-Version: 1.0
X-OriginatorOrg: microsoft.com
X-MS-Exchange-CrossTenant-originalarrivaltime: 19 Jun 2017 16:51:01.4514 (UTC)
X-MS-Exchange-CrossTenant-fromentityheader: Hosted
X-MS-Exchange-CrossTenant-id: 72f988bf-86f1-41af-91ab-2d7cd011db47
X-MS-Exchange-Transport-CrossTenantHeadersStamped: DM2PR21MB0042
Archived-At: <https://mailarchive.ietf.org/arch/msg/unbearable/-PNkkvofwM6i2FZx0S8U8gpxT4U>
Subject: Re: [Unbearable] IPR for draft-ietf-tokbind-https
X-BeenThere: unbearable@ietf.org
X-Mailman-Version: 2.1.22
Precedence: list
List-Id: "\"This list is for discussion of proposals for doing better than bearer tokens \(e.g. HTTP cookies, OAuth tokens etc.\) for web applications. The specific goal is chartering a WG focused on preventing security token export and replay attacks.\"" <unbearable.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/unbearable>, <mailto:unbearable-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/unbearable/>
List-Post: <mailto:unbearable@ietf.org>
List-Help: <mailto:unbearable-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/unbearable>, <mailto:unbearable-request@ietf.org?subject=subscribe>
X-List-Received-Date: Mon, 19 Jun 2017 16:54:34 -0000

--_000_DM2PR21MB0091E96712B26FDD088E8A708CC40DM2PR21MB0091namp_
Content-Type: text/plain; charset="us-ascii"
Content-Transfer-Encoding: quoted-printable

I am not aware of any IPR pertaining to HTTPSTB.

Cheers,

Andrei


From: John Bradley [mailto:ve7jtb@ve7jtb.com]
Sent: Sunday, June 18, 2017 6:28 PM
To: IETF TokBind WG <unbearable@ietf.org>
Cc: draft-ietf-tokbind-https@ietf.org
Subject: IPR for draft-ietf-tokbind-https



I am working on the shepherd writeup for the Token Binding over HTTP docume=
nt:
https://tools.ietf.org/html/draft-ietf-tokbind-https-09

One item in the template requires me to indicate whether each document
author has confirmed that any and all appropriate IPR disclosures
required for full conformance with the provisions of BCP 78 and BCP 79
have already been filed.

Could each of you please confirm?


   Magnus Nystroem

   Microsoft Corp.

   USA



   Email: mnystrom@microsoft.com<mailto:mnystrom@microsoft.com>





   Dirk Balfanz (editor)

   Google Inc.

   USA



   Email: balfanz@google.com<mailto:balfanz@google.com>





   Adam Langley

   Google Inc.

   USA



   Email: agl@google.com<mailto:agl@google.com>





   Jeff Hodges

   PayPal

   USA



   Email: Jeff.Hodges@paypal.com<mailto:Jeff.Hodges@paypal.com>


--_000_DM2PR21MB0091E96712B26FDD088E8A708CC40DM2PR21MB0091namp_
Content-Type: text/html; charset="us-ascii"
Content-Transfer-Encoding: quoted-printable

<html xmlns:v=3D"urn:schemas-microsoft-com:vml" xmlns:o=3D"urn:schemas-micr=
osoft-com:office:office" xmlns:w=3D"urn:schemas-microsoft-com:office:word" =
xmlns:m=3D"http://schemas.microsoft.com/office/2004/12/omml" xmlns=3D"http:=
//www.w3.org/TR/REC-html40">
<head>
<meta http-equiv=3D"Content-Type" content=3D"text/html; charset=3Dus-ascii"=
>
<meta name=3D"Generator" content=3D"Microsoft Word 15 (filtered medium)">
<style><!--
/* Font Definitions */
@font-face
	{font-family:"Cambria Math";
	panose-1:2 4 5 3 5 4 6 3 2 4;}
@font-face
	{font-family:Calibri;
	panose-1:2 15 5 2 2 2 4 3 2 4;}
@font-face
	{font-family:Consolas;
	panose-1:2 11 6 9 2 2 4 3 2 4;}
@font-face
	{font-family:Verdana;
	panose-1:2 11 6 4 3 5 4 4 2 4;}
/* Style Definitions */
p.MsoNormal, li.MsoNormal, div.MsoNormal
	{margin:0in;
	margin-bottom:.0001pt;
	font-size:11.0pt;
	font-family:"Calibri",sans-serif;}
a:link, span.MsoHyperlink
	{mso-style-priority:99;
	color:blue;
	text-decoration:underline;}
a:visited, span.MsoHyperlinkFollowed
	{mso-style-priority:99;
	color:purple;
	text-decoration:underline;}
pre
	{mso-style-priority:99;
	mso-style-link:"HTML Preformatted Char";
	margin:0in;
	margin-bottom:.0001pt;
	font-size:10.0pt;
	font-family:"Courier New";}
p.msonormal0, li.msonormal0, div.msonormal0
	{mso-style-name:msonormal;
	mso-margin-top-alt:auto;
	margin-right:0in;
	mso-margin-bottom-alt:auto;
	margin-left:0in;
	font-size:11.0pt;
	font-family:"Calibri",sans-serif;}
span.HTMLPreformattedChar
	{mso-style-name:"HTML Preformatted Char";
	mso-style-priority:99;
	mso-style-link:"HTML Preformatted";
	font-family:Consolas;}
span.EmailStyle20
	{mso-style-type:personal-reply;
	font-family:"Calibri",sans-serif;
	color:windowtext;}
.MsoChpDefault
	{mso-style-type:export-only;
	font-size:10.0pt;}
@page WordSection1
	{size:8.5in 11.0in;
	margin:1.0in 1.0in 1.0in 1.0in;}
div.WordSection1
	{page:WordSection1;}
--></style><!--[if gte mso 9]><xml>
<o:shapedefaults v:ext=3D"edit" spidmax=3D"1026" />
</xml><![endif]--><!--[if gte mso 9]><xml>
<o:shapelayout v:ext=3D"edit">
<o:idmap v:ext=3D"edit" data=3D"1" />
</o:shapelayout></xml><![endif]-->
</head>
<body lang=3D"EN-US" link=3D"blue" vlink=3D"purple">
<div class=3D"WordSection1">
<p class=3D"MsoNormal">I am not aware of any IPR pertaining to HTTPSTB.<o:p=
></o:p></p>
<p class=3D"MsoNormal"><o:p>&nbsp;</o:p></p>
<p class=3D"MsoNormal">Cheers,<o:p></o:p></p>
<p class=3D"MsoNormal"><o:p>&nbsp;</o:p></p>
<p class=3D"MsoNormal">Andrei<o:p></o:p></p>
<p class=3D"MsoNormal"><o:p>&nbsp;</o:p></p>
<p class=3D"MsoNormal"><o:p>&nbsp;</o:p></p>
<div>
<div style=3D"border:none;border-top:solid #E1E1E1 1.0pt;padding:3.0pt 0in =
0in 0in">
<p class=3D"MsoNormal"><b>From:</b> John Bradley [mailto:ve7jtb@ve7jtb.com]=
 <br>
<b>Sent:</b> Sunday, June 18, 2017 6:28 PM<br>
<b>To:</b> IETF TokBind WG &lt;unbearable@ietf.org&gt;<br>
<b>Cc:</b> draft-ietf-tokbind-https@ietf.org<br>
<b>Subject:</b> IPR for draft-ietf-tokbind-https<o:p></o:p></p>
</div>
</div>
<p class=3D"MsoNormal"><o:p>&nbsp;</o:p></p>
<p class=3D"MsoNormal"><br>
<br>
<span style=3D"font-size:10.0pt;font-family:&quot;Verdana&quot;,sans-serif;=
background:white"><o:p></o:p></span></p>
<div>
<p class=3D"MsoNormal"><span style=3D"font-size:10.0pt;font-family:&quot;Ve=
rdana&quot;,sans-serif;background:white">I am working on the shepherd write=
up for the&nbsp;Token Binding over HTTP&nbsp;document:<br>
<a href=3D"https://tools.ietf.org/html/draft-ietf-tokbind-https-09">https:/=
/tools.ietf.org/html/draft-ietf-tokbind-https-09</a><br>
<br>
One item in the template requires me to indicate whether each document<br>
author has confirmed that any and all appropriate IPR disclosures<br>
required for full conformance with the provisions of BCP 78 and BCP 79<br>
have already been filed.<br>
<br>
Could each of you please confirm?<o:p></o:p></span></p>
</div>
<div>
<p class=3D"MsoNormal"><o:p>&nbsp;</o:p></p>
</div>
<div>
<pre style=3D"break-before: page;font-variant-ligatures: normal"><span styl=
e=3D"background:white">&nbsp;&nbsp; Magnus Nystroem<o:p></o:p></span></pre>
<pre><span style=3D"background:white">&nbsp;&nbsp; Microsoft Corp.<o:p></o:=
p></span></pre>
<pre><span style=3D"background:white">&nbsp;&nbsp; USA<o:p></o:p></span></p=
re>
<pre><span style=3D"background:white"><o:p>&nbsp;</o:p></span></pre>
<pre><span style=3D"background:white">&nbsp;&nbsp; Email: <a href=3D"mailto=
:mnystrom@microsoft.com">mnystrom@microsoft.com</a><o:p></o:p></span></pre>
<pre><span style=3D"background:white"><o:p>&nbsp;</o:p></span></pre>
<pre><span style=3D"background:white"><o:p>&nbsp;</o:p></span></pre>
<pre><span style=3D"background:white">&nbsp;&nbsp; Dirk Balfanz (editor)<o:=
p></o:p></span></pre>
<pre><span style=3D"background:white">&nbsp;&nbsp; Google Inc.<o:p></o:p></=
span></pre>
<pre><span style=3D"background:white">&nbsp;&nbsp; USA<o:p></o:p></span></p=
re>
<pre><span style=3D"background:white"><o:p>&nbsp;</o:p></span></pre>
<pre><span style=3D"background:white">&nbsp;&nbsp; Email: <a href=3D"mailto=
:balfanz@google.com">balfanz@google.com</a><o:p></o:p></span></pre>
<pre><span style=3D"background:white"><o:p>&nbsp;</o:p></span></pre>
<pre><span style=3D"background:white"><o:p>&nbsp;</o:p></span></pre>
<pre><span style=3D"background:white">&nbsp;&nbsp; Adam Langley<o:p></o:p><=
/span></pre>
<pre><span style=3D"background:white">&nbsp;&nbsp; Google Inc.<o:p></o:p></=
span></pre>
<pre><span style=3D"background:white">&nbsp;&nbsp; USA<o:p></o:p></span></p=
re>
<pre><span style=3D"background:white"><o:p>&nbsp;</o:p></span></pre>
<pre><span style=3D"background:white">&nbsp;&nbsp; Email: <a href=3D"mailto=
:agl@google.com">agl@google.com</a><o:p></o:p></span></pre>
<pre><span style=3D"background:white"><o:p>&nbsp;</o:p></span></pre>
<pre><span style=3D"background:white"><o:p>&nbsp;</o:p></span></pre>
<pre><span style=3D"background:white">&nbsp;&nbsp; Jeff Hodges<o:p></o:p></=
span></pre>
<pre><span style=3D"background:white"> &nbsp;&nbsp;PayPal<o:p></o:p></span>=
</pre>
<pre><span style=3D"background:white">&nbsp;&nbsp; USA<o:p></o:p></span></p=
re>
<pre><span style=3D"background:white"><o:p>&nbsp;</o:p></span></pre>
<pre><span style=3D"background:white">&nbsp;&nbsp; Email: <a href=3D"mailto=
:Jeff.Hodges@paypal.com">Jeff.Hodges@paypal.com</a><o:p></o:p></span></pre>
<div>
<p class=3D"MsoNormal"><span style=3D"font-size:10.0pt;font-family:&quot;Ve=
rdana&quot;,sans-serif;background:white"><o:p>&nbsp;</o:p></span></p>
</div>
</div>
</div>
</body>
</html>

--_000_DM2PR21MB0091E96712B26FDD088E8A708CC40DM2PR21MB0091namp_--


From nobody Mon Jun 19 10:12:50 2017
Return-Path: <Jeff.Hodges@kingsmountain.com>
X-Original-To: unbearable@ietfa.amsl.com
Delivered-To: unbearable@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 674E01315BC for <unbearable@ietfa.amsl.com>; Mon, 19 Jun 2017 10:12:43 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -4.701
X-Spam-Level: 
X-Spam-Status: No, score=-4.701 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, RCVD_IN_DNSWL_NONE=-0.0001, RCVD_IN_MSPIKE_H2=-2.8, SPF_PASS=-0.001] autolearn=unavailable autolearn_force=no
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id e2TJBQHSA-yO for <unbearable@ietfa.amsl.com>; Mon, 19 Jun 2017 10:12:42 -0700 (PDT)
Received: from gproxy6.mail.unifiedlayer.com (gproxy6-pub.mail.unifiedlayer.com [67.222.39.168]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 39C881315E9 for <unbearable@ietf.org>; Mon, 19 Jun 2017 10:12:38 -0700 (PDT)
Received: from cmgw4 (unknown [10.0.90.85]) by gproxy6.mail.unifiedlayer.com (Postfix) with ESMTP id CB77E1E0772 for <unbearable@ietf.org>; Mon, 19 Jun 2017 11:12:37 -0600 (MDT)
Received: from box514.bluehost.com ([74.220.219.114]) by cmgw4 with  id ahCa1v0272UhLwi01hCdgl; Mon, 19 Jun 2017 11:12:37 -0600
X-Authority-Analysis: v=2.2 cv=QdwWhoTv c=1 sm=1 tr=0 a=9W6Fsu4pMcyimqnCr1W0/w==:117 a=9W6Fsu4pMcyimqnCr1W0/w==:17 a=IkcTkHD0fZMA:10 a=LWSFodeU3zMA:10 a=c33-g30VdtSQ20XL7wQA:9 a=QEXdDO2ut3YA:10
Received: from [173.224.162.69] (port=32975 helo=[10.225.80.213]) by box514.bluehost.com with esmtpsa (TLSv1.2:ECDHE-RSA-AES128-GCM-SHA256:128) (Exim 4.87) (envelope-from <Jeff.Hodges@KingsMountain.com>) id 1dN0E6-0000BZ-Ip; Mon, 19 Jun 2017 11:12:34 -0600
From: =JeffH <Jeff.Hodges@KingsMountain.com>
To: John Bradley <ve7jtb@ve7jtb.com>, IETF TokBind WG <unbearable@ietf.org>, TBPROTO authors <draft-ietf-tokbind-protocol@ietf.org>
Message-ID: <feb75975-3682-acfe-8bb5-daade1ed242f@KingsMountain.com>
Date: Mon, 19 Jun 2017 10:12:32 -0700
User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10.12; rv:52.0) Gecko/20100101 Thunderbird/52.2.0
MIME-Version: 1.0
Content-Type: text/plain; charset=utf-8; format=flowed
Content-Language: en-US
Content-Transfer-Encoding: 7bit
X-AntiAbuse: This header was added to track abuse, please include it with any abuse report
X-AntiAbuse: Primary Hostname - box514.bluehost.com
X-AntiAbuse: Original Domain - ietf.org
X-AntiAbuse: Originator/Caller UID/GID - [47 12] / [47 12]
X-AntiAbuse: Sender Address Domain - KingsMountain.com
X-BWhitelist: no
X-Source-IP: 173.224.162.69
X-Exim-ID: 1dN0E6-0000BZ-Ip
X-Source: 
X-Source-Args: 
X-Source-Dir: 
X-Source-Sender: ([10.225.80.213]) [173.224.162.69]:32975
X-Source-Auth: jeff.hodges+kingsmountain.com
X-Email-Count: 5
X-Source-Cap: a2luZ3Ntb3U7a2luZ3Ntb3U7Ym94NTE0LmJsdWVob3N0LmNvbQ==
Archived-At: <https://mailarchive.ietf.org/arch/msg/unbearable/DE1dvfbYVDv3gVmepXM9sOeAKhQ>
Subject: Re: [Unbearable] IPR for draft-ietf-tokbind-https
X-BeenThere: unbearable@ietf.org
X-Mailman-Version: 2.1.22
Precedence: list
List-Id: "\"This list is for discussion of proposals for doing better than bearer tokens \(e.g. HTTP cookies, OAuth tokens etc.\) for web applications. The specific goal is chartering a WG focused on preventing security token export and replay attacks.\"" <unbearable.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/unbearable>, <mailto:unbearable-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/unbearable/>
List-Post: <mailto:unbearable@ietf.org>
List-Help: <mailto:unbearable-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/unbearable>, <mailto:unbearable-request@ietf.org?subject=subscribe>
X-List-Received-Date: Mon, 19 Jun 2017 17:12:43 -0000

I am not aware of any IPR pertaining to HTTPSTB.

thx,

=JeffH


From nobody Mon Jun 19 10:14:34 2017
Return-Path: <Jeff.Hodges@kingsmountain.com>
X-Original-To: unbearable@ietfa.amsl.com
Delivered-To: unbearable@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id CDD9112948F for <unbearable@ietfa.amsl.com>; Mon, 19 Jun 2017 10:14:33 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -4.201
X-Spam-Level: 
X-Spam-Status: No, score=-4.201 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, RCVD_IN_DNSWL_NONE=-0.0001, RCVD_IN_MSPIKE_H2=-2.8, RCVD_IN_SORBS_SPAM=0.5, SPF_PASS=-0.001] autolearn=unavailable autolearn_force=no
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id tcKBoSTxEHen for <unbearable@ietfa.amsl.com>; Mon, 19 Jun 2017 10:14:33 -0700 (PDT)
Received: from gproxy7.mail.unifiedlayer.com (gproxy7-pub.mail.unifiedlayer.com [70.40.196.235]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 38BBB13160D for <unbearable@ietf.org>; Mon, 19 Jun 2017 10:13:59 -0700 (PDT)
Received: from cmgw4 (unknown [10.0.90.85]) by gproxy7.mail.unifiedlayer.com (Postfix) with ESMTP id 842BD21664B for <unbearable@ietf.org>; Mon, 19 Jun 2017 11:11:29 -0600 (MDT)
Received: from box514.bluehost.com ([74.220.219.114]) by cmgw4 with  id ahBR1v01K2UhLwi01hBU5g; Mon, 19 Jun 2017 11:11:29 -0600
X-Authority-Analysis: v=2.2 cv=QdwWhoTv c=1 sm=1 tr=0 a=9W6Fsu4pMcyimqnCr1W0/w==:117 a=9W6Fsu4pMcyimqnCr1W0/w==:17 a=IkcTkHD0fZMA:10 a=LWSFodeU3zMA:10 a=e0eV9bYtWDaurPkJTTcA:9 a=QEXdDO2ut3YA:10
Received: from [173.224.162.69] (port=31321 helo=[10.225.80.213]) by box514.bluehost.com with esmtpsa (TLSv1.2:ECDHE-RSA-AES128-GCM-SHA256:128) (Exim 4.87) (envelope-from <Jeff.Hodges@KingsMountain.com>) id 1dN0Cy-0007c2-7C; Mon, 19 Jun 2017 11:11:24 -0600
To: John Bradley <ve7jtb@ve7jtb.com>, IETF TokBind WG <unbearable@ietf.org>, TBPROTO authors <draft-ietf-tokbind-protocol@ietf.org>
From: =JeffH <Jeff.Hodges@KingsMountain.com>
Message-ID: <3bb3791d-706d-8a62-68c6-300950967dc1@KingsMountain.com>
Date: Mon, 19 Jun 2017 10:11:13 -0700
User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10.12; rv:52.0) Gecko/20100101 Thunderbird/52.2.0
MIME-Version: 1.0
Content-Type: text/plain; charset=utf-8; format=flowed
Content-Language: en-US
Content-Transfer-Encoding: 7bit
X-AntiAbuse: This header was added to track abuse, please include it with any abuse report
X-AntiAbuse: Primary Hostname - box514.bluehost.com
X-AntiAbuse: Original Domain - ietf.org
X-AntiAbuse: Originator/Caller UID/GID - [47 12] / [47 12]
X-AntiAbuse: Sender Address Domain - KingsMountain.com
X-BWhitelist: no
X-Source-IP: 173.224.162.69
X-Exim-ID: 1dN0Cy-0007c2-7C
X-Source: 
X-Source-Args: 
X-Source-Dir: 
X-Source-Sender: ([10.225.80.213]) [173.224.162.69]:31321
X-Source-Auth: jeff.hodges+kingsmountain.com
X-Email-Count: 2
X-Source-Cap: a2luZ3Ntb3U7a2luZ3Ntb3U7Ym94NTE0LmJsdWVob3N0LmNvbQ==
Archived-At: <https://mailarchive.ietf.org/arch/msg/unbearable/l6IyBK035xv02zoPQEdUIViYLXY>
Subject: Re: [Unbearable] IPR for draft-ietf-tokbind-protocol
X-BeenThere: unbearable@ietf.org
X-Mailman-Version: 2.1.22
Precedence: list
List-Id: "\"This list is for discussion of proposals for doing better than bearer tokens \(e.g. HTTP cookies, OAuth tokens etc.\) for web applications. The specific goal is chartering a WG focused on preventing security token export and replay attacks.\"" <unbearable.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/unbearable>, <mailto:unbearable-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/unbearable/>
List-Post: <mailto:unbearable@ietf.org>
List-Help: <mailto:unbearable-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/unbearable>, <mailto:unbearable-request@ietf.org?subject=subscribe>
X-List-Received-Date: Mon, 19 Jun 2017 17:14:34 -0000

I am not aware of any IPR pertaining to TBPROTO.

thx,

=JeffH


From nobody Mon Jun 19 13:43:55 2017
Return-Path: <mnystrom@microsoft.com>
X-Original-To: unbearable@ietfa.amsl.com
Delivered-To: unbearable@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id CD94C126C89; Mon, 19 Jun 2017 13:43:53 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2
X-Spam-Level: 
X-Spam-Status: No, score=-2 tagged_above=-999 required=5 tests=[BAYES_00=-1.9,  DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, HTML_MESSAGE=0.001, RCVD_IN_DNSWL_NONE=-0.0001, SPF_HELO_PASS=-0.001, SPF_PASS=-0.001, URIBL_BLOCKED=0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (1024-bit key) header.d=microsoft.com
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id AGZ9Hed7mhZC; Mon, 19 Jun 2017 13:43:51 -0700 (PDT)
Received: from NAM01-BN3-obe.outbound.protection.outlook.com (mail-bn3nam01on0121.outbound.protection.outlook.com [104.47.33.121]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 08E65126C22; Mon, 19 Jun 2017 13:43:51 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=microsoft.com; s=selector1; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version; bh=PFKS8EDUGVgX3SpDTlgRfjlvo9VpnbAmvbEWOhvdg48=; b=CB3Ds1nSvKuQwi65hSlKuDWH3oQvXXYkobuPwtwsyh80fVl85bhNTlIxzJzkwjsxasq3YXo8XmUOlE8t6J7fC7fNUJOTZhPqoG3wgQthUR7Wi5QUNy7Xi6e3QR6Hv888/7ITFsCHzqMHAKhLOzbnGsMq6QoUHGwKaw9bqJwKWMs=
Received: from MWHPR21MB0157.namprd21.prod.outlook.com (10.173.52.15) by MWHPR21MB0286.namprd21.prod.outlook.com (10.173.53.16) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_128_CBC_SHA256_P256) id 15.1.1178.10; Mon, 19 Jun 2017 20:43:36 +0000
Received: from MWHPR21MB0157.namprd21.prod.outlook.com ([10.173.52.15]) by MWHPR21MB0157.namprd21.prod.outlook.com ([10.173.52.15]) with mapi id 15.01.1199.007; Mon, 19 Jun 2017 20:43:47 +0000
From: =?iso-8859-1?Q?Magnus_Nystr=F6m?= <mnystrom@microsoft.com>
To: Andrei Popov <Andrei.Popov@microsoft.com>, John Bradley <ve7jtb@ve7jtb.com>, IETF TokBind WG <unbearable@ietf.org>
CC: "draft-ietf-tokbind-https@ietf.org" <draft-ietf-tokbind-https@ietf.org>
Thread-Topic: IPR for draft-ietf-tokbind-https
Thread-Index: AQHS6JtMZUtNhZ7MskSR7JdfGZkZGaIsZz+AgABBAnA=
Date: Mon, 19 Jun 2017 20:43:47 +0000
Message-ID: <MWHPR21MB0157DF0698615C71B17BD5ECCCC40@MWHPR21MB0157.namprd21.prod.outlook.com>
References: <634F056D-5B5F-4570-AE30-9F3F6F6AE3A5@ve7jtb.com> <DM2PR21MB0091E96712B26FDD088E8A708CC40@DM2PR21MB0091.namprd21.prod.outlook.com>
In-Reply-To: <DM2PR21MB0091E96712B26FDD088E8A708CC40@DM2PR21MB0091.namprd21.prod.outlook.com>
Accept-Language: en-US
Content-Language: en-US
X-MS-Has-Attach: 
X-MS-TNEF-Correlator: 
authentication-results: microsoft.com; dkim=none (message not signed) header.d=none;microsoft.com; dmarc=none action=none header.from=microsoft.com;
x-originating-ip: [64.134.97.105]
x-ms-publictraffictype: Email
x-microsoft-exchange-diagnostics: 1; MWHPR21MB0286; 7:5wz2n4np0qXp3XSvE3Z26ftcWnzPYSEB5BChoeaqoFatiw2P8p684DZ9Kqjm3fQRkOHitfLyt3ozROGORc5kjVFETkxe1hjk/bBkCBUSpUw3/+K1rR727CTIfK8DpIMmy2/EOwnYHjOjdPN+8VdPEmx/bA5aA5glMkS4mYjK9wDjoFXTv4b7lv0KtJ8tqi6wy3AQZLyV1813lksueI4CwUYpBIk1utRtANHvXmBTK6RR/DXhShdskNYYmizxKW2eBIdAkXlHPkcM3R84jdtypgkmTV8mQPwXTGvh4xm6eIGOcPa9Mqu7Yk9ltSI5m6zualORRvvfN6Y6E7sV71t7uTVt8hxRH9lmFhWSUHDVNCygU0lEKk6/aNU100LSXJJ/UCZxcWy1CAueszBPPf2H1ejEMmo9IURweZ6nQ4GwdEByo4xSXNq5xG1xLMx5C8b7mr/RFR5lTzT0vL2VSvpWftaOz6NIXHRhQnU2U7szYuOk8zrU9jb4kvcZUY9rN697+85GbvF1Ss9mNWjuFR6IHUOasAFhw4IyklaZsng8+d03fic5jt20KGvkIbKGFthrQGJ2S2tuibh3EQ9dNdpU7eU4y0iE4nB4zA8n1OAd0r2G94usrAQwHXa/V6vEhLy8rHRA3yiFTa1VZq2RaOKj988KOGwdn6EzAGpsR8YpfVCgJqbJTDH7EGpOkFjfXPKhlz94KmErl4RlfQzKxAjBHGEgKCcu5obywpWHPboz8z/s6dJeiFY65NvGiUqTCR6csq99lTEZNqUEXNIDvg2jdvl2bQikkejpDxw2Vy2Nd/sb7Y7H9ZWbqEAI57fJDhky
x-forefront-antispam-report: SFV:SKI; SCL:-1SFV:NSPM; SFS:(10019020)(39450400003)(39400400002)(39840400002)(39850400002)(39410400002)(39860400002)(377454003)(252514010)(9686003)(7736002)(5005710100001)(8990500004)(6306002)(54896002)(14454004)(230783001)(99286003)(55016002)(3660700001)(7906003)(189998001)(38730400002)(606005)(966005)(53936002)(10090500001)(2561002)(236005)(6506006)(66066001)(1511001)(6436002)(77096006)(790700001)(86362001)(86612001)(2950100002)(478600001)(81166006)(4326008)(8676002)(3846002)(19609705001)(25786009)(54356999)(50986999)(76176999)(5660300001)(122556002)(7696004)(102836003)(2906002)(33656002)(10290500003)(74316002)(8936002)(2900100001)(3280700002)(229853002); DIR:OUT; SFP:1102; SCL:1; SRVR:MWHPR21MB0286; H:MWHPR21MB0157.namprd21.prod.outlook.com; FPR:; SPF:None; MLV:sfv; LANG:en; 
x-ms-office365-filtering-correlation-id: a39dc139-1099-4d0b-7915-08d4b753e253
x-ms-office365-filtering-ht: Tenant
x-microsoft-antispam: UriScan:; BCL:0; PCL:0; RULEID:(300000500041)(300135000095)(300000501041)(300135300095)(22001)(300000502041)(300135100095)(2017030254075)(300000503041)(300135400095)(48565401081)(201703131423075)(201703031133081)(300000504041)(300135200095)(300000505041)(300135600095)(300000506037)(300135500095); SRVR:MWHPR21MB0286; 
x-ms-traffictypediagnostic: MWHPR21MB0286:
x-microsoft-antispam-prvs: <MWHPR21MB0286BD6143593344558395BDCCC40@MWHPR21MB0286.namprd21.prod.outlook.com>
x-exchange-antispam-report-test: UriScan:(252895345309445)(211936372134217)(21748063052155); 
x-exchange-antispam-report-cfa-test: BCL:0; PCL:0; RULEID:(100000700101)(100105000095)(100000701101)(100105300095)(100000702101)(100105100095)(61425038)(6040450)(601004)(2401047)(8121501046)(5005006)(93006095)(93001095)(100000703101)(100105400095)(10201501046)(3002001)(6055026)(61426038)(61427038)(6041248)(20161123564025)(20161123562025)(201703131423075)(201702281528075)(201703061421075)(201703061406153)(20161123560025)(20161123555025)(20161123558100)(6072148)(100000704101)(100105200095)(100000705101)(100105500095); SRVR:MWHPR21MB0286; BCL:0; PCL:0; RULEID:(100000800101)(100110000095)(100000801101)(100110300095)(100000802101)(100110100095)(100000803101)(100110400095)(100000804101)(100110200095)(100000805101)(100110500095); SRVR:MWHPR21MB0286; 
x-forefront-prvs: 0343AC1D30
spamdiagnosticoutput: 1:99
spamdiagnosticmetadata: NSPM
Content-Type: multipart/alternative; boundary="_000_MWHPR21MB0157DF0698615C71B17BD5ECCCC40MWHPR21MB0157namp_"
MIME-Version: 1.0
X-OriginatorOrg: microsoft.com
X-MS-Exchange-CrossTenant-originalarrivaltime: 19 Jun 2017 20:43:47.1184 (UTC)
X-MS-Exchange-CrossTenant-fromentityheader: Hosted
X-MS-Exchange-CrossTenant-id: 72f988bf-86f1-41af-91ab-2d7cd011db47
X-MS-Exchange-Transport-CrossTenantHeadersStamped: MWHPR21MB0286
Archived-At: <https://mailarchive.ietf.org/arch/msg/unbearable/3JmCYYUFW3GsQeQg09uVg8AyGGU>
Subject: Re: [Unbearable] IPR for draft-ietf-tokbind-https
X-BeenThere: unbearable@ietf.org
X-Mailman-Version: 2.1.22
Precedence: list
List-Id: "\"This list is for discussion of proposals for doing better than bearer tokens \(e.g. HTTP cookies, OAuth tokens etc.\) for web applications. The specific goal is chartering a WG focused on preventing security token export and replay attacks.\"" <unbearable.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/unbearable>, <mailto:unbearable-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/unbearable/>
List-Post: <mailto:unbearable@ietf.org>
List-Help: <mailto:unbearable-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/unbearable>, <mailto:unbearable-request@ietf.org?subject=subscribe>
X-List-Received-Date: Mon, 19 Jun 2017 20:43:54 -0000

--_000_MWHPR21MB0157DF0698615C71B17BD5ECCCC40MWHPR21MB0157namp_
Content-Type: text/plain; charset="iso-8859-1"
Content-Transfer-Encoding: quoted-printable

Same here

From: Andrei Popov [mailto:Andrei.Popov@microsoft.com]
Sent: Monday, June 19, 2017 12:51
To: John Bradley <ve7jtb@ve7jtb.com>; IETF TokBind WG <unbearable@ietf.org>
Cc: draft-ietf-tokbind-https@ietf.org
Subject: RE: IPR for draft-ietf-tokbind-https

I am not aware of any IPR pertaining to HTTPSTB.

Cheers,

Andrei


From: John Bradley [mailto:ve7jtb@ve7jtb.com]
Sent: Sunday, June 18, 2017 6:28 PM
To: IETF TokBind WG <unbearable@ietf.org<mailto:unbearable@ietf.org>>
Cc: draft-ietf-tokbind-https@ietf.org<mailto:draft-ietf-tokbind-https@ietf.=
org>
Subject: IPR for draft-ietf-tokbind-https


I am working on the shepherd writeup for the Token Binding over HTTP docume=
nt:
https://tools.ietf.org/html/draft-ietf-tokbind-https-09

One item in the template requires me to indicate whether each document
author has confirmed that any and all appropriate IPR disclosures
required for full conformance with the provisions of BCP 78 and BCP 79
have already been filed.

Could each of you please confirm?


   Magnus Nystroem

   Microsoft Corp.

   USA



   Email: mnystrom@microsoft.com<mailto:mnystrom@microsoft.com>





   Dirk Balfanz (editor)

   Google Inc.

   USA



   Email: balfanz@google.com<mailto:balfanz@google.com>





   Adam Langley

   Google Inc.

   USA



   Email: agl@google.com<mailto:agl@google.com>





   Jeff Hodges

   PayPal

   USA



   Email: Jeff.Hodges@paypal.com<mailto:Jeff.Hodges@paypal.com>


--_000_MWHPR21MB0157DF0698615C71B17BD5ECCCC40MWHPR21MB0157namp_
Content-Type: text/html; charset="iso-8859-1"
Content-Transfer-Encoding: quoted-printable

<html xmlns:v=3D"urn:schemas-microsoft-com:vml" xmlns:o=3D"urn:schemas-micr=
osoft-com:office:office" xmlns:w=3D"urn:schemas-microsoft-com:office:word" =
xmlns:m=3D"http://schemas.microsoft.com/office/2004/12/omml" xmlns=3D"http:=
//www.w3.org/TR/REC-html40">
<head>
<meta http-equiv=3D"Content-Type" content=3D"text/html; charset=3Diso-8859-=
1">
<meta name=3D"Generator" content=3D"Microsoft Word 15 (filtered medium)">
<style><!--
/* Font Definitions */
@font-face
	{font-family:"Cambria Math";
	panose-1:2 4 5 3 5 4 6 3 2 4;}
@font-face
	{font-family:Calibri;
	panose-1:2 15 5 2 2 2 4 3 2 4;}
@font-face
	{font-family:Consolas;
	panose-1:2 11 6 9 2 2 4 3 2 4;}
@font-face
	{font-family:Verdana;
	panose-1:2 11 6 4 3 5 4 4 2 4;}
/* Style Definitions */
p.MsoNormal, li.MsoNormal, div.MsoNormal
	{margin:0in;
	margin-bottom:.0001pt;
	font-size:11.0pt;
	font-family:"Calibri",sans-serif;}
a:link, span.MsoHyperlink
	{mso-style-priority:99;
	color:blue;
	text-decoration:underline;}
a:visited, span.MsoHyperlinkFollowed
	{mso-style-priority:99;
	color:purple;
	text-decoration:underline;}
pre
	{mso-style-priority:99;
	mso-style-link:"HTML Preformatted Char";
	margin:0in;
	margin-bottom:.0001pt;
	font-size:10.0pt;
	font-family:"Courier New";}
span.HTMLPreformattedChar
	{mso-style-name:"HTML Preformatted Char";
	mso-style-priority:99;
	mso-style-link:"HTML Preformatted";
	font-family:Consolas;}
p.msonormal0, li.msonormal0, div.msonormal0
	{mso-style-name:msonormal;
	mso-margin-top-alt:auto;
	margin-right:0in;
	mso-margin-bottom-alt:auto;
	margin-left:0in;
	font-size:11.0pt;
	font-family:"Calibri",sans-serif;}
span.EmailStyle20
	{mso-style-type:personal;
	font-family:"Calibri",sans-serif;
	color:windowtext;}
span.EmailStyle22
	{mso-style-type:personal-reply;
	font-family:"Calibri",sans-serif;
	color:windowtext;}
.MsoChpDefault
	{mso-style-type:export-only;
	font-size:10.0pt;}
@page WordSection1
	{size:8.5in 11.0in;
	margin:1.0in 1.0in 1.0in 1.0in;}
div.WordSection1
	{page:WordSection1;}
--></style><!--[if gte mso 9]><xml>
<o:shapedefaults v:ext=3D"edit" spidmax=3D"1026" />
</xml><![endif]--><!--[if gte mso 9]><xml>
<o:shapelayout v:ext=3D"edit">
<o:idmap v:ext=3D"edit" data=3D"1" />
</o:shapelayout></xml><![endif]-->
</head>
<body lang=3D"EN-US" link=3D"blue" vlink=3D"purple">
<div class=3D"WordSection1">
<p class=3D"MsoNormal">Same here<o:p></o:p></p>
<p class=3D"MsoNormal"><a name=3D"_MailEndCompose"><o:p>&nbsp;</o:p></a></p=
>
<span style=3D"mso-bookmark:_MailEndCompose"></span>
<div>
<div style=3D"border:none;border-top:solid #E1E1E1 1.0pt;padding:3.0pt 0in =
0in 0in">
<p class=3D"MsoNormal"><b>From:</b> Andrei Popov [mailto:Andrei.Popov@micro=
soft.com]
<br>
<b>Sent:</b> Monday, June 19, 2017 12:51<br>
<b>To:</b> John Bradley &lt;ve7jtb@ve7jtb.com&gt;; IETF TokBind WG &lt;unbe=
arable@ietf.org&gt;<br>
<b>Cc:</b> draft-ietf-tokbind-https@ietf.org<br>
<b>Subject:</b> RE: IPR for draft-ietf-tokbind-https<o:p></o:p></p>
</div>
</div>
<p class=3D"MsoNormal"><o:p>&nbsp;</o:p></p>
<p class=3D"MsoNormal">I am not aware of any IPR pertaining to HTTPSTB.<o:p=
></o:p></p>
<p class=3D"MsoNormal"><o:p>&nbsp;</o:p></p>
<p class=3D"MsoNormal">Cheers,<o:p></o:p></p>
<p class=3D"MsoNormal"><o:p>&nbsp;</o:p></p>
<p class=3D"MsoNormal">Andrei<o:p></o:p></p>
<p class=3D"MsoNormal"><o:p>&nbsp;</o:p></p>
<p class=3D"MsoNormal"><o:p>&nbsp;</o:p></p>
<div>
<div style=3D"border:none;border-top:solid #E1E1E1 1.0pt;padding:3.0pt 0in =
0in 0in">
<p class=3D"MsoNormal"><b>From:</b> John Bradley [<a href=3D"mailto:ve7jtb@=
ve7jtb.com">mailto:ve7jtb@ve7jtb.com</a>]
<br>
<b>Sent:</b> Sunday, June 18, 2017 6:28 PM<br>
<b>To:</b> IETF TokBind WG &lt;<a href=3D"mailto:unbearable@ietf.org">unbea=
rable@ietf.org</a>&gt;<br>
<b>Cc:</b> <a href=3D"mailto:draft-ietf-tokbind-https@ietf.org">draft-ietf-=
tokbind-https@ietf.org</a><br>
<b>Subject:</b> IPR for draft-ietf-tokbind-https<o:p></o:p></p>
</div>
</div>
<p class=3D"MsoNormal"><o:p>&nbsp;</o:p></p>
<p class=3D"MsoNormal" style=3D"margin-bottom:12.0pt"><span style=3D"font-s=
ize:10.0pt;font-family:&quot;Verdana&quot;,sans-serif;background:white"><o:=
p>&nbsp;</o:p></span></p>
<div>
<p class=3D"MsoNormal"><span style=3D"font-size:10.0pt;font-family:&quot;Ve=
rdana&quot;,sans-serif;background:white">I am working on the shepherd write=
up for the&nbsp;Token Binding over HTTP&nbsp;document:<br>
<a href=3D"https://tools.ietf.org/html/draft-ietf-tokbind-https-09">https:/=
/tools.ietf.org/html/draft-ietf-tokbind-https-09</a><br>
<br>
One item in the template requires me to indicate whether each document<br>
author has confirmed that any and all appropriate IPR disclosures<br>
required for full conformance with the provisions of BCP 78 and BCP 79<br>
have already been filed.<br>
<br>
Could each of you please confirm?<o:p></o:p></span></p>
</div>
<div>
<p class=3D"MsoNormal"><o:p>&nbsp;</o:p></p>
</div>
<div>
<pre style=3D"break-before: page;font-variant-ligatures: normal"><span styl=
e=3D"background:white">&nbsp;&nbsp; Magnus Nystroem<o:p></o:p></span></pre>
<pre><span style=3D"background:white">&nbsp;&nbsp; Microsoft Corp.<o:p></o:=
p></span></pre>
<pre><span style=3D"background:white">&nbsp;&nbsp; USA<o:p></o:p></span></p=
re>
<pre><span style=3D"background:white"><o:p>&nbsp;</o:p></span></pre>
<pre><span style=3D"background:white">&nbsp;&nbsp; Email: <a href=3D"mailto=
:mnystrom@microsoft.com">mnystrom@microsoft.com</a><o:p></o:p></span></pre>
<pre><span style=3D"background:white"><o:p>&nbsp;</o:p></span></pre>
<pre><span style=3D"background:white"><o:p>&nbsp;</o:p></span></pre>
<pre><span style=3D"background:white">&nbsp;&nbsp; Dirk Balfanz (editor)<o:=
p></o:p></span></pre>
<pre><span style=3D"background:white">&nbsp;&nbsp; Google Inc.<o:p></o:p></=
span></pre>
<pre><span style=3D"background:white">&nbsp;&nbsp; USA<o:p></o:p></span></p=
re>
<pre><span style=3D"background:white"><o:p>&nbsp;</o:p></span></pre>
<pre><span style=3D"background:white">&nbsp;&nbsp; Email: <a href=3D"mailto=
:balfanz@google.com">balfanz@google.com</a><o:p></o:p></span></pre>
<pre><span style=3D"background:white"><o:p>&nbsp;</o:p></span></pre>
<pre><span style=3D"background:white"><o:p>&nbsp;</o:p></span></pre>
<pre><span style=3D"background:white">&nbsp;&nbsp; Adam Langley<o:p></o:p><=
/span></pre>
<pre><span style=3D"background:white">&nbsp;&nbsp; Google Inc.<o:p></o:p></=
span></pre>
<pre><span style=3D"background:white">&nbsp;&nbsp; USA<o:p></o:p></span></p=
re>
<pre><span style=3D"background:white"><o:p>&nbsp;</o:p></span></pre>
<pre><span style=3D"background:white">&nbsp;&nbsp; Email: <a href=3D"mailto=
:agl@google.com">agl@google.com</a><o:p></o:p></span></pre>
<pre><span style=3D"background:white"><o:p>&nbsp;</o:p></span></pre>
<pre><span style=3D"background:white"><o:p>&nbsp;</o:p></span></pre>
<pre><span style=3D"background:white">&nbsp;&nbsp; Jeff Hodges<o:p></o:p></=
span></pre>
<pre><span style=3D"background:white"> &nbsp;&nbsp;PayPal<o:p></o:p></span>=
</pre>
<pre><span style=3D"background:white">&nbsp;&nbsp; USA<o:p></o:p></span></p=
re>
<pre><span style=3D"background:white"><o:p>&nbsp;</o:p></span></pre>
<pre><span style=3D"background:white">&nbsp;&nbsp; Email: <a href=3D"mailto=
:Jeff.Hodges@paypal.com">Jeff.Hodges@paypal.com</a><o:p></o:p></span></pre>
<div>
<p class=3D"MsoNormal"><span style=3D"font-size:10.0pt;font-family:&quot;Ve=
rdana&quot;,sans-serif;background:white"><o:p>&nbsp;</o:p></span></p>
</div>
</div>
</div>
</body>
</html>

--_000_MWHPR21MB0157DF0698615C71B17BD5ECCCC40MWHPR21MB0157namp_--


From nobody Mon Jun 19 13:44:58 2017
Return-Path: <mnystrom@microsoft.com>
X-Original-To: unbearable@ietfa.amsl.com
Delivered-To: unbearable@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 412B91294F0; Mon, 19 Jun 2017 13:44:55 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.02
X-Spam-Level: 
X-Spam-Status: No, score=-2.02 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, HTML_MESSAGE=0.001, RCVD_IN_DNSWL_NONE=-0.0001, RCVD_IN_MSPIKE_H4=-0.01, RCVD_IN_MSPIKE_WL=-0.01, SPF_HELO_PASS=-0.001, SPF_PASS=-0.001, URIBL_BLOCKED=0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (1024-bit key) header.d=microsoft.com
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id 0_SlJ-9tsE-A; Mon, 19 Jun 2017 13:44:52 -0700 (PDT)
Received: from NAM01-BN3-obe.outbound.protection.outlook.com (mail-bn3nam01on0128.outbound.protection.outlook.com [104.47.33.128]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id EE525129442; Mon, 19 Jun 2017 13:44:51 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=microsoft.com; s=selector1; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version; bh=JzBrrIZ6jMpXTh8Gju06SSgE6BF5jLIiI0d0hV0TWBg=; b=LCARaqT2GF1eLZtNj2OSTjy5xINVr0CzfBsFtYQow3lrVgkyYEi5ujB8BM0jTKh74SbbkTLobuWMHHSmPPBils69VHugaSPtvxd9t4NrnPDjQ0pEMmewqpwckcoR+GMeaHj/IIccqCQHvQHtJUPedjl0LnsCjPi2HT6A6VU8UGA=
Received: from MWHPR21MB0157.namprd21.prod.outlook.com (10.173.52.15) by MWHPR21MB0286.namprd21.prod.outlook.com (10.173.53.16) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_128_CBC_SHA256_P256) id 15.1.1178.10; Mon, 19 Jun 2017 20:44:06 +0000
Received: from MWHPR21MB0157.namprd21.prod.outlook.com ([10.173.52.15]) by MWHPR21MB0157.namprd21.prod.outlook.com ([10.173.52.15]) with mapi id 15.01.1199.007; Mon, 19 Jun 2017 20:44:17 +0000
From: =?iso-8859-1?Q?Magnus_Nystr=F6m?= <mnystrom@microsoft.com>
To: Andrei Popov <Andrei.Popov@microsoft.com>, John Bradley <ve7jtb@ve7jtb.com>, IETF TokBind WG <unbearable@ietf.org>
CC: "draft-ietf-tokbind-negotiation@ietf.org" <draft-ietf-tokbind-negotiation@ietf.org>
Thread-Topic: IPR for draft-ietf-tokbind-negotiation
Thread-Index: AQHS6JtKr2tD0mqiO0uSxShBm5r1haIsZxeAgABBTrA=
Date: Mon, 19 Jun 2017 20:44:17 +0000
Message-ID: <MWHPR21MB01576B6A2B85338989FE001FCCC40@MWHPR21MB0157.namprd21.prod.outlook.com>
References: <EE89D9AF-F52B-48ED-8046-F441A67818A4@ve7jtb.com> <DM2PR21MB0091485AB9D0EB25296C2CBB8CC40@DM2PR21MB0091.namprd21.prod.outlook.com>
In-Reply-To: <DM2PR21MB0091485AB9D0EB25296C2CBB8CC40@DM2PR21MB0091.namprd21.prod.outlook.com>
Accept-Language: en-US
Content-Language: en-US
X-MS-Has-Attach: 
X-MS-TNEF-Correlator: 
authentication-results: microsoft.com; dkim=none (message not signed) header.d=none;microsoft.com; dmarc=none action=none header.from=microsoft.com;
x-originating-ip: [64.134.97.105]
x-ms-publictraffictype: Email
x-microsoft-exchange-diagnostics: 1; MWHPR21MB0286; 7:Eg8Jr9YCFwVdz4BB+qrvYW45pUll0Yn/9PNwkk1fNdh3wsljoCmUuY8aRgTPgnWpwC20XOmEZOoTAgC2WlHvfE/Kg15v4LXkY1/X++KEW6i+jsF8OXO+c11B+D7/YQFGMe53jkLPkZNbAe8sYvIdrex83bA3P1SLII9ziKecW//UqYS0SaETk2RrfU1Vi8RP/Oq7t3SYWy2x8KZJF1hW6x3NzokQc1WloeMxum92OKls4kwIF5E6IdvTx9Q88stz+q+v7CuLu1aSxvIQ2vocD8d8pApP3+52VTCxf5n4cRn/37MnCwIfDXqXEpPxAQsxLG5icKE2HWOmFXPHKLsEmRnsnED0/OE3cFKU1LC4wqhW8+7gWdPSqzUiFWlYhcsASshxJ9qkW1rsPm+Jy7Xq7w69/T7hm0KyAZzITEvEpDbLmSCHuIvT4NWUWh+VX9CfVsRREO0ojoqJQFDswFsAnLC6NpFc0anWL8t/dqBkZcKZZRiStRa8pIySPphQ10S+1557y17kqqL7DR3/2o+YNHDMDygyb5SlLbeemiACgNhDTbe/8doT3xFx8E43EvVXtL30hZVk4GXE14rPsKd7Io9Mu4EUYXRw87UAsQOchWnc/ziseS3CF5YpRZAyY9oKgENZcS8qxXUCri43/H/fUGnMmI6ohx/ZiKKfIjoNcpweNraB+g0VoQz1Akzde9Tccyk0UBZN7RUUfNl6kYo9/ef3yJNgqMwSi2rAMocYwdXomznvd43wsUzQHwpt84am0oZAyzdouVJF90mS1jVScMFBtAvoLceOPTN5WOsuvMh0eq4CEKrKT6QaTj/a6dgq
x-forefront-antispam-report: SFV:SKI; SCL:-1SFV:NSPM; SFS:(10019020)(39450400003)(39400400002)(39840400002)(39850400002)(39410400002)(39860400002)(377454003)(252514010)(9686003)(7736002)(5005710100001)(8990500004)(6306002)(54896002)(14454004)(230783001)(99286003)(55016002)(3660700001)(7906003)(189998001)(38730400002)(606005)(966005)(53936002)(10090500001)(2561002)(236005)(6506006)(66066001)(1511001)(6436002)(77096006)(790700001)(86362001)(86612001)(2950100002)(478600001)(81166006)(4326008)(8676002)(3846002)(19609705001)(25786009)(54356999)(50986999)(76176999)(5660300001)(122556002)(7696004)(102836003)(2906002)(33656002)(10290500003)(74316002)(8936002)(2900100001)(3280700002)(229853002); DIR:OUT; SFP:1102; SCL:1; SRVR:MWHPR21MB0286; H:MWHPR21MB0157.namprd21.prod.outlook.com; FPR:; SPF:None; MLV:sfv; LANG:en; 
x-ms-office365-filtering-correlation-id: 6a5330f4-2f75-4110-755e-08d4b753f430
x-ms-office365-filtering-ht: Tenant
x-microsoft-antispam: UriScan:; BCL:0; PCL:0; RULEID:(300000500041)(300135000095)(300000501041)(300135300095)(22001)(300000502041)(300135100095)(2017030254075)(300000503041)(300135400095)(48565401081)(201703131423075)(201703031133081)(300000504041)(300135200095)(300000505041)(300135600095)(300000506037)(300135500095); SRVR:MWHPR21MB0286; 
x-ms-traffictypediagnostic: MWHPR21MB0286:
x-microsoft-antispam-prvs: <MWHPR21MB0286C847CD7646B94B124C21CCC40@MWHPR21MB0286.namprd21.prod.outlook.com>
x-exchange-antispam-report-test: UriScan:(192374486261705)(189930954265078)(211936372134217)(219752817060721)(21748063052155);
x-exchange-antispam-report-cfa-test: BCL:0; PCL:0; RULEID:(100000700101)(100105000095)(100000701101)(100105300095)(100000702101)(100105100095)(61425038)(6040450)(601004)(2401047)(8121501046)(5005006)(93006095)(93001095)(100000703101)(100105400095)(10201501046)(3002001)(6055026)(61426038)(61427038)(6041248)(20161123564025)(20161123562025)(201703131423075)(201702281528075)(201703061421075)(201703061406153)(20161123560025)(20161123555025)(20161123558100)(6072148)(100000704101)(100105200095)(100000705101)(100105500095); SRVR:MWHPR21MB0286; BCL:0; PCL:0; RULEID:(100000800101)(100110000095)(100000801101)(100110300095)(100000802101)(100110100095)(100000803101)(100110400095)(100000804101)(100110200095)(100000805101)(100110500095); SRVR:MWHPR21MB0286; 
x-forefront-prvs: 0343AC1D30
spamdiagnosticoutput: 1:99
spamdiagnosticmetadata: NSPM
Content-Type: multipart/alternative; boundary="_000_MWHPR21MB01576B6A2B85338989FE001FCCC40MWHPR21MB0157namp_"
MIME-Version: 1.0
X-OriginatorOrg: microsoft.com
X-MS-Exchange-CrossTenant-originalarrivaltime: 19 Jun 2017 20:44:17.1348 (UTC)
X-MS-Exchange-CrossTenant-fromentityheader: Hosted
X-MS-Exchange-CrossTenant-id: 72f988bf-86f1-41af-91ab-2d7cd011db47
X-MS-Exchange-Transport-CrossTenantHeadersStamped: MWHPR21MB0286
Archived-At: <https://mailarchive.ietf.org/arch/msg/unbearable/Gg0i1hTdnZ85Uu3MBNnCqwtwxoE>
Subject: Re: [Unbearable] IPR for draft-ietf-tokbind-negotiation
X-BeenThere: unbearable@ietf.org
X-Mailman-Version: 2.1.22
Precedence: list
List-Id: "\"This list is for discussion of proposals for doing better than bearer tokens \(e.g. HTTP cookies, OAuth tokens etc.\) for web applications. The specific goal is chartering a WG focused on preventing security token export and replay attacks.\"" <unbearable.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/unbearable>, <mailto:unbearable-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/unbearable/>
List-Post: <mailto:unbearable@ietf.org>
List-Help: <mailto:unbearable-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/unbearable>, <mailto:unbearable-request@ietf.org?subject=subscribe>
X-List-Received-Date: Mon, 19 Jun 2017 20:44:55 -0000

--_000_MWHPR21MB01576B6A2B85338989FE001FCCC40MWHPR21MB0157namp_
Content-Type: text/plain; charset="iso-8859-1"
Content-Transfer-Encoding: quoted-printable

Same here

From: Andrei Popov [mailto:Andrei.Popov@microsoft.com]
Sent: Monday, June 19, 2017 12:50
To: John Bradley <ve7jtb@ve7jtb.com>; IETF TokBind WG <unbearable@ietf.org>
Cc: draft-ietf-tokbind-negotiation@ietf.org
Subject: RE: IPR for draft-ietf-tokbind-negotiation

I am not aware of any IPR pertaining to TBNEGO.

Cheers,

Andrei

From: John Bradley [mailto:ve7jtb@ve7jtb.com]
Sent: Sunday, June 18, 2017 6:28 PM
To: IETF TokBind WG <unbearable@ietf.org<mailto:unbearable@ietf.org>>
Cc: draft-ietf-tokbind-negotiation@ietf.org<mailto:draft-ietf-tokbind-negot=
iation@ietf.org>
Subject: IPR for draft-ietf-tokbind-negotiation


I am working on the shepherd writeup for the Transport Layer Security (TLS)=
 Extension for Token Binding Protocol Negotiation document:
https://tools.ietf.org/html/draft-ietf-tokbind-negotiation-08<https://na01.=
safelinks.protection.outlook.com/?url=3Dhttps%3A%2F%2Ftools.ietf.org%2Fhtml=
%2Fdraft-ietf-tokbind-negotiation-08&data=3D02%7C01%7Cmnystrom%40microsoft.=
com%7Ca77c985a16c34bcf895f08d4b733c533%7C72f988bf86f141af91ab2d7cd011db47%7=
C1%7C0%7C636334880354237648&sdata=3DZH8edyU2pxueJ8UQQu6sCKv2BBLN9D42JqY980v=
C6kM%3D&reserved=3D0>

One item in the template requires me to indicate whether each document
author has confirmed that any and all appropriate IPR disclosures
required for full conformance with the provisions of BCP 78 and BCP 79
have already been filed.

Could each of you please confirm?

   Magnus Nystroem

   Microsoft Corp.

   USA



   Email: mnystrom@microsoft.com<mailto:mnystrom@microsoft.com>





   Dirk Balfanz

   Google Inc.

   USA



   Email: balfanz@google.com<mailto:balfanz@google.com>





   Adam Langley

   Google Inc.

   USA



   Email: agl@google.com<mailto:agl@google.com>







--_000_MWHPR21MB01576B6A2B85338989FE001FCCC40MWHPR21MB0157namp_
Content-Type: text/html; charset="iso-8859-1"
Content-Transfer-Encoding: quoted-printable

<html xmlns:v=3D"urn:schemas-microsoft-com:vml" xmlns:o=3D"urn:schemas-micr=
osoft-com:office:office" xmlns:w=3D"urn:schemas-microsoft-com:office:word" =
xmlns:m=3D"http://schemas.microsoft.com/office/2004/12/omml" xmlns=3D"http:=
//www.w3.org/TR/REC-html40">
<head>
<meta http-equiv=3D"Content-Type" content=3D"text/html; charset=3Diso-8859-=
1">
<meta name=3D"Generator" content=3D"Microsoft Word 15 (filtered medium)">
<style><!--
/* Font Definitions */
@font-face
	{font-family:"Cambria Math";
	panose-1:2 4 5 3 5 4 6 3 2 4;}
@font-face
	{font-family:Calibri;
	panose-1:2 15 5 2 2 2 4 3 2 4;}
@font-face
	{font-family:Consolas;
	panose-1:2 11 6 9 2 2 4 3 2 4;}
/* Style Definitions */
p.MsoNormal, li.MsoNormal, div.MsoNormal
	{margin:0in;
	margin-bottom:.0001pt;
	font-size:11.0pt;
	font-family:"Calibri",sans-serif;}
a:link, span.MsoHyperlink
	{mso-style-priority:99;
	color:blue;
	text-decoration:underline;}
a:visited, span.MsoHyperlinkFollowed
	{mso-style-priority:99;
	color:purple;
	text-decoration:underline;}
pre
	{mso-style-priority:99;
	mso-style-link:"HTML Preformatted Char";
	margin:0in;
	margin-bottom:.0001pt;
	font-size:10.0pt;
	font-family:"Courier New";}
span.HTMLPreformattedChar
	{mso-style-name:"HTML Preformatted Char";
	mso-style-priority:99;
	mso-style-link:"HTML Preformatted";
	font-family:Consolas;}
p.msonormal0, li.msonormal0, div.msonormal0
	{mso-style-name:msonormal;
	mso-margin-top-alt:auto;
	margin-right:0in;
	mso-margin-bottom-alt:auto;
	margin-left:0in;
	font-size:11.0pt;
	font-family:"Calibri",sans-serif;}
span.EmailStyle20
	{mso-style-type:personal;
	font-family:"Calibri",sans-serif;
	color:windowtext;}
span.EmailStyle22
	{mso-style-type:personal-reply;
	font-family:"Calibri",sans-serif;
	color:windowtext;}
.MsoChpDefault
	{mso-style-type:export-only;
	font-size:10.0pt;}
@page WordSection1
	{size:8.5in 11.0in;
	margin:1.0in 1.0in 1.0in 1.0in;}
div.WordSection1
	{page:WordSection1;}
--></style><!--[if gte mso 9]><xml>
<o:shapedefaults v:ext=3D"edit" spidmax=3D"1026" />
</xml><![endif]--><!--[if gte mso 9]><xml>
<o:shapelayout v:ext=3D"edit">
<o:idmap v:ext=3D"edit" data=3D"1" />
</o:shapelayout></xml><![endif]-->
</head>
<body lang=3D"EN-US" link=3D"blue" vlink=3D"purple">
<div class=3D"WordSection1">
<p class=3D"MsoNormal">Same here<o:p></o:p></p>
<p class=3D"MsoNormal"><a name=3D"_MailEndCompose"><o:p>&nbsp;</o:p></a></p=
>
<span style=3D"mso-bookmark:_MailEndCompose"></span>
<div>
<div style=3D"border:none;border-top:solid #E1E1E1 1.0pt;padding:3.0pt 0in =
0in 0in">
<p class=3D"MsoNormal"><b>From:</b> Andrei Popov [mailto:Andrei.Popov@micro=
soft.com]
<br>
<b>Sent:</b> Monday, June 19, 2017 12:50<br>
<b>To:</b> John Bradley &lt;ve7jtb@ve7jtb.com&gt;; IETF TokBind WG &lt;unbe=
arable@ietf.org&gt;<br>
<b>Cc:</b> draft-ietf-tokbind-negotiation@ietf.org<br>
<b>Subject:</b> RE: IPR for draft-ietf-tokbind-negotiation<o:p></o:p></p>
</div>
</div>
<p class=3D"MsoNormal"><o:p>&nbsp;</o:p></p>
<p class=3D"MsoNormal">I am not aware of any IPR pertaining to TBNEGO.<o:p>=
</o:p></p>
<p class=3D"MsoNormal"><o:p>&nbsp;</o:p></p>
<p class=3D"MsoNormal">Cheers,<o:p></o:p></p>
<p class=3D"MsoNormal"><o:p>&nbsp;</o:p></p>
<p class=3D"MsoNormal">Andrei<o:p></o:p></p>
<p class=3D"MsoNormal"><o:p>&nbsp;</o:p></p>
<div>
<div style=3D"border:none;border-top:solid #E1E1E1 1.0pt;padding:3.0pt 0in =
0in 0in">
<p class=3D"MsoNormal"><b>From:</b> John Bradley [<a href=3D"mailto:ve7jtb@=
ve7jtb.com">mailto:ve7jtb@ve7jtb.com</a>]
<br>
<b>Sent:</b> Sunday, June 18, 2017 6:28 PM<br>
<b>To:</b> IETF TokBind WG &lt;<a href=3D"mailto:unbearable@ietf.org">unbea=
rable@ietf.org</a>&gt;<br>
<b>Cc:</b> <a href=3D"mailto:draft-ietf-tokbind-negotiation@ietf.org">draft=
-ietf-tokbind-negotiation@ietf.org</a><br>
<b>Subject:</b> IPR for draft-ietf-tokbind-negotiation<o:p></o:p></p>
</div>
</div>
<p class=3D"MsoNormal"><o:p>&nbsp;</o:p></p>
<p class=3D"MsoNormal" style=3D"margin-bottom:12.0pt"><br>
I&nbsp;am working on the shepherd writeup for the&nbsp;Transport Layer Secu=
rity (TLS) Extension for Token Binding&nbsp;Protocol&nbsp;Negotiation&nbsp;=
document:<br>
<a href=3D"https://na01.safelinks.protection.outlook.com/?url=3Dhttps%3A%2F=
%2Ftools.ietf.org%2Fhtml%2Fdraft-ietf-tokbind-negotiation-08&amp;data=3D02%=
7C01%7Cmnystrom%40microsoft.com%7Ca77c985a16c34bcf895f08d4b733c533%7C72f988=
bf86f141af91ab2d7cd011db47%7C1%7C0%7C636334880354237648&amp;sdata=3DZH8edyU=
2pxueJ8UQQu6sCKv2BBLN9D42JqY980vC6kM%3D&amp;reserved=3D0">https://tools.iet=
f.org/html/draft-ietf-tokbind-negotiation-08</a><br>
<br>
One item in the template requires me to indicate whether each document<br>
author has confirmed that any and all appropriate IPR disclosures<br>
required for full conformance with the provisions of BCP 78 and BCP 79<br>
have already been filed.<br>
<br>
Could each of you please confirm?<o:p></o:p></p>
<div>
<pre style=3D"break-before: page;font-variant-ligatures: normal;orphans: 2;=
widows: 2">&nbsp;&nbsp; Magnus Nystroem<o:p></o:p></pre>
<pre>&nbsp;&nbsp; Microsoft Corp.<o:p></o:p></pre>
<pre>&nbsp;&nbsp; USA<o:p></o:p></pre>
<pre><o:p>&nbsp;</o:p></pre>
<pre>&nbsp;&nbsp; Email: <a href=3D"mailto:mnystrom@microsoft.com">mnystrom=
@microsoft.com</a><o:p></o:p></pre>
<pre><o:p>&nbsp;</o:p></pre>
<pre><o:p>&nbsp;</o:p></pre>
<pre>&nbsp;&nbsp; Dirk Balfanz<o:p></o:p></pre>
<pre>&nbsp;&nbsp; Google Inc.<o:p></o:p></pre>
<pre>&nbsp;&nbsp; USA<o:p></o:p></pre>
<pre><o:p>&nbsp;</o:p></pre>
<pre>&nbsp;&nbsp; Email: <a href=3D"mailto:balfanz@google.com">balfanz@goog=
le.com</a><o:p></o:p></pre>
<pre><o:p>&nbsp;</o:p></pre>
<pre><o:p>&nbsp;</o:p></pre>
<pre>&nbsp;&nbsp; Adam Langley<o:p></o:p></pre>
<pre>&nbsp;&nbsp; Google Inc.<o:p></o:p></pre>
<pre>&nbsp;&nbsp; USA<o:p></o:p></pre>
<pre><o:p>&nbsp;</o:p></pre>
<pre>&nbsp;&nbsp; Email: <a href=3D"mailto:agl@google.com">agl@google.com</=
a><o:p></o:p></pre>
<pre><o:p>&nbsp;</o:p></pre>
<pre><o:p>&nbsp;</o:p></pre>
<pre><o:p>&nbsp;</o:p></pre>
</div>
</div>
</body>
</html>

--_000_MWHPR21MB01576B6A2B85338989FE001FCCC40MWHPR21MB0157namp_--


From nobody Mon Jun 19 13:49:02 2017
Return-Path: <mnystrom@microsoft.com>
X-Original-To: unbearable@ietfa.amsl.com
Delivered-To: unbearable@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 0DA78127A91; Mon, 19 Jun 2017 13:49:01 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.021
X-Spam-Level: 
X-Spam-Status: No, score=-2.021 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, RCVD_IN_DNSWL_NONE=-0.0001, RCVD_IN_MSPIKE_H3=-0.01, RCVD_IN_MSPIKE_WL=-0.01, SPF_HELO_PASS=-0.001, SPF_PASS=-0.001, URIBL_BLOCKED=0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (1024-bit key) header.d=microsoft.com
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id qVJK3Jlbz3kN; Mon, 19 Jun 2017 13:48:59 -0700 (PDT)
Received: from NAM01-BN3-obe.outbound.protection.outlook.com (mail-bn3nam01on0119.outbound.protection.outlook.com [104.47.33.119]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 08162126C22; Mon, 19 Jun 2017 13:48:58 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=microsoft.com; s=selector1; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version; bh=+48v1/weC6+ASG4jBGTWlEFaX9DbVUeMlwUVuavxi6A=; b=gTQ/6PRaEjuIZLyxYB0kruGLDAsE8pABzJUN6OCB0YyMKSJKKD4ETuLHe1ukbA/AdR1fHKh58WyCnsxizgSY+y/LdxB8BMYY1vCbXf4ksBRZA9cG/Cn5K1BDFD9LiznbshRzUvDNMrnNjrczl4V4AzvgD8TnPFj1nn2Qrm5FUm0=
Received: from MWHPR21MB0157.namprd21.prod.outlook.com (10.173.52.15) by MWHPR21MB0286.namprd21.prod.outlook.com (10.173.53.16) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_128_CBC_SHA256_P256) id 15.1.1178.10; Mon, 19 Jun 2017 20:43:42 +0000
Received: from MWHPR21MB0157.namprd21.prod.outlook.com ([10.173.52.15]) by MWHPR21MB0157.namprd21.prod.outlook.com ([10.173.52.15]) with mapi id 15.01.1199.007; Mon, 19 Jun 2017 20:43:53 +0000
From: =?iso-8859-1?Q?Magnus_Nystr=F6m?= <mnystrom@microsoft.com>
To: Andrei Popov <Andrei.Popov@microsoft.com>, John Bradley <ve7jtb@ve7jtb.com>, IETF TokBind WG <unbearable@ietf.org>
CC: "draft-ietf-tokbind-protocol@ietf.org" <draft-ietf-tokbind-protocol@ietf.org>
Thread-Topic: IPR for draft-ietf-tokbind-protocol
Thread-Index: AQHS6JtMW8mgS7nA/UqR2RXoFx7lgqIsZy+AgABBGXA=
Date: Mon, 19 Jun 2017 20:43:52 +0000
Message-ID: <MWHPR21MB015706CAB2A39B3487140B5CCCC40@MWHPR21MB0157.namprd21.prod.outlook.com>
References: <C7D885CC-9B96-4AA4-9EA0-6087084000B3@ve7jtb.com> <DM2PR21MB0091680D1C3E2D3EBE2E29598CC40@DM2PR21MB0091.namprd21.prod.outlook.com>
In-Reply-To: <DM2PR21MB0091680D1C3E2D3EBE2E29598CC40@DM2PR21MB0091.namprd21.prod.outlook.com>
Accept-Language: en-US
Content-Language: en-US
X-MS-Has-Attach: 
X-MS-TNEF-Correlator: 
authentication-results: microsoft.com; dkim=none (message not signed) header.d=none;microsoft.com; dmarc=none action=none header.from=microsoft.com;
x-originating-ip: [64.134.97.105]
x-ms-publictraffictype: Email
x-microsoft-exchange-diagnostics: 1; MWHPR21MB0286; 7:4rMq3mfXHLYjVP8Vfu4J8dIn4FDlJpRkmqZb73rNBiqfOgWnMjkGTyCQhnE6KeLS1/ndJt8SsxydVVEozfgK9KhG2h8noEfnUfSJRv+fQXagnTU8fYhHRGx97pklfMyUE2zYGi52YC96P4Dxj1yLGQTwXPahyJOUC9XraTmYqMZdVLuKwm5HESnwwmf3sl5sn646ejmB33PMpWynS1jJZ10AkRC90J7FGVTsujU6c+0uLZevDshFbttdIdSSK+vuAMeSf8ScqF61ktELZ24WR7xMHqO2Ulg/qjtKf9+3SaAvMU/2mp9RnE6PedWbaJk9cLP/bW/uNQJks25F1WW6h5zU+Ndp5KvthEHX36Wm+LBTt5PeFnJlENYfL4DWMVyNCb2+8KFl50vM7TT72xjFqYpg9PMVpvsFJVeHVX4QrfwysLuSCxNrKnkIDNgfOwBkoXuWPpnnSo+ttn3nsppmRCYT52vbzwgZLUi67iJuvfYr8iB/wb3Ks2SJNEOjlirE5V8eAs2AYxsVp9L6kX3/OP0QPRU4ZpYe/fSAbDoWhYSGoH6FIHxzkj6lZYi5Axr799trlSxCvueF4JB8LSzJn9vdBiMHtLMFn0X6HeMf/q6jw5hrk+0E5GlI27uReKqjSjv3EL+tFM7Az8StBi+q+fEN5YAcWD2uqP4raLTQzGgrjCe35KxSwCIog1TvOC86YFdsRklFDagWMzwlE6RrdnbiyHnZx8c9WTF6TJvpWFFyJRZYxcFRZIl5z5ryjZB25Qf+Pj7BVtbTR4tzsuqkkrBkzoRxKkVHJSfQdbxZjLC4JEePTzCkXe5PPUDHSU7t
x-forefront-antispam-report: SFV:SKI; SCL:-1SFV:NSPM; SFS:(10019020)(6009001)(39450400003)(39400400002)(39840400002)(39850400002)(39410400002)(39860400002)(13464003)(377454003)(252514010)(9686003)(7736002)(5005710100001)(8990500004)(6306002)(14454004)(230783001)(99286003)(55016002)(3660700001)(189998001)(38730400002)(966005)(53936002)(10090500001)(2561002)(6506006)(66066001)(1511001)(6436002)(77096006)(86362001)(575784001)(86612001)(2950100002)(478600001)(81166006)(4326008)(8676002)(3846002)(25786009)(54356999)(50986999)(76176999)(305945005)(5660300001)(122556002)(7696004)(102836003)(2906002)(33656002)(10290500003)(74316002)(8936002)(2900100001)(3280700002)(229853002); DIR:OUT; SFP:1102; SCL:1; SRVR:MWHPR21MB0286; H:MWHPR21MB0157.namprd21.prod.outlook.com; FPR:; SPF:None; MLV:sfv; LANG:en; 
x-ms-office365-filtering-correlation-id: ca324cdf-ffb9-4ad7-f327-08d4b753e5d3
x-ms-office365-filtering-ht: Tenant
x-microsoft-antispam: UriScan:; BCL:0; PCL:0; RULEID:(300000500041)(300135000095)(300000501041)(300135300095)(22001)(300000502041)(300135100095)(2017030254075)(300000503041)(300135400095)(48565401081)(201703131423075)(201703031133081)(300000504041)(300135200095)(300000505041)(300135600095)(300000506037)(300135500095); SRVR:MWHPR21MB0286; 
x-ms-traffictypediagnostic: MWHPR21MB0286:
x-microsoft-antispam-prvs: <MWHPR21MB0286CD34AB1E5B1F20E0A900CCC40@MWHPR21MB0286.namprd21.prod.outlook.com>
x-exchange-antispam-report-test: UriScan:(252895345309445)(189930954265078)(211936372134217)(219752817060721); 
x-exchange-antispam-report-cfa-test: BCL:0; PCL:0; RULEID:(100000700101)(100105000095)(100000701101)(100105300095)(100000702101)(100105100095)(61425038)(6040450)(601004)(2401047)(8121501046)(5005006)(93006095)(93001095)(100000703101)(100105400095)(10201501046)(3002001)(6055026)(61426038)(61427038)(6041248)(20161123564025)(20161123562025)(201703131423075)(201702281528075)(201703061421075)(201703061406153)(20161123560025)(20161123555025)(20161123558100)(6072148)(100000704101)(100105200095)(100000705101)(100105500095); SRVR:MWHPR21MB0286; BCL:0; PCL:0; RULEID:(100000800101)(100110000095)(100000801101)(100110300095)(100000802101)(100110100095)(100000803101)(100110400095)(100000804101)(100110200095)(100000805101)(100110500095); SRVR:MWHPR21MB0286; 
x-forefront-prvs: 0343AC1D30
spamdiagnosticoutput: 1:99
spamdiagnosticmetadata: NSPM
Content-Type: text/plain; charset="iso-8859-1"
Content-Transfer-Encoding: quoted-printable
MIME-Version: 1.0
X-OriginatorOrg: microsoft.com
X-MS-Exchange-CrossTenant-originalarrivaltime: 19 Jun 2017 20:43:52.9467 (UTC)
X-MS-Exchange-CrossTenant-fromentityheader: Hosted
X-MS-Exchange-CrossTenant-id: 72f988bf-86f1-41af-91ab-2d7cd011db47
X-MS-Exchange-Transport-CrossTenantHeadersStamped: MWHPR21MB0286
Archived-At: <https://mailarchive.ietf.org/arch/msg/unbearable/xQ1R-WbUyjcJkTqncNVoSNkmch4>
Subject: Re: [Unbearable] IPR for draft-ietf-tokbind-protocol
X-BeenThere: unbearable@ietf.org
X-Mailman-Version: 2.1.22
Precedence: list
List-Id: "\"This list is for discussion of proposals for doing better than bearer tokens \(e.g. HTTP cookies, OAuth tokens etc.\) for web applications. The specific goal is chartering a WG focused on preventing security token export and replay attacks.\"" <unbearable.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/unbearable>, <mailto:unbearable-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/unbearable/>
List-Post: <mailto:unbearable@ietf.org>
List-Help: <mailto:unbearable-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/unbearable>, <mailto:unbearable-request@ietf.org?subject=subscribe>
X-List-Received-Date: Mon, 19 Jun 2017 20:49:01 -0000

Same here

-----Original Message-----
From: Andrei Popov [mailto:Andrei.Popov@microsoft.com]=20
Sent: Monday, June 19, 2017 12:51
To: John Bradley <ve7jtb@ve7jtb.com>; IETF TokBind WG <unbearable@ietf.org>
Cc: draft-ietf-tokbind-protocol@ietf.org
Subject: RE: IPR for draft-ietf-tokbind-protocol

I am not aware of any IPR pertaining to TBPROTO.

Cheers,

Andrei

-----Original Message-----
From: John Bradley [mailto:ve7jtb@ve7jtb.com]=20
Sent: Sunday, June 18, 2017 6:28 PM
To: IETF TokBind WG <unbearable@ietf.org>
Cc: draft-ietf-tokbind-protocol@ietf.org
Subject: IPR for draft-ietf-tokbind-protocol

I am working on the shepherd writeup for the The Token Binding Protocol Ver=
sion 1.0 document:
https://na01.safelinks.protection.outlook.com/?url=3Dhttps%3A%2F%2Ftools.ie=
tf.org%2Fhtml%2Fdraft-ietf-tokbind-protocol-14&data=3D02%7C01%7Cmnystrom%40=
microsoft.com%7Cc55b502a0ea442ea4e6608d4b733d08c%7C72f988bf86f141af91ab2d7c=
d011db47%7C1%7C0%7C636334880551440155&sdata=3DsCL0IhtMf7gzLuKciWUjmipHFBTXj=
nZ4LjSW%2B1fcdB0%3D&reserved=3D0

One item in the template requires me to indicate whether each document
author has confirmed that any and all appropriate IPR disclosures
required for full conformance with the provisions of BCP 78 and BCP 79
have already been filed.

Could each of you please confirm?

   Andrei Popov (editor)
   Microsoft Corp.
   USA

   Email: andreipo@microsoft.com


   Magnus Nystroem
   Microsoft Corp.
   USA

   Email: mnystrom@microsoft.com


   Dirk Balfanz
   Google Inc.
   USA

   Email: balfanz@google.com


   Adam Langley
   Google Inc.
   USA

   Email: agl@google.com


   Jeff Hodges
   PayPal
   USA

   Email: Jeff.Hodges@paypal.com





From nobody Mon Jun 19 15:22:44 2017
Return-Path: <agl@google.com>
X-Original-To: unbearable@ietfa.amsl.com
Delivered-To: unbearable@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id AE4971316E1 for <unbearable@ietfa.amsl.com>; Mon, 19 Jun 2017 15:22:42 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.701
X-Spam-Level: 
X-Spam-Status: No, score=-2.701 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, HTML_MESSAGE=0.001, RCVD_IN_DNSWL_LOW=-0.7, RP_MATCHES_RCVD=-0.001, SPF_PASS=-0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (2048-bit key) header.d=google.com
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id UE6TbxBqZSVk for <unbearable@ietfa.amsl.com>; Mon, 19 Jun 2017 15:22:41 -0700 (PDT)
Received: from mail-yw0-x22f.google.com (mail-yw0-x22f.google.com [IPv6:2607:f8b0:4002:c05::22f]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id DD412129329 for <unbearable@ietf.org>; Mon, 19 Jun 2017 15:22:40 -0700 (PDT)
Received: by mail-yw0-x22f.google.com with SMTP id e142so45918909ywa.1 for <unbearable@ietf.org>; Mon, 19 Jun 2017 15:22:40 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=20161025; h=mime-version:in-reply-to:references:from:date:message-id:subject:to :cc; bh=EUP6iIQ0v5a3+i0NqKGPeX2QEkKDrGIlmLZim9mY5fs=; b=eHPGhhkUTuKcm1hW7wlMiuyaQMV6wlqd1AgSM7VUmfgFHrxHFyr11rXv57VvYabnwa BiX/S8XXaTYto9B0E9LrPSgiCdmK3BU1sILmi2Ml91ICbMWLzEzL79TZagwR8SBcDacy pEIryOaPP0OYP++OxRGqg5crcUflcbcQtRfckdeSAH0AXgrcSRjQmkBQGsnlC/uG0QEB 64l+lqaymDJxfxC8KK7htkNH98vM/3IaJQIxwVB2kXhm3idzgTWOoJIPXmoAr+nVx/oC LRF0mKdWCFCBqTdjPEJsERtdCb4EcKShU6GaDDezwrp6LiPMdTg0ysnzFaeduULXEvzR IE2A==
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20161025; h=x-gm-message-state:mime-version:in-reply-to:references:from:date :message-id:subject:to:cc; bh=EUP6iIQ0v5a3+i0NqKGPeX2QEkKDrGIlmLZim9mY5fs=; b=lgoPPP7zoijuKJJnJxYq5QZKvK4vboEvjCWNS/8Y3PRXyfeOcGNV4D/BeKgz20nF8E lHLic8tXznT2zLIyGVQ1jMxmijKioEPcyb8eBpRvY/NJI45LZXEFmMYO9HAkH0XmaTeQ 0IfNDdQs0Z94NRqpWVaEdF+jnnGBr1fvjChNCk/QMvMIIGemPnp+ogSTc76SgBP3/SKC a8/lvNZrMuZLpbc1Tzk4SyPCgoyT0jPk0lJ6+R3XAIRn9/2fpmJurqF9F6p1OTVbTnLe hiicPSpBJzDpaBXvteR+8KxktzPfJunDWVSIXu3Q7QK5Sbj/L4sVj1NgfGgSQ+u4AX/e mVMg==
X-Gm-Message-State: AKS2vOwn25/jvBHd9Dhsl4UVro/fr6MuQIyMYu6CyfKa3V3znnYBdycv F1moXWA+k/kPSQCtnqMX/NytB0MOHU/B
X-Received: by 10.129.160.78 with SMTP id x75mr21295069ywg.98.1497910960024; Mon, 19 Jun 2017 15:22:40 -0700 (PDT)
MIME-Version: 1.0
Received: by 10.37.52.75 with HTTP; Mon, 19 Jun 2017 15:22:19 -0700 (PDT)
In-Reply-To: <DM2PR21MB0091680D1C3E2D3EBE2E29598CC40@DM2PR21MB0091.namprd21.prod.outlook.com>
References: <C7D885CC-9B96-4AA4-9EA0-6087084000B3@ve7jtb.com> <DM2PR21MB0091680D1C3E2D3EBE2E29598CC40@DM2PR21MB0091.namprd21.prod.outlook.com>
From: Adam Langley <agl@google.com>
Date: Mon, 19 Jun 2017 15:22:19 -0700
Message-ID: <CAL9PXLxHjAir5RuoZD3coZ5dTcAQESnk187u3ePjWuvj4s8pYg@mail.gmail.com>
To: Andrei Popov <Andrei.Popov@microsoft.com>
Cc: John Bradley <ve7jtb@ve7jtb.com>, IETF TokBind WG <unbearable@ietf.org>,  "draft-ietf-tokbind-protocol@ietf.org" <draft-ietf-tokbind-protocol@ietf.org>
Content-Type: multipart/alternative; boundary="94eb2c0879caadfdd50552579222"
Archived-At: <https://mailarchive.ietf.org/arch/msg/unbearable/9Hul7n-4POZubHtwP4xdeF43pBE>
Subject: Re: [Unbearable] IPR for draft-ietf-tokbind-protocol
X-BeenThere: unbearable@ietf.org
X-Mailman-Version: 2.1.22
Precedence: list
List-Id: "\"This list is for discussion of proposals for doing better than bearer tokens \(e.g. HTTP cookies, OAuth tokens etc.\) for web applications. The specific goal is chartering a WG focused on preventing security token export and replay attacks.\"" <unbearable.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/unbearable>, <mailto:unbearable-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/unbearable/>
List-Post: <mailto:unbearable@ietf.org>
List-Help: <mailto:unbearable-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/unbearable>, <mailto:unbearable-request@ietf.org?subject=subscribe>
X-List-Received-Date: Mon, 19 Jun 2017 22:22:42 -0000

--94eb2c0879caadfdd50552579222
Content-Type: text/plain; charset="UTF-8"

I am not aware of any IPR pertaining to TBPROTO.


Cheers

AGL

--94eb2c0879caadfdd50552579222
Content-Type: text/html; charset="UTF-8"
Content-Transfer-Encoding: quoted-printable

<div dir=3D"ltr"><span style=3D"font-size:12.8px">I am not aware of any IPR=
 pertaining to TBPROTO.</span><br><div class=3D"gmail_extra"><br></div><div=
 class=3D"gmail_extra"><br></div><div class=3D"gmail_extra">Cheers</div><di=
v class=3D"gmail_extra"><br></div><div class=3D"gmail_extra">AGL</div></div=
>

--94eb2c0879caadfdd50552579222--


From nobody Mon Jun 19 15:23:03 2017
Return-Path: <agl@google.com>
X-Original-To: unbearable@ietfa.amsl.com
Delivered-To: unbearable@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 7985C129329 for <unbearable@ietfa.amsl.com>; Mon, 19 Jun 2017 15:23:01 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.001
X-Spam-Level: 
X-Spam-Status: No, score=-2.001 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, HTML_MESSAGE=0.001, RCVD_IN_DNSWL_NONE=-0.0001, RP_MATCHES_RCVD=-0.001, SPF_PASS=-0.001] autolearn=unavailable autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (2048-bit key) header.d=google.com
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id ICpfYO-67bd2 for <unbearable@ietfa.amsl.com>; Mon, 19 Jun 2017 15:22:59 -0700 (PDT)
Received: from mail-yb0-x22f.google.com (mail-yb0-x22f.google.com [IPv6:2607:f8b0:4002:c09::22f]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 77CF6131823 for <unbearable@ietf.org>; Mon, 19 Jun 2017 15:22:57 -0700 (PDT)
Received: by mail-yb0-x22f.google.com with SMTP id t7so32125490yba.3 for <unbearable@ietf.org>; Mon, 19 Jun 2017 15:22:57 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=20161025; h=mime-version:in-reply-to:references:from:date:message-id:subject:to :cc; bh=AVdiHixRpSrvey4M7cUY/nQazrP2Vg0fcLgApB/VxYU=; b=aTuIZTGAiEJ064oNqkiFxGaBDK14NBpoHNqBUMgs0Am9b7whfE4f/J4Qbxv2wAn0X4 neZ+QCMrv0HtqoggpQMTQ5CDJPmlqonLqucTGRjtPbRlUi8D5u4b+LHVzBfRgrp6eKoz /8yO6+rONHsqiMHB3V0XW3VV2Bofq7EnWlT04b+QHuhsR95t6htCTCfJwdDn4uSNPxvi VM6Hcpu9Wyj3fNkN5/NU3UUqGNE9+/cdEkU5Q1AcrPLbnfvAwgD8RisgrWsxpBPhj/cY SfkOCqLsX00r/1QLd3r6QRkEG1zIZDS1Gt2hysoySBKgLCqzTpNHnxBfvU46L/yh1pb7 5lxg==
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20161025; h=x-gm-message-state:mime-version:in-reply-to:references:from:date :message-id:subject:to:cc; bh=AVdiHixRpSrvey4M7cUY/nQazrP2Vg0fcLgApB/VxYU=; b=jRBu+mQ09GCcFO9Oxra9qnpZxz9CmQuWO9mw0POxsFO/nLF/l86/4qRFYrrXVtkRTO YUvks1ntrPj5wqW2FN18bBmKl0vOGzRI9N25pP7NeWFUK9gxCTev4tv5yqtnDRgtgSiG tNynYXSM83RcFcEaZz7uuo6G9w+vgGY5u/N5Z1Jy74BT/rHLBtVp8oYi74Mfk5z3CZsH BiA7KPZr0aCi3veZLPyF83L2CVHrQc5ICauwC4lkNvZxKyY34UTBaLBQcc/X9l84ZEzD qq4cWJ2Scl9ox1L2rxvh6S8CRT3zPPumgt7D6tVMgqf5wvWT+jnIcQad/YvVUIWtXRMw ku7w==
X-Gm-Message-State: AKS2vOxCTitZ0CrnW7cWhG6yJxtoikTEO8FKSUHwNDyju31OlSkXAfPj 7ut/0xeUp9BxiuXw2fT7n0eZfszR99VU
X-Received: by 10.37.7.2 with SMTP id 2mr20267538ybh.126.1497910976571; Mon, 19 Jun 2017 15:22:56 -0700 (PDT)
MIME-Version: 1.0
Received: by 10.37.52.75 with HTTP; Mon, 19 Jun 2017 15:22:35 -0700 (PDT)
In-Reply-To: <DM2PR21MB0091485AB9D0EB25296C2CBB8CC40@DM2PR21MB0091.namprd21.prod.outlook.com>
References: <EE89D9AF-F52B-48ED-8046-F441A67818A4@ve7jtb.com> <DM2PR21MB0091485AB9D0EB25296C2CBB8CC40@DM2PR21MB0091.namprd21.prod.outlook.com>
From: Adam Langley <agl@google.com>
Date: Mon, 19 Jun 2017 15:22:35 -0700
Message-ID: <CAL9PXLynTnKX5GWi77Xjh5rF7W+2n7aR1GUq-a2LY4Cp7ZNnZQ@mail.gmail.com>
To: Andrei Popov <Andrei.Popov@microsoft.com>
Cc: John Bradley <ve7jtb@ve7jtb.com>, IETF TokBind WG <unbearable@ietf.org>,  "draft-ietf-tokbind-negotiation@ietf.org" <draft-ietf-tokbind-negotiation@ietf.org>
Content-Type: multipart/alternative; boundary="001a114ff5d6aa69730552579343"
Archived-At: <https://mailarchive.ietf.org/arch/msg/unbearable/iCQdNsZaT3Z2cLSY_eQsSjaiJD4>
Subject: Re: [Unbearable] IPR for draft-ietf-tokbind-negotiation
X-BeenThere: unbearable@ietf.org
X-Mailman-Version: 2.1.22
Precedence: list
List-Id: "\"This list is for discussion of proposals for doing better than bearer tokens \(e.g. HTTP cookies, OAuth tokens etc.\) for web applications. The specific goal is chartering a WG focused on preventing security token export and replay attacks.\"" <unbearable.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/unbearable>, <mailto:unbearable-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/unbearable/>
List-Post: <mailto:unbearable@ietf.org>
List-Help: <mailto:unbearable-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/unbearable>, <mailto:unbearable-request@ietf.org?subject=subscribe>
X-List-Received-Date: Mon, 19 Jun 2017 22:23:01 -0000

--001a114ff5d6aa69730552579343
Content-Type: text/plain; charset="UTF-8"

I am not aware of any IPR pertaining to TBNEGO.


Cheers

AGL

--001a114ff5d6aa69730552579343
Content-Type: text/html; charset="UTF-8"
Content-Transfer-Encoding: quoted-printable

<div dir=3D"ltr"><span style=3D"font-size:12.8px">I am not aware of any IPR=
 pertaining to TBNEGO.</span><br><div class=3D"gmail_extra"><br></div><div =
class=3D"gmail_extra"><br></div><div class=3D"gmail_extra">Cheers</div><div=
 class=3D"gmail_extra"><br></div><div class=3D"gmail_extra">AGL</div></div>

--001a114ff5d6aa69730552579343--


From nobody Mon Jun 19 15:23:17 2017
Return-Path: <agl@google.com>
X-Original-To: unbearable@ietfa.amsl.com
Delivered-To: unbearable@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 46E19131848 for <unbearable@ietfa.amsl.com>; Mon, 19 Jun 2017 15:23:15 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.001
X-Spam-Level: 
X-Spam-Status: No, score=-2.001 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, HTML_MESSAGE=0.001, RP_MATCHES_RCVD=-0.001, SPF_PASS=-0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (2048-bit key) header.d=google.com
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id DUfvJMa1UukJ for <unbearable@ietfa.amsl.com>; Mon, 19 Jun 2017 15:23:13 -0700 (PDT)
Received: from mail-yw0-x229.google.com (mail-yw0-x229.google.com [IPv6:2607:f8b0:4002:c05::229]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id BE0D61315DC for <unbearable@ietf.org>; Mon, 19 Jun 2017 15:23:13 -0700 (PDT)
Received: by mail-yw0-x229.google.com with SMTP id l75so45884755ywc.3 for <unbearable@ietf.org>; Mon, 19 Jun 2017 15:23:13 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=20161025; h=mime-version:in-reply-to:references:from:date:message-id:subject:to :cc; bh=udcgi3Y7F8Zbm9VGOtvYPRJADosxfaPoKTiZivTjBVQ=; b=LYNnjIzkBJgxfPNsOBFgmCC4Yvnnbs4ynHgYel9G9/1H+2JUn2zzayfM/NlDnshHss cvTUGm1YClpqafLCYIe54wbr2dESzFi7aa9jp9/e9Sev29YsJKMNlSRqPMuiL8Kbyl4R Ur8PDNtkRnHtY2/cywq5EpR0ksDXvy+m4LZ5MPhsbdPXoeaG8eW9xB9PoidSvboDiGCA Kkh33oDYzz19rZBVPlg7npc68LC6oYUhvx5jF10c45AJuOjAZvO56rTid3+ftJGy2wIo z/trsTK2BNvMSymwCzNpyf87E+rStOLrRGaNlpzqAj6yhE7+KsXifdDKhXGNjPKfjT3V 1Zag==
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20161025; h=x-gm-message-state:mime-version:in-reply-to:references:from:date :message-id:subject:to:cc; bh=udcgi3Y7F8Zbm9VGOtvYPRJADosxfaPoKTiZivTjBVQ=; b=bWEcXi2xZj5jJRC0FAguRV/CyghcpahKxTRz+KkehHOu5pa2xi4bXPlD6O030WTd9L 2q2B7MhdMWYbX8kHwphJ4IAKZpm18Va5cAJBkX4NyFp2U1AQThsY1xpAlvWFvQO1SNT/ W1rIoDzhc+ncRsA4ktclQNpecr8QYVBbnzYJMzKJS521NbmbGofbPz5FgBUoiURj6CRU dlGxkgMi8HCmKIG9auC+RCXTp73kewRdWX1lIX5wH+RCXmQ2mmAL9+7Ik4sLaTmhRTcf NTa1kNY6IIDewiMBaTi/SgAW8+WFLgE+zwRimHoKRRPx9BbK/Q75EjZihqeBkkl1vwpJ LibQ==
X-Gm-Message-State: AKS2vOx8lIzRsRrVCRWVpjF2PyymR1DFxAHRCpsNPCjdN+TzVz528Z8f e6hWPz5h89ReJ6cMB/q+IAg2A+wpey6C
X-Received: by 10.129.72.75 with SMTP id v72mr20522336ywa.160.1497910992904; Mon, 19 Jun 2017 15:23:12 -0700 (PDT)
MIME-Version: 1.0
Received: by 10.37.52.75 with HTTP; Mon, 19 Jun 2017 15:22:52 -0700 (PDT)
In-Reply-To: <DM2PR21MB0091E96712B26FDD088E8A708CC40@DM2PR21MB0091.namprd21.prod.outlook.com>
References: <634F056D-5B5F-4570-AE30-9F3F6F6AE3A5@ve7jtb.com> <DM2PR21MB0091E96712B26FDD088E8A708CC40@DM2PR21MB0091.namprd21.prod.outlook.com>
From: Adam Langley <agl@google.com>
Date: Mon, 19 Jun 2017 15:22:52 -0700
Message-ID: <CAL9PXLzJ6KeC-99zp2egJ=kCdYZOb8ToTRinOVLL9Azdw-Cxhg@mail.gmail.com>
To: Andrei Popov <Andrei.Popov@microsoft.com>
Cc: John Bradley <ve7jtb@ve7jtb.com>, IETF TokBind WG <unbearable@ietf.org>,  "draft-ietf-tokbind-https@ietf.org" <draft-ietf-tokbind-https@ietf.org>
Content-Type: multipart/alternative; boundary="001a114dcd76a3f87e0552579456"
Archived-At: <https://mailarchive.ietf.org/arch/msg/unbearable/kSKP5wUvL7VyxRO5u9hmRf8WYw8>
Subject: Re: [Unbearable] IPR for draft-ietf-tokbind-https
X-BeenThere: unbearable@ietf.org
X-Mailman-Version: 2.1.22
Precedence: list
List-Id: "\"This list is for discussion of proposals for doing better than bearer tokens \(e.g. HTTP cookies, OAuth tokens etc.\) for web applications. The specific goal is chartering a WG focused on preventing security token export and replay attacks.\"" <unbearable.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/unbearable>, <mailto:unbearable-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/unbearable/>
List-Post: <mailto:unbearable@ietf.org>
List-Help: <mailto:unbearable-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/unbearable>, <mailto:unbearable-request@ietf.org?subject=subscribe>
X-List-Received-Date: Mon, 19 Jun 2017 22:23:15 -0000

--001a114dcd76a3f87e0552579456
Content-Type: text/plain; charset="UTF-8"

I am not aware of any IPR pertaining to HTTPSTB.


Cheers

AGL

--001a114dcd76a3f87e0552579456
Content-Type: text/html; charset="UTF-8"
Content-Transfer-Encoding: quoted-printable

<div dir=3D"ltr"><span style=3D"font-size:12.8px">I am not aware of any IPR=
 pertaining to HTTPSTB.</span><br><div><span style=3D"font-size:12.8px"><br=
></span></div><div><span style=3D"font-size:12.8px"><br></span></div><div><=
span style=3D"font-size:12.8px">Cheers</span></div><div><span style=3D"font=
-size:12.8px"><br></span></div><div><span style=3D"font-size:12.8px">AGL</s=
pan></div></div>

--001a114dcd76a3f87e0552579456--


From nobody Tue Jun 20 22:23:43 2017
Return-Path: <balfanz@google.com>
X-Original-To: unbearable@ietfa.amsl.com
Delivered-To: unbearable@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id D8ED8127058 for <unbearable@ietfa.amsl.com>; Tue, 20 Jun 2017 22:23:41 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2
X-Spam-Level: 
X-Spam-Status: No, score=-2 tagged_above=-999 required=5 tests=[BAYES_00=-1.9,  DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, HTML_MESSAGE=0.001, RCVD_IN_DNSWL_NONE=-0.0001, RP_MATCHES_RCVD=-0.001, SPF_PASS=-0.001, URIBL_BLOCKED=0.001] autolearn=unavailable autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (2048-bit key) header.d=google.com
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id C4SUrfB8yI8X for <unbearable@ietfa.amsl.com>; Tue, 20 Jun 2017 22:23:39 -0700 (PDT)
Received: from mail-wr0-x230.google.com (mail-wr0-x230.google.com [IPv6:2a00:1450:400c:c0c::230]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 62A53126CC7 for <unbearable@ietf.org>; Tue, 20 Jun 2017 22:23:39 -0700 (PDT)
Received: by mail-wr0-x230.google.com with SMTP id y25so79175031wrd.2 for <unbearable@ietf.org>; Tue, 20 Jun 2017 22:23:39 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=20161025; h=mime-version:references:in-reply-to:from:date:message-id:subject:to :cc; bh=/960LtqPjdB6eozvlvmw9HEswOXCSoFHfOO3QyEUnVc=; b=I6qDXHCiXsTW0+4C1e/VEyUJSnMSjiJvrcf1totOaC1cb9HY3iKGld584hTckxk9iM TnqWtja0veqEBwWRD5A5i1sbc2oUzkuobbuztdpbhdCMVSZzOAZrGHrKRkWn4OtcoDm0 C4CyZIrNtW8G1vYho6ruvu1LAUlCyRtXUpra2BABDOUys6+eFRm/ku/Er+D69G9OQHvv 5cYSdy3ZO3OF4whyj+olbbmtCBqFgb6OBTF386dUzvGfKBmTiszWLTJuN827DquEWLk/ rxaFpR1xWCo+XcKYwrphft8QU8uEoNSW8m4OK5ApbhL1roiVY0Vl51fXP9w+1Uf26XOL Msyg==
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20161025; h=x-gm-message-state:mime-version:references:in-reply-to:from:date :message-id:subject:to:cc; bh=/960LtqPjdB6eozvlvmw9HEswOXCSoFHfOO3QyEUnVc=; b=eJM7wfASWZ0eFVDjhMsLkZ2Xplfjbtq8gNWoOUiXnPTrXdTeMVZjRPgIyBgvcmJsbE zZ4y2CoKpEpshAlRG/SeQeaJRb91rdVlZlAyDe+psc9aZZdLC+r75yn5/Wog2poYzFag aq8bL1lhkfBRXVAjrWfgOUNXigLNl0Ffv3LM2dMktfA8PuSkJWVI1L5kfX83bFf0ZwA6 X3BmjmN1vhFcYo8XH8rwRtElxhgxOTPqmGutOAsYfcVH3GlIEvQ3poZzM2hEe8q6VQu9 UDFWNLd3nT/hWMEOGFNtuayNxquGKrX++KYK1ES0sb0CafuDfl7V4nopm9pUGkxmOhUM fAiw==
X-Gm-Message-State: AKS2vOzQij2lu3x6w1qiJTIwdAgRslY6Ngi3Nz/HDcdY1ubpxM5PfhOF CUCoxlecyAq3gPAq3B21oQUN2BlxiO/O
X-Received: by 10.223.171.3 with SMTP id q3mr3551987wrc.12.1498022617580; Tue, 20 Jun 2017 22:23:37 -0700 (PDT)
MIME-Version: 1.0
References: <EE89D9AF-F52B-48ED-8046-F441A67818A4@ve7jtb.com> <DM2PR21MB0091485AB9D0EB25296C2CBB8CC40@DM2PR21MB0091.namprd21.prod.outlook.com>
In-Reply-To: <DM2PR21MB0091485AB9D0EB25296C2CBB8CC40@DM2PR21MB0091.namprd21.prod.outlook.com>
From: Dirk Balfanz <balfanz@google.com>
Date: Wed, 21 Jun 2017 05:23:25 +0000
Message-ID: <CADHfa2D9Y+D4Zcq-VVHefJP750fW0GwpHVmiz4uCL6_iUMPLuA@mail.gmail.com>
To: Andrei Popov <Andrei.Popov@microsoft.com>, IETF TokBind WG <unbearable@ietf.org>, John Bradley <ve7jtb@ve7jtb.com>
Cc: "draft-ietf-tokbind-negotiation@ietf.org" <draft-ietf-tokbind-negotiation@ietf.org>
Content-Type: multipart/alternative; boundary="94eb2c1b440afd1e0805527191fd"
Archived-At: <https://mailarchive.ietf.org/arch/msg/unbearable/Pxnj-Oo39hoaufrgMuuT-8Ulh98>
Subject: Re: [Unbearable] IPR for draft-ietf-tokbind-negotiation
X-BeenThere: unbearable@ietf.org
X-Mailman-Version: 2.1.22
Precedence: list
List-Id: "\"This list is for discussion of proposals for doing better than bearer tokens \(e.g. HTTP cookies, OAuth tokens etc.\) for web applications. The specific goal is chartering a WG focused on preventing security token export and replay attacks.\"" <unbearable.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/unbearable>, <mailto:unbearable-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/unbearable/>
List-Post: <mailto:unbearable@ietf.org>
List-Help: <mailto:unbearable-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/unbearable>, <mailto:unbearable-request@ietf.org?subject=subscribe>
X-List-Received-Date: Wed, 21 Jun 2017 05:23:42 -0000

--94eb2c1b440afd1e0805527191fd
Content-Type: text/plain; charset="UTF-8"

I am not aware of any IPR pertaining to TBNEGO.

Dirk.

On Mon, Jun 19, 2017 at 6:53 PM Andrei Popov <Andrei.Popov@microsoft.com>
wrote:

> I am not aware of any IPR pertaining to TBNEGO.
>
>
>
> Cheers,
>
>
>
> Andrei
>
>
>
> *From:* John Bradley [mailto:ve7jtb@ve7jtb.com]
> *Sent:* Sunday, June 18, 2017 6:28 PM
> *To:* IETF TokBind WG <unbearable@ietf.org>
> *Cc:* draft-ietf-tokbind-negotiation@ietf.org
> *Subject:* IPR for draft-ietf-tokbind-negotiation
>
>
>
>
> I am working on the shepherd writeup for the Transport Layer Security
> (TLS) Extension for Token Binding Protocol Negotiation document:
> https://tools.ietf.org/html/draft-ietf-tokbind-negotiation-08
>
> One item in the template requires me to indicate whether each document
> author has confirmed that any and all appropriate IPR disclosures
> required for full conformance with the provisions of BCP 78 and BCP 79
> have already been filed.
>
> Could each of you please confirm?
>
>    Magnus Nystroem
>
>    Microsoft Corp.
>
>    USA
>
>
>
>    Email: mnystrom@microsoft.com
>
>
>
>
>
>    Dirk Balfanz
>
>    Google Inc.
>
>    USA
>
>
>
>    Email: balfanz@google.com
>
>
>
>
>
>    Adam Langley
>
>    Google Inc.
>
>    USA
>
>
>
>    Email: agl@google.com
>
>
>
>
>
>
>
>

--94eb2c1b440afd1e0805527191fd
Content-Type: text/html; charset="UTF-8"
Content-Transfer-Encoding: quoted-printable

<div><p class=3D"MsoNormal">I am not aware of any IPR pertaining to TBNEGO.=
<u></u><u></u></p><p class=3D"MsoNormal"><u></u>Dirk.</p></div><div><br><di=
v class=3D"gmail_quote"><div>On Mon, Jun 19, 2017 at 6:53 PM Andrei Popov &=
lt;<a href=3D"mailto:Andrei.Popov@microsoft.com">Andrei.Popov@microsoft.com=
</a>&gt; wrote:<br></div><blockquote class=3D"gmail_quote" style=3D"margin:=
0 0 0 .8ex;border-left:1px #ccc solid;padding-left:1ex">





<div lang=3D"EN-US" link=3D"blue" vlink=3D"purple">
<div class=3D"m_-1067726542496011384WordSection1">
<p class=3D"MsoNormal">I am not aware of any IPR pertaining to TBNEGO.<u></=
u><u></u></p>
<p class=3D"MsoNormal"><u></u>=C2=A0<u></u></p>
<p class=3D"MsoNormal">Cheers,<u></u><u></u></p>
<p class=3D"MsoNormal"><u></u>=C2=A0<u></u></p>
<p class=3D"MsoNormal">Andrei<u></u><u></u></p>
<p class=3D"MsoNormal"><u></u>=C2=A0<u></u></p>
<div>
<div style=3D"border:none;border-top:solid #e1e1e1 1.0pt;padding:3.0pt 0in =
0in 0in">
<p class=3D"MsoNormal"><b>From:</b> John Bradley [mailto:<a href=3D"mailto:=
ve7jtb@ve7jtb.com" target=3D"_blank">ve7jtb@ve7jtb.com</a>] <br>
<b>Sent:</b> Sunday, June 18, 2017 6:28 PM<br>
<b>To:</b> IETF TokBind WG &lt;<a href=3D"mailto:unbearable@ietf.org" targe=
t=3D"_blank">unbearable@ietf.org</a>&gt;<br>
<b>Cc:</b> <a href=3D"mailto:draft-ietf-tokbind-negotiation@ietf.org" targe=
t=3D"_blank">draft-ietf-tokbind-negotiation@ietf.org</a><br>
<b>Subject:</b> IPR for draft-ietf-tokbind-negotiation<u></u><u></u></p>
</div>
</div></div></div><div lang=3D"EN-US" link=3D"blue" vlink=3D"purple"><div c=
lass=3D"m_-1067726542496011384WordSection1">
<p class=3D"MsoNormal"><u></u>=C2=A0<u></u></p>
<p class=3D"MsoNormal" style=3D"margin-bottom:12.0pt"><br>
I=C2=A0am working on the shepherd writeup for the=C2=A0Transport Layer Secu=
rity (TLS) Extension for Token Binding=C2=A0Protocol=C2=A0Negotiation=C2=A0=
document:<br>
<a href=3D"https://tools.ietf.org/html/draft-ietf-tokbind-negotiation-08" t=
arget=3D"_blank">https://tools.ietf.org/html/draft-ietf-tokbind-negotiation=
-08</a><br>
<br>
One item in the template requires me to indicate whether each document<br>
author has confirmed that any and all appropriate IPR disclosures<br>
required for full conformance with the provisions of BCP 78 and BCP 79<br>
have already been filed.<br>
<br>
Could each of you please confirm?<u></u><u></u></p>
<div>
<pre style=3D"font-variant-ligatures:normal">=C2=A0=C2=A0 Magnus Nystroem<u=
></u><u></u></pre>
<pre>=C2=A0=C2=A0 Microsoft Corp.<u></u><u></u></pre>
<pre>=C2=A0=C2=A0 USA<u></u><u></u></pre>
<pre><u></u>=C2=A0<u></u></pre>
<pre>=C2=A0=C2=A0 Email: <a href=3D"mailto:mnystrom@microsoft.com" target=
=3D"_blank">mnystrom@microsoft.com</a><u></u><u></u></pre>
<pre><u></u>=C2=A0<u></u></pre>
<pre><u></u>=C2=A0<u></u></pre>
<pre>=C2=A0=C2=A0 Dirk Balfanz<u></u><u></u></pre>
<pre>=C2=A0=C2=A0 Google Inc.<u></u><u></u></pre>
<pre>=C2=A0=C2=A0 USA<u></u><u></u></pre>
<pre><u></u>=C2=A0<u></u></pre>
<pre>=C2=A0=C2=A0 Email: <a href=3D"mailto:balfanz@google.com" target=3D"_b=
lank">balfanz@google.com</a><u></u><u></u></pre>
<pre><u></u>=C2=A0<u></u></pre>
<pre><u></u>=C2=A0<u></u></pre>
<pre>=C2=A0=C2=A0 Adam Langley<u></u><u></u></pre>
<pre>=C2=A0=C2=A0 Google Inc.<u></u><u></u></pre>
<pre>=C2=A0=C2=A0 USA<u></u><u></u></pre>
<pre><u></u>=C2=A0<u></u></pre>
<pre>=C2=A0=C2=A0 Email: <a href=3D"mailto:agl@google.com" target=3D"_blank=
">agl@google.com</a><u></u><u></u></pre>
<pre><u></u>=C2=A0<u></u></pre>
<pre><u></u>=C2=A0<u></u></pre>
<pre><u></u>=C2=A0<u></u></pre>
</div>
</div></div></blockquote></div></div>

--94eb2c1b440afd1e0805527191fd--


From nobody Tue Jun 20 22:27:45 2017
Return-Path: <balfanz@google.com>
X-Original-To: unbearable@ietfa.amsl.com
Delivered-To: unbearable@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 3985D12741D for <unbearable@ietfa.amsl.com>; Tue, 20 Jun 2017 22:27:44 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.001
X-Spam-Level: 
X-Spam-Status: No, score=-2.001 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, HTML_MESSAGE=0.001, RCVD_IN_DNSWL_NONE=-0.0001, RP_MATCHES_RCVD=-0.001, SPF_PASS=-0.001] autolearn=unavailable autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (2048-bit key) header.d=google.com
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id ZsIQzcRwy-iH for <unbearable@ietfa.amsl.com>; Tue, 20 Jun 2017 22:27:42 -0700 (PDT)
Received: from mail-wr0-x22b.google.com (mail-wr0-x22b.google.com [IPv6:2a00:1450:400c:c0c::22b]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id C4DEB126CC7 for <unbearable@ietf.org>; Tue, 20 Jun 2017 22:27:41 -0700 (PDT)
Received: by mail-wr0-x22b.google.com with SMTP id r103so118571640wrb.0 for <unbearable@ietf.org>; Tue, 20 Jun 2017 22:27:41 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=20161025; h=mime-version:references:in-reply-to:from:date:message-id:subject:to :cc; bh=7K2z+L9OvOJq18VSLdeRL3qDVDlUlEYJ6Ph0PZ7DQeE=; b=GbNkZTVuh6h7o1PrhxlTHfYJr6qlMx3SeJCuDg+D4DDHRBhuYfZBcfPFIu2Y+finMm IFKUWGX8zl40zyg/rH8Mj22QDbZqwUzD/cm7MBmwQhaBYNDVyhAdrNElkm1fCrTGOMy0 m9G4HjUq4tpIZWOFMo6wNvTLf0y6z1A095ukdlAwBNqg9abu0TCl0eVBei/3U7XW+DMl KlMU7r0n2Q1FRyAdcuaO+mLA0xp54bzBk3sD9+jX7tv7uHMqxNfb6YfsYNQ6HTBWPlmQ ludBmkh0HQlNKp3z8ctU2NZ5m7iY6Tck1uMmlorDJQMEkHDoGzSCO5vv44D9cqXwrFIs 7RXg==
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20161025; h=x-gm-message-state:mime-version:references:in-reply-to:from:date :message-id:subject:to:cc; bh=7K2z+L9OvOJq18VSLdeRL3qDVDlUlEYJ6Ph0PZ7DQeE=; b=CxCe3jAAL7n/NwsSLJYHR1ztf6gg+lvtpHawFhGNjwoEldzcay+ctD2nmzeFnPfGwL WTxGjraKwQ1xBo5rOP9KtITShEiDj+vanl/bvTd0gSBZfLB+bEq6ZC8cI1SBr/9fHaBM MqjWr1A5xpqkhlpxpUNhThAKSF4zXXhQC6mETPRclBv8E85JzD0PLrQqUhOPOOjX0BqO f28kOZ/lxTGnJi79nv3VzcCHkghyf0AeHlX+DSU83KaELkhAlIRjQp3igoNLQqHuWMvB lgFx3o642D2XSMkvvOpmBoWZYKk4Wwpr2d5w1J5B8XTMAA+rvHF6UmqqVy7oTAgIaZqk MWaQ==
X-Gm-Message-State: AKS2vOzPXVdBGTSqAYxUQFhW/iVHy/1GYOdhm78WNIxqOryCYof6ifqL UV0KUfCPDD29DyUQw3bmh5nsJe/paN4F
X-Received: by 10.223.176.119 with SMTP id g52mr22894024wra.26.1498022860172;  Tue, 20 Jun 2017 22:27:40 -0700 (PDT)
MIME-Version: 1.0
References: <C7D885CC-9B96-4AA4-9EA0-6087084000B3@ve7jtb.com> <DM2PR21MB0091680D1C3E2D3EBE2E29598CC40@DM2PR21MB0091.namprd21.prod.outlook.com> <CAL9PXLxHjAir5RuoZD3coZ5dTcAQESnk187u3ePjWuvj4s8pYg@mail.gmail.com>
In-Reply-To: <CAL9PXLxHjAir5RuoZD3coZ5dTcAQESnk187u3ePjWuvj4s8pYg@mail.gmail.com>
From: Dirk Balfanz <balfanz@google.com>
Date: Wed, 21 Jun 2017 05:27:29 +0000
Message-ID: <CADHfa2CTPgp6Pza07pFtG5Nqae9qQoovFNnM=_B32jjgEz1B2A@mail.gmail.com>
To: Adam Langley <agl@google.com>, Andrei Popov <Andrei.Popov@microsoft.com>
Cc: John Bradley <ve7jtb@ve7jtb.com>, IETF TokBind WG <unbearable@ietf.org>,  "draft-ietf-tokbind-protocol@ietf.org" <draft-ietf-tokbind-protocol@ietf.org>
Content-Type: multipart/alternative; boundary="001a113cae7672844e055271a08a"
Archived-At: <https://mailarchive.ietf.org/arch/msg/unbearable/SFbtjN8H7kTgtpRYRcgpYx4C8gQ>
Subject: Re: [Unbearable] IPR for draft-ietf-tokbind-protocol
X-BeenThere: unbearable@ietf.org
X-Mailman-Version: 2.1.22
Precedence: list
List-Id: "\"This list is for discussion of proposals for doing better than bearer tokens \(e.g. HTTP cookies, OAuth tokens etc.\) for web applications. The specific goal is chartering a WG focused on preventing security token export and replay attacks.\"" <unbearable.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/unbearable>, <mailto:unbearable-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/unbearable/>
List-Post: <mailto:unbearable@ietf.org>
List-Help: <mailto:unbearable-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/unbearable>, <mailto:unbearable-request@ietf.org?subject=subscribe>
X-List-Received-Date: Wed, 21 Jun 2017 05:27:44 -0000

--001a113cae7672844e055271a08a
Content-Type: text/plain; charset="UTF-8"

Same here.

Dirk.

On Tue, Jun 20, 2017 at 12:22 AM Adam Langley <agl@google.com> wrote:

> I am not aware of any IPR pertaining to TBPROTO.
>
>
> Cheers
>
> AGL
>

--001a113cae7672844e055271a08a
Content-Type: text/html; charset="UTF-8"
Content-Transfer-Encoding: quoted-printable

Same here. <br><br>Dirk. <br><br><div class=3D"gmail_quote"><div dir=3D"ltr=
">On Tue, Jun 20, 2017 at 12:22 AM Adam Langley &lt;<a href=3D"mailto:agl@g=
oogle.com">agl@google.com</a>&gt; wrote:<br></div><blockquote class=3D"gmai=
l_quote" style=3D"margin:0 0 0 .8ex;border-left:1px #ccc solid;padding-left=
:1ex"><div dir=3D"ltr"><span style=3D"font-size:12.8px">I am not aware of a=
ny IPR pertaining to TBPROTO.</span><br><div class=3D"gmail_extra"><br></di=
v><div class=3D"gmail_extra"><br></div><div class=3D"gmail_extra">Cheers</d=
iv><div class=3D"gmail_extra"><br></div></div><div dir=3D"ltr"><div class=
=3D"gmail_extra">AGL</div></div>
</blockquote></div>

--001a113cae7672844e055271a08a--


From nobody Tue Jun 20 22:28:13 2017
Return-Path: <balfanz@google.com>
X-Original-To: unbearable@ietfa.amsl.com
Delivered-To: unbearable@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 0BA6C1314E1 for <unbearable@ietfa.amsl.com>; Tue, 20 Jun 2017 22:28:11 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2
X-Spam-Level: 
X-Spam-Status: No, score=-2 tagged_above=-999 required=5 tests=[BAYES_00=-1.9,  DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, HTML_MESSAGE=0.001, RCVD_IN_DNSWL_NONE=-0.0001, RP_MATCHES_RCVD=-0.001, SPF_PASS=-0.001, URIBL_BLOCKED=0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (2048-bit key) header.d=google.com
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id XG1vUpDw9UKi for <unbearable@ietfa.amsl.com>; Tue, 20 Jun 2017 22:28:09 -0700 (PDT)
Received: from mail-wr0-x231.google.com (mail-wr0-x231.google.com [IPv6:2a00:1450:400c:c0c::231]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 65155127342 for <unbearable@ietf.org>; Tue, 20 Jun 2017 22:28:09 -0700 (PDT)
Received: by mail-wr0-x231.google.com with SMTP id c11so63096778wrc.3 for <unbearable@ietf.org>; Tue, 20 Jun 2017 22:28:09 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=20161025; h=mime-version:references:in-reply-to:from:date:message-id:subject:to; bh=4TXd9v2x/wkm0ljS2hLGMxMST86GozbI9U2/NpreWQk=; b=qzVXEZwKMdJxjCxQnpUUiojuy79lVryy9zYZmBPUETE4oDAhAIzrNrw2MSOAKPmuzs icjIQ4qkudBNHDoPEdSsCEZNsDVAbO/+/74BUG18Z0ceiu3gxbYRQPZMlQgmd0UZ/AYJ HHUCqmdZmbes707GXoZ/D6LXxSH32jaTR50bRqlNKbjzGsMWD3hKKssHfMj5+gblDP8s ImInMBQmad7t/cGyjbZRSnoep5kRco6Iz0U4y/2DFutk/FPAFni2lkazTA2UikLMQRPr 3isVRFZ1Kc4JYmeNNcMMgRDDYUi5RgU8YtG78c9aFgZF/zVic6E7Q33kf9o9W+Or1gjL E58Q==
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20161025; h=x-gm-message-state:mime-version:references:in-reply-to:from:date :message-id:subject:to; bh=4TXd9v2x/wkm0ljS2hLGMxMST86GozbI9U2/NpreWQk=; b=CunZrO6TtVzK9iqm9vxlWqRcT6wYMU2bNa3WNE0cQqJqjDS6h7M2aLNxYTH/7gy8Dc pPaQgKuqlAVFHNqHtx2H2nmrd3gRWiTLeFVugUei68Y6OqoO3B9h9ekb4JZ2QnzEoJXT lGLr7P6Ty7MeCrnSJFlyB+F3bwtANScuxASsR243Sj+wWfCUBPj8M53Z3XqRuflTm6cb xTUz5G5/4DuvKW7VG2Daz6QkD6SAOwJBrrmIfwByWtcE1/8c1xra8EXdL8wocO/S/szs apjzotgWrVBr91qFEoNEB4E49iZ29fgZAq3nhmHt7gu9LrCxH2rDgnscRt2B1Ew2qGJV kJtg==
X-Gm-Message-State: AKS2vOyLzhNfPfcbWdtS2NKCrCWozBrDX0XTUObkjCkF+7ID/SWZG2f3 mxGcsvdUfQLTZT72Wt4YdOv76JFxaP5A23k=
X-Received: by 10.223.171.3 with SMTP id q3mr3562609wrc.12.1498022887794; Tue, 20 Jun 2017 22:28:07 -0700 (PDT)
MIME-Version: 1.0
References: <feb75975-3682-acfe-8bb5-daade1ed242f@KingsMountain.com>
In-Reply-To: <feb75975-3682-acfe-8bb5-daade1ed242f@KingsMountain.com>
From: Dirk Balfanz <balfanz@google.com>
Date: Wed, 21 Jun 2017 05:27:56 +0000
Message-ID: <CADHfa2CL3Jy+BZR4uYDeJ4u=G4reWuSF1JcN7Ky89OX=xhqNew@mail.gmail.com>
To: "=JeffH" <Jeff.Hodges@kingsmountain.com>, IETF TokBind WG <unbearable@ietf.org>, John Bradley <ve7jtb@ve7jtb.com>, TBPROTO authors <draft-ietf-tokbind-protocol@ietf.org>
Content-Type: multipart/alternative; boundary="94eb2c1b440a182e44055271a281"
Archived-At: <https://mailarchive.ietf.org/arch/msg/unbearable/zrhJiIp5B13oUbGW4wlFufIZIuY>
Subject: Re: [Unbearable] IPR for draft-ietf-tokbind-https
X-BeenThere: unbearable@ietf.org
X-Mailman-Version: 2.1.22
Precedence: list
List-Id: "\"This list is for discussion of proposals for doing better than bearer tokens \(e.g. HTTP cookies, OAuth tokens etc.\) for web applications. The specific goal is chartering a WG focused on preventing security token export and replay attacks.\"" <unbearable.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/unbearable>, <mailto:unbearable-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/unbearable/>
List-Post: <mailto:unbearable@ietf.org>
List-Help: <mailto:unbearable-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/unbearable>, <mailto:unbearable-request@ietf.org?subject=subscribe>
X-List-Received-Date: Wed, 21 Jun 2017 05:28:11 -0000

--94eb2c1b440a182e44055271a281
Content-Type: text/plain; charset="UTF-8"

Same here.

Dirk.


On Mon, Jun 19, 2017 at 7:12 PM =JeffH <Jeff.Hodges@kingsmountain.com>
wrote:

> I am not aware of any IPR pertaining to HTTPSTB.
>
> thx,
>
> =JeffH
>

--94eb2c1b440a182e44055271a281
Content-Type: text/html; charset="UTF-8"
Content-Transfer-Encoding: quoted-printable

<div>Same here.=C2=A0</div><div><br></div><div>Dirk.=C2=A0</div><div><br></=
div><div><br><div class=3D"gmail_quote"><div>On Mon, Jun 19, 2017 at 7:12 P=
M =3DJeffH &lt;<a href=3D"mailto:Jeff.Hodges@kingsmountain.com">Jeff.Hodges=
@kingsmountain.com</a>&gt; wrote:<br></div><blockquote class=3D"gmail_quote=
" style=3D"margin:0 0 0 .8ex;border-left:1px #ccc solid;padding-left:1ex">I=
 am not aware of any IPR pertaining to HTTPSTB.<br>
<br>
thx,<br>
<br>
=3DJeffH<br>
</blockquote></div></div>

--94eb2c1b440a182e44055271a281--


From nobody Fri Jun 23 03:51:16 2017
Return-Path: <denis.ietf@free.fr>
X-Original-To: unbearable@ietfa.amsl.com
Delivered-To: unbearable@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 5DDD5128B88; Fri, 23 Jun 2017 03:51:14 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.597
X-Spam-Level: 
X-Spam-Status: No, score=-2.597 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, FREEMAIL_FROM=0.001, HTML_MESSAGE=0.001, RCVD_IN_DNSWL_LOW=-0.7, URIBL_BLOCKED=0.001] autolearn=ham autolearn_force=no
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id D6eE0OywHBTZ; Fri, 23 Jun 2017 03:51:11 -0700 (PDT)
Received: from smtp6-g21.free.fr (smtp6-g21.free.fr [IPv6:2a01:e0c:1:1599::15]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id E5F2B1200ED; Fri, 23 Jun 2017 03:51:10 -0700 (PDT)
Received: from [192.168.0.13] (unknown [88.182.125.39]) by smtp6-g21.free.fr (Postfix) with ESMTP id 088677803A5; Fri, 23 Jun 2017 12:51:08 +0200 (CEST)
To: saag@ietf.org, OAuth WG <oauth@ietf.org>, IETF Tokbind WG <unbearable@ietf.org>
References: <8d869aa1-568e-788f-b8f9-b056fc5d771c@KingsMountain.com> <14050b8e-6cd9-9be7-6a1a-3d8cbe1f19cf@free.fr>
From: Denis <denis.ietf@free.fr>
Message-ID: <df3ed42c-909e-7ff7-9af4-f4a1f43a81cc@free.fr>
Date: Fri, 23 Jun 2017 12:51:16 +0200
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; rv:52.0) Gecko/20100101 Thunderbird/52.1.1
MIME-Version: 1.0
In-Reply-To: <14050b8e-6cd9-9be7-6a1a-3d8cbe1f19cf@free.fr>
Content-Type: multipart/alternative; boundary="------------2B9F9D64C442E497FC835ED4"
Content-Language: en-US
Archived-At: <https://mailarchive.ietf.org/arch/msg/unbearable/dn_tob6yiFjT5CQiTVhBb6tSVuI>
Subject: [Unbearable] New Special Publication 800-63-3 "Digital Identity Guidelines" Suite published
X-BeenThere: unbearable@ietf.org
X-Mailman-Version: 2.1.22
Precedence: list
List-Id: "\"This list is for discussion of proposals for doing better than bearer tokens \(e.g. HTTP cookies, OAuth tokens etc.\) for web applications. The specific goal is chartering a WG focused on preventing security token export and replay attacks.\"" <unbearable.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/unbearable>, <mailto:unbearable-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/unbearable/>
List-Post: <mailto:unbearable@ietf.org>
List-Help: <mailto:unbearable-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/unbearable>, <mailto:unbearable-request@ietf.org?subject=subscribe>
X-List-Received-Date: Fri, 23 Jun 2017 10:51:14 -0000

This is a multi-part message in MIME format.
--------------2B9F9D64C442E497FC835ED4
Content-Type: text/plain; charset=utf-8; format=flowed
Content-Transfer-Encoding: 8bit

I also read section 8 (Security) from NIST Special Publication 800-63C 
(Digital Identity Guidelines).
See: https://pages.nist.gov/800-63-3/sp800-63c.html

Section 8.1 states:*
*

    *"*For the purpose of these types of threats, any authorized parties
    who attempt to exceed their privileges
       are considered attackers".

Section 9.3 identifies a specific use case:

    "In some instances, an RP does not require a full value of an
    attribute. For example, an RP may need to know
       whether the subscriber is over 13 years old, but has no need for
    the full date of birth".

However, Bob who is over 13 might attempt to forward an assertion that 
he legitimately obtained from an IdP to Alice
who is less than 13. This is a collusion attack that has been named : 
the ABC attack (Alice and Bob Collusion attack).
The first description of this attack is available at: 
https://www.ietf.org/mail-archive/web/oauth/current/msg16767.html

Such a threat or attack is not identified in this NIST document and 
hence no mitigation mechanism is being proposed.

Access token binding protection methods developed either by the Token 
Binding WG or by the OAuth WG do not allow
to counter the ABC attack. Either the legitimate user (e.g. Bob) can 
provide his key to another user (e.g. Alice), or
if it can't (e.g. because it is protected by a secure element) he sends 
requests to his secure element to perform
the cryptographic computations that the other user (e.g. Alice) needs. 
The RP will be unable to know which piece of software
or hardware has performed the cryptographic computations.

There are two ways to counter this threat:


    -either to include into the assertion a set of attributes that
    allows to uniquely identify the user (e.g. name, first name and
    other attributes)
    but which is against both data minimization privacy principles and
    unlinkability privacy principles,


    -or to use secure elements that allow to only include an attribute
    like "over 13" into the assertion and which are able to defeat the
    ABC attack.


    On July 13, at the OAuth Security Workshop 2017that will take place
    in Zürich, I will present two methods using secure elements while
    preserving the user's privacy that are able to defeat the ABC
    attack. The title of this presentation is :


    " A privacy by design eID scheme supporting Attribute-based Access
    Control (ABAC)".


    See: https://zisc.ethz.ch/oauth-security-workshop-2017/


    Denis


PS. This email is also posted to the OAuth WG mailing list and the the 
Token Binding mailing list. Sorry for duplications.


> Thank you for providing the links. I read in particular section 5.2 
> (Privacy Requirements) from
> NIST Special Publication 800-63C (Digital Identity Guidelines) which 
> is reproduced below :
>
>
>       (See: https://pages.nist.gov/800-63-3/sp800-63c.html)
>
>
>       5.2 Privacy Requirements
>
> Federation involves the transfer of personal attributes from a third 
> party that is not otherwise involved
> in a transaction — the IdP. Federation also potentially gives the IdP 
> broad visibility into subscriber activities.
> Accordingly, there are specific privacy requirements associated with 
> federation.
>
> Communication between the RP and the IdP could reveal to the IdP where 
> the subscriber is conducting a transaction.
> Communication with multiple RPs allows the IdP to build a profile of 
> subscriber transactions that would not have existed
> without federation. This aggregation could enable new opportunities 
> for subscriber tracking and use of profile information
> that do not always align with subscribers’ privacy interests.
>
> The IdP SHALL NOT disclose information on subscriber activities at an 
> RP to any party, nor use the subscriber’s information
> for any purpose other than federated authentication, related fraud 
> mitigation, to comply with law or legal process, or in the case of a 
> specific user request, to transmit the information.
>
> The IdP SHOULDemploy technical measures, such as the use of pairwise 
> pseudonymous identifiers described in Section 6.3 
> <https://pages.nist.gov/800-63-3/sp800-63c.html#ppi>
> or privacy-enhancing cryptographic protocols, to provide unlinkability 
> and discourage subscriber activity tracking and profiling. (...)
>
> From the point of view of human users, this requirement ("SHALL NOT") 
> and this recommendation ("SHOULD") are not satisfactory,
> since IdPs would be in a position to *act as Big Brother*.
>
> The right requirement should be:
>
> The IdP SHALL NOT be able to know where the subscribers are conducting 
> transactions.
>
>
> This has major implications on other parts of these documents.
>
> Denis
>
>> Of possible interest...
>>
>> [congrats to Jim Fenton and Paul Grassi]
>>
>> <https://pages.nist.gov/800-63-3/>
>>
>> SP 800-63-3   Digital Identity Guidelines
>> SP 800-63A    Enrollment and Identity Proofing
>> SP 800-63B    Authentication and Lifecycle Management
>> SP 800-63C    Federation and Assertions
>>
>>
>> On 6/22/17, 7:33 AM, "National Institute of Standards and Technology 
>> (NIST)" wrote:
>>
>> Mic Drop — Announcing the New Special Publication 800-63 Suite!
>> 06/22/2017 10:02 AM EDT
>> <http://trustedidentities.blogs.govdelivery.com/2017/06/22/mic-drop-announcing-the-new-special-publication-800-63-suite/> 
>>
>>
>> More than a year in the making, after a large, cross-industry effort, 
>> we are proud to announce that the new Special Publication (SP) 800-63 
>> IS. NOW. FINAL. With your help, Electronic Authentication Guidelines 
>> has evolved into Digital Identity Guidelines—a suite of documents 
>> covering digital identity from initial risk assessment to deployment 
>> of federated identity solutions. Check it out now at 
>> <https://pages.nist.gov/800-63>!
>>
>> _______________________________________________
>> saag mailing list
>> saag@ietf.org
>> https://www.ietf.org/mailman/listinfo/saag
>
>
>
>
> _______________________________________________
> saag mailing list
> saag@ietf.org
> https://www.ietf.org/mailman/listinfo/saag



--------------2B9F9D64C442E497FC835ED4
Content-Type: text/html; charset=utf-8
Content-Transfer-Encoding: 8bit

<html>
  <head>
    <meta http-equiv="Content-Type" content="text/html; charset=utf-8">
  </head>
  <body text="#000000" bgcolor="#FFFFFF">
    <div class="moz-cite-prefix"><!--[if gte mso 9]><xml>
 <w:WordDocument>
  <w:View>Normal</w:View>
  <w:Zoom>0</w:Zoom>
  <w:HyphenationZone>21</w:HyphenationZone>
  <w:DoNotOptimizeForBrowser/>
 </w:WordDocument>
</xml><![endif]-->
      <p class="MsoNormal"
        style="margin-top:6.0pt;mso-margin-bottom-alt:auto"><font
          face="Arial">I also read
          section 8 (Security) from NIST Special Publication 800-63C
          (Digital Identity
          Guidelines). <br>
          See: <font color="#3333ff"><a
              href="https://pages.nist.gov/800-63-3/sp800-63c.html">https://pages.nist.gov/800-63-3/sp800-63c.html</a></font></font></p>
      <font face="Arial">
      </font>
      <p
style="margin-top:6.0pt;margin-right:0cm;margin-bottom:0cm;margin-left:0cm;margin-bottom:.0001pt"><font
          face="Arial">Section 8.1 states:<b> <br>
          </b></font></p>
      <blockquote>
        <p
style="margin-top:6.0pt;margin-right:0cm;margin-bottom:0cm;margin-left:0cm;margin-bottom:.0001pt"><font
            face="Arial"><b>"</b>For the purpose of these types of
            threats, any authorized parties who attempt to exceed their
            privileges <br>
              are
            considered attackers".</font></p>
      </blockquote>
      <font face="Arial">
      </font>
      <p
style="margin-top:6.0pt;margin-right:0cm;margin-bottom:0cm;margin-left:0cm;margin-bottom:.0001pt"><font
          face="Arial">Section 9.3 identifies a specific use case: <br>
        </font></p>
      <blockquote>
        <p
style="margin-top:6.0pt;margin-right:0cm;margin-bottom:0cm;margin-left:0cm;margin-bottom:.0001pt"><font
            face="Arial">"In some instances, an RP
            does not require a full value of an attribute. For example,
            an RP may need to
            know <br>
              whether the subscriber is over 13 years old, but has no
            need for the full
            date of birth". </font></p>
      </blockquote>
      <font face="Arial">
      </font>
      <p
style="margin-top:6.0pt;margin-right:0cm;margin-bottom:0cm;margin-left:0cm;margin-bottom:.0001pt"><font
          face="Arial">However, Bob who is over 13 might attempt to
          forward an assertion that
          he legitimately obtained from an IdP to Alice <br>
          who is less than 13. This is a collusion attack that has been
          named : the ABC attack (Alice and Bob
          Collusion attack).<br>
          The first description of this attack is available at: <font
            color="#3333ff"><a class="moz-txt-link-freetext" href="https://www.ietf.org/mail-archive/web/oauth/current/msg16767.html">https://www.ietf.org/mail-archive/web/oauth/current/msg16767.html</a></font><br>
          <br>
          Such a threat or attack is not identified in this NIST
          document and hence no mitigation
          mechanism is being proposed. <br>
        </font><font face="Arial"></font><br>
      </p>
      <font face="Arial">Access token binding protection methods
        developed either by the Token Binding WG or by the OAuth WG do
        not allow <br>
        to counter the ABC attack. Either the legitimate user (e.g. Bob)
        can provide his key to another user (e.g. Alice), or <br>
        if it can't (e.g. because it is protected by a secure element)
        he sends requests to his secure element to perform <br>
        the cryptographic computations that the other user (e.g. Alice)
        needs. The RP will be unable to know which piece of software <br>
        or hardware has performed the cryptographic computations.<br>
        <br>
      </font><font face="Arial">There are two ways to counter this
        threat:</font>
      <font face="Arial">
      </font>
      <h2
        style="margin-top:6.0pt;margin-right:0cm;margin-bottom:0cm;margin-left:
        36.0pt;margin-bottom:.0001pt;text-indent:-18.0pt;mso-list:l1
        level1 lfo5;
        tab-stops:list 36.0pt"><font face="Arial"><span
            style="font-size: 12pt; font-weight: normal;" lang="EN-US">-<span
              style="font-style: normal; font-weight: normal; font-size:
              7pt; line-height: normal; font-size-adjust: none;
              font-stretch: normal; font-feature-settings: normal;
              font-language-override: normal; font-kerning: auto;
              font-synthesis: weight style; font-variant: normal;">      
            </span></span><span style="font-size: 12pt; font-weight:
            normal;" lang="EN-US">either to
            include into the assertion a set of attributes that allows
            to uniquely identify
            the user (e.g. name, first name and other attributes) <br>
            but which is against both data
            minimization privacy principles and unlinkability privacy
            principles, </span></font></h2>
      <font face="Arial">
      </font>
      <h2
        style="margin-top:6.0pt;margin-right:0cm;margin-bottom:0cm;margin-left:
        36.0pt;margin-bottom:.0001pt;text-indent:-18.0pt;mso-list:l1
        level1 lfo5;
        tab-stops:list 36.0pt"><font face="Arial"><span
            style="font-size: 12pt; font-weight: normal;" lang="EN-US">-<span
              style="font-style: normal; font-weight: normal; font-size:
              7pt; line-height: normal; font-size-adjust: none;
              font-stretch: normal; font-feature-settings: normal;
              font-language-override: normal; font-kerning: auto;
              font-synthesis: weight style; font-variant: normal;">      
            </span></span><span style="font-size: 12pt; font-weight:
            normal;" lang="EN-US">or to use secure elements that allow
            to only include an attribute like "over 13"
            into the assertion and which are able to defeat the ABC
            attack.</span></font></h2>
      <h2><font face="Arial"><span style="font-size: 12pt; font-weight:
            normal;" lang="EN-US">On July 13, at
            the OAuth Security Workshop 2017</span><span
            style="font-size: 12pt;" lang="EN-US"> </span><span
            style="font-size: 12pt; font-weight: normal;" lang="EN-US">that
            will take place in Zürich, I will
            present two methods using secure elements while<br>
            preserving the user's privacy that are able to defeat the
            ABC attack. The title of this presentation is : <br>
          </span></font></h2>
      <h2><font face="Arial"><span style="font-size: 12pt; font-weight:
            normal;" lang="EN-US">" A privacy by design
            eID scheme supporting Attribute-based Access Control
            (ABAC)".</span><span style="font-size: 12pt; font-weight:
            normal;" lang="EN-US"><br>
          </span></font></h2>
      <h2><font face="Arial"><span style="font-size: 12pt; font-weight:
            normal;" lang="EN-US">See: <span style="color:blue"><a class="moz-txt-link-freetext" href="https://zisc.ethz.ch/oauth-security-workshop-2017/">https://zisc.ethz.ch/oauth-security-workshop-2017/</a></span></span></font>
      </h2>
      <h2
        style="margin-top:6.0pt;margin-right:0cm;margin-bottom:0cm;margin-left:
        0cm;margin-bottom:.0001pt"><font face="Arial"><span
            style="font-size: 12pt; font-weight: normal;" lang="EN-US">Denis</span></font></h2>
      <br>
      <font face="Arial">PS. This email is also posted to the OAuth WG
        mailing list and the the Token Binding mailing list. Sorry for
        duplications.<br>
        <br>
        <br>
      </font></div>
    <blockquote type="cite"
      cite="mid:14050b8e-6cd9-9be7-6a1a-3d8cbe1f19cf@free.fr">
      <meta http-equiv="Content-Type" content="text/html; charset=utf-8">
      <div class="moz-cite-prefix"><!--[if gte mso 9]><xml>
 <w:WordDocument>
  <w:View>Normal</w:View>
  <w:Zoom>0</w:Zoom>
  <w:HyphenationZone>21</w:HyphenationZone>
  <w:DoNotOptimizeForBrowser/>
 </w:WordDocument>
</xml><![endif]-->
        <p class="MsoNormal" style="margin-top:6.0pt"><span
            style="font-family: Arial;mso-ansi-language:EN-US"
            lang="EN-US">Thank you for providing the links. I read in
            particular section 5.2 (Privacy Requirements) from <br>
            NIST Special Publication 800-63C (Digital Identity
            Guidelines) which is reproduced below :</span></p>
        <h3
          style="margin-top:6.0pt;margin-right:0cm;margin-bottom:0cm;margin-left:
          0cm;margin-bottom:.0001pt"><span
            style="font-size:12.0pt;mso-bidi-font-size:
13.5pt;font-family:Arial;mso-ansi-language:EN-US;font-weight:normal"
            lang="EN-US">(See: <span style="color:blue"><a
                class="moz-txt-link-freetext"
                href="https://pages.nist.gov/800-63-3/sp800-63c.html"
                moz-do-not-send="true">https://pages.nist.gov/800-63-3/sp800-63c.html</a>)</span></span></h3>
        <p class="MsoNormal"
          style="margin-top:6.0pt;margin-right:0cm;margin-bottom:0cm;
          margin-left:36.0pt;margin-bottom:.0001pt"><span
            style="font-family: Arial;mso-ansi-language:EN-US"
            lang="EN-US"> </span></p>
        <h3
          style="margin-top:6.0pt;margin-right:0cm;margin-bottom:0cm;margin-left:
          36.0pt;margin-bottom:.0001pt"><span style="font-size:12.0pt;
mso-bidi-font-size:13.5pt;font-family:Arial;mso-ansi-language:EN-US"
            lang="EN-US">5.2 Privacy Requirements</span></h3>
        <p
style="margin-top:6.0pt;margin-right:0cm;margin-bottom:0cm;margin-left:36.0pt;margin-bottom:.0001pt"><span
            style="font-family:Arial;mso-ansi-language: EN-US"
            lang="EN-US">Federation involves the transfer of personal
            attributes from a third party that is not otherwise involved
            <br>
            in a transaction — the IdP. Federation also potentially
            gives the IdP broad visibility into subscriber activities. <br>
            Accordingly, there are specific privacy requirements
            associated with federation.</span></p>
        <p
style="margin-top:6.0pt;margin-right:0cm;margin-bottom:0cm;margin-left:36.0pt;margin-bottom:.0001pt"><span
            style="font-family:Arial;mso-ansi-language: EN-US"
            lang="EN-US">Communication between the RP and the IdP could
            reveal to the IdP where the subscriber is conducting a
            transaction.<br>
            <span style="background:lime; mso-highlight:lime">Communication
              with multiple RPs allows the IdP to build a profile of
              subscriber transactions that would not have existed <br>
              without federation.</span> This aggregation could enable
            new opportunities for subscriber tracking and use of profile
            information <br>
            that do not always align with subscribers’ privacy
            interests.</span></p>
        <p
style="margin-top:6.0pt;margin-right:0cm;margin-bottom:0cm;margin-left:36.0pt;margin-bottom:.0001pt"><span
            style="font-family:Arial;background:
            yellow;mso-highlight:yellow;mso-ansi-language:EN-US"
            lang="EN-US">The IdP SHALL NOT </span><span
            style="font-family:Arial;mso-ansi-language:EN-US"
            lang="EN-US">disclose information on subscriber activities
            at an RP to any party, nor use the subscriber’s information
            <br>
            for any purpose other than federated authentication, related
            fraud mitigation, to comply with law or legal process, or in
            the case of a specific user request, to transmit the
            information. </span></p>
        <p
style="margin-top:6.0pt;margin-right:0cm;margin-bottom:0cm;margin-left:36.0pt;margin-bottom:.0001pt"><span
            style="font-family:Arial;background:
            yellow;mso-highlight:yellow;mso-ansi-language:EN-US"
            lang="EN-US">The IdP SHOULD</span><span
            style="font-family:Arial;mso-ansi-language:EN-US"
            lang="EN-US"> employ technical measures, such as the use of
            pairwise pseudonymous identifiers described in </span><span
            style="font-family:Arial"><a
              href="https://pages.nist.gov/800-63-3/sp800-63c.html#ppi"
              moz-do-not-send="true"><span
                style="mso-ansi-language:EN-US" lang="EN-US">Section 6.3</span></a></span><span
            style="font-family:Arial;mso-ansi-language:EN-US"
            lang="EN-US"> <br>
            or privacy-enhancing cryptographic protocols, to provide
            unlinkability and discourage subscriber activity tracking
            and profiling. (...)</span></p>
        <p class="MsoNormal"
          style="margin-top:6.0pt;margin-right:0cm;margin-bottom:0cm;
          margin-left:36.0pt;margin-bottom:.0001pt"><span
            style="font-family: Arial;mso-ansi-language:EN-US"
            lang="EN-US"> </span></p>
        <p class="MsoNormal" style="margin-top:6.0pt"><span
            style="font-family: Arial;mso-ansi-language:EN-US"
            lang="EN-US">From the point of view of human users, this
            requirement ("SHALL NOT") and this recommendation ("SHOULD")
            are not satisfactory, <br>
            since IdPs would be in a position to <b><span
                style="color:blue">act as Big Brother</span></b>. </span></p>
        <p class="MsoNormal" style="margin-top:6.0pt"><span
            style="font-family: Arial;mso-ansi-language:EN-US"
            lang="EN-US">The right requirement should be:</span></p>
        <p class="MsoNormal"
          style="margin-top:6.0pt;margin-right:0cm;margin-bottom:0cm;
          margin-left:36.0pt;margin-bottom:.0001pt"><span
            style="font-family:
Arial;background:yellow;mso-highlight:yellow;mso-ansi-language:EN-US"
            lang="EN-US">The IdP SHALL NOT be able to know where the
            subscribers are conducting transactions.</span><span
            style="font-family:Arial;mso-ansi-language:EN-US"
            lang="EN-US"></span></p>
        <span style="font-family: Arial;mso-ansi-language:EN-US"
          lang="EN-US"><br>
          This has major implications on other parts of these documents.<br>
          <br>
          Denis<br>
        </span> <br>
      </div>
      <blockquote type="cite"
        cite="mid:8d869aa1-568e-788f-b8f9-b056fc5d771c@KingsMountain.com">Of
        possible interest... <br>
        <br>
        [congrats to Jim Fenton and Paul Grassi] <br>
        <br>
        <a class="moz-txt-link-rfc2396E"
          href="https://pages.nist.gov/800-63-3/" moz-do-not-send="true">&lt;https://pages.nist.gov/800-63-3/&gt;</a>
        <br>
        <br>
        SP 800-63-3   Digital Identity Guidelines <br>
        SP 800-63A    Enrollment and Identity Proofing <br>
        SP 800-63B    Authentication and Lifecycle Management <br>
        SP 800-63C    Federation and Assertions <br>
        <br>
        <br>
        On 6/22/17, 7:33 AM, "National Institute of Standards and
        Technology (NIST)" wrote: <br>
        <br>
        Mic Drop — Announcing the New Special Publication 800-63 Suite!
        <br>
        06/22/2017 10:02 AM EDT <br>
        <a class="moz-txt-link-rfc2396E"
href="http://trustedidentities.blogs.govdelivery.com/2017/06/22/mic-drop-announcing-the-new-special-publication-800-63-suite/"
          moz-do-not-send="true">&lt;http://trustedidentities.blogs.govdelivery.com/2017/06/22/mic-drop-announcing-the-new-special-publication-800-63-suite/&gt;</a>
        <br>
        <br>
        More than a year in the making, after a large, cross-industry
        effort, we are proud to announce that the new Special
        Publication (SP) 800-63 IS. NOW. FINAL. With your help,
        Electronic Authentication Guidelines has evolved into Digital
        Identity Guidelines—a suite of documents covering digital
        identity from initial risk assessment to deployment of federated
        identity solutions. Check it out now at <a
          class="moz-txt-link-rfc2396E"
          href="https://pages.nist.gov/800-63" moz-do-not-send="true">&lt;https://pages.nist.gov/800-63&gt;</a>!
        <br>
        <br>
        _______________________________________________ <br>
        saag mailing list <br>
        <a class="moz-txt-link-abbreviated" href="mailto:saag@ietf.org"
          moz-do-not-send="true">saag@ietf.org</a> <br>
        <a class="moz-txt-link-freetext"
          href="https://www.ietf.org/mailman/listinfo/saag"
          moz-do-not-send="true">https://www.ietf.org/mailman/listinfo/saag</a>
        <br>
      </blockquote>
      <p><br>
      </p>
      <br>
      <fieldset class="mimeAttachmentHeader"></fieldset>
      <br>
      <pre wrap="">_______________________________________________
saag mailing list
<a class="moz-txt-link-abbreviated" href="mailto:saag@ietf.org">saag@ietf.org</a>
<a class="moz-txt-link-freetext" href="https://www.ietf.org/mailman/listinfo/saag">https://www.ietf.org/mailman/listinfo/saag</a>
</pre>
    </blockquote>
    <p><br>
    </p>
  </body>
</html>

--------------2B9F9D64C442E497FC835ED4--


From nobody Fri Jun 23 17:16:59 2017
Return-Path: <agenda@ietf.org>
X-Original-To: unbearable@ietf.org
Delivered-To: unbearable@ietfa.amsl.com
Received: from ietfa.amsl.com (localhost [IPv6:::1]) by ietfa.amsl.com (Postfix) with ESMTP id 97C3812EB92; Fri, 23 Jun 2017 17:07:17 -0700 (PDT)
MIME-Version: 1.0
Content-Type: text/plain; charset="utf-8"
Content-Transfer-Encoding: 7bit
From: "\"IETF Secretariat\"" <agenda@ietf.org>
To: <tokbind-chairs@ietf.org>, <leifj@sunet.se>
Cc: unbearable@ietf.org, ekr@rtfm.com
X-Test-IDTracker: no
X-IETF-IDTracker: 6.55.1
Auto-Submitted: auto-generated
Precedence: bulk
Message-ID: <149826283756.7840.11902554649235065224.idtracker@ietfa.amsl.com>
Date: Fri, 23 Jun 2017 17:07:17 -0700
Archived-At: <https://mailarchive.ietf.org/arch/msg/unbearable/1IqW_RA1ntHnPEWQyrCwWlQ_eqY>
Subject: [Unbearable] tokbind - Requested session has been scheduled for IETF 99
X-BeenThere: unbearable@ietf.org
X-Mailman-Version: 2.1.22
List-Id: "\"This list is for discussion of proposals for doing better than bearer tokens \(e.g. HTTP cookies, OAuth tokens etc.\) for web applications. The specific goal is chartering a WG focused on preventing security token export and replay attacks.\"" <unbearable.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/unbearable>, <mailto:unbearable-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/unbearable/>
List-Post: <mailto:unbearable@ietf.org>
List-Help: <mailto:unbearable-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/unbearable>, <mailto:unbearable-request@ietf.org?subject=subscribe>
X-List-Received-Date: Sat, 24 Jun 2017 00:07:18 -0000

Dear Leif Johansson,

The session(s) that you have requested have been scheduled.
Below is the scheduled session information followed by
the original request. 

tokbind Session 1 (1:30:00)
    Monday, Afternoon Session II 1550-1720
    Room Name: Berlin/Brussels size: 100
    ---------------------------------------------
    


Request Information:


---------------------------------------------------------
Working Group Name: Token Binding
Area Name: Security Area
Session Requester: Leif Johansson

Number of Sessions: 1
Length of Session(s):  1.5 Hours
Number of Attendees: 50
Conflicts to Avoid: 
 First Priority: ace tls oauth secevent




People who must be present:
  Eric Rescorla
  Stephen Farrell
  Leif Johansson
  Dirk Balfanz
  John Bradley
  Andrey Popov
  Mike Jones

Resources Requested:

Special Requests:
  Key contributors are unable to attend on Friday. Please if possible avoid Friday scheduling.
---------------------------------------------------------


From nobody Wed Jun 28 15:12:25 2017
Return-Path: <internet-drafts@ietf.org>
X-Original-To: unbearable@ietf.org
Delivered-To: unbearable@ietfa.amsl.com
Received: from ietfa.amsl.com (localhost [IPv6:::1]) by ietfa.amsl.com (Postfix) with ESMTP id 16AAB126CB6; Wed, 28 Jun 2017 15:12:18 -0700 (PDT)
MIME-Version: 1.0
Content-Type: text/plain; charset="utf-8"
Content-Transfer-Encoding: 7bit
From: internet-drafts@ietf.org
To: <i-d-announce@ietf.org>
Cc: unbearable@ietf.org
X-Test-IDTracker: no
X-IETF-IDTracker: 6.55.1
Auto-Submitted: auto-generated
Precedence: bulk
Message-ID: <149868793805.5443.4284920405751222901@ietfa.amsl.com>
Date: Wed, 28 Jun 2017 15:12:18 -0700
Archived-At: <https://mailarchive.ietf.org/arch/msg/unbearable/hM7jlRthOeYzjLIoiT1BIDJdveU>
Subject: [Unbearable] I-D Action: draft-ietf-tokbind-tls13-0rtt-02.txt
X-BeenThere: unbearable@ietf.org
X-Mailman-Version: 2.1.22
List-Id: "\"This list is for discussion of proposals for doing better than bearer tokens \(e.g. HTTP cookies, OAuth tokens etc.\) for web applications. The specific goal is chartering a WG focused on preventing security token export and replay attacks.\"" <unbearable.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/unbearable>, <mailto:unbearable-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/unbearable/>
List-Post: <mailto:unbearable@ietf.org>
List-Help: <mailto:unbearable-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/unbearable>, <mailto:unbearable-request@ietf.org?subject=subscribe>
X-List-Received-Date: Wed, 28 Jun 2017 22:12:18 -0000

A New Internet-Draft is available from the on-line Internet-Drafts directories.
This draft is a work item of the Token Binding of the IETF.

        Title           : Token Binding for 0-RTT TLS 1.3 Connections
        Author          : Nick Harper
	Filename        : draft-ietf-tokbind-tls13-0rtt-02.txt
	Pages           : 11
	Date            : 2017-06-28

Abstract:
   This document describes how Token Binding can be used in the 0-RTT
   data of a TLS 1.3 connection.  This involves a new TLS extension to
   negotiate and indicate the use of Token Binding in 0-RTT data.  A
   TokenBindingMessage sent in 0-RTT data has different security
   properties than one sent after the TLS handshake has finished, which
   this document also describes.


The IETF datatracker status page for this draft is:
https://datatracker.ietf.org/doc/draft-ietf-tokbind-tls13-0rtt/

There are also htmlized versions available at:
https://tools.ietf.org/html/draft-ietf-tokbind-tls13-0rtt-02
https://datatracker.ietf.org/doc/html/draft-ietf-tokbind-tls13-0rtt-02

A diff from the previous version is available at:
https://www.ietf.org/rfcdiff?url2=draft-ietf-tokbind-tls13-0rtt-02


Please note that it may take a couple of minutes from the time of submission
until the htmlized version and diff are available at tools.ietf.org.

Internet-Drafts are also available by anonymous FTP at:
ftp://ftp.ietf.org/internet-drafts/


From nobody Wed Jun 28 15:25:53 2017
Return-Path: <nharper@google.com>
X-Original-To: unbearable@ietfa.amsl.com
Delivered-To: unbearable@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 04391126CB6 for <unbearable@ietfa.amsl.com>; Wed, 28 Jun 2017 15:25:50 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.702
X-Spam-Level: 
X-Spam-Status: No, score=-2.702 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, RCVD_IN_DNSWL_LOW=-0.7, RP_MATCHES_RCVD=-0.001, SPF_PASS=-0.001] autolearn=unavailable autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (2048-bit key) header.d=google.com
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id 1qr29oCdAKWA for <unbearable@ietfa.amsl.com>; Wed, 28 Jun 2017 15:25:47 -0700 (PDT)
Received: from mail-lf0-x22b.google.com (mail-lf0-x22b.google.com [IPv6:2a00:1450:4010:c07::22b]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id DB76A12EC82 for <unbearable@ietf.org>; Wed, 28 Jun 2017 15:25:35 -0700 (PDT)
Received: by mail-lf0-x22b.google.com with SMTP id h22so42883747lfk.3 for <unbearable@ietf.org>; Wed, 28 Jun 2017 15:25:35 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=20161025; h=mime-version:in-reply-to:references:from:date:message-id:subject:to :cc; bh=5hAQsYCegJRdGDZHy1g+KdIumVOeqojsz1EsfOCcoyE=; b=AOWray2nL8fsZl7ZYOdN5hNdCIn5nFWXz0ckPaZttGBHLOBoJdSt68NASHuIFJZmvi Am5wArUuVRyUvnl3N+km44wqkmoeQN82HgUVwbWf4zBjxblwNTPS5HOVz/1l4DtT7GhU VtIEUaY+rnlHR7g7hywQoJWDW/67+67NaXOihsGyiOLgkOxIdBLbaXgSAiGWdrCqNh9C r+kntqELM3+NRd6aD6Er7wjRa2AWPn15IhbSWh18BTREZR8VfS6hz3ASV9MuUqHqV8Qb Rrnz4Xi/zUtZYBdymfnxWrq7HruKU2zjIKHAng+gQzhwGa5AYUaIwRD78TJ48OXiLmt+ 8tAw==
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20161025; h=x-gm-message-state:mime-version:in-reply-to:references:from:date :message-id:subject:to:cc; bh=5hAQsYCegJRdGDZHy1g+KdIumVOeqojsz1EsfOCcoyE=; b=JQMJh01XHNKc912HN5JLRcjxR96n7qhzExkCr73Xe/oRqQ43peQZvk3Ik6f+DzzrqD vR0XmOj/wr3JpvNBUd9XWfH0rgvw0/WRR2yIBALXrBEgt9Sycrtg9uvchwBlMcCyQQsy 2KsmCRrv7DIMt6a1hWKLtG/KMxTug4Olgvi5Arw8s5JsjnAGuPS7ebY3uPNTSU5ZrbC5 5btN0WsrbW6rCuR0gQYGDGezR9hJJaeSAAlgraC6WJjI1+ew294oE1Oamwvw7aJqBQlY icxhpM3qGQp2mKyXdSGXDm6O19zT4uHgSX1IuCah/xZGn7mUh4Ym2dnfszC05nRopXfP /CZA==
X-Gm-Message-State: AKS2vOyT1RKIM2aVZyhsyWyKskNKtmDdfAi/6hUuN8MChwsH7TYBdHcT PUiczhV2hrPAcOmvt86Z1sc/AuQaBhupjH8=
X-Received: by 10.46.14.17 with SMTP id 17mr3801436ljo.8.1498688733639; Wed, 28 Jun 2017 15:25:33 -0700 (PDT)
MIME-Version: 1.0
Received: by 10.25.44.73 with HTTP; Wed, 28 Jun 2017 15:25:13 -0700 (PDT)
In-Reply-To: <149868793805.5443.4284920405751222901@ietfa.amsl.com>
References: <149868793805.5443.4284920405751222901@ietfa.amsl.com>
From: Nick Harper <nharper@google.com>
Date: Wed, 28 Jun 2017 15:25:13 -0700
Message-ID: <CACdeXiLqmdVpQryrPOBnUrbrk24Vap7QrASK-_vnwH91vwkZ3A@mail.gmail.com>
To: IETF Tokbind WG <unbearable@ietf.org>
Cc: tokbind-chairs@ietf.org
Content-Type: text/plain; charset="UTF-8"
Archived-At: <https://mailarchive.ietf.org/arch/msg/unbearable/Hn60LTs5zzxvCgSuMR_H1wR_Hlk>
Subject: Re: [Unbearable] I-D Action: draft-ietf-tokbind-tls13-0rtt-02.txt
X-BeenThere: unbearable@ietf.org
X-Mailman-Version: 2.1.22
Precedence: list
List-Id: "\"This list is for discussion of proposals for doing better than bearer tokens \(e.g. HTTP cookies, OAuth tokens etc.\) for web applications. The specific goal is chartering a WG focused on preventing security token export and replay attacks.\"" <unbearable.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/unbearable>, <mailto:unbearable-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/unbearable/>
List-Post: <mailto:unbearable@ietf.org>
List-Help: <mailto:unbearable-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/unbearable>, <mailto:unbearable-request@ietf.org?subject=subscribe>
X-List-Received-Date: Wed, 28 Jun 2017 22:25:50 -0000

Here's a summary of the changes since the last draft:

- If TB is accepted in 0-RTT data, keep using the early exporter for
the whole connection. There was some discussion on this in Chicago,
with more on the mailing list. Chairs, can you confirm whether we
reached consensus on the mailing list or whether we should take a hum
in Prague?

- 0-RTT TB cannot be used with externally provisioned PSKs or with a
PSK-only key exchange mode

- A new TLS extension is used for negotiating and indicating use of 0-RTT TB

- The replay indication TLS extension has been removed

- Some editorial and document structure changes

On Wed, Jun 28, 2017 at 3:12 PM,  <internet-drafts@ietf.org> wrote:
>
> A New Internet-Draft is available from the on-line Internet-Drafts directories.
> This draft is a work item of the Token Binding of the IETF.
>
>         Title           : Token Binding for 0-RTT TLS 1.3 Connections
>         Author          : Nick Harper
>         Filename        : draft-ietf-tokbind-tls13-0rtt-02.txt
>         Pages           : 11
>         Date            : 2017-06-28
>
> Abstract:
>    This document describes how Token Binding can be used in the 0-RTT
>    data of a TLS 1.3 connection.  This involves a new TLS extension to
>    negotiate and indicate the use of Token Binding in 0-RTT data.  A
>    TokenBindingMessage sent in 0-RTT data has different security
>    properties than one sent after the TLS handshake has finished, which
>    this document also describes.
>
>
> The IETF datatracker status page for this draft is:
> https://datatracker.ietf.org/doc/draft-ietf-tokbind-tls13-0rtt/
>
> There are also htmlized versions available at:
> https://tools.ietf.org/html/draft-ietf-tokbind-tls13-0rtt-02
> https://datatracker.ietf.org/doc/html/draft-ietf-tokbind-tls13-0rtt-02
>
> A diff from the previous version is available at:
> https://www.ietf.org/rfcdiff?url2=draft-ietf-tokbind-tls13-0rtt-02
>
>
> Please note that it may take a couple of minutes from the time of submission
> until the htmlized version and diff are available at tools.ietf.org.
>
> Internet-Drafts are also available by anonymous FTP at:
> ftp://ftp.ietf.org/internet-drafts/
>
> _______________________________________________
> Unbearable mailing list
> Unbearable@ietf.org
> https://www.ietf.org/mailman/listinfo/unbearable


From nobody Wed Jun 28 15:37:51 2017
Return-Path: <nharper@google.com>
X-Original-To: unbearable@ietfa.amsl.com
Delivered-To: unbearable@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id C905612EC2A for <unbearable@ietfa.amsl.com>; Wed, 28 Jun 2017 15:37:50 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.702
X-Spam-Level: 
X-Spam-Status: No, score=-2.702 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, RCVD_IN_DNSWL_LOW=-0.7, RP_MATCHES_RCVD=-0.001, SPF_PASS=-0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (2048-bit key) header.d=google.com
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id CnvZ84pdQgOt for <unbearable@ietfa.amsl.com>; Wed, 28 Jun 2017 15:37:47 -0700 (PDT)
Received: from mail-lf0-x229.google.com (mail-lf0-x229.google.com [IPv6:2a00:1450:4010:c07::229]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 41337129C2B for <unbearable@ietf.org>; Wed, 28 Jun 2017 15:37:47 -0700 (PDT)
Received: by mail-lf0-x229.google.com with SMTP id b207so43011119lfg.2 for <unbearable@ietf.org>; Wed, 28 Jun 2017 15:37:47 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=20161025; h=mime-version:from:date:message-id:subject:to; bh=bTmD+5BxWBdNBbUxK1QBF9mrQISqPfFLjRclmQ/DXRU=; b=YLt/7zu12dGy5IL9YcmtpK1mDC9CCmiXcPDz9gXd1CeELWAb8UC2oq6P+2FvrC9K/T vQt8AlMwiJYv6YQgNnaq8YjRTSycH2LZp7c0qFskfM2ANuTtWp5cgIu9wmM5jL4bD0ou A3QxefUCXZAYmKYX1zhNvU6a/mvD+xnRqe3tw/qC8Jp23hlb/EF/kk0OdB6oeYFpb3tT 7pkoNX23t0SWLLbtx+1CaD3WLXojwMfX3O2DWRQ/Zbluq0/AZZ5KqjliuodlGdo/7pj4 A8aBiYdbeyr67TOZ29hl5R0q764Zunff7oMLHyqBEtFudgnPpf3sqhZjrMZ4BLGG96J1 LVYg==
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20161025; h=x-gm-message-state:mime-version:from:date:message-id:subject:to; bh=bTmD+5BxWBdNBbUxK1QBF9mrQISqPfFLjRclmQ/DXRU=; b=DVdqIVjIZbLFr02aEhDZfJpdg6JwLx+BDRrAzTcFXsriqBMFR0MNVal9qdHkCQdISB 9hmmMXfxZn5//o2uL0ar8Lya3BwN2x2o8h7J8UraA4WreNRxvdRbedA8FqzXDOc0Tzai SUCzJaPNUsK+shzeWWH0NkZnfXLrQlx5EdDY0HhPVyteNVkYhGszcaYV+E/S+t0TV0Os fasTXJTXoSfGYLEld0X/EoluZbkRTWikiI9C13kV2Zjzj2LcnUXjv7lw8rUPgJ0caFIo n5t6wNFRK3Ay69KjI4iiNmn9LlR5f/m1a6gaqqzmIuEGP35XKgP1NoS9NytTjEB5L5nC LnBg==
X-Gm-Message-State: AKS2vOxBUnIwMwwx24+R7oQFDEmz1eWyswqa41GerHk/h+qIqFDxyq7L suKI3WJFaglPiG6hS4aUImPVvnXtMOG6tT1gJg==
X-Received: by 10.46.75.9 with SMTP id y9mr3867135lja.60.1498689465088; Wed, 28 Jun 2017 15:37:45 -0700 (PDT)
MIME-Version: 1.0
Received: by 10.25.44.73 with HTTP; Wed, 28 Jun 2017 15:37:24 -0700 (PDT)
From: Nick Harper <nharper@google.com>
Date: Wed, 28 Jun 2017 15:37:24 -0700
Message-ID: <CACdeXiJmaP4=TLKBhVsZmaPA=ayZMLSWiMxM1pHYM6gMVK4zKQ@mail.gmail.com>
To: IETF Tokbind WG <unbearable@ietf.org>
Content-Type: text/plain; charset="UTF-8"
Archived-At: <https://mailarchive.ietf.org/arch/msg/unbearable/j6K-nW0xsb0QEySSBZ950BIlHAI>
Subject: [Unbearable] TLS 1.3 support for Token Binding
X-BeenThere: unbearable@ietf.org
X-Mailman-Version: 2.1.22
Precedence: list
List-Id: "\"This list is for discussion of proposals for doing better than bearer tokens \(e.g. HTTP cookies, OAuth tokens etc.\) for web applications. The specific goal is chartering a WG focused on preventing security token export and replay attacks.\"" <unbearable.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/unbearable>, <mailto:unbearable-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/unbearable/>
List-Post: <mailto:unbearable@ietf.org>
List-Help: <mailto:unbearable-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/unbearable>, <mailto:unbearable-request@ietf.org?subject=subscribe>
X-List-Received-Date: Wed, 28 Jun 2017 22:37:51 -0000

draft-ietf-tokbind-tls13-0rtt is defining how Token Binding can work
on 0-RTT connections, but so far this WG doesn't have anything
defining how Token Binding should work in TLS 1.3 on connections
without early data. I'm fine adding that to
draft-ietf-tokbind-tls13-0rtt, but I think it would be better suited
to be in a separate draft. (A separate draft would allow those who
don't care for 0-RTT Token Binding to completely ignore it when
implementing Token Binding for TLS 1.3.)

Here's what I think needs to be in a TLS 1.3 Token Binding draft:
- negotiation extension goes in EncryptedExtensions instead of ServerHello
- clarify definition of exporter using TLS 1.3 terminology instead of
RFC 5705 terminology
- define some behavior for the interaction of the TB negotiation
extension with 0-RTT (in this draft, it would be "don't use TB with
0-RTT")

Do other WG members think we need a separate draft for that?


From nobody Wed Jun 28 19:48:29 2017
Return-Path: <kaduk@mit.edu>
X-Original-To: unbearable@ietfa.amsl.com
Delivered-To: unbearable@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id CB135126C22; Wed, 28 Jun 2017 19:48:27 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -4.222
X-Spam-Level: 
X-Spam-Status: No, score=-4.222 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, RCVD_IN_DNSWL_MED=-2.3, RCVD_IN_MSPIKE_H3=-0.01, RCVD_IN_MSPIKE_WL=-0.01, RP_MATCHES_RCVD=-0.001, SPF_PASS=-0.001] autolearn=ham autolearn_force=no
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id ze_yeyMD3Gwl; Wed, 28 Jun 2017 19:48:26 -0700 (PDT)
Received: from dmz-mailsec-scanner-5.mit.edu (dmz-mailsec-scanner-5.mit.edu [18.7.68.34]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 15D8E12420B; Wed, 28 Jun 2017 19:48:25 -0700 (PDT)
X-AuditID: 12074422-365ff70000007251-3a-59546a77bd30
Received: from mailhub-auth-3.mit.edu ( [18.9.21.43]) (using TLS with cipher DHE-RSA-AES256-SHA (256/256 bits)) (Client did not present a certificate) by dmz-mailsec-scanner-5.mit.edu (Symantec Messaging Gateway) with SMTP id E9.91.29265.77A64595; Wed, 28 Jun 2017 22:48:24 -0400 (EDT)
Received: from outgoing.mit.edu (outgoing-auth-1.mit.edu [18.9.28.11]) by mailhub-auth-3.mit.edu (8.13.8/8.9.2) with ESMTP id v5T2mMlq030950; Wed, 28 Jun 2017 22:48:23 -0400
Received: from kduck.kaduk.org (24-107-191-124.dhcp.stls.mo.charter.com [24.107.191.124]) (authenticated bits=56) (User authenticated as kaduk@ATHENA.MIT.EDU) by outgoing.mit.edu (8.13.8/8.12.4) with ESMTP id v5T2mIdQ007455 (version=TLSv1/SSLv3 cipher=DHE-RSA-AES256-SHA bits=256 verify=NOT); Wed, 28 Jun 2017 22:48:21 -0400
Date: Wed, 28 Jun 2017 21:48:18 -0500
From: Benjamin Kaduk <kaduk@mit.edu>
To: Nick Harper <nharper@google.com>
Cc: IETF Tokbind WG <unbearable@ietf.org>, tokbind-chairs@ietf.org
Message-ID: <20170629024818.GI68391@kduck.kaduk.org>
References: <149868793805.5443.4284920405751222901@ietfa.amsl.com> <CACdeXiLqmdVpQryrPOBnUrbrk24Vap7QrASK-_vnwH91vwkZ3A@mail.gmail.com>
MIME-Version: 1.0
Content-Type: text/plain; charset=us-ascii
Content-Disposition: inline
In-Reply-To: <CACdeXiLqmdVpQryrPOBnUrbrk24Vap7QrASK-_vnwH91vwkZ3A@mail.gmail.com>
User-Agent: Mutt/1.7.1 (2016-10-04)
X-Brightmail-Tracker: H4sIAAAAAAAAA+NgFnrHIsWRmVeSWpSXmKPExsUixCmqrVuRFRJpMO+ChUX/jn2MFsvnz2ez OPd4IZMDs8eCTaUeS5b8ZApgiuKySUnNySxLLdK3S+DKaJlyl7HgH3fFpjkn2RsYT3F2MXJy SAiYSJzedoCti5GLQ0hgMZNER287M4SzkVHi3OEZUJmrTBK3zq5jB2lhEVCVWLz9JAuIzSag ItHQfZkZxBYBsudfvc4KYjMLOEl8e9HHBGILC3hJzFj0BKieg4MXaN37SSEgYSGBTkaJhwvl QGxeAUGJkzOfsEC0aknc+PeSCaScWUBaYvk/DpAwp0CgxL31G8EuEBVQlvh7+B7LBEaBWUi6 ZyHpnoXQvYCReRWjbEpulW5uYmZOcWqybnFyYl5eapGuqV5uZoleakrpJkZQsLK7KO1gnPjP 6xCjAAejEg8vw9rgSCHWxLLiytxDjJIcTEqivNEJIZFCfEn5KZUZicUZ8UWlOanFhxglOJiV RHi5zIFyvCmJlVWpRfkwKWkOFiVxXnGNxgghgfTEktTs1NSC1CKYrAwHh5IEb2kmUKNgUWp6 akVaZk4JQpqJgxNkOA/QcLZ4kOHFBYm5xZnpEPlTjIpS4rx3MoASAiCJjNI8uF5QMpHI3l/z ilEc6BVh3t0gK3iAiQiu+xXQYCagwSzzAkAGlyQipKQaGHlnrlKqP7BMikvYqOH8vfX/5Vd+ OHJOOIx7e4q7/9Fl/+4zXnp1+6D+TOklbFeXKrC+s5w0a631/les796e9ujq6/h1P0zv0IU9 twSKAx6Z+28NeJla0i2bwLI/su/08Sa+h5OnrHxjHctzVuc/U3/+pOr1zF4GxlsclhbxdK9N M8go9e97nqbEUpyRaKjFXFScCAA/fa1mAQMAAA==
Archived-At: <https://mailarchive.ietf.org/arch/msg/unbearable/vUdaErXk9Vvjy-HveDeJ_aLIRVY>
Subject: Re: [Unbearable] I-D Action: draft-ietf-tokbind-tls13-0rtt-02.txt
X-BeenThere: unbearable@ietf.org
X-Mailman-Version: 2.1.22
Precedence: list
List-Id: "\"This list is for discussion of proposals for doing better than bearer tokens \(e.g. HTTP cookies, OAuth tokens etc.\) for web applications. The specific goal is chartering a WG focused on preventing security token export and replay attacks.\"" <unbearable.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/unbearable>, <mailto:unbearable-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/unbearable/>
List-Post: <mailto:unbearable@ietf.org>
List-Help: <mailto:unbearable-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/unbearable>, <mailto:unbearable-request@ietf.org?subject=subscribe>
X-List-Received-Date: Thu, 29 Jun 2017 02:48:28 -0000

On Wed, Jun 28, 2017 at 03:25:13PM -0700, Nick Harper wrote:
> Here's a summary of the changes since the last draft:
> 
> - If TB is accepted in 0-RTT data, keep using the early exporter for
> the whole connection. There was some discussion on this in Chicago,
> with more on the mailing list. Chairs, can you confirm whether we
> reached consensus on the mailing list or whether we should take a hum
> in Prague?

I am a WG chair, but not a tokbind chair, but that question does not
seem to make sense.  Consensus must be reached (or confirmed) on the
mailing list, so deciding there wasn't enough feedback on the list and
going to an in-room hum seems backwards, procedurally.

> - 0-RTT TB cannot be used with externally provisioned PSKs or with a
> PSK-only key exchange mode
> 
> - A new TLS extension is used for negotiating and indicating use of 0-RTT TB
> 
> - The replay indication TLS extension has been removed

Some discussion on the httpbis list brought up that this document should
mandate that 0-RTT token binding is only used in conjunction with
a TLS stack that provides strong anti-replay protections (i.e., zero
additional replays possible and one retransmission via DKG attack).  In other
words, the time-based scheme of (draft-02) section 6.4 should be removed,
and perhaps 6.3.1 reworded somewhat.

(It also brought up multiple peoples' sentiments that 0-RTT token binding
is a bad idea in general, but this may not be procedurally the right time
to have that discussion.)

-Ben


From nobody Thu Jun 29 02:05:43 2017
Return-Path: <leifj@sunet.se>
X-Original-To: unbearable@ietfa.amsl.com
Delivered-To: unbearable@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id E17BF12ECCB for <unbearable@ietfa.amsl.com>; Thu, 29 Jun 2017 02:05:42 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.601
X-Spam-Level: 
X-Spam-Status: No, score=-2.601 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, RCVD_IN_DNSWL_LOW=-0.7, SPF_PASS=-0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (2048-bit key) header.d=sunet-se.20150623.gappssmtp.com
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id 1rGmrh-d7W8f for <unbearable@ietfa.amsl.com>; Thu, 29 Jun 2017 02:05:41 -0700 (PDT)
Received: from mail-lf0-x22d.google.com (mail-lf0-x22d.google.com [IPv6:2a00:1450:4010:c07::22d]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 7956412ECEF for <unbearable@ietf.org>; Thu, 29 Jun 2017 02:05:34 -0700 (PDT)
Received: by mail-lf0-x22d.google.com with SMTP id l13so48951120lfl.1 for <unbearable@ietf.org>; Thu, 29 Jun 2017 02:05:34 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=sunet-se.20150623.gappssmtp.com; s=20150623; h=subject:to:cc:references:from:message-id:date:user-agent :mime-version:in-reply-to:content-language:content-transfer-encoding; bh=XJwQiYKnatnzzxkBQV+9HxeK/obAFQp76i9wJOcisO8=; b=wOsz2VPdrdhlONpC9mFnuJkezQ+F57yGNFhdpsa1hmb1zsJgjU/bL1deqAC0HrF+5k RmDqI5/t1QIEJkvnlfiwDsxQ5jRqq8clMzTxE4fD1HMCqNqqgZ6Buf++9v2BpRjVzPq8 AlRwU38JA/ZxIaczboowHpbIpC73n95vWOTtFreyWr1TBYSFQrihhmS52jFQCTgmLWo6 WveRhQQdO81U2UbkFgfo2p3N4JalWKFV7BPNji427qWl9BX4aNbkHv950d6j9mepKzx/ pCl+09ap8q33nmWLiCNnSoviIKGcsQALyx9CgGQBNQiMa6KCds2B6fIjhtmRbUJbIZzh E4Kg==
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20161025; h=x-gm-message-state:subject:to:cc:references:from:message-id:date :user-agent:mime-version:in-reply-to:content-language :content-transfer-encoding; bh=XJwQiYKnatnzzxkBQV+9HxeK/obAFQp76i9wJOcisO8=; b=KLUjcrTMf44HKbL4daG/z3QPovw5gRA9M7OkxykgM2r059UmhO0KXlcj1YPgy4TLTZ O2UDbWfdsPCNZWvFZ/H1c/0gzjBtv3QLsoPCjXBW6prNGEg8QFtYFkBcOHHI35haYTPC SInNKXpeLKTrQt46puQWYTpq+wXecKyNAHVKDqN+Sf1rm+uay3JrxjMCYoBfN4nQwYsQ HGIPramULSnA+LOQFdi6YqhsoWtnC+rv6FNuYJf91e1E+Qu68WGKYLiOL2aZwXRbQiHN XLqypA/1h3GiVl7ZrZcduGNsR8W1dHW0o1U16BxPRDaL+jZrqY6vCaTLZGziVbO9pGdw 0TYQ==
X-Gm-Message-State: AKS2vOxc2tzXDtjffTjDFXq1360UpEmeG/0xoX4JQJvupA/fc0EAFgUe 3y+6g9rJP7oi/IEh
X-Received: by 10.25.16.224 with SMTP id 93mr5336349lfq.118.1498727132975; Thu, 29 Jun 2017 02:05:32 -0700 (PDT)
Received: from [10.0.0.129] (h-155-4-129-189.NA.cust.bahnhof.se. [155.4.129.189]) by smtp.gmail.com with ESMTPSA id r203sm1135626lff.67.2017.06.29.02.05.32 (version=TLS1_2 cipher=ECDHE-RSA-AES128-GCM-SHA256 bits=128/128); Thu, 29 Jun 2017 02:05:32 -0700 (PDT)
To: Benjamin Kaduk <kaduk@mit.edu>, Nick Harper <nharper@google.com>
Cc: IETF Tokbind WG <unbearable@ietf.org>, tokbind-chairs@ietf.org
References: <149868793805.5443.4284920405751222901@ietfa.amsl.com> <CACdeXiLqmdVpQryrPOBnUrbrk24Vap7QrASK-_vnwH91vwkZ3A@mail.gmail.com> <20170629024818.GI68391@kduck.kaduk.org>
From: Leif Johansson <leifj@sunet.se>
Message-ID: <9057a735-a907-d06c-327b-a959e4f554f0@sunet.se>
Date: Thu, 29 Jun 2017 11:05:31 +0200
User-Agent: Mozilla/5.0 (X11; Linux x86_64; rv:52.0) Gecko/20100101 Thunderbird/52.1.1
MIME-Version: 1.0
In-Reply-To: <20170629024818.GI68391@kduck.kaduk.org>
Content-Type: text/plain; charset=utf-8
Content-Language: en-US
Content-Transfer-Encoding: 7bit
Archived-At: <https://mailarchive.ietf.org/arch/msg/unbearable/wzhPONpcnVjDyoffaS1T0v9oTjg>
Subject: Re: [Unbearable] I-D Action: draft-ietf-tokbind-tls13-0rtt-02.txt
X-BeenThere: unbearable@ietf.org
X-Mailman-Version: 2.1.22
Precedence: list
List-Id: "\"This list is for discussion of proposals for doing better than bearer tokens \(e.g. HTTP cookies, OAuth tokens etc.\) for web applications. The specific goal is chartering a WG focused on preventing security token export and replay attacks.\"" <unbearable.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/unbearable>, <mailto:unbearable-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/unbearable/>
List-Post: <mailto:unbearable@ietf.org>
List-Help: <mailto:unbearable-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/unbearable>, <mailto:unbearable-request@ietf.org?subject=subscribe>
X-List-Received-Date: Thu, 29 Jun 2017 09:05:43 -0000

On 2017-06-29 04:48, Benjamin Kaduk wrote:
> On Wed, Jun 28, 2017 at 03:25:13PM -0700, Nick Harper wrote:
>> Here's a summary of the changes since the last draft:
>>
>> - If TB is accepted in 0-RTT data, keep using the early exporter for
>> the whole connection. There was some discussion on this in Chicago,
>> with more on the mailing list. Chairs, can you confirm whether we
>> reached consensus on the mailing list or whether we should take a hum
>> in Prague?
> 
> I am a WG chair, but not a tokbind chair, but that question does not
> seem to make sense.  Consensus must be reached (or confirmed) on the
> mailing list, so deciding there wasn't enough feedback on the list and
> going to an in-room hum seems backwards, procedurally.

Judging consensus is sometimes tricky. I think what Nick meant was that
we may want to do a hum in Prague /in addition to/ seeking confirmation
on the list.

> 
>> - 0-RTT TB cannot be used with externally provisioned PSKs or with a
>> PSK-only key exchange mode
>>
>> - A new TLS extension is used for negotiating and indicating use of 0-RTT TB
>>
>> - The replay indication TLS extension has been removed
> 
> Some discussion on the httpbis list brought up that this document should
> mandate that 0-RTT token binding is only used in conjunction with
> a TLS stack that provides strong anti-replay protections (i.e., zero
> additional replays possible and one retransmission via DKG attack).  In other
> words, the time-based scheme of (draft-02) section 6.4 should be removed,
> and perhaps 6.3.1 reworded somewhat.
> 
> (It also brought up multiple peoples' sentiments that 0-RTT token binding
> is a bad idea in general, but this may not be procedurally the right time
> to have that discussion.)
> 
> -Ben
> 


From nobody Thu Jun 29 11:33:27 2017
Return-Path: <nharper@google.com>
X-Original-To: unbearable@ietfa.amsl.com
Delivered-To: unbearable@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 2AD77129B05 for <unbearable@ietfa.amsl.com>; Thu, 29 Jun 2017 11:33:26 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.701
X-Spam-Level: 
X-Spam-Status: No, score=-2.701 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, RCVD_IN_DNSWL_LOW=-0.7, RP_MATCHES_RCVD=-0.001, SPF_PASS=-0.001, URIBL_BLOCKED=0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (2048-bit key) header.d=google.com
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id CuAk5GL2tRK6 for <unbearable@ietfa.amsl.com>; Thu, 29 Jun 2017 11:33:24 -0700 (PDT)
Received: from mail-lf0-x236.google.com (mail-lf0-x236.google.com [IPv6:2a00:1450:4010:c07::236]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 0A2AF126BFD for <unbearable@ietf.org>; Thu, 29 Jun 2017 11:33:24 -0700 (PDT)
Received: by mail-lf0-x236.google.com with SMTP id b207so57779273lfg.2 for <unbearable@ietf.org>; Thu, 29 Jun 2017 11:33:23 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=20161025; h=mime-version:in-reply-to:references:from:date:message-id:subject:to :cc; bh=Ua1ZkDOf29VG73xxJUxfdXSwV4etdm+e7/jy/yy1XNs=; b=joa8uG0WV1qb+wNHCvnyEe6B0aYwaXvhx/r8Mx/2V28JOEeg70tbz2ia6dosQ4zA+R ryts5MB6DgSz28iTZGdqqecGomMY7/6YC84dRkfJ70aBe2cUBlxl49Qj1TzLk3zcRlO6 ZOG0/iZ6ANJwSGnfOUl1tBDVDR8TnRwU7G0/pF86CQWCl8Ei9whDbmOlbAy9BhtRCQ/o k3Ay5nwFYWNWZjiVNuhR/HWHXw3e5yWk/fE9ZPdzelLQpEURX0i4D56MoS3+JtpRXwiE yYcI56fKZ1PJ67O/DbDasgz6Ls2YoMIG5se0iiHZ+Vbyvu7TlNkAOmTZ1wN9Ym/IDRjd xxMw==
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20161025; h=x-gm-message-state:mime-version:in-reply-to:references:from:date :message-id:subject:to:cc; bh=Ua1ZkDOf29VG73xxJUxfdXSwV4etdm+e7/jy/yy1XNs=; b=JhlJur4nNzZb+SyyjUGhVFKFARzALAl5QAW03SuZmr5Le4z2vqMr9Wop18EmnPJ99C 0B+zbxNdTVQLJnTacWf4XHlII8g9HXYCq1j0P8UTkiFrijOvPDpYYY1m7KloYI/HalRc xADLmXWNG0PBsG3yVuxtetgHbyuXLYgr5hbDMcUv+cEcanl7jewvN/YrDcFmO7TeXMCr IU9pDi2o7I04CYyAAjYaiVg5Uys0yc+Sg1OvxY/J2g9rY2XPAuaTti0nd5AEd5L2aIQM r6aoc3+M3K8MHbrypwMgCKvXpdW+VAe4kcUSxoL960iJI0sme2ISxdV17dqHp7Ism845 ubEg==
X-Gm-Message-State: AKS2vOwAUUxod/r2JzIUrraej/kDyBmjMI+k/Y0WjGzaI/0HhOSzgR2C Vp+qnXfnX5dVJlqilfISU33GeJCdh70wjFqwUw==
X-Received: by 10.46.71.21 with SMTP id u21mr2888245lja.115.1498761202063; Thu, 29 Jun 2017 11:33:22 -0700 (PDT)
MIME-Version: 1.0
Received: by 10.25.44.73 with HTTP; Thu, 29 Jun 2017 11:33:01 -0700 (PDT)
In-Reply-To: <9057a735-a907-d06c-327b-a959e4f554f0@sunet.se>
References: <149868793805.5443.4284920405751222901@ietfa.amsl.com> <CACdeXiLqmdVpQryrPOBnUrbrk24Vap7QrASK-_vnwH91vwkZ3A@mail.gmail.com> <20170629024818.GI68391@kduck.kaduk.org> <9057a735-a907-d06c-327b-a959e4f554f0@sunet.se>
From: Nick Harper <nharper@google.com>
Date: Thu, 29 Jun 2017 11:33:01 -0700
Message-ID: <CACdeXiKOGptZ2WSZ_nVo-LmS5W0kqUszx_BpOcOWnfV05KO7mQ@mail.gmail.com>
To: Leif Johansson <leifj@sunet.se>
Cc: Benjamin Kaduk <kaduk@mit.edu>, IETF Tokbind WG <unbearable@ietf.org>, tokbind-chairs@ietf.org
Content-Type: text/plain; charset="UTF-8"
Archived-At: <https://mailarchive.ietf.org/arch/msg/unbearable/4s80fYwG2hSnwe6PxnYcWDlLNGo>
Subject: Re: [Unbearable] I-D Action: draft-ietf-tokbind-tls13-0rtt-02.txt
X-BeenThere: unbearable@ietf.org
X-Mailman-Version: 2.1.22
Precedence: list
List-Id: "\"This list is for discussion of proposals for doing better than bearer tokens \(e.g. HTTP cookies, OAuth tokens etc.\) for web applications. The specific goal is chartering a WG focused on preventing security token export and replay attacks.\"" <unbearable.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/unbearable>, <mailto:unbearable-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/unbearable/>
List-Post: <mailto:unbearable@ietf.org>
List-Help: <mailto:unbearable-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/unbearable>, <mailto:unbearable-request@ietf.org?subject=subscribe>
X-List-Received-Date: Thu, 29 Jun 2017 18:33:26 -0000

On Thu, Jun 29, 2017 at 2:05 AM, Leif Johansson <leifj@sunet.se> wrote:
> On 2017-06-29 04:48, Benjamin Kaduk wrote:
>> On Wed, Jun 28, 2017 at 03:25:13PM -0700, Nick Harper wrote:
>>> Here's a summary of the changes since the last draft:
>>>
>>> - If TB is accepted in 0-RTT data, keep using the early exporter for
>>> the whole connection. There was some discussion on this in Chicago,
>>> with more on the mailing list. Chairs, can you confirm whether we
>>> reached consensus on the mailing list or whether we should take a hum
>>> in Prague?
>>
>> I am a WG chair, but not a tokbind chair, but that question does not
>> seem to make sense.  Consensus must be reached (or confirmed) on the
>> mailing list, so deciding there wasn't enough feedback on the list and
>> going to an in-room hum seems backwards, procedurally.
>
> Judging consensus is sometimes tricky. I think what Nick meant was that
> we may want to do a hum in Prague /in addition to/ seeking confirmation
> on the list.

It is unclear to me whether consensus was reached (hence deferring to
the chairs on that judgement). If we don't have consensus, I'm fine
continuing the discussion on list and in Prague. Let me check that I
understand the process properly: first, discuss (on list and possibly
in person), then if the discussion sounds like it's reached a
consensus, optionally hum in person, and then confirm consensus on the
list. Does that sound about right?
>
>>
>>> - 0-RTT TB cannot be used with externally provisioned PSKs or with a
>>> PSK-only key exchange mode
>>>
>>> - A new TLS extension is used for negotiating and indicating use of 0-RTT TB
>>>
>>> - The replay indication TLS extension has been removed
>>
>> Some discussion on the httpbis list brought up that this document should
>> mandate that 0-RTT token binding is only used in conjunction with
>> a TLS stack that provides strong anti-replay protections (i.e., zero
>> additional replays possible and one retransmission via DKG attack).  In other
>> words, the time-based scheme of (draft-02) section 6.4 should be removed,
>> and perhaps 6.3.1 reworded somewhat.

I read over the "New Version Notification for
draft-thomson-http-replay-00.txt" thread on the httpbis list. My
understanding of the issue raised on that list is simply that there
are attacks on 0-RTT Token Binding if there isn't a strict global
anti-replay mechanism. There are still attacks possible on 0-RTT Token
Binding even if there is a strict global anti-replay mechanism. I need
to consider what additional attacks are possible without such a
mechanism, and if any of those attacks require less privileges than
the attacks possible with the mechanism.
>>
>> (It also brought up multiple peoples' sentiments that 0-RTT token binding
>> is a bad idea in general, but this may not be procedurally the right time
>> to have that discussion.)
>>
>> -Ben
>>
>
I'm aware that multiple people think that 0-RTT token binding is a bad
idea in general. So far, the impression I've gotten of this sentiment
is "0-RTT Token Binding is not something I have any interest in
implementing". If the sentiment is closer to "0-RTT Token Binding is
such a horrible thing that no one should be implementing it", then
maybe we should discuss that sooner.


From nobody Thu Jun 29 12:02:33 2017
Return-Path: <ve7jtb@ve7jtb.com>
X-Original-To: unbearable@ietfa.amsl.com
Delivered-To: unbearable@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 75E39129ABD for <unbearable@ietfa.amsl.com>; Thu, 29 Jun 2017 12:02:26 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.899
X-Spam-Level: 
X-Spam-Status: No, score=-1.899 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, HTML_MESSAGE=0.001, RCVD_IN_DNSWL_NONE=-0.0001, SPF_PASS=-0.001, URIBL_BLOCKED=0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (2048-bit key) header.d=ve7jtb-com.20150623.gappssmtp.com
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id K6xb8aQrULKh for <unbearable@ietfa.amsl.com>; Thu, 29 Jun 2017 12:02:24 -0700 (PDT)
Received: from mail-qt0-x234.google.com (mail-qt0-x234.google.com [IPv6:2607:f8b0:400d:c0d::234]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id AA614126D05 for <unbearable@ietf.org>; Thu, 29 Jun 2017 12:02:12 -0700 (PDT)
Received: by mail-qt0-x234.google.com with SMTP id i2so82246379qta.3 for <unbearable@ietf.org>; Thu, 29 Jun 2017 12:02:12 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=ve7jtb-com.20150623.gappssmtp.com; s=20150623; h=from:message-id:mime-version:subject:date:in-reply-to:cc:to :references; bh=0L0jPyG9Cq+Gbgei0NGfi14pne3Rlwmol7RqTF+iM2U=; b=IuhpPX1iw5ajhtat5MQHaarwe1724xVwY2J574/MZz43Rs+m3EEoXQ8KZPz/Jv9XCV gjgkDnO1Lh/MWsN2wYAMs/TNRe51cVprmk8lXc6DizdCdTKL/ETslfC3X729DnJ3sO3Y RD9+cXo7YFvgiujMwKpDNwtmHIkDm79uiptS9cJgwTM1MihY2Szsec9CAeGqIPtu3sFJ zTbK8tUt022Ox8N2xiqqaCDLFlmsyi+QyS8MdbKJs2MmUYxtoIuKFSvVWMu+ZWQw3A3q tEWYcq7sgWLBVdTWsIaCg7EHHkyFgbWQ5a1SuN1IlYxQFxQfNM7C1PHfS9NE4UBmhDe2 ueiQ==
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20161025; h=x-gm-message-state:from:message-id:mime-version:subject:date :in-reply-to:cc:to:references; bh=0L0jPyG9Cq+Gbgei0NGfi14pne3Rlwmol7RqTF+iM2U=; b=Lk89fBc3B5ach6GYoB1UvYeBDWZHZHZBwfjot0+CuTo1tHv3t3NmH2hzP4Yy8QRPLG L6e+qQqNiHfKD34fIIS0yw59LCuIwUAZVBn8gpIG1nqazNoEdRyOwmy6S2CkL3ztOiLF FK03jf2pVa6mJ/REGkEzFwU3wYghYTwAM8vvgRaTNIWgAmqcUMCOapMmzmMplvp7SJws fX0aVb5Q1IXw/3vsAxInjSQFQvaCevTa5tmWyW36E32PDb34WRgdEhWFgIZs/8ZzEo5s H6cz83VmOwtiAL5j8ZWXU6qQV2wbPpE2dgZxiZYgIg8lp86Ec4fABqJYKUJqeU65rtlw Y/JA==
X-Gm-Message-State: AKS2vOzFE2dQgSrz0dcM/CQ9bXdGismwixxH8dXxh/qGRTNYFFgF7rwX JE+4CL2uVjjNmOzY
X-Received: by 10.200.9.55 with SMTP id t52mr21947108qth.107.1498762930343; Thu, 29 Jun 2017 12:02:10 -0700 (PDT)
Received: from johns-mbp.lan ([191.115.107.144]) by smtp.gmail.com with ESMTPSA id l207sm4318914qke.36.2017.06.29.12.02.07 (version=TLS1_2 cipher=ECDHE-RSA-AES128-GCM-SHA256 bits=128/128); Thu, 29 Jun 2017 12:02:09 -0700 (PDT)
From: John Bradley <ve7jtb@ve7jtb.com>
Message-Id: <97A1224B-5B6C-41EC-9FE0-CA0DE53746E1@ve7jtb.com>
Mime-Version: 1.0 (Mac OS X Mail 10.3 \(3273\))
Date: Thu, 29 Jun 2017 15:02:05 -0400
In-Reply-To: <CACdeXiKOGptZ2WSZ_nVo-LmS5W0kqUszx_BpOcOWnfV05KO7mQ@mail.gmail.com>
Cc: Leif Johansson <leifj@sunet.se>, Benjamin Kaduk <kaduk@mit.edu>, IETF Tokbind WG <unbearable@ietf.org>, tokbind-chairs@ietf.org
To: Nick Harper <nharper@google.com>
References: <149868793805.5443.4284920405751222901@ietfa.amsl.com> <CACdeXiLqmdVpQryrPOBnUrbrk24Vap7QrASK-_vnwH91vwkZ3A@mail.gmail.com> <20170629024818.GI68391@kduck.kaduk.org> <9057a735-a907-d06c-327b-a959e4f554f0@sunet.se> <CACdeXiKOGptZ2WSZ_nVo-LmS5W0kqUszx_BpOcOWnfV05KO7mQ@mail.gmail.com>
X-Mailer: Apple Mail (2.3273)
Content-Type: multipart/signed; protocol="application/pkcs7-signature"; micalg=sha-256; boundary="001a1144dfa027f58005531df0fc"
Archived-At: <https://mailarchive.ietf.org/arch/msg/unbearable/jL4MdhRPc16aFGAtpwxGx_xbg1g>
Subject: Re: [Unbearable] I-D Action: draft-ietf-tokbind-tls13-0rtt-02.txt
X-BeenThere: unbearable@ietf.org
X-Mailman-Version: 2.1.22
Precedence: list
List-Id: "\"This list is for discussion of proposals for doing better than bearer tokens \(e.g. HTTP cookies, OAuth tokens etc.\) for web applications. The specific goal is chartering a WG focused on preventing security token export and replay attacks.\"" <unbearable.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/unbearable>, <mailto:unbearable-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/unbearable/>
List-Post: <mailto:unbearable@ietf.org>
List-Help: <mailto:unbearable-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/unbearable>, <mailto:unbearable-request@ietf.org?subject=subscribe>
X-List-Received-Date: Thu, 29 Jun 2017 19:02:26 -0000

--001a1144dfa027f58005531df0fc
Content-Type: multipart/alternative;
 boundary="Apple-Mail=_079E6D8C-19FC-4992-B425-7E25BF8A101A"


--Apple-Mail=_079E6D8C-19FC-4992-B425-7E25BF8A101A
Content-Transfer-Encoding: quoted-printable
Content-Type: text/plain;
	charset=utf-8

Inline

> On Jun 29, 2017, at 2:33 PM, Nick Harper <nharper@google.com> wrote:
>=20
> On Thu, Jun 29, 2017 at 2:05 AM, Leif Johansson <leifj@sunet.se =
<mailto:leifj@sunet.se>> wrote:
>> On 2017-06-29 04:48, Benjamin Kaduk wrote:
>>> On Wed, Jun 28, 2017 at 03:25:13PM -0700, Nick Harper wrote:
>>>> Here's a summary of the changes since the last draft:
>>>>=20
>>>> - If TB is accepted in 0-RTT data, keep using the early exporter =
for
>>>> the whole connection. There was some discussion on this in Chicago,
>>>> with more on the mailing list. Chairs, can you confirm whether we
>>>> reached consensus on the mailing list or whether we should take a =
hum
>>>> in Prague?
>>>=20
>>> I am a WG chair, but not a tokbind chair, but that question does not
>>> seem to make sense.  Consensus must be reached (or confirmed) on the
>>> mailing list, so deciding there wasn't enough feedback on the list =
and
>>> going to an in-room hum seems backwards, procedurally.
>>=20
>> Judging consensus is sometimes tricky. I think what Nick meant was =
that
>> we may want to do a hum in Prague /in addition to/ seeking =
confirmation
>> on the list.
>=20
> It is unclear to me whether consensus was reached (hence deferring to
> the chairs on that judgement). If we don't have consensus, I'm fine
> continuing the discussion on list and in Prague. Let me check that I
> understand the process properly: first, discuss (on list and possibly
> in person), then if the discussion sounds like it's reached a
> consensus, optionally hum in person, and then confirm consensus on the
> list. Does that sound about right?

Yes
>>=20
>>>=20
>>>> - 0-RTT TB cannot be used with externally provisioned PSKs or with =
a
>>>> PSK-only key exchange mode
>>>>=20
>>>> - A new TLS extension is used for negotiating and indicating use of =
0-RTT TB
>>>>=20
>>>> - The replay indication TLS extension has been removed
>>>=20
>>> Some discussion on the httpbis list brought up that this document =
should
>>> mandate that 0-RTT token binding is only used in conjunction with
>>> a TLS stack that provides strong anti-replay protections (i.e., zero
>>> additional replays possible and one retransmission via DKG attack).  =
In other
>>> words, the time-based scheme of (draft-02) section 6.4 should be =
removed,
>>> and perhaps 6.3.1 reworded somewhat.
>=20
> I read over the "New Version Notification for
> draft-thomson-http-replay-00.txt" thread on the httpbis list. My
> understanding of the issue raised on that list is simply that there
> are attacks on 0-RTT Token Binding if there isn't a strict global
> anti-replay mechanism. There are still attacks possible on 0-RTT Token
> Binding even if there is a strict global anti-replay mechanism. I need
> to consider what additional attacks are possible without such a
> mechanism, and if any of those attacks require less privileges than
> the attacks possible with the mechanism.
>>>=20
>>> (It also brought up multiple peoples' sentiments that 0-RTT token =
binding
>>> is a bad idea in general, but this may not be procedurally the right =
time
>>> to have that discussion.)
>>>=20
>>> -Ben
>>>=20
>>=20
> I'm aware that multiple people think that 0-RTT token binding is a bad
> idea in general. So far, the impression I've gotten of this sentiment
> is "0-RTT Token Binding is not something I have any interest in
> implementing". If the sentiment is closer to "0-RTT Token Binding is
> such a horrible thing that no one should be implementing it", then
> maybe we should discuss that sooner.

A good point,  if the attacks are still possible then supporting 0-RTT =
is problematic. =20
On the other hand 0-RTT is a big speed boost for resumed connections.  =
It is hard to imagine that servers are going to disable it to use token =
binding over the long term.

I don=E2=80=99t believe the WG has any real consensus on this yet.   The =
draft spec is helpfull for us to discuss the issues.  =20

I encourage more discussion on the list on the topic of the draft and if =
this is the correct way to deal with 0-rtt if there are counter =
opinions.

Regards
John B.


--Apple-Mail=_079E6D8C-19FC-4992-B425-7E25BF8A101A
Content-Transfer-Encoding: quoted-printable
Content-Type: text/html;
	charset=utf-8

<html><head><meta http-equiv=3D"Content-Type" content=3D"text/html =
charset=3Dutf-8"></head><body style=3D"word-wrap: break-word; =
-webkit-nbsp-mode: space; -webkit-line-break: after-white-space;" =
class=3D"">Inline<div class=3D""><br class=3D""><div><blockquote =
type=3D"cite" class=3D""><div class=3D"">On Jun 29, 2017, at 2:33 PM, =
Nick Harper &lt;<a href=3D"mailto:nharper@google.com" =
class=3D"">nharper@google.com</a>&gt; wrote:</div><br =
class=3D"Apple-interchange-newline"><div class=3D""><span =
style=3D"font-family: Helvetica; font-size: 12px; font-style: normal; =
font-variant-caps: normal; font-weight: normal; letter-spacing: normal; =
text-align: start; text-indent: 0px; text-transform: none; white-space: =
normal; word-spacing: 0px; -webkit-text-stroke-width: 0px; float: none; =
display: inline !important;" class=3D"">On Thu, Jun 29, 2017 at 2:05 AM, =
Leif Johansson &lt;</span><a href=3D"mailto:leifj@sunet.se" =
style=3D"font-family: Helvetica; font-size: 12px; font-style: normal; =
font-variant-caps: normal; font-weight: normal; letter-spacing: normal; =
orphans: auto; text-align: start; text-indent: 0px; text-transform: =
none; white-space: normal; widows: auto; word-spacing: 0px; =
-webkit-text-size-adjust: auto; -webkit-text-stroke-width: 0px;" =
class=3D"">leifj@sunet.se</a><span style=3D"font-family: Helvetica; =
font-size: 12px; font-style: normal; font-variant-caps: normal; =
font-weight: normal; letter-spacing: normal; text-align: start; =
text-indent: 0px; text-transform: none; white-space: normal; =
word-spacing: 0px; -webkit-text-stroke-width: 0px; float: none; display: =
inline !important;" class=3D"">&gt; wrote:</span><br style=3D"font-family:=
 Helvetica; font-size: 12px; font-style: normal; font-variant-caps: =
normal; font-weight: normal; letter-spacing: normal; text-align: start; =
text-indent: 0px; text-transform: none; white-space: normal; =
word-spacing: 0px; -webkit-text-stroke-width: 0px;" class=3D""><blockquote=
 type=3D"cite" style=3D"font-family: Helvetica; font-size: 12px; =
font-style: normal; font-variant-caps: normal; font-weight: normal; =
letter-spacing: normal; orphans: auto; text-align: start; text-indent: =
0px; text-transform: none; white-space: normal; widows: auto; =
word-spacing: 0px; -webkit-text-size-adjust: auto; =
-webkit-text-stroke-width: 0px;" class=3D"">On 2017-06-29 04:48, =
Benjamin Kaduk wrote:<br class=3D""><blockquote type=3D"cite" =
class=3D"">On Wed, Jun 28, 2017 at 03:25:13PM -0700, Nick Harper =
wrote:<br class=3D""><blockquote type=3D"cite" class=3D"">Here's a =
summary of the changes since the last draft:<br class=3D""><br =
class=3D"">- If TB is accepted in 0-RTT data, keep using the early =
exporter for<br class=3D"">the whole connection. There was some =
discussion on this in Chicago,<br class=3D"">with more on the mailing =
list. Chairs, can you confirm whether we<br class=3D"">reached consensus =
on the mailing list or whether we should take a hum<br class=3D"">in =
Prague?<br class=3D""></blockquote><br class=3D"">I am a WG chair, but =
not a tokbind chair, but that question does not<br class=3D"">seem to =
make sense. &nbsp;Consensus must be reached (or confirmed) on the<br =
class=3D"">mailing list, so deciding there wasn't enough feedback on the =
list and<br class=3D"">going to an in-room hum seems backwards, =
procedurally.<br class=3D""></blockquote><br class=3D"">Judging =
consensus is sometimes tricky. I think what Nick meant was that<br =
class=3D"">we may want to do a hum in Prague /in addition to/ seeking =
confirmation<br class=3D"">on the list.<br class=3D""></blockquote><br =
style=3D"font-family: Helvetica; font-size: 12px; font-style: normal; =
font-variant-caps: normal; font-weight: normal; letter-spacing: normal; =
text-align: start; text-indent: 0px; text-transform: none; white-space: =
normal; word-spacing: 0px; -webkit-text-stroke-width: 0px;" =
class=3D""><span style=3D"font-family: Helvetica; font-size: 12px; =
font-style: normal; font-variant-caps: normal; font-weight: normal; =
letter-spacing: normal; text-align: start; text-indent: 0px; =
text-transform: none; white-space: normal; word-spacing: 0px; =
-webkit-text-stroke-width: 0px; float: none; display: inline =
!important;" class=3D"">It is unclear to me whether consensus was =
reached (hence deferring to</span><br style=3D"font-family: Helvetica; =
font-size: 12px; font-style: normal; font-variant-caps: normal; =
font-weight: normal; letter-spacing: normal; text-align: start; =
text-indent: 0px; text-transform: none; white-space: normal; =
word-spacing: 0px; -webkit-text-stroke-width: 0px;" class=3D""><span =
style=3D"font-family: Helvetica; font-size: 12px; font-style: normal; =
font-variant-caps: normal; font-weight: normal; letter-spacing: normal; =
text-align: start; text-indent: 0px; text-transform: none; white-space: =
normal; word-spacing: 0px; -webkit-text-stroke-width: 0px; float: none; =
display: inline !important;" class=3D"">the chairs on that judgement). =
If we don't have consensus, I'm fine</span><br style=3D"font-family: =
Helvetica; font-size: 12px; font-style: normal; font-variant-caps: =
normal; font-weight: normal; letter-spacing: normal; text-align: start; =
text-indent: 0px; text-transform: none; white-space: normal; =
word-spacing: 0px; -webkit-text-stroke-width: 0px;" class=3D""><span =
style=3D"font-family: Helvetica; font-size: 12px; font-style: normal; =
font-variant-caps: normal; font-weight: normal; letter-spacing: normal; =
text-align: start; text-indent: 0px; text-transform: none; white-space: =
normal; word-spacing: 0px; -webkit-text-stroke-width: 0px; float: none; =
display: inline !important;" class=3D"">continuing the discussion on =
list and in Prague. Let me check that I</span><br style=3D"font-family: =
Helvetica; font-size: 12px; font-style: normal; font-variant-caps: =
normal; font-weight: normal; letter-spacing: normal; text-align: start; =
text-indent: 0px; text-transform: none; white-space: normal; =
word-spacing: 0px; -webkit-text-stroke-width: 0px;" class=3D""><span =
style=3D"font-family: Helvetica; font-size: 12px; font-style: normal; =
font-variant-caps: normal; font-weight: normal; letter-spacing: normal; =
text-align: start; text-indent: 0px; text-transform: none; white-space: =
normal; word-spacing: 0px; -webkit-text-stroke-width: 0px; float: none; =
display: inline !important;" class=3D"">understand the process properly: =
first, discuss (on list and possibly</span><br style=3D"font-family: =
Helvetica; font-size: 12px; font-style: normal; font-variant-caps: =
normal; font-weight: normal; letter-spacing: normal; text-align: start; =
text-indent: 0px; text-transform: none; white-space: normal; =
word-spacing: 0px; -webkit-text-stroke-width: 0px;" class=3D""><span =
style=3D"font-family: Helvetica; font-size: 12px; font-style: normal; =
font-variant-caps: normal; font-weight: normal; letter-spacing: normal; =
text-align: start; text-indent: 0px; text-transform: none; white-space: =
normal; word-spacing: 0px; -webkit-text-stroke-width: 0px; float: none; =
display: inline !important;" class=3D"">in person), then if the =
discussion sounds like it's reached a</span><br style=3D"font-family: =
Helvetica; font-size: 12px; font-style: normal; font-variant-caps: =
normal; font-weight: normal; letter-spacing: normal; text-align: start; =
text-indent: 0px; text-transform: none; white-space: normal; =
word-spacing: 0px; -webkit-text-stroke-width: 0px;" class=3D""><span =
style=3D"font-family: Helvetica; font-size: 12px; font-style: normal; =
font-variant-caps: normal; font-weight: normal; letter-spacing: normal; =
text-align: start; text-indent: 0px; text-transform: none; white-space: =
normal; word-spacing: 0px; -webkit-text-stroke-width: 0px; float: none; =
display: inline !important;" class=3D"">consensus, optionally hum in =
person, and then confirm consensus on the</span><br style=3D"font-family: =
Helvetica; font-size: 12px; font-style: normal; font-variant-caps: =
normal; font-weight: normal; letter-spacing: normal; text-align: start; =
text-indent: 0px; text-transform: none; white-space: normal; =
word-spacing: 0px; -webkit-text-stroke-width: 0px;" class=3D""><span =
style=3D"font-family: Helvetica; font-size: 12px; font-style: normal; =
font-variant-caps: normal; font-weight: normal; letter-spacing: normal; =
text-align: start; text-indent: 0px; text-transform: none; white-space: =
normal; word-spacing: 0px; -webkit-text-stroke-width: 0px; float: none; =
display: inline !important;" class=3D"">list. Does that sound about =
right?</span><br style=3D"font-family: Helvetica; font-size: 12px; =
font-style: normal; font-variant-caps: normal; font-weight: normal; =
letter-spacing: normal; text-align: start; text-indent: 0px; =
text-transform: none; white-space: normal; word-spacing: 0px; =
-webkit-text-stroke-width: 0px;" class=3D""></div></blockquote><div><br =
class=3D""></div>Yes<br class=3D""><blockquote type=3D"cite" =
class=3D""><div class=3D""><blockquote type=3D"cite" style=3D"font-family:=
 Helvetica; font-size: 12px; font-style: normal; font-variant-caps: =
normal; font-weight: normal; letter-spacing: normal; orphans: auto; =
text-align: start; text-indent: 0px; text-transform: none; white-space: =
normal; widows: auto; word-spacing: 0px; -webkit-text-size-adjust: auto; =
-webkit-text-stroke-width: 0px;" class=3D""><br class=3D""><blockquote =
type=3D"cite" class=3D""><br class=3D""><blockquote type=3D"cite" =
class=3D"">- 0-RTT TB cannot be used with externally provisioned PSKs or =
with a<br class=3D"">PSK-only key exchange mode<br class=3D""><br =
class=3D"">- A new TLS extension is used for negotiating and indicating =
use of 0-RTT TB<br class=3D""><br class=3D"">- The replay indication TLS =
extension has been removed<br class=3D""></blockquote><br class=3D"">Some =
discussion on the httpbis list brought up that this document should<br =
class=3D"">mandate that 0-RTT token binding is only used in conjunction =
with<br class=3D"">a TLS stack that provides strong anti-replay =
protections (i.e., zero<br class=3D"">additional replays possible and =
one retransmission via DKG attack). &nbsp;In other<br class=3D"">words, =
the time-based scheme of (draft-02) section 6.4 should be removed,<br =
class=3D"">and perhaps 6.3.1 reworded somewhat.<br =
class=3D""></blockquote></blockquote><br style=3D"font-family: =
Helvetica; font-size: 12px; font-style: normal; font-variant-caps: =
normal; font-weight: normal; letter-spacing: normal; text-align: start; =
text-indent: 0px; text-transform: none; white-space: normal; =
word-spacing: 0px; -webkit-text-stroke-width: 0px;" class=3D""><span =
style=3D"font-family: Helvetica; font-size: 12px; font-style: normal; =
font-variant-caps: normal; font-weight: normal; letter-spacing: normal; =
text-align: start; text-indent: 0px; text-transform: none; white-space: =
normal; word-spacing: 0px; -webkit-text-stroke-width: 0px; float: none; =
display: inline !important;" class=3D"">I read over the "New Version =
Notification for</span><br style=3D"font-family: Helvetica; font-size: =
12px; font-style: normal; font-variant-caps: normal; font-weight: =
normal; letter-spacing: normal; text-align: start; text-indent: 0px; =
text-transform: none; white-space: normal; word-spacing: 0px; =
-webkit-text-stroke-width: 0px;" class=3D""><span style=3D"font-family: =
Helvetica; font-size: 12px; font-style: normal; font-variant-caps: =
normal; font-weight: normal; letter-spacing: normal; text-align: start; =
text-indent: 0px; text-transform: none; white-space: normal; =
word-spacing: 0px; -webkit-text-stroke-width: 0px; float: none; display: =
inline !important;" class=3D"">draft-thomson-http-replay-00.txt" thread =
on the httpbis list. My</span><br style=3D"font-family: Helvetica; =
font-size: 12px; font-style: normal; font-variant-caps: normal; =
font-weight: normal; letter-spacing: normal; text-align: start; =
text-indent: 0px; text-transform: none; white-space: normal; =
word-spacing: 0px; -webkit-text-stroke-width: 0px;" class=3D""><span =
style=3D"font-family: Helvetica; font-size: 12px; font-style: normal; =
font-variant-caps: normal; font-weight: normal; letter-spacing: normal; =
text-align: start; text-indent: 0px; text-transform: none; white-space: =
normal; word-spacing: 0px; -webkit-text-stroke-width: 0px; float: none; =
display: inline !important;" class=3D"">understanding of the issue =
raised on that list is simply that there</span><br style=3D"font-family: =
Helvetica; font-size: 12px; font-style: normal; font-variant-caps: =
normal; font-weight: normal; letter-spacing: normal; text-align: start; =
text-indent: 0px; text-transform: none; white-space: normal; =
word-spacing: 0px; -webkit-text-stroke-width: 0px;" class=3D""><span =
style=3D"font-family: Helvetica; font-size: 12px; font-style: normal; =
font-variant-caps: normal; font-weight: normal; letter-spacing: normal; =
text-align: start; text-indent: 0px; text-transform: none; white-space: =
normal; word-spacing: 0px; -webkit-text-stroke-width: 0px; float: none; =
display: inline !important;" class=3D"">are attacks on 0-RTT Token =
Binding if there isn't a strict global</span><br style=3D"font-family: =
Helvetica; font-size: 12px; font-style: normal; font-variant-caps: =
normal; font-weight: normal; letter-spacing: normal; text-align: start; =
text-indent: 0px; text-transform: none; white-space: normal; =
word-spacing: 0px; -webkit-text-stroke-width: 0px;" class=3D""><span =
style=3D"font-family: Helvetica; font-size: 12px; font-style: normal; =
font-variant-caps: normal; font-weight: normal; letter-spacing: normal; =
text-align: start; text-indent: 0px; text-transform: none; white-space: =
normal; word-spacing: 0px; -webkit-text-stroke-width: 0px; float: none; =
display: inline !important;" class=3D"">anti-replay mechanism. There are =
still attacks possible on 0-RTT Token</span><br style=3D"font-family: =
Helvetica; font-size: 12px; font-style: normal; font-variant-caps: =
normal; font-weight: normal; letter-spacing: normal; text-align: start; =
text-indent: 0px; text-transform: none; white-space: normal; =
word-spacing: 0px; -webkit-text-stroke-width: 0px;" class=3D""><span =
style=3D"font-family: Helvetica; font-size: 12px; font-style: normal; =
font-variant-caps: normal; font-weight: normal; letter-spacing: normal; =
text-align: start; text-indent: 0px; text-transform: none; white-space: =
normal; word-spacing: 0px; -webkit-text-stroke-width: 0px; float: none; =
display: inline !important;" class=3D"">Binding even if there is a =
strict global anti-replay mechanism. I need</span><br =
style=3D"font-family: Helvetica; font-size: 12px; font-style: normal; =
font-variant-caps: normal; font-weight: normal; letter-spacing: normal; =
text-align: start; text-indent: 0px; text-transform: none; white-space: =
normal; word-spacing: 0px; -webkit-text-stroke-width: 0px;" =
class=3D""><span style=3D"font-family: Helvetica; font-size: 12px; =
font-style: normal; font-variant-caps: normal; font-weight: normal; =
letter-spacing: normal; text-align: start; text-indent: 0px; =
text-transform: none; white-space: normal; word-spacing: 0px; =
-webkit-text-stroke-width: 0px; float: none; display: inline =
!important;" class=3D"">to consider what additional attacks are possible =
without such a</span><br style=3D"font-family: Helvetica; font-size: =
12px; font-style: normal; font-variant-caps: normal; font-weight: =
normal; letter-spacing: normal; text-align: start; text-indent: 0px; =
text-transform: none; white-space: normal; word-spacing: 0px; =
-webkit-text-stroke-width: 0px;" class=3D""><span style=3D"font-family: =
Helvetica; font-size: 12px; font-style: normal; font-variant-caps: =
normal; font-weight: normal; letter-spacing: normal; text-align: start; =
text-indent: 0px; text-transform: none; white-space: normal; =
word-spacing: 0px; -webkit-text-stroke-width: 0px; float: none; display: =
inline !important;" class=3D"">mechanism, and if any of those attacks =
require less privileges than</span><br style=3D"font-family: Helvetica; =
font-size: 12px; font-style: normal; font-variant-caps: normal; =
font-weight: normal; letter-spacing: normal; text-align: start; =
text-indent: 0px; text-transform: none; white-space: normal; =
word-spacing: 0px; -webkit-text-stroke-width: 0px;" class=3D""><span =
style=3D"font-family: Helvetica; font-size: 12px; font-style: normal; =
font-variant-caps: normal; font-weight: normal; letter-spacing: normal; =
text-align: start; text-indent: 0px; text-transform: none; white-space: =
normal; word-spacing: 0px; -webkit-text-stroke-width: 0px; float: none; =
display: inline !important;" class=3D"">the attacks possible with the =
mechanism.</span><br style=3D"font-family: Helvetica; font-size: 12px; =
font-style: normal; font-variant-caps: normal; font-weight: normal; =
letter-spacing: normal; text-align: start; text-indent: 0px; =
text-transform: none; white-space: normal; word-spacing: 0px; =
-webkit-text-stroke-width: 0px;" class=3D""><blockquote type=3D"cite" =
style=3D"font-family: Helvetica; font-size: 12px; font-style: normal; =
font-variant-caps: normal; font-weight: normal; letter-spacing: normal; =
orphans: auto; text-align: start; text-indent: 0px; text-transform: =
none; white-space: normal; widows: auto; word-spacing: 0px; =
-webkit-text-size-adjust: auto; -webkit-text-stroke-width: 0px;" =
class=3D""><blockquote type=3D"cite" class=3D""><br class=3D"">(It also =
brought up multiple peoples' sentiments that 0-RTT token binding<br =
class=3D"">is a bad idea in general, but this may not be procedurally =
the right time<br class=3D"">to have that discussion.)<br class=3D""><br =
class=3D"">-Ben<br class=3D""><br class=3D""></blockquote><br =
class=3D""></blockquote><span style=3D"font-family: Helvetica; =
font-size: 12px; font-style: normal; font-variant-caps: normal; =
font-weight: normal; letter-spacing: normal; text-align: start; =
text-indent: 0px; text-transform: none; white-space: normal; =
word-spacing: 0px; -webkit-text-stroke-width: 0px; float: none; display: =
inline !important;" class=3D"">I'm aware that multiple people think that =
0-RTT token binding is a bad</span><br style=3D"font-family: Helvetica; =
font-size: 12px; font-style: normal; font-variant-caps: normal; =
font-weight: normal; letter-spacing: normal; text-align: start; =
text-indent: 0px; text-transform: none; white-space: normal; =
word-spacing: 0px; -webkit-text-stroke-width: 0px;" class=3D""><span =
style=3D"font-family: Helvetica; font-size: 12px; font-style: normal; =
font-variant-caps: normal; font-weight: normal; letter-spacing: normal; =
text-align: start; text-indent: 0px; text-transform: none; white-space: =
normal; word-spacing: 0px; -webkit-text-stroke-width: 0px; float: none; =
display: inline !important;" class=3D"">idea in general. So far, the =
impression I've gotten of this sentiment</span><br style=3D"font-family: =
Helvetica; font-size: 12px; font-style: normal; font-variant-caps: =
normal; font-weight: normal; letter-spacing: normal; text-align: start; =
text-indent: 0px; text-transform: none; white-space: normal; =
word-spacing: 0px; -webkit-text-stroke-width: 0px;" class=3D""><span =
style=3D"font-family: Helvetica; font-size: 12px; font-style: normal; =
font-variant-caps: normal; font-weight: normal; letter-spacing: normal; =
text-align: start; text-indent: 0px; text-transform: none; white-space: =
normal; word-spacing: 0px; -webkit-text-stroke-width: 0px; float: none; =
display: inline !important;" class=3D"">is "0-RTT Token Binding is not =
something I have any interest in</span><br style=3D"font-family: =
Helvetica; font-size: 12px; font-style: normal; font-variant-caps: =
normal; font-weight: normal; letter-spacing: normal; text-align: start; =
text-indent: 0px; text-transform: none; white-space: normal; =
word-spacing: 0px; -webkit-text-stroke-width: 0px;" class=3D""><span =
style=3D"font-family: Helvetica; font-size: 12px; font-style: normal; =
font-variant-caps: normal; font-weight: normal; letter-spacing: normal; =
text-align: start; text-indent: 0px; text-transform: none; white-space: =
normal; word-spacing: 0px; -webkit-text-stroke-width: 0px; float: none; =
display: inline !important;" class=3D"">implementing". If the sentiment =
is closer to "0-RTT Token Binding is</span><br style=3D"font-family: =
Helvetica; font-size: 12px; font-style: normal; font-variant-caps: =
normal; font-weight: normal; letter-spacing: normal; text-align: start; =
text-indent: 0px; text-transform: none; white-space: normal; =
word-spacing: 0px; -webkit-text-stroke-width: 0px;" class=3D""><span =
style=3D"font-family: Helvetica; font-size: 12px; font-style: normal; =
font-variant-caps: normal; font-weight: normal; letter-spacing: normal; =
text-align: start; text-indent: 0px; text-transform: none; white-space: =
normal; word-spacing: 0px; -webkit-text-stroke-width: 0px; float: none; =
display: inline !important;" class=3D"">such a horrible thing that no =
one should be implementing it", then</span><br style=3D"font-family: =
Helvetica; font-size: 12px; font-style: normal; font-variant-caps: =
normal; font-weight: normal; letter-spacing: normal; text-align: start; =
text-indent: 0px; text-transform: none; white-space: normal; =
word-spacing: 0px; -webkit-text-stroke-width: 0px;" class=3D""><span =
style=3D"font-family: Helvetica; font-size: 12px; font-style: normal; =
font-variant-caps: normal; font-weight: normal; letter-spacing: normal; =
text-align: start; text-indent: 0px; text-transform: none; white-space: =
normal; word-spacing: 0px; -webkit-text-stroke-width: 0px; float: none; =
display: inline !important;" class=3D"">maybe we should discuss that =
sooner.</span></div></blockquote><br class=3D""></div><div>A good point, =
&nbsp;if the attacks are still possible then supporting 0-RTT is =
problematic. &nbsp;</div><div>On the other hand 0-RTT is a big speed =
boost for resumed connections. &nbsp;It is hard to imagine that servers =
are going to disable it to use token binding over the long =
term.</div><div><br class=3D""></div><div>I don=E2=80=99t believe the WG =
has any real consensus on this yet. &nbsp; The draft spec is helpfull =
for us to discuss the issues. &nbsp;&nbsp;</div><div><br =
class=3D""></div><div>I encourage more discussion on the list on the =
topic of the draft and if this is the correct way to deal with 0-rtt if =
there are counter opinions.</div><div><br =
class=3D""></div><div>Regards</div><div>John B.</div><br =
class=3D""></div></body></html>=

--Apple-Mail=_079E6D8C-19FC-4992-B425-7E25BF8A101A--

--001a1144dfa027f58005531df0fc
Content-Type: application/pkcs7-signature; name="smime.p7s"
Content-Transfer-Encoding: base64
Content-Disposition: attachment; filename="smime.p7s"
Content-Description: S/MIME Cryptographic Signature

MIIRGwYJKoZIhvcNAQcCoIIRDDCCEQgCAQExDzANBglghkgBZQMEAgEFADALBgkqhkiG9w0BBwGg
gg4rMIIErzCCA5egAwIBAgIRAOAjyxUSg1OJrWFuelRnayEwDQYJKoZIhvcNAQELBQAwbzELMAkG
A1UEBhMCU0UxFDASBgNVBAoTC0FkZFRydXN0IEFCMSYwJAYDVQQLEx1BZGRUcnVzdCBFeHRlcm5h
bCBUVFAgTmV0d29yazEiMCAGA1UEAxMZQWRkVHJ1c3QgRXh0ZXJuYWwgQ0EgUm9vdDAeFw0xNDEy
MjIwMDAwMDBaFw0yMDA1MzAxMDQ4MzhaMIGbMQswCQYDVQQGEwJHQjEbMBkGA1UECBMSR3JlYXRl
ciBNYW5jaGVzdGVyMRAwDgYDVQQHEwdTYWxmb3JkMRowGAYDVQQKExFDT01PRE8gQ0EgTGltaXRl
ZDFBMD8GA1UEAxM4Q09NT0RPIFNIQS0yNTYgQ2xpZW50IEF1dGhlbnRpY2F0aW9uIGFuZCBTZWN1
cmUgRW1haWwgQ0EwggEiMA0GCSqGSIb3DQEBAQUAA4IBDwAwggEKAoIBAQCJsQ3aelMZTnBSHbxW
pgYmt7hJ4JbnUavx8FoTSRWjtIwbYLx6UUKneYykIt8XYU6R1XYjChTTSgJ/th0JgG6lBD3ZursW
/qGHqS5DUkMWfK8yUMimT1rpCNjPkyWce4joMGTmpPhWgP0qJBQzF5msROVpi6NGBkvCM9TpQJ8G
sLGsk0C5tQiTOpwqU6MQ2z0gYTxVA47ZTnYlAiEp+qN8cXZP7uFfgen7VIDbw3s1UreE3iI9LDAt
MX9ZvVI3sDNpLUPr+tal8Zd3Z1GM2e4n67ylBzh2jKSpOP/fjPUDrEm+yvdzmToPMquclToTPQ5G
Old0YVC+xkA/y+Tin6IhAgMBAAGjggEXMIIBEzAfBgNVHSMEGDAWgBStvZh6NLQm9/rEJlTvA73g
JMtUGjAdBgNVHQ4EFgQUkmFrguGioKpP7GfxwqP3tIAAwewwDgYDVR0PAQH/BAQDAgGGMBIGA1Ud
EwEB/wQIMAYBAf8CAQAwHQYDVR0lBBYwFAYIKwYBBQUHAwIGCCsGAQUFBwMEMBEGA1UdIAQKMAgw
BgYEVR0gADBEBgNVHR8EPTA7MDmgN6A1hjNodHRwOi8vY3JsLnVzZXJ0cnVzdC5jb20vQWRkVHJ1
c3RFeHRlcm5hbENBUm9vdC5jcmwwNQYIKwYBBQUHAQEEKTAnMCUGCCsGAQUFBzABhhlodHRwOi8v
b2NzcC51c2VydHJ1c3QuY29tMA0GCSqGSIb3DQEBCwUAA4IBAQAbKm6sVcE6q4jF2O3NVfOqa2Er
wAkQI5kPxWZqb7H1tLV3Xg8CYQDffQX+ErOkgIAA/PsdW2pyAgpBvAW6wVjVJsLq1U2E+/6CmM9Y
G+MiY5xS+LsFNqt9WKXeqztj5drVc+/s4Pt74qP/8EIjnMq2jU0+5EsYA7KoLdTYu0JLkGmFENum
NzToe+ABEKWcyjrHn0+ING6KZdAairup3MrKNtH0/MJkKTWv1rGncRHSA0Oxjz6a7J4yU/R2ksqG
NAe5LMrmHErYmQ3BhuKQkvtaQmojIRDpZcf11bt+6oyFIAJi6tE6ByxZxZkz8jiJ5bbpFnofeRT2
ShAaJvp8ivubMIIENjCCAx6gAwIBAgIBATANBgkqhkiG9w0BAQUFADBvMQswCQYDVQQGEwJTRTEU
MBIGA1UEChMLQWRkVHJ1c3QgQUIxJjAkBgNVBAsTHUFkZFRydXN0IEV4dGVybmFsIFRUUCBOZXR3
b3JrMSIwIAYDVQQDExlBZGRUcnVzdCBFeHRlcm5hbCBDQSBSb290MB4XDTAwMDUzMDEwNDgzOFoX
DTIwMDUzMDEwNDgzOFowbzELMAkGA1UEBhMCU0UxFDASBgNVBAoTC0FkZFRydXN0IEFCMSYwJAYD
VQQLEx1BZGRUcnVzdCBFeHRlcm5hbCBUVFAgTmV0d29yazEiMCAGA1UEAxMZQWRkVHJ1c3QgRXh0
ZXJuYWwgQ0EgUm9vdDCCASIwDQYJKoZIhvcNAQEBBQADggEPADCCAQoCggEBALf3GjPm8gAELTng
TlvtH7xsD821+iO2zt6bETOXpClMfZOfvUq8k+0DGuOPz+VtUFrWlymUWoCwSXrbLpX9uMq/Nzgt
Hj6RQa1wVsfwTz/oMp50ysiQVOnGXw94nZpAPA6sYapeFI+eh6FqUNzXmk6vBbOmcZSccbNQYArH
E504B4YCqOmoaSYYkKtMsE8jqzpPhNjfzp/haW+710LXa0Tkx63ubUFfclpxCDezeWWkWaCUN/cA
Lw3CknLa0Dhy2xSoRcRdKn23tNbE7qzNE0S3ySvdQwAl+mG5aWpYIxG3pzOPVnVZ9c0p10a3Citl
ttNCbxWyuHv77+ldU9U0WicCAwEAAaOB3DCB2TAdBgNVHQ4EFgQUrb2YejS0Jvf6xCZU7wO94CTL
VBowCwYDVR0PBAQDAgEGMA8GA1UdEwEB/wQFMAMBAf8wgZkGA1UdIwSBkTCBjoAUrb2YejS0Jvf6
xCZU7wO94CTLVBqhc6RxMG8xCzAJBgNVBAYTAlNFMRQwEgYDVQQKEwtBZGRUcnVzdCBBQjEmMCQG
A1UECxMdQWRkVHJ1c3QgRXh0ZXJuYWwgVFRQIE5ldHdvcmsxIjAgBgNVBAMTGUFkZFRydXN0IEV4
dGVybmFsIENBIFJvb3SCAQEwDQYJKoZIhvcNAQEFBQADggEBALCb4IUlwtYj4g+WBpKdQZic2YR5
gdkeWxQHIzZlj7DYd7usQWxHYINRsPkyPef89iYTx4AWpb9a/IfPeHmJIZriTAcKhjW88t5RxNKW
t9x+Tu5w/Rw56wwCURQtjr0W4MHfRnXnJK3s9EK0hZNwEGe6nQY1ShjTK3rMUUKhemPR5ruhxSvC
Nr4TDea9Y355e6cJDUCrat2PisP29owaQgVR1EX1n6diIWgVIEM8med8vSTYqZEXc4g/VhsxOBi0
cQ+azcgOno4uG+GMmIPLHzHxREzGBHNJdmAPx/i9F4BrLunMTA5amnkPIAou1Z5jJh5VkpTYghda
e9C8x49OhgQwggU6MIIEIqADAgECAhEA2TLMtWuXNcB2cbqZ/VgVujANBgkqhkiG9w0BAQsFADCB
mzELMAkGA1UEBhMCR0IxGzAZBgNVBAgTEkdyZWF0ZXIgTWFuY2hlc3RlcjEQMA4GA1UEBxMHU2Fs
Zm9yZDEaMBgGA1UEChMRQ09NT0RPIENBIExpbWl0ZWQxQTA/BgNVBAMTOENPTU9ETyBTSEEtMjU2
IENsaWVudCBBdXRoZW50aWNhdGlvbiBhbmQgU2VjdXJlIEVtYWlsIENBMB4XDTE3MDEwOTAwMDAw
MFoXDTE4MDEwOTIzNTk1OVowIjEgMB4GCSqGSIb3DQEJARYRdmU3anRiQHZlN2p0Yi5jb20wggEi
MA0GCSqGSIb3DQEBAQUAA4IBDwAwggEKAoIBAQDW2rqobOFQ/XmzH3DG2UK1Dt6jtc+OFZ71KQoB
o8IZa/V94Ey12BPjBcoj+cjHNVsLd2QiUpMcf5sZFMX1cmvpR7TiUISgVcHe8zgiUUvN5Jn5tPDM
Kb4E34TtDEG2X5FyY35AwCl8NV/loj2D5KLid9BLdVTJjfqokjLQ/4qCQjWBjfTpIdAdr3lXfg5f
a5UPyIkphEIplM8/yGfX0W/PBl804XAL0gesLrfEMdgG58UCN1wJMgH4uRKmKU/U2Ap4W9hTpioN
M722U8x7N6P1v6MqTAWCUaskdOp+ktNxFGxOlCE7BEo/EIaWbEt5RHwDePctScDLsi56+VI3TysR
AgMBAAGjggHvMIIB6zAfBgNVHSMEGDAWgBSSYWuC4aKgqk/sZ/HCo/e0gADB7DAdBgNVHQ4EFgQU
Yg3SsFWhMro4Abonbn1IX4JKj5QwDgYDVR0PAQH/BAQDAgWgMAwGA1UdEwEB/wQCMAAwIAYDVR0l
BBkwFwYIKwYBBQUHAwQGCysGAQQBsjEBAwUCMBEGCWCGSAGG+EIBAQQEAwIFIDBGBgNVHSAEPzA9
MDsGDCsGAQQBsjEBAgEBATArMCkGCCsGAQUFBwIBFh1odHRwczovL3NlY3VyZS5jb21vZG8ubmV0
L0NQUzBdBgNVHR8EVjBUMFKgUKBOhkxodHRwOi8vY3JsLmNvbW9kb2NhLmNvbS9DT01PRE9TSEEy
NTZDbGllbnRBdXRoZW50aWNhdGlvbmFuZFNlY3VyZUVtYWlsQ0EuY3JsMIGQBggrBgEFBQcBAQSB
gzCBgDBYBggrBgEFBQcwAoZMaHR0cDovL2NydC5jb21vZG9jYS5jb20vQ09NT0RPU0hBMjU2Q2xp
ZW50QXV0aGVudGljYXRpb25hbmRTZWN1cmVFbWFpbENBLmNydDAkBggrBgEFBQcwAYYYaHR0cDov
L29jc3AuY29tb2RvY2EuY29tMBwGA1UdEQQVMBOBEXZlN2p0YkB2ZTdqdGIuY29tMA0GCSqGSIb3
DQEBCwUAA4IBAQCC26y+6/+SJoRQWepca+rB9eSSwaCAb8nNqA+00ZiOHb+6UbbV1xa7Z8wDIuEL
5UKbNtQ2NDArvzF9YI0xNafoV1AEmP/3+ljxQHSEI0U1p2h401sOx+nSjcwtTzACso1lw+I0oJYM
JFITOIfZy8HgFpCipBrQAp9jMJ+KSKDX3xu/hzPosfdnXp7sV1KAjkFrAtR3AnQYfJ5W8QrsmC4N
BbiAKoYWUSdklqn3v1neTG/+oOhcw7hcGZo+YmPyF9Cdy0gBtwSHPt8hluhg2TlzmqYfi0dVL/mU
jCBNUY/BFH+MBqKF7sOIRMv8ALWceVaM/NEcBciKs4eR99A4cw9ZMYICtDCCArACAQEwgbEwgZsx
CzAJBgNVBAYTAkdCMRswGQYDVQQIExJHcmVhdGVyIE1hbmNoZXN0ZXIxEDAOBgNVBAcTB1NhbGZv
cmQxGjAYBgNVBAoTEUNPTU9ETyBDQSBMaW1pdGVkMUEwPwYDVQQDEzhDT01PRE8gU0hBLTI1NiBD
bGllbnQgQXV0aGVudGljYXRpb24gYW5kIFNlY3VyZSBFbWFpbCBDQQIRANkyzLVrlzXAdnG6mf1Y
FbowDQYJYIZIAWUDBAIBBQCggdQwLwYJKoZIhvcNAQkEMSIEICzHx1bJzmjK09vF6OqheCw5SSCr
UWHuQo9/XrKFJXbVMBgGCSqGSIb3DQEJAzELBgkqhkiG9w0BBwEwHAYJKoZIhvcNAQkFMQ8XDTE3
MDYyOTE5MDIxMVowaQYJKoZIhvcNAQkPMVwwWjALBglghkgBZQMEASowCwYJYIZIAWUDBAEWMAsG
CWCGSAFlAwQBAjAKBggqhkiG9w0DBzALBgkqhkiG9w0BAQowCwYJKoZIhvcNAQEHMAsGCWCGSAFl
AwQCATANBgkqhkiG9w0BAQEFAASCAQDEy71BuSEvr/gFl/MKN8zHv73e+q5szgRdF6k53uLKL6oY
LBnWOLbHy11sIml8GbANTCQh8SFCfke0/I9ZKB/j1d2/M4ZFGYVbW98Ag+dX/fQdar6J9LgHVp7w
ppUy6Q1prF9sI2Yz1FHsbY5z/bzPd9CF52hR0qTY20U+6cDT8OJBdq5nL8sQkHsG0sMaMsrqxWyI
ZeEwTEv6qrCxvPg31rzW8JDdXkMDo7dbNWUBSQkFABcXBdJE54miSCYLyxGPnSBlLQRWSIQ2Z4C4
epIWAfNe3oDNKpLJ0HwlEK2fjg1tIZjORId2dCejYaoGt4tQbu+dp9IZMtdXEzPDo6Ul
--001a1144dfa027f58005531df0fc--


From nobody Thu Jun 29 13:16:38 2017
Return-Path: <Andrei.Popov@microsoft.com>
X-Original-To: unbearable@ietfa.amsl.com
Delivered-To: unbearable@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id B5274129C1E; Thu, 29 Jun 2017 13:16:37 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.02
X-Spam-Level: 
X-Spam-Status: No, score=-2.02 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, HTML_MESSAGE=0.001, RCVD_IN_DNSWL_NONE=-0.0001, RCVD_IN_MSPIKE_H3=-0.01, RCVD_IN_MSPIKE_WL=-0.01, SPF_HELO_PASS=-0.001, SPF_PASS=-0.001, URIBL_BLOCKED=0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (1024-bit key) header.d=microsoft.com
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id uuwF0t4dGNKN; Thu, 29 Jun 2017 13:16:35 -0700 (PDT)
Received: from NAM02-CY1-obe.outbound.protection.outlook.com (mail-cys01nam02on0137.outbound.protection.outlook.com [104.47.37.137]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 394C3129B25; Thu, 29 Jun 2017 13:16:35 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=microsoft.com; s=selector1; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version; bh=dpJYwyJUKpgKfNO0gw+h69Fweyp7Xp8dNbbYIwOSzaA=; b=RGt3W9C8j5i6jnkAo+S4R0MNwzjyEj4lWOXQz9tLl9Z2UrRCWM2IwyyX9p1HqVd30JUXu5xmsCIR/hog51nR85HyRYysg37qvYCmlBZU4md2+Ih1sCm7tIu3boQTqzyiU1NIU6c5RzO1T8xyNBiHg+u2KCmK7+I7wkUVEljAa6Y=
Received: from DM2PR21MB0091.namprd21.prod.outlook.com (10.161.141.14) by DM2PR21MB0090.namprd21.prod.outlook.com (10.161.141.139) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_128_CBC_SHA256_P256) id 15.1.1240.4; Thu, 29 Jun 2017 20:16:33 +0000
Received: from DM2PR21MB0091.namprd21.prod.outlook.com ([fe80::5001:5681:2188:eed6]) by DM2PR21MB0091.namprd21.prod.outlook.com ([fe80::5001:5681:2188:eed6%18]) with mapi id 15.01.1240.007; Thu, 29 Jun 2017 20:16:33 +0000
From: Andrei Popov <Andrei.Popov@microsoft.com>
To: John Bradley <ve7jtb@ve7jtb.com>, Nick Harper <nharper@google.com>
CC: IETF Tokbind WG <unbearable@ietf.org>, Leif Johansson <leifj@sunet.se>, "tokbind-chairs@ietf.org" <tokbind-chairs@ietf.org>, Benjamin Kaduk <kaduk@mit.edu>
Thread-Topic: [Unbearable] I-D Action: draft-ietf-tokbind-tls13-0rtt-02.txt
Thread-Index: AQHS8FuyDX/argdPUkWbDRpR6gbRSqI62hqAgABJgQCAAGllgIAAno+AgAAIH4CAABJI8A==
Date: Thu, 29 Jun 2017 20:16:33 +0000
Message-ID: <DM2PR21MB009122B46F7497493AFF953C8CD20@DM2PR21MB0091.namprd21.prod.outlook.com>
References: <149868793805.5443.4284920405751222901@ietfa.amsl.com> <CACdeXiLqmdVpQryrPOBnUrbrk24Vap7QrASK-_vnwH91vwkZ3A@mail.gmail.com> <20170629024818.GI68391@kduck.kaduk.org> <9057a735-a907-d06c-327b-a959e4f554f0@sunet.se> <CACdeXiKOGptZ2WSZ_nVo-LmS5W0kqUszx_BpOcOWnfV05KO7mQ@mail.gmail.com> <97A1224B-5B6C-41EC-9FE0-CA0DE53746E1@ve7jtb.com>
In-Reply-To: <97A1224B-5B6C-41EC-9FE0-CA0DE53746E1@ve7jtb.com>
Accept-Language: en-US
Content-Language: en-US
X-MS-Has-Attach: 
X-MS-TNEF-Correlator: 
authentication-results: ve7jtb.com; dkim=none (message not signed) header.d=none;ve7jtb.com; dmarc=none action=none header.from=microsoft.com;
x-originating-ip: [2001:4898:80e8:e::4ca]
x-ms-publictraffictype: Email
x-microsoft-exchange-diagnostics: 1; DM2PR21MB0090; 7:ixGzebDAeNwaJdJ+h8EzCwcj3nSiHF/EEr9WLVmZWwgl3io/8IL4IwJMl613a6m+PkuuaBP+z1qQ3P4zxX8J3zOmMGYUa7w1NxOFuNXWzvilDrBk9TUZdoR1qN9Jt5tOOKy5cJTV+wvxf0mlUbKFcfQaOxIGQaP1yZRc1WISWFQBGYzWGYuNnZcDamdOBX55RZR1cQRusY/vRHyowVbJH4oRIc+8UyjF4p29xzKPNjcu7VDOYA/ah6n8GeeKffBb0l6KWTNAOmS4yqLlGNtT8ttnMkD21gSxyij9lLN/v8cBZ0E+DuxWssj96VUO3s0RdNy5/gjH+PbsB2ObgtEoMbGU5dry06PfuUesdLNlk8deOnOPhUn1ryJnvFdQabkARtekSBAro/59U8uxBAKhCma3CyT46wCrubejiEcjH+lQCuWnvteLFapi3ZpAhONKmE/B876b2xbG3IpucbvEkoegSNRY+eTFKe3Vmvx4/Qh4sZZv97QAiWsJplMqihx3AV3tMJ7fnA7f+eGXw0u4CwjaWWXKcpohbKVhswLP4tAYoPOtOvU3Mb1Y6nnqL/z3SP5UzAg1pZLz4aMrkgUgurEScQG21wdaxSdZemV/FkLdXdsuPD0OpEgnPll5ADl1n5MoUjLr4CqyGWCld9x6dzZntW3w8nhFNQXtJCLBn7mkL1UaKB0/9Rw33lGFcYBre8AqsD1OxEffLB/2Hw8EIVAmggm48m8OzRFNEkPFj1dSf85QkmRzrGKiVW4SYKAXYUNmNiQbVR2vcUS3KWx8R89NBBb5GVZytjcomnozHEE4xWjghqgjHoPCd4yI1r1Q
x-ms-office365-filtering-correlation-id: fbec9512-7a72-42ec-eb97-08d4bf2bbc93
x-ms-office365-filtering-ht: Tenant
x-microsoft-antispam: UriScan:; BCL:0; PCL:0; RULEID:(300000500095)(300135000095)(300000501095)(300135300095)(22001)(300000502095)(300135100095)(2017030254075)(48565401081)(300000503095)(300135400095)(2017052603031)(201703131423075)(201703031133081)(300000504095)(300135200095)(300000505095)(300135600095)(300000506095)(300135500095); SRVR:DM2PR21MB0090; 
x-ms-traffictypediagnostic: DM2PR21MB0090:
x-microsoft-antispam-prvs: <DM2PR21MB00900CE6E2C65F7E93FAD14F8CD20@DM2PR21MB0090.namprd21.prod.outlook.com>
x-exchange-antispam-report-test: UriScan:(151999592597050)(125551606395959)(278178393323532)(26388249023172)(236129657087228)(192374486261705)(211936372134217)(100405760836317)(148574349560750)(21748063052155);
x-exchange-antispam-report-cfa-test: BCL:0; PCL:0; RULEID:(100000700101)(100105000095)(100000701101)(100105300095)(100000702101)(100105100095)(61425038)(6040450)(601004)(2401047)(8121501046)(2017060910018)(5005006)(3002001)(10201501046)(93006095)(93001095)(100000703101)(100105400095)(6055026)(61426038)(61427038)(6041248)(20161123564025)(20161123555025)(20161123562025)(201703131423075)(201702281528075)(201703061421075)(201703061406153)(20161123558100)(20161123560025)(6072148)(100000704101)(100105200095)(100000705101)(100105500095); SRVR:DM2PR21MB0090; BCL:0; PCL:0; RULEID:(100000800101)(100110000095)(100000801101)(100110300095)(100000802101)(100110100095)(100000803101)(100110400095)(100000804101)(100110200095)(100000805101)(100110500095); SRVR:DM2PR21MB0090; 
x-forefront-prvs: 0353563E2B
x-forefront-antispam-report: SFV:NSPM; SFS:(10019020)(39400400002)(39410400002)(39850400002)(39840400002)(39450400003)(39860400002)(24454002)(377424004)(377454003)(2900100001)(8676002)(53936002)(229853002)(6436002)(2906002)(81166006)(8990500004)(38730400002)(2950100002)(25786009)(86612001)(86362001)(8936002)(7696004)(5660300001)(4326008)(10290500003)(7736002)(93886004)(53546010)(74316002)(10090500001)(230783001)(3280700002)(14454004)(9686003)(3660700001)(102836003)(790700001)(54896002)(6116002)(236005)(6306002)(55016002)(99286003)(33656002)(5005710100001)(6246003)(6506006)(5250100002)(76176999)(54356999)(189998001)(478600001)(50986999)(54906002)(72206003); DIR:OUT; SFP:1102; SCL:1; SRVR:DM2PR21MB0090; H:DM2PR21MB0091.namprd21.prod.outlook.com; FPR:; SPF:None; MLV:sfv; LANG:en; 
spamdiagnosticoutput: 1:99
spamdiagnosticmetadata: NSPM
Content-Type: multipart/alternative; boundary="_000_DM2PR21MB009122B46F7497493AFF953C8CD20DM2PR21MB0091namp_"
MIME-Version: 1.0
X-OriginatorOrg: microsoft.com
X-MS-Exchange-CrossTenant-originalarrivaltime: 29 Jun 2017 20:16:33.2673 (UTC)
X-MS-Exchange-CrossTenant-fromentityheader: Hosted
X-MS-Exchange-CrossTenant-id: 72f988bf-86f1-41af-91ab-2d7cd011db47
X-MS-Exchange-Transport-CrossTenantHeadersStamped: DM2PR21MB0090
Archived-At: <https://mailarchive.ietf.org/arch/msg/unbearable/0pXRpjkd30r_bKWlqoDfGZQKRlY>
Subject: Re: [Unbearable] I-D Action: draft-ietf-tokbind-tls13-0rtt-02.txt
X-BeenThere: unbearable@ietf.org
X-Mailman-Version: 2.1.22
Precedence: list
List-Id: "\"This list is for discussion of proposals for doing better than bearer tokens \(e.g. HTTP cookies, OAuth tokens etc.\) for web applications. The specific goal is chartering a WG focused on preventing security token export and replay attacks.\"" <unbearable.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/unbearable>, <mailto:unbearable-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/unbearable/>
List-Post: <mailto:unbearable@ietf.org>
List-Help: <mailto:unbearable-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/unbearable>, <mailto:unbearable-request@ietf.org?subject=subscribe>
X-List-Received-Date: Thu, 29 Jun 2017 20:16:38 -0000

--_000_DM2PR21MB009122B46F7497493AFF953C8CD20DM2PR21MB0091namp_
Content-Type: text/plain; charset="utf-8"
Content-Transfer-Encoding: base64

ICAqICAgQSBnb29kIHBvaW50LCAgaWYgdGhlIGF0dGFja3MgYXJlIHN0aWxsIHBvc3NpYmxlIHRo
ZW4gc3VwcG9ydGluZyAwLVJUVCBpcyBwcm9ibGVtYXRpYy4NCiAgKiAgIE9uIHRoZSBvdGhlciBo
YW5kIDAtUlRUIGlzIGEgYmlnIHNwZWVkIGJvb3N0IGZvciByZXN1bWVkIGNvbm5lY3Rpb25zLiAg
SXQgaXMgaGFyZCB0byBpbWFnaW5lIHRoYXQgc2VydmVycyBhcmUgZ29pbmcgdG8gZGlzYWJsZSBp
dCB0byB1c2UgdG9rZW4gYmluZGluZyBvdmVyIHRoZSBsb25nIHRlcm0uDQoNClRoZXJlIGlzIG9m
dGVuIGEgdHJhZGVvZmYgYmV0d2VlbiBzZWN1cml0eSBhbmQgcGVyZm9ybWFuY2U7IHNvbWUgc2Vy
dmVycyBtYXkgY2hvb3NlIDAtUlRUIGJhc2VkIG9uIHRoZWlyIGJ1c2luZXNzIHJlcXVpcmVtZW50
cywgYW5kIG90aGVycyBtYXkgY2hvb3NlIFRCLiBJIGRvIG5vdCB0aGluayB0aGF0IGl0IGlzIG5l
Y2Vzc2FyeSB0byByZWNvbmNpbGUgVEIgYW5kIDAtUlRUIChhbHRob3VnaCBpdCB3b3VsZCBoYXZl
IGJlZW4gYXdlc29tZSBpZiB3ZSBjb3VsZCkuIEZyb20gbXkgcGVyc3BlY3RpdmUsIGl0IGlzIG1v
cmUgaW1wb3J0YW50IHRvIGtlZXAgVEIgc2VjdXJlIHRoYW4gdG8gbWFrZSBpdCB3b3JrIHdpdGgg
MC1SVFQ6IHJlcGxheWFibGUgVEIgd291bGQgYmUgYSB3YXN0ZSBvZiBDUFUgY3ljbGVzLg0KDQpD
aGVlcnMsDQoNCkFuZHJlaQ0KDQpGcm9tOiBVbmJlYXJhYmxlIFttYWlsdG86dW5iZWFyYWJsZS1i
b3VuY2VzQGlldGYub3JnXSBPbiBCZWhhbGYgT2YgSm9obiBCcmFkbGV5DQpTZW50OiBUaHVyc2Rh
eSwgSnVuZSAyOSwgMjAxNyAxMjowMiBQTQ0KVG86IE5pY2sgSGFycGVyIDxuaGFycGVyQGdvb2ds
ZS5jb20+DQpDYzogSUVURiBUb2tiaW5kIFdHIDx1bmJlYXJhYmxlQGlldGYub3JnPjsgTGVpZiBK
b2hhbnNzb24gPGxlaWZqQHN1bmV0LnNlPjsgdG9rYmluZC1jaGFpcnNAaWV0Zi5vcmc7IEJlbmph
bWluIEthZHVrIDxrYWR1a0BtaXQuZWR1Pg0KU3ViamVjdDogUmU6IFtVbmJlYXJhYmxlXSBJLUQg
QWN0aW9uOiBkcmFmdC1pZXRmLXRva2JpbmQtdGxzMTMtMHJ0dC0wMi50eHQNCg0KSW5saW5lDQoN
Ck9uIEp1biAyOSwgMjAxNywgYXQgMjozMyBQTSwgTmljayBIYXJwZXIgPG5oYXJwZXJAZ29vZ2xl
LmNvbTxtYWlsdG86bmhhcnBlckBnb29nbGUuY29tPj4gd3JvdGU6DQoNCk9uIFRodSwgSnVuIDI5
LCAyMDE3IGF0IDI6MDUgQU0sIExlaWYgSm9oYW5zc29uIDxsZWlmakBzdW5ldC5zZTxtYWlsdG86
bGVpZmpAc3VuZXQuc2U+PiB3cm90ZToNCg0KT24gMjAxNy0wNi0yOSAwNDo0OCwgQmVuamFtaW4g
S2FkdWsgd3JvdGU6DQoNCk9uIFdlZCwgSnVuIDI4LCAyMDE3IGF0IDAzOjI1OjEzUE0gLTA3MDAs
IE5pY2sgSGFycGVyIHdyb3RlOg0KDQpIZXJlJ3MgYSBzdW1tYXJ5IG9mIHRoZSBjaGFuZ2VzIHNp
bmNlIHRoZSBsYXN0IGRyYWZ0Og0KDQotIElmIFRCIGlzIGFjY2VwdGVkIGluIDAtUlRUIGRhdGEs
IGtlZXAgdXNpbmcgdGhlIGVhcmx5IGV4cG9ydGVyIGZvcg0KdGhlIHdob2xlIGNvbm5lY3Rpb24u
IFRoZXJlIHdhcyBzb21lIGRpc2N1c3Npb24gb24gdGhpcyBpbiBDaGljYWdvLA0Kd2l0aCBtb3Jl
IG9uIHRoZSBtYWlsaW5nIGxpc3QuIENoYWlycywgY2FuIHlvdSBjb25maXJtIHdoZXRoZXIgd2UN
CnJlYWNoZWQgY29uc2Vuc3VzIG9uIHRoZSBtYWlsaW5nIGxpc3Qgb3Igd2hldGhlciB3ZSBzaG91
bGQgdGFrZSBhIGh1bQ0KaW4gUHJhZ3VlPw0KDQpJIGFtIGEgV0cgY2hhaXIsIGJ1dCBub3QgYSB0
b2tiaW5kIGNoYWlyLCBidXQgdGhhdCBxdWVzdGlvbiBkb2VzIG5vdA0Kc2VlbSB0byBtYWtlIHNl
bnNlLiAgQ29uc2Vuc3VzIG11c3QgYmUgcmVhY2hlZCAob3IgY29uZmlybWVkKSBvbiB0aGUNCm1h
aWxpbmcgbGlzdCwgc28gZGVjaWRpbmcgdGhlcmUgd2Fzbid0IGVub3VnaCBmZWVkYmFjayBvbiB0
aGUgbGlzdCBhbmQNCmdvaW5nIHRvIGFuIGluLXJvb20gaHVtIHNlZW1zIGJhY2t3YXJkcywgcHJv
Y2VkdXJhbGx5Lg0KDQpKdWRnaW5nIGNvbnNlbnN1cyBpcyBzb21ldGltZXMgdHJpY2t5LiBJIHRo
aW5rIHdoYXQgTmljayBtZWFudCB3YXMgdGhhdA0Kd2UgbWF5IHdhbnQgdG8gZG8gYSBodW0gaW4g
UHJhZ3VlIC9pbiBhZGRpdGlvbiB0by8gc2Vla2luZyBjb25maXJtYXRpb24NCm9uIHRoZSBsaXN0
Lg0KDQpJdCBpcyB1bmNsZWFyIHRvIG1lIHdoZXRoZXIgY29uc2Vuc3VzIHdhcyByZWFjaGVkICho
ZW5jZSBkZWZlcnJpbmcgdG8NCnRoZSBjaGFpcnMgb24gdGhhdCBqdWRnZW1lbnQpLiBJZiB3ZSBk
b24ndCBoYXZlIGNvbnNlbnN1cywgSSdtIGZpbmUNCmNvbnRpbnVpbmcgdGhlIGRpc2N1c3Npb24g
b24gbGlzdCBhbmQgaW4gUHJhZ3VlLiBMZXQgbWUgY2hlY2sgdGhhdCBJDQp1bmRlcnN0YW5kIHRo
ZSBwcm9jZXNzIHByb3Blcmx5OiBmaXJzdCwgZGlzY3VzcyAob24gbGlzdCBhbmQgcG9zc2libHkN
CmluIHBlcnNvbiksIHRoZW4gaWYgdGhlIGRpc2N1c3Npb24gc291bmRzIGxpa2UgaXQncyByZWFj
aGVkIGENCmNvbnNlbnN1cywgb3B0aW9uYWxseSBodW0gaW4gcGVyc29uLCBhbmQgdGhlbiBjb25m
aXJtIGNvbnNlbnN1cyBvbiB0aGUNCmxpc3QuIERvZXMgdGhhdCBzb3VuZCBhYm91dCByaWdodD8N
Cg0KWWVzDQoNCg0KDQoNCg0KLSAwLVJUVCBUQiBjYW5ub3QgYmUgdXNlZCB3aXRoIGV4dGVybmFs
bHkgcHJvdmlzaW9uZWQgUFNLcyBvciB3aXRoIGENClBTSy1vbmx5IGtleSBleGNoYW5nZSBtb2Rl
DQoNCi0gQSBuZXcgVExTIGV4dGVuc2lvbiBpcyB1c2VkIGZvciBuZWdvdGlhdGluZyBhbmQgaW5k
aWNhdGluZyB1c2Ugb2YgMC1SVFQgVEINCg0KLSBUaGUgcmVwbGF5IGluZGljYXRpb24gVExTIGV4
dGVuc2lvbiBoYXMgYmVlbiByZW1vdmVkDQoNClNvbWUgZGlzY3Vzc2lvbiBvbiB0aGUgaHR0cGJp
cyBsaXN0IGJyb3VnaHQgdXAgdGhhdCB0aGlzIGRvY3VtZW50IHNob3VsZA0KbWFuZGF0ZSB0aGF0
IDAtUlRUIHRva2VuIGJpbmRpbmcgaXMgb25seSB1c2VkIGluIGNvbmp1bmN0aW9uIHdpdGgNCmEg
VExTIHN0YWNrIHRoYXQgcHJvdmlkZXMgc3Ryb25nIGFudGktcmVwbGF5IHByb3RlY3Rpb25zIChp
LmUuLCB6ZXJvDQphZGRpdGlvbmFsIHJlcGxheXMgcG9zc2libGUgYW5kIG9uZSByZXRyYW5zbWlz
c2lvbiB2aWEgREtHIGF0dGFjaykuICBJbiBvdGhlcg0Kd29yZHMsIHRoZSB0aW1lLWJhc2VkIHNj
aGVtZSBvZiAoZHJhZnQtMDIpIHNlY3Rpb24gNi40IHNob3VsZCBiZSByZW1vdmVkLA0KYW5kIHBl
cmhhcHMgNi4zLjEgcmV3b3JkZWQgc29tZXdoYXQuDQoNCkkgcmVhZCBvdmVyIHRoZSAiTmV3IFZl
cnNpb24gTm90aWZpY2F0aW9uIGZvcg0KZHJhZnQtdGhvbXNvbi1odHRwLXJlcGxheS0wMC50eHQi
IHRocmVhZCBvbiB0aGUgaHR0cGJpcyBsaXN0LiBNeQ0KdW5kZXJzdGFuZGluZyBvZiB0aGUgaXNz
dWUgcmFpc2VkIG9uIHRoYXQgbGlzdCBpcyBzaW1wbHkgdGhhdCB0aGVyZQ0KYXJlIGF0dGFja3Mg
b24gMC1SVFQgVG9rZW4gQmluZGluZyBpZiB0aGVyZSBpc24ndCBhIHN0cmljdCBnbG9iYWwNCmFu
dGktcmVwbGF5IG1lY2hhbmlzbS4gVGhlcmUgYXJlIHN0aWxsIGF0dGFja3MgcG9zc2libGUgb24g
MC1SVFQgVG9rZW4NCkJpbmRpbmcgZXZlbiBpZiB0aGVyZSBpcyBhIHN0cmljdCBnbG9iYWwgYW50
aS1yZXBsYXkgbWVjaGFuaXNtLiBJIG5lZWQNCnRvIGNvbnNpZGVyIHdoYXQgYWRkaXRpb25hbCBh
dHRhY2tzIGFyZSBwb3NzaWJsZSB3aXRob3V0IHN1Y2ggYQ0KbWVjaGFuaXNtLCBhbmQgaWYgYW55
IG9mIHRob3NlIGF0dGFja3MgcmVxdWlyZSBsZXNzIHByaXZpbGVnZXMgdGhhbg0KdGhlIGF0dGFj
a3MgcG9zc2libGUgd2l0aCB0aGUgbWVjaGFuaXNtLg0KDQoNCihJdCBhbHNvIGJyb3VnaHQgdXAg
bXVsdGlwbGUgcGVvcGxlcycgc2VudGltZW50cyB0aGF0IDAtUlRUIHRva2VuIGJpbmRpbmcNCmlz
IGEgYmFkIGlkZWEgaW4gZ2VuZXJhbCwgYnV0IHRoaXMgbWF5IG5vdCBiZSBwcm9jZWR1cmFsbHkg
dGhlIHJpZ2h0IHRpbWUNCnRvIGhhdmUgdGhhdCBkaXNjdXNzaW9uLikNCg0KLUJlbg0KDQpJJ20g
YXdhcmUgdGhhdCBtdWx0aXBsZSBwZW9wbGUgdGhpbmsgdGhhdCAwLVJUVCB0b2tlbiBiaW5kaW5n
IGlzIGEgYmFkDQppZGVhIGluIGdlbmVyYWwuIFNvIGZhciwgdGhlIGltcHJlc3Npb24gSSd2ZSBn
b3R0ZW4gb2YgdGhpcyBzZW50aW1lbnQNCmlzICIwLVJUVCBUb2tlbiBCaW5kaW5nIGlzIG5vdCBz
b21ldGhpbmcgSSBoYXZlIGFueSBpbnRlcmVzdCBpbg0KaW1wbGVtZW50aW5nIi4gSWYgdGhlIHNl
bnRpbWVudCBpcyBjbG9zZXIgdG8gIjAtUlRUIFRva2VuIEJpbmRpbmcgaXMNCnN1Y2ggYSBob3Jy
aWJsZSB0aGluZyB0aGF0IG5vIG9uZSBzaG91bGQgYmUgaW1wbGVtZW50aW5nIGl0IiwgdGhlbg0K
bWF5YmUgd2Ugc2hvdWxkIGRpc2N1c3MgdGhhdCBzb29uZXIuDQoNCkEgZ29vZCBwb2ludCwgIGlm
IHRoZSBhdHRhY2tzIGFyZSBzdGlsbCBwb3NzaWJsZSB0aGVuIHN1cHBvcnRpbmcgMC1SVFQgaXMg
cHJvYmxlbWF0aWMuDQpPbiB0aGUgb3RoZXIgaGFuZCAwLVJUVCBpcyBhIGJpZyBzcGVlZCBib29z
dCBmb3IgcmVzdW1lZCBjb25uZWN0aW9ucy4gIEl0IGlzIGhhcmQgdG8gaW1hZ2luZSB0aGF0IHNl
cnZlcnMgYXJlIGdvaW5nIHRvIGRpc2FibGUgaXQgdG8gdXNlIHRva2VuIGJpbmRpbmcgb3ZlciB0
aGUgbG9uZyB0ZXJtLg0KDQpJIGRvbuKAmXQgYmVsaWV2ZSB0aGUgV0cgaGFzIGFueSByZWFsIGNv
bnNlbnN1cyBvbiB0aGlzIHlldC4gICBUaGUgZHJhZnQgc3BlYyBpcyBoZWxwZnVsbCBmb3IgdXMg
dG8gZGlzY3VzcyB0aGUgaXNzdWVzLg0KDQpJIGVuY291cmFnZSBtb3JlIGRpc2N1c3Npb24gb24g
dGhlIGxpc3Qgb24gdGhlIHRvcGljIG9mIHRoZSBkcmFmdCBhbmQgaWYgdGhpcyBpcyB0aGUgY29y
cmVjdCB3YXkgdG8gZGVhbCB3aXRoIDAtcnR0IGlmIHRoZXJlIGFyZSBjb3VudGVyIG9waW5pb25z
Lg0KDQpSZWdhcmRzDQpKb2huIEIuDQoNCg==

--_000_DM2PR21MB009122B46F7497493AFF953C8CD20DM2PR21MB0091namp_
Content-Type: text/html; charset="utf-8"
Content-Transfer-Encoding: base64

PGh0bWwgeG1sbnM6dj0idXJuOnNjaGVtYXMtbWljcm9zb2Z0LWNvbTp2bWwiIHhtbG5zOm89InVy
bjpzY2hlbWFzLW1pY3Jvc29mdC1jb206b2ZmaWNlOm9mZmljZSIgeG1sbnM6dz0idXJuOnNjaGVt
YXMtbWljcm9zb2Z0LWNvbTpvZmZpY2U6d29yZCIgeG1sbnM6bT0iaHR0cDovL3NjaGVtYXMubWlj
cm9zb2Z0LmNvbS9vZmZpY2UvMjAwNC8xMi9vbW1sIiB4bWxucz0iaHR0cDovL3d3dy53My5vcmcv
VFIvUkVDLWh0bWw0MCI+DQo8aGVhZD4NCjxtZXRhIGh0dHAtZXF1aXY9IkNvbnRlbnQtVHlwZSIg
Y29udGVudD0idGV4dC9odG1sOyBjaGFyc2V0PXV0Zi04Ij4NCjxtZXRhIG5hbWU9IkdlbmVyYXRv
ciIgY29udGVudD0iTWljcm9zb2Z0IFdvcmQgMTUgKGZpbHRlcmVkIG1lZGl1bSkiPg0KPHN0eWxl
PjwhLS0NCi8qIEZvbnQgRGVmaW5pdGlvbnMgKi8NCkBmb250LWZhY2UNCgl7Zm9udC1mYW1pbHk6
SGVsdmV0aWNhOw0KCXBhbm9zZS0xOjIgMTEgNiA0IDIgMiAyIDIgMiA0O30NCkBmb250LWZhY2UN
Cgl7Zm9udC1mYW1pbHk6V2luZ2RpbmdzOw0KCXBhbm9zZS0xOjUgMCAwIDAgMCAwIDAgMCAwIDA7
fQ0KQGZvbnQtZmFjZQ0KCXtmb250LWZhbWlseToiQ2FtYnJpYSBNYXRoIjsNCglwYW5vc2UtMToy
IDQgNSAzIDUgNCA2IDMgMiA0O30NCkBmb250LWZhY2UNCgl7Zm9udC1mYW1pbHk6Q2FsaWJyaTsN
CglwYW5vc2UtMToyIDE1IDUgMiAyIDIgNCAzIDIgNDt9DQovKiBTdHlsZSBEZWZpbml0aW9ucyAq
Lw0KcC5Nc29Ob3JtYWwsIGxpLk1zb05vcm1hbCwgZGl2Lk1zb05vcm1hbA0KCXttYXJnaW46MGlu
Ow0KCW1hcmdpbi1ib3R0b206LjAwMDFwdDsNCglmb250LXNpemU6MTEuMHB0Ow0KCWZvbnQtZmFt
aWx5OiJDYWxpYnJpIixzYW5zLXNlcmlmO30NCmE6bGluaywgc3Bhbi5Nc29IeXBlcmxpbmsNCgl7
bXNvLXN0eWxlLXByaW9yaXR5Ojk5Ow0KCWNvbG9yOmJsdWU7DQoJdGV4dC1kZWNvcmF0aW9uOnVu
ZGVybGluZTt9DQphOnZpc2l0ZWQsIHNwYW4uTXNvSHlwZXJsaW5rRm9sbG93ZWQNCgl7bXNvLXN0
eWxlLXByaW9yaXR5Ojk5Ow0KCWNvbG9yOnB1cnBsZTsNCgl0ZXh0LWRlY29yYXRpb246dW5kZXJs
aW5lO30NCnAuTXNvTGlzdFBhcmFncmFwaCwgbGkuTXNvTGlzdFBhcmFncmFwaCwgZGl2Lk1zb0xp
c3RQYXJhZ3JhcGgNCgl7bXNvLXN0eWxlLXByaW9yaXR5OjM0Ow0KCW1hcmdpbi10b3A6MGluOw0K
CW1hcmdpbi1yaWdodDowaW47DQoJbWFyZ2luLWJvdHRvbTowaW47DQoJbWFyZ2luLWxlZnQ6LjVp
bjsNCgltYXJnaW4tYm90dG9tOi4wMDAxcHQ7DQoJZm9udC1zaXplOjExLjBwdDsNCglmb250LWZh
bWlseToiQ2FsaWJyaSIsc2Fucy1zZXJpZjt9DQpwLm1zb25vcm1hbDAsIGxpLm1zb25vcm1hbDAs
IGRpdi5tc29ub3JtYWwwDQoJe21zby1zdHlsZS1uYW1lOm1zb25vcm1hbDsNCgltc28tbWFyZ2lu
LXRvcC1hbHQ6YXV0bzsNCgltYXJnaW4tcmlnaHQ6MGluOw0KCW1zby1tYXJnaW4tYm90dG9tLWFs
dDphdXRvOw0KCW1hcmdpbi1sZWZ0OjBpbjsNCglmb250LXNpemU6MTEuMHB0Ow0KCWZvbnQtZmFt
aWx5OiJDYWxpYnJpIixzYW5zLXNlcmlmO30NCnNwYW4uRW1haWxTdHlsZTE4DQoJe21zby1zdHls
ZS10eXBlOnBlcnNvbmFsLXJlcGx5Ow0KCWZvbnQtZmFtaWx5OiJDYWxpYnJpIixzYW5zLXNlcmlm
Ow0KCWNvbG9yOndpbmRvd3RleHQ7fQ0KLk1zb0NocERlZmF1bHQNCgl7bXNvLXN0eWxlLXR5cGU6
ZXhwb3J0LW9ubHk7DQoJZm9udC1zaXplOjEwLjBwdDt9DQpAcGFnZSBXb3JkU2VjdGlvbjENCgl7
c2l6ZTo4LjVpbiAxMS4waW47DQoJbWFyZ2luOjEuMGluIDEuMGluIDEuMGluIDEuMGluO30NCmRp
di5Xb3JkU2VjdGlvbjENCgl7cGFnZTpXb3JkU2VjdGlvbjE7fQ0KLyogTGlzdCBEZWZpbml0aW9u
cyAqLw0KQGxpc3QgbDANCgl7bXNvLWxpc3QtaWQ6ODEzMzI3OTU1Ow0KCW1zby1saXN0LXR5cGU6
aHlicmlkOw0KCW1zby1saXN0LXRlbXBsYXRlLWlkczotMTQxMzIxMzM3OCAtOTA0NTA4OTg2IDY3
Njk4NjkxIDY3Njk4NjkzIDY3Njk4Njg5IDY3Njk4NjkxIDY3Njk4NjkzIDY3Njk4Njg5IDY3Njk4
NjkxIDY3Njk4NjkzO30NCkBsaXN0IGwwOmxldmVsMQ0KCXttc28tbGV2ZWwtc3RhcnQtYXQ6MDsN
Cgltc28tbGV2ZWwtbnVtYmVyLWZvcm1hdDpidWxsZXQ7DQoJbXNvLWxldmVsLXRleHQ674OYOw0K
CW1zby1sZXZlbC10YWItc3RvcDpub25lOw0KCW1zby1sZXZlbC1udW1iZXItcG9zaXRpb246bGVm
dDsNCgl0ZXh0LWluZGVudDotLjI1aW47DQoJZm9udC1mYW1pbHk6V2luZ2RpbmdzOw0KCW1zby1m
YXJlYXN0LWZvbnQtZmFtaWx5OkNhbGlicmk7DQoJbXNvLWJpZGktZm9udC1mYW1pbHk6IlRpbWVz
IE5ldyBSb21hbiI7fQ0KQGxpc3QgbDA6bGV2ZWwyDQoJe21zby1sZXZlbC1udW1iZXItZm9ybWF0
OmJ1bGxldDsNCgltc28tbGV2ZWwtdGV4dDpvOw0KCW1zby1sZXZlbC10YWItc3RvcDpub25lOw0K
CW1zby1sZXZlbC1udW1iZXItcG9zaXRpb246bGVmdDsNCgl0ZXh0LWluZGVudDotLjI1aW47DQoJ
Zm9udC1mYW1pbHk6IkNvdXJpZXIgTmV3Ijt9DQpAbGlzdCBsMDpsZXZlbDMNCgl7bXNvLWxldmVs
LW51bWJlci1mb3JtYXQ6YnVsbGV0Ow0KCW1zby1sZXZlbC10ZXh0Ou+CpzsNCgltc28tbGV2ZWwt
dGFiLXN0b3A6bm9uZTsNCgltc28tbGV2ZWwtbnVtYmVyLXBvc2l0aW9uOmxlZnQ7DQoJdGV4dC1p
bmRlbnQ6LS4yNWluOw0KCWZvbnQtZmFtaWx5OldpbmdkaW5nczt9DQpAbGlzdCBsMDpsZXZlbDQN
Cgl7bXNvLWxldmVsLW51bWJlci1mb3JtYXQ6YnVsbGV0Ow0KCW1zby1sZXZlbC10ZXh0Ou+CtzsN
Cgltc28tbGV2ZWwtdGFiLXN0b3A6bm9uZTsNCgltc28tbGV2ZWwtbnVtYmVyLXBvc2l0aW9uOmxl
ZnQ7DQoJdGV4dC1pbmRlbnQ6LS4yNWluOw0KCWZvbnQtZmFtaWx5OlN5bWJvbDt9DQpAbGlzdCBs
MDpsZXZlbDUNCgl7bXNvLWxldmVsLW51bWJlci1mb3JtYXQ6YnVsbGV0Ow0KCW1zby1sZXZlbC10
ZXh0Om87DQoJbXNvLWxldmVsLXRhYi1zdG9wOm5vbmU7DQoJbXNvLWxldmVsLW51bWJlci1wb3Np
dGlvbjpsZWZ0Ow0KCXRleHQtaW5kZW50Oi0uMjVpbjsNCglmb250LWZhbWlseToiQ291cmllciBO
ZXciO30NCkBsaXN0IGwwOmxldmVsNg0KCXttc28tbGV2ZWwtbnVtYmVyLWZvcm1hdDpidWxsZXQ7
DQoJbXNvLWxldmVsLXRleHQ674KnOw0KCW1zby1sZXZlbC10YWItc3RvcDpub25lOw0KCW1zby1s
ZXZlbC1udW1iZXItcG9zaXRpb246bGVmdDsNCgl0ZXh0LWluZGVudDotLjI1aW47DQoJZm9udC1m
YW1pbHk6V2luZ2RpbmdzO30NCkBsaXN0IGwwOmxldmVsNw0KCXttc28tbGV2ZWwtbnVtYmVyLWZv
cm1hdDpidWxsZXQ7DQoJbXNvLWxldmVsLXRleHQ674K3Ow0KCW1zby1sZXZlbC10YWItc3RvcDpu
b25lOw0KCW1zby1sZXZlbC1udW1iZXItcG9zaXRpb246bGVmdDsNCgl0ZXh0LWluZGVudDotLjI1
aW47DQoJZm9udC1mYW1pbHk6U3ltYm9sO30NCkBsaXN0IGwwOmxldmVsOA0KCXttc28tbGV2ZWwt
bnVtYmVyLWZvcm1hdDpidWxsZXQ7DQoJbXNvLWxldmVsLXRleHQ6bzsNCgltc28tbGV2ZWwtdGFi
LXN0b3A6bm9uZTsNCgltc28tbGV2ZWwtbnVtYmVyLXBvc2l0aW9uOmxlZnQ7DQoJdGV4dC1pbmRl
bnQ6LS4yNWluOw0KCWZvbnQtZmFtaWx5OiJDb3VyaWVyIE5ldyI7fQ0KQGxpc3QgbDA6bGV2ZWw5
DQoJe21zby1sZXZlbC1udW1iZXItZm9ybWF0OmJ1bGxldDsNCgltc28tbGV2ZWwtdGV4dDrvgqc7
DQoJbXNvLWxldmVsLXRhYi1zdG9wOm5vbmU7DQoJbXNvLWxldmVsLW51bWJlci1wb3NpdGlvbjps
ZWZ0Ow0KCXRleHQtaW5kZW50Oi0uMjVpbjsNCglmb250LWZhbWlseTpXaW5nZGluZ3M7fQ0Kb2wN
Cgl7bWFyZ2luLWJvdHRvbTowaW47fQ0KdWwNCgl7bWFyZ2luLWJvdHRvbTowaW47fQ0KLS0+PC9z
dHlsZT48IS0tW2lmIGd0ZSBtc28gOV0+PHhtbD4NCjxvOnNoYXBlZGVmYXVsdHMgdjpleHQ9ImVk
aXQiIHNwaWRtYXg9IjEwMjYiIC8+DQo8L3htbD48IVtlbmRpZl0tLT48IS0tW2lmIGd0ZSBtc28g
OV0+PHhtbD4NCjxvOnNoYXBlbGF5b3V0IHY6ZXh0PSJlZGl0Ij4NCjxvOmlkbWFwIHY6ZXh0PSJl
ZGl0IiBkYXRhPSIxIiAvPg0KPC9vOnNoYXBlbGF5b3V0PjwveG1sPjwhW2VuZGlmXS0tPg0KPC9o
ZWFkPg0KPGJvZHkgbGFuZz0iRU4tVVMiIGxpbms9ImJsdWUiIHZsaW5rPSJwdXJwbGUiPg0KPGRp
diBjbGFzcz0iV29yZFNlY3Rpb24xIj4NCjx1bCBzdHlsZT0ibWFyZ2luLXRvcDowaW4iIHR5cGU9
ImRpc2MiPg0KPGxpIGNsYXNzPSJNc29MaXN0UGFyYWdyYXBoIiBzdHlsZT0ibWFyZ2luLWxlZnQ6
MGluO21zby1saXN0OmwwIGxldmVsMSBsZm8xIj5BIGdvb2QgcG9pbnQsICZuYnNwO2lmIHRoZSBh
dHRhY2tzIGFyZSBzdGlsbCBwb3NzaWJsZSB0aGVuIHN1cHBvcnRpbmcgMC1SVFQgaXMgcHJvYmxl
bWF0aWMuICZuYnNwOzxvOnA+PC9vOnA+PC9saT48bGkgY2xhc3M9Ik1zb0xpc3RQYXJhZ3JhcGgi
IHN0eWxlPSJtYXJnaW4tbGVmdDowaW47bXNvLWxpc3Q6bDAgbGV2ZWwxIGxmbzEiPk9uIHRoZSBv
dGhlciBoYW5kIDAtUlRUIGlzIGEgYmlnIHNwZWVkIGJvb3N0IGZvciByZXN1bWVkIGNvbm5lY3Rp
b25zLiAmbmJzcDtJdCBpcyBoYXJkIHRvIGltYWdpbmUgdGhhdCBzZXJ2ZXJzIGFyZSBnb2luZyB0
byBkaXNhYmxlIGl0IHRvIHVzZSB0b2tlbiBiaW5kaW5nIG92ZXIgdGhlIGxvbmcgdGVybS48bzpw
PjwvbzpwPjwvbGk+PC91bD4NCjxwIGNsYXNzPSJNc29Ob3JtYWwiPjxvOnA+Jm5ic3A7PC9vOnA+
PC9wPg0KPHAgY2xhc3M9Ik1zb05vcm1hbCI+VGhlcmUgaXMgb2Z0ZW4gYSB0cmFkZW9mZiBiZXR3
ZWVuIHNlY3VyaXR5IGFuZCBwZXJmb3JtYW5jZTsgc29tZSBzZXJ2ZXJzIG1heSBjaG9vc2UgMC1S
VFQgYmFzZWQgb24gdGhlaXIgYnVzaW5lc3MgcmVxdWlyZW1lbnRzLCBhbmQgb3RoZXJzIG1heSBj
aG9vc2UgVEIuIEkgZG8gbm90IHRoaW5rIHRoYXQgaXQgaXMgbmVjZXNzYXJ5IHRvIHJlY29uY2ls
ZSBUQiBhbmQgMC1SVFQgKGFsdGhvdWdoIGl0IHdvdWxkIGhhdmUNCiBiZWVuIGF3ZXNvbWUgaWYg
d2UgY291bGQpLiBGcm9tIG15IHBlcnNwZWN0aXZlLCBpdCBpcyBtb3JlIGltcG9ydGFudCB0byBr
ZWVwIFRCIHNlY3VyZSB0aGFuIHRvIG1ha2UgaXQgd29yayB3aXRoIDAtUlRUOiByZXBsYXlhYmxl
IFRCIHdvdWxkIGJlIGEgd2FzdGUgb2YgQ1BVIGN5Y2xlcy48bzpwPjwvbzpwPjwvcD4NCjxwIGNs
YXNzPSJNc29Ob3JtYWwiPjxvOnA+Jm5ic3A7PC9vOnA+PC9wPg0KPHAgY2xhc3M9Ik1zb05vcm1h
bCI+Q2hlZXJzLDxvOnA+PC9vOnA+PC9wPg0KPHAgY2xhc3M9Ik1zb05vcm1hbCI+PG86cD4mbmJz
cDs8L286cD48L3A+DQo8cCBjbGFzcz0iTXNvTm9ybWFsIj5BbmRyZWk8bzpwPjwvbzpwPjwvcD4N
CjxwIGNsYXNzPSJNc29Ob3JtYWwiPjxvOnA+Jm5ic3A7PC9vOnA+PC9wPg0KPGRpdj4NCjxkaXYg
c3R5bGU9ImJvcmRlcjpub25lO2JvcmRlci10b3A6c29saWQgI0UxRTFFMSAxLjBwdDtwYWRkaW5n
OjMuMHB0IDBpbiAwaW4gMGluIj4NCjxwIGNsYXNzPSJNc29Ob3JtYWwiPjxiPkZyb206PC9iPiBV
bmJlYXJhYmxlIFttYWlsdG86dW5iZWFyYWJsZS1ib3VuY2VzQGlldGYub3JnXQ0KPGI+T24gQmVo
YWxmIE9mIDwvYj5Kb2huIEJyYWRsZXk8YnI+DQo8Yj5TZW50OjwvYj4gVGh1cnNkYXksIEp1bmUg
MjksIDIwMTcgMTI6MDIgUE08YnI+DQo8Yj5Ubzo8L2I+IE5pY2sgSGFycGVyICZsdDtuaGFycGVy
QGdvb2dsZS5jb20mZ3Q7PGJyPg0KPGI+Q2M6PC9iPiBJRVRGIFRva2JpbmQgV0cgJmx0O3VuYmVh
cmFibGVAaWV0Zi5vcmcmZ3Q7OyBMZWlmIEpvaGFuc3NvbiAmbHQ7bGVpZmpAc3VuZXQuc2UmZ3Q7
OyB0b2tiaW5kLWNoYWlyc0BpZXRmLm9yZzsgQmVuamFtaW4gS2FkdWsgJmx0O2thZHVrQG1pdC5l
ZHUmZ3Q7PGJyPg0KPGI+U3ViamVjdDo8L2I+IFJlOiBbVW5iZWFyYWJsZV0gSS1EIEFjdGlvbjog
ZHJhZnQtaWV0Zi10b2tiaW5kLXRsczEzLTBydHQtMDIudHh0PG86cD48L286cD48L3A+DQo8L2Rp
dj4NCjwvZGl2Pg0KPHAgY2xhc3M9Ik1zb05vcm1hbCI+PG86cD4mbmJzcDs8L286cD48L3A+DQo8
cCBjbGFzcz0iTXNvTm9ybWFsIj5JbmxpbmU8bzpwPjwvbzpwPjwvcD4NCjxkaXY+DQo8cCBjbGFz
cz0iTXNvTm9ybWFsIj48bzpwPiZuYnNwOzwvbzpwPjwvcD4NCjxkaXY+DQo8YmxvY2txdW90ZSBz
dHlsZT0ibWFyZ2luLXRvcDo1LjBwdDttYXJnaW4tYm90dG9tOjUuMHB0Ij4NCjxkaXY+DQo8cCBj
bGFzcz0iTXNvTm9ybWFsIj5PbiBKdW4gMjksIDIwMTcsIGF0IDI6MzMgUE0sIE5pY2sgSGFycGVy
ICZsdDs8YSBocmVmPSJtYWlsdG86bmhhcnBlckBnb29nbGUuY29tIj5uaGFycGVyQGdvb2dsZS5j
b208L2E+Jmd0OyB3cm90ZTo8bzpwPjwvbzpwPjwvcD4NCjwvZGl2Pg0KPHAgY2xhc3M9Ik1zb05v
cm1hbCI+PG86cD4mbmJzcDs8L286cD48L3A+DQo8ZGl2Pg0KPHAgY2xhc3M9Ik1zb05vcm1hbCI+
PHNwYW4gc3R5bGU9ImZvbnQtc2l6ZTo5LjBwdDtmb250LWZhbWlseTomcXVvdDtIZWx2ZXRpY2Em
cXVvdDssc2Fucy1zZXJpZiI+T24gVGh1LCBKdW4gMjksIDIwMTcgYXQgMjowNSBBTSwgTGVpZiBK
b2hhbnNzb24gJmx0Ozwvc3Bhbj48YSBocmVmPSJtYWlsdG86bGVpZmpAc3VuZXQuc2UiPjxzcGFu
IHN0eWxlPSJmb250LXNpemU6OS4wcHQ7Zm9udC1mYW1pbHk6JnF1b3Q7SGVsdmV0aWNhJnF1b3Q7
LHNhbnMtc2VyaWYiPmxlaWZqQHN1bmV0LnNlPC9zcGFuPjwvYT48c3BhbiBzdHlsZT0iZm9udC1z
aXplOjkuMHB0O2ZvbnQtZmFtaWx5OiZxdW90O0hlbHZldGljYSZxdW90OyxzYW5zLXNlcmlmIj4m
Z3Q7DQogd3JvdGU6PGJyIHN0eWxlPSJmb250LXZhcmlhbnQtY2Fwczogbm9ybWFsO3RleHQtYWxp
Z246c3RhcnQ7LXdlYmtpdC10ZXh0LXN0cm9rZS13aWR0aDogMHB4O3dvcmQtc3BhY2luZzowcHgi
Pg0KPGJyPg0KPC9zcGFuPjxvOnA+PC9vOnA+PC9wPg0KPGJsb2NrcXVvdGUgc3R5bGU9Im1hcmdp
bi10b3A6NS4wcHQ7bWFyZ2luLWJvdHRvbTo1LjBwdCI+DQo8cCBjbGFzcz0iTXNvTm9ybWFsIj48
c3BhbiBzdHlsZT0iZm9udC1zaXplOjkuMHB0O2ZvbnQtZmFtaWx5OiZxdW90O0hlbHZldGljYSZx
dW90OyxzYW5zLXNlcmlmIj5PbiAyMDE3LTA2LTI5IDA0OjQ4LCBCZW5qYW1pbiBLYWR1ayB3cm90
ZTo8YnI+DQo8YnI+DQo8bzpwPjwvbzpwPjwvc3Bhbj48L3A+DQo8YmxvY2txdW90ZSBzdHlsZT0i
bWFyZ2luLXRvcDo1LjBwdDttYXJnaW4tYm90dG9tOjUuMHB0Ij4NCjxwIGNsYXNzPSJNc29Ob3Jt
YWwiPjxzcGFuIHN0eWxlPSJmb250LXNpemU6OS4wcHQ7Zm9udC1mYW1pbHk6JnF1b3Q7SGVsdmV0
aWNhJnF1b3Q7LHNhbnMtc2VyaWYiPk9uIFdlZCwgSnVuIDI4LCAyMDE3IGF0IDAzOjI1OjEzUE0g
LTA3MDAsIE5pY2sgSGFycGVyIHdyb3RlOjxicj4NCjxicj4NCjxvOnA+PC9vOnA+PC9zcGFuPjwv
cD4NCjxibG9ja3F1b3RlIHN0eWxlPSJtYXJnaW4tdG9wOjUuMHB0O21hcmdpbi1ib3R0b206NS4w
cHQiPg0KPHAgY2xhc3M9Ik1zb05vcm1hbCI+PHNwYW4gc3R5bGU9ImZvbnQtc2l6ZTo5LjBwdDtm
b250LWZhbWlseTomcXVvdDtIZWx2ZXRpY2EmcXVvdDssc2Fucy1zZXJpZiI+SGVyZSdzIGEgc3Vt
bWFyeSBvZiB0aGUgY2hhbmdlcyBzaW5jZSB0aGUgbGFzdCBkcmFmdDo8YnI+DQo8YnI+DQotIElm
IFRCIGlzIGFjY2VwdGVkIGluIDAtUlRUIGRhdGEsIGtlZXAgdXNpbmcgdGhlIGVhcmx5IGV4cG9y
dGVyIGZvcjxicj4NCnRoZSB3aG9sZSBjb25uZWN0aW9uLiBUaGVyZSB3YXMgc29tZSBkaXNjdXNz
aW9uIG9uIHRoaXMgaW4gQ2hpY2Fnbyw8YnI+DQp3aXRoIG1vcmUgb24gdGhlIG1haWxpbmcgbGlz
dC4gQ2hhaXJzLCBjYW4geW91IGNvbmZpcm0gd2hldGhlciB3ZTxicj4NCnJlYWNoZWQgY29uc2Vu
c3VzIG9uIHRoZSBtYWlsaW5nIGxpc3Qgb3Igd2hldGhlciB3ZSBzaG91bGQgdGFrZSBhIGh1bTxi
cj4NCmluIFByYWd1ZT88bzpwPjwvbzpwPjwvc3Bhbj48L3A+DQo8L2Jsb2NrcXVvdGU+DQo8cCBj
bGFzcz0iTXNvTm9ybWFsIj48c3BhbiBzdHlsZT0iZm9udC1zaXplOjkuMHB0O2ZvbnQtZmFtaWx5
OiZxdW90O0hlbHZldGljYSZxdW90OyxzYW5zLXNlcmlmIj48YnI+DQpJIGFtIGEgV0cgY2hhaXIs
IGJ1dCBub3QgYSB0b2tiaW5kIGNoYWlyLCBidXQgdGhhdCBxdWVzdGlvbiBkb2VzIG5vdDxicj4N
CnNlZW0gdG8gbWFrZSBzZW5zZS4gJm5ic3A7Q29uc2Vuc3VzIG11c3QgYmUgcmVhY2hlZCAob3Ig
Y29uZmlybWVkKSBvbiB0aGU8YnI+DQptYWlsaW5nIGxpc3QsIHNvIGRlY2lkaW5nIHRoZXJlIHdh
c24ndCBlbm91Z2ggZmVlZGJhY2sgb24gdGhlIGxpc3QgYW5kPGJyPg0KZ29pbmcgdG8gYW4gaW4t
cm9vbSBodW0gc2VlbXMgYmFja3dhcmRzLCBwcm9jZWR1cmFsbHkuPG86cD48L286cD48L3NwYW4+
PC9wPg0KPC9ibG9ja3F1b3RlPg0KPHAgY2xhc3M9Ik1zb05vcm1hbCI+PHNwYW4gc3R5bGU9ImZv
bnQtc2l6ZTo5LjBwdDtmb250LWZhbWlseTomcXVvdDtIZWx2ZXRpY2EmcXVvdDssc2Fucy1zZXJp
ZiI+PGJyPg0KSnVkZ2luZyBjb25zZW5zdXMgaXMgc29tZXRpbWVzIHRyaWNreS4gSSB0aGluayB3
aGF0IE5pY2sgbWVhbnQgd2FzIHRoYXQ8YnI+DQp3ZSBtYXkgd2FudCB0byBkbyBhIGh1bSBpbiBQ
cmFndWUgL2luIGFkZGl0aW9uIHRvLyBzZWVraW5nIGNvbmZpcm1hdGlvbjxicj4NCm9uIHRoZSBs
aXN0LjxvOnA+PC9vOnA+PC9zcGFuPjwvcD4NCjwvYmxvY2txdW90ZT4NCjxwIGNsYXNzPSJNc29O
b3JtYWwiPjxzcGFuIHN0eWxlPSJmb250LXNpemU6OS4wcHQ7Zm9udC1mYW1pbHk6JnF1b3Q7SGVs
dmV0aWNhJnF1b3Q7LHNhbnMtc2VyaWYiPjxicj4NCkl0IGlzIHVuY2xlYXIgdG8gbWUgd2hldGhl
ciBjb25zZW5zdXMgd2FzIHJlYWNoZWQgKGhlbmNlIGRlZmVycmluZyB0bzxicj4NCnRoZSBjaGFp
cnMgb24gdGhhdCBqdWRnZW1lbnQpLiBJZiB3ZSBkb24ndCBoYXZlIGNvbnNlbnN1cywgSSdtIGZp
bmU8YnI+DQpjb250aW51aW5nIHRoZSBkaXNjdXNzaW9uIG9uIGxpc3QgYW5kIGluIFByYWd1ZS4g
TGV0IG1lIGNoZWNrIHRoYXQgSTxicj4NCnVuZGVyc3RhbmQgdGhlIHByb2Nlc3MgcHJvcGVybHk6
IGZpcnN0LCBkaXNjdXNzIChvbiBsaXN0IGFuZCBwb3NzaWJseTxicj4NCmluIHBlcnNvbiksIHRo
ZW4gaWYgdGhlIGRpc2N1c3Npb24gc291bmRzIGxpa2UgaXQncyByZWFjaGVkIGE8YnI+DQpjb25z
ZW5zdXMsIG9wdGlvbmFsbHkgaHVtIGluIHBlcnNvbiwgYW5kIHRoZW4gY29uZmlybSBjb25zZW5z
dXMgb24gdGhlPGJyPg0KbGlzdC4gRG9lcyB0aGF0IHNvdW5kIGFib3V0IHJpZ2h0Pzwvc3Bhbj48
bzpwPjwvbzpwPjwvcD4NCjwvZGl2Pg0KPC9ibG9ja3F1b3RlPg0KPGRpdj4NCjxwIGNsYXNzPSJN
c29Ob3JtYWwiPjxvOnA+Jm5ic3A7PC9vOnA+PC9wPg0KPC9kaXY+DQo8cCBjbGFzcz0iTXNvTm9y
bWFsIj5ZZXM8YnI+DQo8YnI+DQo8bzpwPjwvbzpwPjwvcD4NCjxibG9ja3F1b3RlIHN0eWxlPSJt
YXJnaW4tdG9wOjUuMHB0O21hcmdpbi1ib3R0b206NS4wcHQ7Zm9udC12YXJpYW50LWNhcHM6IG5v
cm1hbDtvcnBoYW5zOiBhdXRvO3RleHQtYWxpZ246c3RhcnQ7d2lkb3dzOiBhdXRvOy13ZWJraXQt
dGV4dC1zaXplLWFkanVzdDogYXV0bzstd2Via2l0LXRleHQtc3Ryb2tlLXdpZHRoOiAwcHg7d29y
ZC1zcGFjaW5nOjBweCI+DQo8ZGl2Pg0KPGJsb2NrcXVvdGUgc3R5bGU9Im1hcmdpbi10b3A6NS4w
cHQ7bWFyZ2luLWJvdHRvbTo1LjBwdCI+DQo8cCBjbGFzcz0iTXNvTm9ybWFsIj48c3BhbiBzdHls
ZT0iZm9udC1zaXplOjkuMHB0O2ZvbnQtZmFtaWx5OiZxdW90O0hlbHZldGljYSZxdW90OyxzYW5z
LXNlcmlmIj48YnI+DQo8YnI+DQo8bzpwPjwvbzpwPjwvc3Bhbj48L3A+DQo8YmxvY2txdW90ZSBz
dHlsZT0ibWFyZ2luLXRvcDo1LjBwdDttYXJnaW4tYm90dG9tOjUuMHB0Ij4NCjxwIGNsYXNzPSJN
c29Ob3JtYWwiPjxzcGFuIHN0eWxlPSJmb250LXNpemU6OS4wcHQ7Zm9udC1mYW1pbHk6JnF1b3Q7
SGVsdmV0aWNhJnF1b3Q7LHNhbnMtc2VyaWYiPjxicj4NCjxicj4NCjxvOnA+PC9vOnA+PC9zcGFu
PjwvcD4NCjxibG9ja3F1b3RlIHN0eWxlPSJtYXJnaW4tdG9wOjUuMHB0O21hcmdpbi1ib3R0b206
NS4wcHQiPg0KPHAgY2xhc3M9Ik1zb05vcm1hbCI+PHNwYW4gc3R5bGU9ImZvbnQtc2l6ZTo5LjBw
dDtmb250LWZhbWlseTomcXVvdDtIZWx2ZXRpY2EmcXVvdDssc2Fucy1zZXJpZiI+LSAwLVJUVCBU
QiBjYW5ub3QgYmUgdXNlZCB3aXRoIGV4dGVybmFsbHkgcHJvdmlzaW9uZWQgUFNLcyBvciB3aXRo
IGE8YnI+DQpQU0stb25seSBrZXkgZXhjaGFuZ2UgbW9kZTxicj4NCjxicj4NCi0gQSBuZXcgVExT
IGV4dGVuc2lvbiBpcyB1c2VkIGZvciBuZWdvdGlhdGluZyBhbmQgaW5kaWNhdGluZyB1c2Ugb2Yg
MC1SVFQgVEI8YnI+DQo8YnI+DQotIFRoZSByZXBsYXkgaW5kaWNhdGlvbiBUTFMgZXh0ZW5zaW9u
IGhhcyBiZWVuIHJlbW92ZWQ8bzpwPjwvbzpwPjwvc3Bhbj48L3A+DQo8L2Jsb2NrcXVvdGU+DQo8
cCBjbGFzcz0iTXNvTm9ybWFsIj48c3BhbiBzdHlsZT0iZm9udC1zaXplOjkuMHB0O2ZvbnQtZmFt
aWx5OiZxdW90O0hlbHZldGljYSZxdW90OyxzYW5zLXNlcmlmIj48YnI+DQpTb21lIGRpc2N1c3Np
b24gb24gdGhlIGh0dHBiaXMgbGlzdCBicm91Z2h0IHVwIHRoYXQgdGhpcyBkb2N1bWVudCBzaG91
bGQ8YnI+DQptYW5kYXRlIHRoYXQgMC1SVFQgdG9rZW4gYmluZGluZyBpcyBvbmx5IHVzZWQgaW4g
Y29uanVuY3Rpb24gd2l0aDxicj4NCmEgVExTIHN0YWNrIHRoYXQgcHJvdmlkZXMgc3Ryb25nIGFu
dGktcmVwbGF5IHByb3RlY3Rpb25zIChpLmUuLCB6ZXJvPGJyPg0KYWRkaXRpb25hbCByZXBsYXlz
IHBvc3NpYmxlIGFuZCBvbmUgcmV0cmFuc21pc3Npb24gdmlhIERLRyBhdHRhY2spLiAmbmJzcDtJ
biBvdGhlcjxicj4NCndvcmRzLCB0aGUgdGltZS1iYXNlZCBzY2hlbWUgb2YgKGRyYWZ0LTAyKSBz
ZWN0aW9uIDYuNCBzaG91bGQgYmUgcmVtb3ZlZCw8YnI+DQphbmQgcGVyaGFwcyA2LjMuMSByZXdv
cmRlZCBzb21ld2hhdC48bzpwPjwvbzpwPjwvc3Bhbj48L3A+DQo8L2Jsb2NrcXVvdGU+DQo8L2Js
b2NrcXVvdGU+DQo8cCBjbGFzcz0iTXNvTm9ybWFsIj48c3BhbiBzdHlsZT0iZm9udC1zaXplOjku
MHB0O2ZvbnQtZmFtaWx5OiZxdW90O0hlbHZldGljYSZxdW90OyxzYW5zLXNlcmlmIj48YnI+DQpJ
IHJlYWQgb3ZlciB0aGUgJnF1b3Q7TmV3IFZlcnNpb24gTm90aWZpY2F0aW9uIGZvcjxicj4NCmRy
YWZ0LXRob21zb24taHR0cC1yZXBsYXktMDAudHh0JnF1b3Q7IHRocmVhZCBvbiB0aGUgaHR0cGJp
cyBsaXN0LiBNeTxicj4NCnVuZGVyc3RhbmRpbmcgb2YgdGhlIGlzc3VlIHJhaXNlZCBvbiB0aGF0
IGxpc3QgaXMgc2ltcGx5IHRoYXQgdGhlcmU8YnI+DQphcmUgYXR0YWNrcyBvbiAwLVJUVCBUb2tl
biBCaW5kaW5nIGlmIHRoZXJlIGlzbid0IGEgc3RyaWN0IGdsb2JhbDxicj4NCmFudGktcmVwbGF5
IG1lY2hhbmlzbS4gVGhlcmUgYXJlIHN0aWxsIGF0dGFja3MgcG9zc2libGUgb24gMC1SVFQgVG9r
ZW48YnI+DQpCaW5kaW5nIGV2ZW4gaWYgdGhlcmUgaXMgYSBzdHJpY3QgZ2xvYmFsIGFudGktcmVw
bGF5IG1lY2hhbmlzbS4gSSBuZWVkPGJyPg0KdG8gY29uc2lkZXIgd2hhdCBhZGRpdGlvbmFsIGF0
dGFja3MgYXJlIHBvc3NpYmxlIHdpdGhvdXQgc3VjaCBhPGJyPg0KbWVjaGFuaXNtLCBhbmQgaWYg
YW55IG9mIHRob3NlIGF0dGFja3MgcmVxdWlyZSBsZXNzIHByaXZpbGVnZXMgdGhhbjxicj4NCnRo
ZSBhdHRhY2tzIHBvc3NpYmxlIHdpdGggdGhlIG1lY2hhbmlzbS48YnIgc3R5bGU9ImZvbnQtdmFy
aWFudC1jYXBzOiBub3JtYWw7dGV4dC1hbGlnbjpzdGFydDstd2Via2l0LXRleHQtc3Ryb2tlLXdp
ZHRoOiAwcHg7d29yZC1zcGFjaW5nOjBweCI+DQo8YnI+DQo8L3NwYW4+PG86cD48L286cD48L3A+
DQo8YmxvY2txdW90ZSBzdHlsZT0ibWFyZ2luLXRvcDo1LjBwdDttYXJnaW4tYm90dG9tOjUuMHB0
Ij4NCjxibG9ja3F1b3RlIHN0eWxlPSJtYXJnaW4tdG9wOjUuMHB0O21hcmdpbi1ib3R0b206NS4w
cHQiPg0KPHAgY2xhc3M9Ik1zb05vcm1hbCIgc3R5bGU9Im1hcmdpbi1ib3R0b206MTIuMHB0Ij48
c3BhbiBzdHlsZT0iZm9udC1zaXplOjkuMHB0O2ZvbnQtZmFtaWx5OiZxdW90O0hlbHZldGljYSZx
dW90OyxzYW5zLXNlcmlmIj48YnI+DQooSXQgYWxzbyBicm91Z2h0IHVwIG11bHRpcGxlIHBlb3Bs
ZXMnIHNlbnRpbWVudHMgdGhhdCAwLVJUVCB0b2tlbiBiaW5kaW5nPGJyPg0KaXMgYSBiYWQgaWRl
YSBpbiBnZW5lcmFsLCBidXQgdGhpcyBtYXkgbm90IGJlIHByb2NlZHVyYWxseSB0aGUgcmlnaHQg
dGltZTxicj4NCnRvIGhhdmUgdGhhdCBkaXNjdXNzaW9uLik8YnI+DQo8YnI+DQotQmVuPG86cD48
L286cD48L3NwYW4+PC9wPg0KPC9ibG9ja3F1b3RlPg0KPHAgY2xhc3M9Ik1zb05vcm1hbCI+PHNw
YW4gc3R5bGU9ImZvbnQtc2l6ZTo5LjBwdDtmb250LWZhbWlseTomcXVvdDtIZWx2ZXRpY2EmcXVv
dDssc2Fucy1zZXJpZiI+PG86cD4mbmJzcDs8L286cD48L3NwYW4+PC9wPg0KPC9ibG9ja3F1b3Rl
Pg0KPHAgY2xhc3M9Ik1zb05vcm1hbCI+PHNwYW4gc3R5bGU9ImZvbnQtc2l6ZTo5LjBwdDtmb250
LWZhbWlseTomcXVvdDtIZWx2ZXRpY2EmcXVvdDssc2Fucy1zZXJpZiI+SSdtIGF3YXJlIHRoYXQg
bXVsdGlwbGUgcGVvcGxlIHRoaW5rIHRoYXQgMC1SVFQgdG9rZW4gYmluZGluZyBpcyBhIGJhZDxi
cj4NCmlkZWEgaW4gZ2VuZXJhbC4gU28gZmFyLCB0aGUgaW1wcmVzc2lvbiBJJ3ZlIGdvdHRlbiBv
ZiB0aGlzIHNlbnRpbWVudDxicj4NCmlzICZxdW90OzAtUlRUIFRva2VuIEJpbmRpbmcgaXMgbm90
IHNvbWV0aGluZyBJIGhhdmUgYW55IGludGVyZXN0IGluPGJyPg0KaW1wbGVtZW50aW5nJnF1b3Q7
LiBJZiB0aGUgc2VudGltZW50IGlzIGNsb3NlciB0byAmcXVvdDswLVJUVCBUb2tlbiBCaW5kaW5n
IGlzPGJyPg0Kc3VjaCBhIGhvcnJpYmxlIHRoaW5nIHRoYXQgbm8gb25lIHNob3VsZCBiZSBpbXBs
ZW1lbnRpbmcgaXQmcXVvdDssIHRoZW48YnI+DQptYXliZSB3ZSBzaG91bGQgZGlzY3VzcyB0aGF0
IHNvb25lci48L3NwYW4+PG86cD48L286cD48L3A+DQo8L2Rpdj4NCjwvYmxvY2txdW90ZT4NCjxw
IGNsYXNzPSJNc29Ob3JtYWwiPjxvOnA+Jm5ic3A7PC9vOnA+PC9wPg0KPC9kaXY+DQo8ZGl2Pg0K
PHAgY2xhc3M9Ik1zb05vcm1hbCI+QSBnb29kIHBvaW50LCAmbmJzcDtpZiB0aGUgYXR0YWNrcyBh
cmUgc3RpbGwgcG9zc2libGUgdGhlbiBzdXBwb3J0aW5nIDAtUlRUIGlzIHByb2JsZW1hdGljLiAm
bmJzcDs8bzpwPjwvbzpwPjwvcD4NCjwvZGl2Pg0KPGRpdj4NCjxwIGNsYXNzPSJNc29Ob3JtYWwi
Pk9uIHRoZSBvdGhlciBoYW5kIDAtUlRUIGlzIGEgYmlnIHNwZWVkIGJvb3N0IGZvciByZXN1bWVk
IGNvbm5lY3Rpb25zLiAmbmJzcDtJdCBpcyBoYXJkIHRvIGltYWdpbmUgdGhhdCBzZXJ2ZXJzIGFy
ZSBnb2luZyB0byBkaXNhYmxlIGl0IHRvIHVzZSB0b2tlbiBiaW5kaW5nIG92ZXIgdGhlIGxvbmcg
dGVybS48bzpwPjwvbzpwPjwvcD4NCjwvZGl2Pg0KPGRpdj4NCjxwIGNsYXNzPSJNc29Ob3JtYWwi
PjxvOnA+Jm5ic3A7PC9vOnA+PC9wPg0KPC9kaXY+DQo8ZGl2Pg0KPHAgY2xhc3M9Ik1zb05vcm1h
bCI+SSBkb27igJl0IGJlbGlldmUgdGhlIFdHIGhhcyBhbnkgcmVhbCBjb25zZW5zdXMgb24gdGhp
cyB5ZXQuICZuYnNwOyBUaGUgZHJhZnQgc3BlYyBpcyBoZWxwZnVsbCBmb3IgdXMgdG8gZGlzY3Vz
cyB0aGUgaXNzdWVzLiAmbmJzcDsmbmJzcDs8bzpwPjwvbzpwPjwvcD4NCjwvZGl2Pg0KPGRpdj4N
CjxwIGNsYXNzPSJNc29Ob3JtYWwiPjxvOnA+Jm5ic3A7PC9vOnA+PC9wPg0KPC9kaXY+DQo8ZGl2
Pg0KPHAgY2xhc3M9Ik1zb05vcm1hbCI+SSBlbmNvdXJhZ2UgbW9yZSBkaXNjdXNzaW9uIG9uIHRo
ZSBsaXN0IG9uIHRoZSB0b3BpYyBvZiB0aGUgZHJhZnQgYW5kIGlmIHRoaXMgaXMgdGhlIGNvcnJl
Y3Qgd2F5IHRvIGRlYWwgd2l0aCAwLXJ0dCBpZiB0aGVyZSBhcmUgY291bnRlciBvcGluaW9ucy48
bzpwPjwvbzpwPjwvcD4NCjwvZGl2Pg0KPGRpdj4NCjxwIGNsYXNzPSJNc29Ob3JtYWwiPjxvOnA+
Jm5ic3A7PC9vOnA+PC9wPg0KPC9kaXY+DQo8ZGl2Pg0KPHAgY2xhc3M9Ik1zb05vcm1hbCI+UmVn
YXJkczxvOnA+PC9vOnA+PC9wPg0KPC9kaXY+DQo8ZGl2Pg0KPHAgY2xhc3M9Ik1zb05vcm1hbCI+
Sm9obiBCLjxvOnA+PC9vOnA+PC9wPg0KPC9kaXY+DQo8cCBjbGFzcz0iTXNvTm9ybWFsIj48bzpw
PiZuYnNwOzwvbzpwPjwvcD4NCjwvZGl2Pg0KPC9kaXY+DQo8L2JvZHk+DQo8L2h0bWw+DQo=

--_000_DM2PR21MB009122B46F7497493AFF953C8CD20DM2PR21MB0091namp_--


From nobody Thu Jun 29 17:18:51 2017
Return-Path: <bcampbell@pingidentity.com>
X-Original-To: unbearable@ietfa.amsl.com
Delivered-To: unbearable@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id C95D3126D45 for <unbearable@ietfa.amsl.com>; Thu, 29 Jun 2017 17:18:49 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: 0.201
X-Spam-Level: 
X-Spam-Status: No, score=0.201 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, HTML_MESSAGE=0.001, RCVD_IN_DNSWL_NONE=-0.0001, SPF_PASS=-0.001, THIS_AD=2.2, URIBL_BLOCKED=0.001] autolearn=no autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (1024-bit key) header.d=pingidentity.com
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id GzWEETUh8ady for <unbearable@ietfa.amsl.com>; Thu, 29 Jun 2017 17:18:47 -0700 (PDT)
Received: from mail-pf0-x236.google.com (mail-pf0-x236.google.com [IPv6:2607:f8b0:400e:c00::236]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id B12931243FE for <unbearable@ietf.org>; Thu, 29 Jun 2017 17:18:47 -0700 (PDT)
Received: by mail-pf0-x236.google.com with SMTP id q86so58117722pfl.3 for <unbearable@ietf.org>; Thu, 29 Jun 2017 17:18:47 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=pingidentity.com; s=gmail; h=mime-version:in-reply-to:references:from:date:message-id:subject:to; bh=CmxDjc5Nyif9lYacJ3tX2ruliS3woZc6s4m9wlEwXHU=; b=hgRTj7AJRrI5TUwvtuvCGOct30ol+uuvqsBw0h//HThWoUNba2mNVNh1N4X7/d4ONW IAcjJadgLE9ixAz9CdeCfPF7jModBDzd2CZbptgq6TmJAUq3+ecjBmPgZ0ik3/kpwp0F 98NQYbEvs3OqJeFN/IbeuBJpbAp4qfd8/CFCw=
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20161025; h=x-gm-message-state:mime-version:in-reply-to:references:from:date :message-id:subject:to; bh=CmxDjc5Nyif9lYacJ3tX2ruliS3woZc6s4m9wlEwXHU=; b=qqfFcfeP8jkNSO5100jvg06EIKxHyuDFSUAZEJo9DDbAiwfqwA9rN51uNTjZagNFUz vrtX+zZa3/z3hgxuXwIdJP+0OB96OF99HMG+xBums2WZpTS8r6DqUH0zArVYDvQZJnCK CA5a38rD+Eywl0JCzhJefm+4fXJx+mFXtqAh1ZwyKVN5pYzsYFZyyK0A/WANRk3fsDZ4 +k4AiYGZ9Br3VJCEToFc8AiNqqyYH/b9d+vbRHhuH+EmblF2a/MMaqtXSNkB4iXqhcYV 0CzZx48EDM/y60TgxhlxdRUBFcz+4pF4xkUBnEFLyhR1kIjtGAz7xQtrgstan4eRvZ97 dn7g==
X-Gm-Message-State: AKS2vOzkpGAZ/9kyrEGNHRCrHLqKQJVL9POBX5vxj3WyjW4lM03dj4mF OKyzeiaeAyQs426GVkpW1YQ6kWZFJFT9JHusT9LnoHi84IEjEhgJDkh9ZqZyG3pbNaTgCF4X5X+ 60mPmwQIP41dsig==
X-Received: by 10.99.44.206 with SMTP id s197mr18542466pgs.116.1498781927050;  Thu, 29 Jun 2017 17:18:47 -0700 (PDT)
MIME-Version: 1.0
Received: by 10.100.129.130 with HTTP; Thu, 29 Jun 2017 17:18:16 -0700 (PDT)
In-Reply-To: <CA+k3eCQs+j3yR4bUQtC1DpEnXRSbA92MSzhynR9YQ0wFemrM1Q@mail.gmail.com>
References: <CA+k3eCQ4Xvea_iqcanPwGECe8+eL_-aKjB4mMnpXfp06OPsJGQ@mail.gmail.com> <CA+k3eCQs+j3yR4bUQtC1DpEnXRSbA92MSzhynR9YQ0wFemrM1Q@mail.gmail.com>
From: Brian Campbell <bcampbell@pingidentity.com>
Date: Thu, 29 Jun 2017 18:18:16 -0600
Message-ID: <CA+k3eCRayp6k30CfFYy5MgtunTpP=xq3Nxar8e_LgonYnZY5fg@mail.gmail.com>
To: IETF Tokbind WG <unbearable@ietf.org>
Content-Type: multipart/alternative; boundary="001a1145a2dc5ba9360553225c9c"
Archived-At: <https://mailarchive.ietf.org/arch/msg/unbearable/RMLOg2L6ExN9XDmLJlWybq6sB3s>
Subject: Re: [Unbearable] Thurs 9am-10am in Lugano: additional TB TTRP meeting
X-BeenThere: unbearable@ietf.org
X-Mailman-Version: 2.1.22
Precedence: list
List-Id: "\"This list is for discussion of proposals for doing better than bearer tokens \(e.g. HTTP cookies, OAuth tokens etc.\) for web applications. The specific goal is chartering a WG focused on preventing security token export and replay attacks.\"" <unbearable.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/unbearable>, <mailto:unbearable-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/unbearable/>
List-Post: <mailto:unbearable@ietf.org>
List-Help: <mailto:unbearable-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/unbearable>, <mailto:unbearable-request@ietf.org?subject=subscribe>
X-List-Received-Date: Fri, 30 Jun 2017 00:18:50 -0000

--001a1145a2dc5ba9360553225c9c
Content-Type: text/plain; charset="UTF-8"

And here is that new draft that reflects that preference of having the TTRP
do the validation and pass the TB IDs to the backend.

---------- Forwarded message ----------
From: <internet-drafts@ietf.org>
Date: Thu, Jun 29, 2017 at 6:03 PM
Subject: New Version Notification for draft-campbell-tokbind-ttrp-00.txt

A new version of I-D, draft-campbell-tokbind-ttrp-00.txt
has been successfully submitted by Brian Campbell and posted to the
IETF repository.

Name:           draft-campbell-tokbind-ttrp
Revision:       00
Title:          HTTPS Token Binding with TLS Terminating Reverse Proxies
Document date:  2017-06-29
Group:          Individual Submission
Pages:          10
URL:            https://www.ietf.org/internet-drafts/draft-campbell-tokbind-
ttrp-00.txt
Status:         https://datatracker.ietf.org/doc/draft-campbell-tokbind-ttr
p/
Htmlized:       https://tools.ietf.org/html/draft-campbell-tokbind-ttrp-00
Htmlized:       https://datatracker.ietf.org/doc/html/draft-campbell-tokbin
d-ttrp-00


Abstract:
   This document defines common HTTP header fields that enable a TLS
   terminating reverse proxy to convey information about the validated
   Token Binding Message sent by the client to a backend server, which
   enables that backend server to bind, or verify the binding of,
   cookies and other security tokens to the client's Token Binding key.



Please note that it may take a couple of minutes from the time of submission
until the htmlized version and diff are available at tools.ietf.org.

The IETF Secretariat

On Mon, Apr 3, 2017 at 12:07 PM, Brian Campbell <bcampbell@pingidentity.com>
wrote:

> Thanks to the several people who came out on Thursday morning to discuss
> the approach around TTRP & TB.
>
> The (more than rough) consensus that morning was that it was more
> appropriate for the TTRP to do the validation of the Token Binding Message
> in the Sec-Token-Binding header. That is contrary to the approach described
> in -00 of draft-campbell-tokbind-tls-term
> <https://tools.ietf.org/html/draft-campbell-tokbind-tls-term-00>. In
> order to move forward and facilitate discussion,I plan to write a new draft
> that reflects that preference of having the TTRP do the validation. Don't
> have an ETA on that just yet but I'll post it to this list when I have
> something readable.
>
>
>
>
>
> On Tue, Mar 28, 2017 at 8:57 AM, Brian Campbell <
> bcampbell@pingidentity.com> wrote:
>
>> Unfortunately, the presentation and discussion on Token Binding and TLS
>> Terminating Reverse Proxies was cut short by the end of Monday's meeting.
>> I would like to invite (or maybe beg) anyone who's interested in, or has
>> input into, the topic to meet again this week to discuss it more. Ideally
>> I'd like to have some sense of consensus on a preferred approach so I can
>> proceed with document work.
>>
>> I've reserved Lugano, the attendee sign-up room, for an hour starting at
>> 9am on Thursday (trying to find a good time was hard, sorry, I hope this
>> works okay for folks) for this ad hoc meeting.
>>
>> Lugano is on the 2nd floor. See https://datatracker.ietf.org/m
>> eeting/98/floor-plan?room=lugano#chicago-swissotel-floor-2
>>
>> The slides that were partially presented at yesterday's meeting are
>> attached for background and context.
>>
>> Hope to see many of you there!
>>
>
>

-- 
*CONFIDENTIALITY NOTICE: This email may contain confidential and privileged 
material for the sole use of the intended recipient(s). Any review, use, 
distribution or disclosure by others is strictly prohibited.  If you have 
received this communication in error, please notify the sender immediately 
by e-mail and delete the message and any file attachments from your 
computer. Thank you.*

--001a1145a2dc5ba9360553225c9c
Content-Type: text/html; charset="UTF-8"
Content-Transfer-Encoding: quoted-printable

<div dir=3D"ltr">And here is that new draft that reflects that preference o=
f having the TTRP do the validation and pass the TB IDs to the backend. <br=
><br><div>---------- Forwarded message ----------<br>From:  <span dir=3D"lt=
r">&lt;<a href=3D"mailto:internet-drafts@ietf.org" target=3D"_blank">intern=
et-drafts@ietf.org</a>&gt;</span><br>Date: Thu, Jun 29, 2017 at 6:03 PM<br>=
Subject: New Version Notification for draft-campbell-tokbind-ttrp-00<wbr>.t=
xt<br><br>
A new version of I-D, draft-campbell-tokbind-ttrp-00<wbr>.txt<br>
has been successfully submitted by Brian Campbell and posted to the<br>
IETF repository.<br>
<br>
Name:=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0draft-campbell-tokbind-ttrp<b=
r>
Revision:=C2=A0 =C2=A0 =C2=A0 =C2=A000<br>
Title:=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 HTTPS Token Binding with TLS Termi=
nating Reverse Proxies<br>
Document date:=C2=A0 2017-06-29<br>
Group:=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 Individual Submission<br>
Pages:=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 10<br>
URL:=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 <a href=3D"https://www.ietf.o=
rg/internet-drafts/draft-campbell-tokbind-ttrp-00.txt" rel=3D"noreferrer" t=
arget=3D"_blank">https://www.ietf.org/internet-<wbr>drafts/draft-campbell-t=
okbind-<wbr>ttrp-00.txt</a><br>
Status:=C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0<a href=3D"https://datatracker.iet=
f.org/doc/draft-campbell-tokbind-ttrp/" rel=3D"noreferrer" target=3D"_blank=
">https://datatracker.ietf.org/<wbr>doc/draft-campbell-tokbind-ttr<wbr>p/</=
a><br>
Htmlized:=C2=A0 =C2=A0 =C2=A0 =C2=A0<a href=3D"https://tools.ietf.org/html/=
draft-campbell-tokbind-ttrp-00" rel=3D"noreferrer" target=3D"_blank">https:=
//tools.ietf.org/html/d<wbr>raft-campbell-tokbind-ttrp-00</a><br>
Htmlized:=C2=A0 =C2=A0 =C2=A0 =C2=A0<a href=3D"https://datatracker.ietf.org=
/doc/html/draft-campbell-tokbind-ttrp-00" rel=3D"noreferrer" target=3D"_bla=
nk">https://datatracker.ietf.org/<wbr>doc/html/draft-campbell-tokbin<wbr>d-=
ttrp-00</a><br>
<br>
<br>
Abstract:<br>
=C2=A0 =C2=A0This document defines common HTTP header fields that enable a =
TLS<br>
=C2=A0 =C2=A0terminating reverse proxy to convey information about the vali=
dated<br>
=C2=A0 =C2=A0Token Binding Message sent by the client to a backend server, =
which<br>
=C2=A0 =C2=A0enables that backend server to bind, or verify the binding of,=
<br>
=C2=A0 =C2=A0cookies and other security tokens to the client&#39;s Token Bi=
nding key.<br>
<br>
<br>
<br>
Please note that it may take a couple of minutes from the time of submissio=
n<br>
until the htmlized version and diff are available at <a href=3D"http://tool=
s.ietf.org" rel=3D"noreferrer" target=3D"_blank">tools.ietf.org</a>.<br>
<br>
The IETF Secretariat</div></div><div class=3D"gmail_extra"><br><div class=
=3D"gmail_quote">On Mon, Apr 3, 2017 at 12:07 PM, Brian Campbell <span dir=
=3D"ltr">&lt;<a href=3D"mailto:bcampbell@pingidentity.com" target=3D"_blank=
">bcampbell@pingidentity.com</a>&gt;</span> wrote:<br><blockquote class=3D"=
gmail_quote" style=3D"margin:0 0 0 .8ex;border-left:1px #ccc solid;padding-=
left:1ex"><div dir=3D"ltr"><div><div>Thanks to the several people who came =
out on Thursday morning to discuss the approach around TTRP &amp; TB. <br><=
br></div>The (more than rough) consensus that morning was that it was more =
appropriate for the TTRP to do the validation of the Token Binding Message =
in the Sec-Token-Binding header. That is contrary to the approach described=
 in <a href=3D"https://tools.ietf.org/html/draft-campbell-tokbind-tls-term-=
00" target=3D"_blank">-00 of draft-campbell-tokbind-tls-ter<wbr>m</a>. In o=
rder to move forward and facilitate discussion,I plan to write a new draft =
that reflects that preference of having the TTRP do the validation. Don&#39=
;t have an ETA on that just yet but I&#39;ll post it to this list when I ha=
ve something readable.<br></div><div><br><br><div><br>=C2=A0<br></div></div=
></div><div class=3D"HOEnZb"><div class=3D"h5"><div class=3D"gmail_extra"><=
br><div class=3D"gmail_quote">On Tue, Mar 28, 2017 at 8:57 AM, Brian Campbe=
ll <span dir=3D"ltr">&lt;<a href=3D"mailto:bcampbell@pingidentity.com" targ=
et=3D"_blank">bcampbell@pingidentity.com</a>&gt;</span> wrote:<br><blockquo=
te class=3D"gmail_quote" style=3D"margin:0 0 0 .8ex;border-left:1px #ccc so=
lid;padding-left:1ex"><div dir=3D"ltr"><div><div>Unfortunately, the present=
ation and discussion on Token Binding and TLS Terminating Reverse Proxies w=
as cut short by the end of Monday&#39;s meeting.=C2=A0 I would like to invi=
te (or maybe beg) anyone who&#39;s interested in, or has input into, the to=
pic to meet again this week to discuss it more. Ideally I&#39;d like to hav=
e some sense of consensus on a preferred approach so I can proceed with doc=
ument work. <br></div><br></div>I&#39;ve reserved Lugano, the attendee sign=
-up room, for an hour starting at 9am on Thursday (trying to find a good ti=
me was hard, sorry, I hope this works okay for folks) for this ad hoc meeti=
ng. <br><br>Lugano is on the 2nd floor. See <a href=3D"https://datatracker.=
ietf.org/meeting/98/floor-plan?room=3Dlugano#chicago-swissotel-floor-2" tar=
get=3D"_blank">https://datatracker.ietf.org/m<wbr>eeting/98/floor-plan?room=
=3Dluga<wbr>no#chicago-swissotel-floor-2</a><br><div><div><div><br></div>Th=
e slides that were partially presented at yesterday&#39;s meeting are attac=
hed for background and context. <br><br></div><div>Hope to see many of you =
there!<br></div></div></div>
</blockquote></div><br></div>
</div></div></blockquote></div><br></div>

<br>
<i style=3D"margin:0px;padding:0px;border:0px;outline:0px;vertical-align:ba=
seline;background:rgb(255,255,255);font-family:proxima-nova-zendesk,system-=
ui,-apple-system,system-ui,&quot;Segoe UI&quot;,Roboto,Oxygen-Sans,Ubuntu,C=
antarell,&quot;Helvetica Neue&quot;,Arial,sans-serif;color:rgb(85,85,85)"><=
span style=3D"margin:0px;padding:0px;border:0px;outline:0px;vertical-align:=
baseline;background:transparent;font-family:proxima-nova-zendesk,system-ui,=
-apple-system,BlinkMacSystemFont,&quot;Segoe UI&quot;,Roboto,Oxygen-Sans,Ub=
untu,Cantarell,&quot;Helvetica Neue&quot;,Arial,sans-serif;font-weight:600"=
><font size=3D"2">CONFIDENTIALITY NOTICE: This email may contain confidenti=
al and privileged material for the sole use of the intended recipient(s). A=
ny review, use, distribution or disclosure by others is strictly prohibited=
.=C2=A0 If you have received this communication in error, please notify the=
 sender immediately by e-mail and delete the message and any file attachmen=
ts from your computer. Thank you.</font></span></i>
--001a1145a2dc5ba9360553225c9c--

