
From nobody Mon Nov 13 04:45:30 2017
Return-Path: <ekr@rtfm.com>
X-Original-To: unbearable@ietfa.amsl.com
Delivered-To: unbearable@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 801E1129418 for <unbearable@ietfa.amsl.com>; Mon, 13 Nov 2017 04:45:29 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.598
X-Spam-Level: 
X-Spam-Status: No, score=-2.598 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, HTML_MESSAGE=0.001, RCVD_IN_DNSWL_LOW=-0.7, URIBL_BLOCKED=0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (2048-bit key) header.d=rtfm-com.20150623.gappssmtp.com
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id 2M6rgF07ey50 for <unbearable@ietfa.amsl.com>; Mon, 13 Nov 2017 04:45:27 -0800 (PST)
Received: from mail-yw0-x230.google.com (mail-yw0-x230.google.com [IPv6:2607:f8b0:4002:c05::230]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id BDA6912783A for <unbearable@ietf.org>; Mon, 13 Nov 2017 04:45:26 -0800 (PST)
Received: by mail-yw0-x230.google.com with SMTP id p74so2887419ywe.2 for <unbearable@ietf.org>; Mon, 13 Nov 2017 04:45:26 -0800 (PST)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=rtfm-com.20150623.gappssmtp.com; s=20150623; h=mime-version:in-reply-to:references:from:date:message-id:subject:to; bh=hIqBzpbR89R/eqt5vFGvUT/OJcnTiL3YCDem1eoxjcc=; b=pnEHRSSUi6jLF7ywzD7SJPmuAMWgoKGK9aGL0QfGGCdAyV3vL5S4WPUBMUZffBLcHg XVCwloVJW5XmfrPJ+6sIBoPrhMoaJDukwUP455B7JoaqUX3TwarlIMiTo4GA2z4s/8Mk xvKTaji1uj3qzV/zuH+Iu5wItyFKNOhZdaRnWx58YCRgSjTxIhLM7oveJtitfgx/1gfh hEfnZNdWDW7/fbX7c9+o3lLXz9Phn4CcU48nNGNCI0VUlbVnOvboLcRiuJltvh8soDwb fol8l1BU0WSJmaQGoQBVTv27wTR6dN1QOVGvi1GYm40lGNCR/30adbIearFqXi3PKaNg mk8g==
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20161025; h=x-gm-message-state:mime-version:in-reply-to:references:from:date :message-id:subject:to; bh=hIqBzpbR89R/eqt5vFGvUT/OJcnTiL3YCDem1eoxjcc=; b=GB7p4UMcWzr4ormWhRjzkEsq8IZ8tNbx3l20UZesw+oQVxghJhvdSIfTuPOtYnTj5t OZSDo0B9r/1kshpw/sAvr9z4fw5XAkbpM+4OlYSv43ZsiRpQgTq/3yfhQJmPERr51+Ec hviB4x7SKbMbhgm2bOOPHnFCHrukzpsewFq3o6Zwqw/dviDJgSF1CNYaTCHx0bSZ1CIe nHx0dVrMnxE4FLYBci2zofZrZ5g5I8qWv3X6FD+MfVWv07D0xvtveSGcwSv+M2SdwcZ7 EknkavgsFQWFt3Nj8oh9ZvrkZVHVok0qd/8UTvt3RZ8o5uVjG7CPSBrYhC0s2UTkCmHt kUOA==
X-Gm-Message-State: AJaThX4SIWmcR2kjthahfsA33t4RNx37PzRycCqzudy/qHPfrhHL4IfP CuxmEVU/wvblE5+I3u/HUL75cfI0YqfL3fHQrMf1q+SSftI=
X-Google-Smtp-Source: AGs4zMYVnd8XjE74QAjacsVvhJKs6GD1cgVWKJP/DqgpeaW2tzrq5yCye10WdJ5pWJlWtTC6NP3A8JNL5kOJgjjlGok=
X-Received: by 10.37.22.8 with SMTP id 8mr5679404ybw.353.1510577125737; Mon, 13 Nov 2017 04:45:25 -0800 (PST)
MIME-Version: 1.0
Received: by 10.129.61.12 with HTTP; Mon, 13 Nov 2017 04:44:45 -0800 (PST)
In-Reply-To: <CABcZeBM6BYN3VoAmQafAm+gXn97e2RjgZKwJVuf6giK+Q_Q6og@mail.gmail.com>
References: <CABcZeBM6BYN3VoAmQafAm+gXn97e2RjgZKwJVuf6giK+Q_Q6og@mail.gmail.com>
From: Eric Rescorla <ekr@rtfm.com>
Date: Mon, 13 Nov 2017 20:44:45 +0800
Message-ID: <CABcZeBNKRu81wGv4UKQL5JHzd3kCTEBF61pnety3aQgRCCGLSw@mail.gmail.com>
To: IETF Tokbind WG <unbearable@ietf.org>, draft-ietf-tokbind-negotiation@tools.ietf.org
Content-Type: multipart/alternative; boundary="001a11416718fc6a32055ddca469"
Archived-At: <https://mailarchive.ietf.org/arch/msg/unbearable/hGzR-lvZgloc1JgHEC7qzIF2ZIs>
Subject: Re: [Unbearable] AD Review: draft-ietf-tokbind-negotiation-09.txt
X-BeenThere: unbearable@ietf.org
X-Mailman-Version: 2.1.22
Precedence: list
List-Id: "\"This list is for discussion of proposals for doing better than bearer tokens \(e.g. HTTP cookies, OAuth tokens etc.\) for web applications. The specific goal is chartering a WG focused on preventing security token export and replay attacks.\"" <unbearable.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/unbearable>, <mailto:unbearable-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/unbearable/>
List-Post: <mailto:unbearable@ietf.org>
List-Help: <mailto:unbearable-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/unbearable>, <mailto:unbearable-request@ietf.org?subject=subscribe>
X-List-Received-Date: Mon, 13 Nov 2017 12:45:29 -0000

--001a11416718fc6a32055ddca469
Content-Type: text/plain; charset="UTF-8"

The new version is looking good. I have two minor comments:

- I still think it would be good to sharpen the discussion of version
negotiation a bit.
Perhaps: "Note that there is no way to advertise a minimum version, so a
client
advertising version N must be prepared to have the server select any older
version; if it has a minimum acceptable version, it MUST check the response
against that and generate an error if the version is too low"

Second:
"Please note that the Token Binding protocol version and key
 parameters are negotiated for each TLS connection, which means that"

You should remove "Please note" because this isn't an aside, it's a new
requirement.

I have pushed the IETF LC button, so feel free to address these later.

-Ekr






On Sun, Oct 8, 2017 at 3:59 AM, Eric Rescorla <ekr@rtfm.com> wrote:

> A rich version of this review can be found at:
>
> https://mozphab-ietf.devsvcdev.mozaws.net/D48
>
>    1. If you make an account and login, you can respond to the comments
>
> and we can try to resolve them before you produce a new draft.
>
>    1. When you're ready to produce a new draft, you can either upload
>
> it to the draft repo or send me the pre-draft and either way I'll
> take care of getting it uploaded here, so we can see diffs, etc.
>
>
> *INLINE COMMENTS*
> View Inline <https://mozphab-ietf.devsvcdev.mozaws.net/D47#inline-326>
> draft-ietf-tokbind-negotiation.txt:102
> uint8 minor;
> } ProtocolVersion;
>
> you should note that this is taken from RFC 5246 or rename it.
>
> View Inline <https://mozphab-ietf.devsvcdev.mozaws.net/D47#inline-327>
> draft-ietf-tokbind-negotiation.txt:110
> ProtocolVersion token_binding_version;
> TokenBindingKeyParameters key_parameters_list<1..2^8-1>
> } TokenBindingParameters;
>
> This is kind of hard to read because you are just defining the size of the
> enum here and then you have the definitions in the other draft. I think you
> should instead copy the definition from the other draft and then have a
> pointer, because as is it looks like no values are defined.
>
> View Inline <https://mozphab-ietf.devsvcdev.mozaws.net/D47#inline-328>
> draft-ietf-tokbind-negotiation.txt:117
> client. [I-D.ietf-tokbind-protocol] describes version {1, 0} of the
> protocol.
>
> I see you are using the TLS 1.2 negotiation structures. You should
> probably add some text to make clear that this implies you are supporting
> all lower values.
>
> View Inline <https://mozphab-ietf.devsvcdev.mozaws.net/D47#inline-329>
> draft-ietf-tokbind-negotiation.txt:158
> protocol version offered by the client in the "token_binding"
> extension and the highest version supported by the server.
>
> Given our experience with TLS negotiation, you probably need to state very
> clearly that you need to do min(client, server) version even if the client
> version is higher than you know about.
>
> View Inline <https://mozphab-ietf.devsvcdev.mozaws.net/D47#inline-330>
> draft-ietf-tokbind-negotiation.txt:193
> extensions are not negotiated (see security considerations
> section below for more details).
>
> I would tend to think that some of these would be illegal_parameter.
>
> View Inline <https://mozphab-ietf.devsvcdev.mozaws.net/D47#inline-331>
> draft-ietf-tokbind-negotiation.txt:210
> Please note that the Token Binding protocol version and key
> parameters are negotiated for each TLS connection, which means that
>
> I would remove "please note" here, because you aren't reminding people,
> this is a separate requirement.
>
> *REPOSITORY*
> rIETFREVIEW ietf-review
>
> *REVISION DETAIL*
> https://mozphab-ietf.devsvcdev.mozaws.net/D47
>
> *EMAIL PREFERENCES*
> https://mozphab-ietf.devsvcdev.mozaws.net/settings/panel/emailpreferences/
>
> *To: *ekr-moz, ekr
>
>

--001a11416718fc6a32055ddca469
Content-Type: text/html; charset="UTF-8"
Content-Transfer-Encoding: quoted-printable

<div dir=3D"ltr">The new version is looking good. I have two minor comments=
:<div><br></div><div>- I still think it would be good to sharpen the discus=
sion of version negotiation a bit.</div><div>Perhaps: &quot;Note that there=
 is no way to advertise a minimum version, so a client</div><div>advertisin=
g version N must be prepared to have the server select any older</div><div>=
version; if it has a minimum acceptable version, it MUST check the response=
</div><div>against that and generate an error if the version is too low&quo=
t;</div><div><br></div><div>Second:</div><div>&quot;Please note that the To=
ken Binding protocol version and key</div><div>=C2=A0parameters are negotia=
ted for each TLS connection, which means that&quot;</div><div><br></div><di=
v>You should remove &quot;Please note&quot; because this isn&#39;t an aside=
, it&#39;s a new requirement.</div><div><br></div><div>I have pushed the IE=
TF LC button, so feel free to address these later.</div><div><br></div><div=
>-Ekr</div><div><br></div><div><br></div><div><br></div><div><br></div><div=
><br></div></div><div class=3D"gmail_extra"><br><div class=3D"gmail_quote">=
On Sun, Oct 8, 2017 at 3:59 AM, Eric Rescorla <span dir=3D"ltr">&lt;<a href=
=3D"mailto:ekr@rtfm.com" target=3D"_blank">ekr@rtfm.com</a>&gt;</span> wrot=
e:<br><blockquote class=3D"gmail_quote" style=3D"margin:0 0 0 .8ex;border-l=
eft:1px #ccc solid;padding-left:1ex"><div dir=3D"ltr"><div class=3D"gmail_q=
uote"><p style=3D"font-size:12.8px">A rich version of this review can be fo=
und at:</p><p style=3D"font-size:12.8px"><a href=3D"https://mozphab-ietf.de=
vsvcdev.mozaws.net/D48" target=3D"_blank">https://mozphab-ietf.devsvcdev<wb=
r>.mozaws.net/D48</a><br></p><ol class=3D"m_1661557792988478208gmail-m_-438=
3080333023756844m_-1066761602980937256gmail-m_-7121777874185719084remarkup-=
list" style=3D"font-size:12.8px"><li class=3D"m_1661557792988478208gmail-m_=
-4383080333023756844m_-1066761602980937256gmail-m_-7121777874185719084remar=
kup-list-item" style=3D"margin-left:15px">If you make an account and login,=
 you can respond to the comments</li></ol><p style=3D"font-size:12.8px">and=
 we can try to resolve them before you produce a new draft.</p><ol class=3D=
"m_1661557792988478208gmail-m_-4383080333023756844m_-1066761602980937256gma=
il-m_-7121777874185719084remarkup-list" start=3D"2" style=3D"font-size:12.8=
px"><li class=3D"m_1661557792988478208gmail-m_-4383080333023756844m_-106676=
1602980937256gmail-m_-7121777874185719084remarkup-list-item" style=3D"margi=
n-left:15px">When you&#39;re ready to produce a new draft, you can either u=
pload</li></ol><p style=3D"font-size:12.8px">it to the draft repo or send m=
e the pre-draft and either way I&#39;ll<br>take care of getting it uploaded=
 here, so we can see diffs, etc.</p><p style=3D"font-size:12.8px"><br></p><=
div><strong>INLINE COMMENTS</strong><div><div style=3D"margin:6px 0px 12px"=
><div style=3D"border:1px solid rgb(199,204,217);border-radius:3px"><div st=
yle=3D"padding:0px;background:rgb(247,247,247);border-color:rgb(227,228,232=
);border-style:solid;border-width:0px 0px 1px;margin:0px"><div style=3D"col=
or:rgb(116,119,125);background:rgb(239,242,244);padding:6px 8px;overflow:hi=
dden"><a style=3D"float:right;text-decoration:none" href=3D"https://mozphab=
-ietf.devsvcdev.mozaws.net/D47#inline-326" rel=3D"noreferrer" target=3D"_bl=
ank">View Inline</a><span style=3D"color:rgb(75,77,81);font-weight:bold">dr=
aft-ietf-tokbind-negot<wbr>iation.txt:102</span></div>
<div style=3D"font-style:normal;font-variant:normal;font-weight:normal;font=
-stretch:normal;font-size:11px;line-height:15px;font-family:Menlo,Consolas,=
Monaco,monospace;white-space:pre-wrap;clear:both;padding:4px 0px;margin:0px=
"><div style=3D"padding:0px 8px;margin:0px 4px;background:rgba(152,207,235,=
0.35)">       uint8 minor;
</div><div style=3D"padding:0px 8px;margin:0px 4px;background:rgba(152,207,=
235,0.35)">   } ProtocolVersion;
</div></div></div>
<div style=3D"margin:8px 0px;padding:0px 12px"><p style=3D"padding:0px;marg=
in:8px">you should note that this is taken from RFC 5246 or rename it.</p><=
/div></div><br><div style=3D"border:1px solid rgb(199,204,217);border-radiu=
s:3px"><div style=3D"padding:0px;background:rgb(247,247,247);border-color:r=
gb(227,228,232);border-style:solid;border-width:0px 0px 1px;margin:0px"><di=
v style=3D"color:rgb(116,119,125);background:rgb(239,242,244);padding:6px 8=
px;overflow:hidden"><a style=3D"float:right;text-decoration:none" href=3D"h=
ttps://mozphab-ietf.devsvcdev.mozaws.net/D47#inline-327" rel=3D"noreferrer"=
 target=3D"_blank">View Inline</a><span style=3D"color:rgb(75,77,81);font-w=
eight:bold">draft-ietf-tokbind-negot<wbr>iation.txt:110</span></div>
<div style=3D"font-style:normal;font-variant:normal;font-weight:normal;font=
-stretch:normal;font-size:11px;line-height:15px;font-family:Menlo,Consolas,=
Monaco,monospace;white-space:pre-wrap;clear:both;padding:4px 0px;margin:0px=
"><div style=3D"padding:0px 8px;margin:0px 4px;background:rgba(152,207,235,=
0.35)">       ProtocolVersion token_binding_version;
</div><div style=3D"padding:0px 8px;margin:0px 4px;background:rgba(152,207,=
235,0.35)">       TokenBindingKeyParameters key_parameters_list&lt;1..2^8-1=
&gt;
</div><div style=3D"padding:0px 8px;margin:0px 4px;background:rgba(152,207,=
235,0.35)">   } TokenBindingParameters;
</div></div></div>
<div style=3D"margin:8px 0px;padding:0px 12px"><p style=3D"padding:0px;marg=
in:8px">This is kind of hard to read because you are just defining the size=
 of the enum here and then you have the definitions in the other draft. I t=
hink you should instead copy the definition from the other draft and then h=
ave a pointer, because as is it looks like no values are defined.</p></div>=
</div><br><div style=3D"border:1px solid rgb(199,204,217);border-radius:3px=
"><div style=3D"padding:0px;background:rgb(247,247,247);border-color:rgb(22=
7,228,232);border-style:solid;border-width:0px 0px 1px;margin:0px"><div sty=
le=3D"color:rgb(116,119,125);background:rgb(239,242,244);padding:6px 8px;ov=
erflow:hidden"><a style=3D"float:right;text-decoration:none" href=3D"https:=
//mozphab-ietf.devsvcdev.mozaws.net/D47#inline-328" rel=3D"noreferrer" targ=
et=3D"_blank">View Inline</a><span style=3D"color:rgb(75,77,81);font-weight=
:bold">draft-ietf-tokbind-negot<wbr>iation.txt:117</span></div>
<div style=3D"font-style:normal;font-variant:normal;font-weight:normal;font=
-stretch:normal;font-size:11px;line-height:15px;font-family:Menlo,Consolas,=
Monaco,monospace;white-space:pre-wrap;clear:both;padding:4px 0px;margin:0px=
"><div style=3D"padding:0px 8px;margin:0px 4px;background:rgba(152,207,235,=
0.35)">   client.  [I-D.ietf-tokbind-protocol] describes version {1, 0} of =
the
</div><div style=3D"padding:0px 8px;margin:0px 4px;background:rgba(152,207,=
235,0.35)">   protocol.
</div></div></div>
<div style=3D"margin:8px 0px;padding:0px 12px"><p style=3D"padding:0px;marg=
in:8px">I see you are using the TLS 1.2 negotiation structures. You should =
probably add some text to make clear that this implies you are supporting a=
ll lower values.</p></div></div><br><div style=3D"border:1px solid rgb(199,=
204,217);border-radius:3px"><div style=3D"padding:0px;background:rgb(247,24=
7,247);border-color:rgb(227,228,232);border-style:solid;border-width:0px 0p=
x 1px;margin:0px"><div style=3D"color:rgb(116,119,125);background:rgb(239,2=
42,244);padding:6px 8px;overflow:hidden"><a style=3D"float:right;text-decor=
ation:none" href=3D"https://mozphab-ietf.devsvcdev.mozaws.net/D47#inline-32=
9" rel=3D"noreferrer" target=3D"_blank">View Inline</a><span style=3D"color=
:rgb(75,77,81);font-weight:bold">draft-ietf-tokbind-negot<wbr>iation.txt:15=
8</span></div>
<div style=3D"font-style:normal;font-variant:normal;font-weight:normal;font=
-stretch:normal;font-size:11px;line-height:15px;font-family:Menlo,Consolas,=
Monaco,monospace;white-space:pre-wrap;clear:both;padding:4px 0px;margin:0px=
"><div style=3D"padding:0px 8px;margin:0px 4px;background:rgba(152,207,235,=
0.35)">   protocol version offered by the client in the &quot;token_binding=
&quot;
</div><div style=3D"padding:0px 8px;margin:0px 4px;background:rgba(152,207,=
235,0.35)">   extension and the highest version supported by the server.
</div></div></div>
<div style=3D"margin:8px 0px;padding:0px 12px"><p style=3D"padding:0px;marg=
in:8px">Given our experience with TLS negotiation, you probably need to sta=
te very clearly that you need to do min(client, server) version even if the=
 client version is higher than you know about.</p></div></div><br><div styl=
e=3D"border:1px solid rgb(199,204,217);border-radius:3px"><div style=3D"pad=
ding:0px;background:rgb(247,247,247);border-color:rgb(227,228,232);border-s=
tyle:solid;border-width:0px 0px 1px;margin:0px"><div style=3D"color:rgb(116=
,119,125);background:rgb(239,242,244);padding:6px 8px;overflow:hidden"><a s=
tyle=3D"float:right;text-decoration:none" href=3D"https://mozphab-ietf.devs=
vcdev.mozaws.net/D47#inline-330" rel=3D"noreferrer" target=3D"_blank">View =
Inline</a><span style=3D"color:rgb(75,77,81);font-weight:bold">draft-ietf-t=
okbind-negot<wbr>iation.txt:193</span></div>
<div style=3D"font-style:normal;font-variant:normal;font-weight:normal;font=
-stretch:normal;font-size:11px;line-height:15px;font-family:Menlo,Consolas,=
Monaco,monospace;white-space:pre-wrap;clear:both;padding:4px 0px;margin:0px=
"><div style=3D"padding:0px 8px;margin:0px 4px;background:rgba(152,207,235,=
0.35)">       extensions are not negotiated (see security considerations
</div><div style=3D"padding:0px 8px;margin:0px 4px;background:rgba(152,207,=
235,0.35)">       section below for more details).
</div></div></div>
<div style=3D"margin:8px 0px;padding:0px 12px"><p style=3D"padding:0px;marg=
in:8px">I would tend to think that some of these would be illegal_parameter=
.</p></div></div><br><div style=3D"border:1px solid rgb(199,204,217);border=
-radius:3px"><div style=3D"padding:0px;background:rgb(247,247,247);border-c=
olor:rgb(227,228,232);border-style:solid;border-width:0px 0px 1px;margin:0p=
x"><div style=3D"color:rgb(116,119,125);background:rgb(239,242,244);padding=
:6px 8px;overflow:hidden"><a style=3D"float:right;text-decoration:none" hre=
f=3D"https://mozphab-ietf.devsvcdev.mozaws.net/D47#inline-331" rel=3D"noref=
errer" target=3D"_blank">View Inline</a><span style=3D"color:rgb(75,77,81);=
font-weight:bold">draft-ietf-tokbind-negot<wbr>iation.txt:210</span></div>
<div style=3D"font-style:normal;font-variant:normal;font-weight:normal;font=
-stretch:normal;font-size:11px;line-height:15px;font-family:Menlo,Consolas,=
Monaco,monospace;white-space:pre-wrap;clear:both;padding:4px 0px;margin:0px=
"><div style=3D"padding:0px 8px;margin:0px 4px;background:rgba(152,207,235,=
0.35)">   Please note that the Token Binding protocol version and key
</div><div style=3D"padding:0px 8px;margin:0px 4px;background:rgba(152,207,=
235,0.35)">   parameters are negotiated for each TLS connection, which mean=
s that
</div></div></div>
<div style=3D"margin:8px 0px;padding:0px 12px"><p style=3D"padding:0px;marg=
in:8px">I would remove &quot;please note&quot; here, because you aren&#39;t=
 reminding people, this is a separate requirement.</p></div></div></div></d=
iv></div><div class=3D"m_1661557792988478208gmail-HOEnZb"><div class=3D"m_1=
661557792988478208gmail-h5"><br><div><strong>REPOSITORY</strong><div><div>r=
IETFREVIEW ietf-review</div></div></div><br><div><strong>REVISION DETAIL</s=
trong><div><a href=3D"https://mozphab-ietf.devsvcdev.mozaws.net/D47" rel=3D=
"noreferrer" target=3D"_blank">https://mozphab-ietf.devsvcdev<wbr>.mozaws.n=
et/D47</a></div></div><br><div><strong>EMAIL PREFERENCES</strong><div><a hr=
ef=3D"https://mozphab-ietf.devsvcdev.mozaws.net/settings/panel/emailprefere=
nces/" rel=3D"noreferrer" target=3D"_blank">https://mozphab-ietf.devsvcdev<=
wbr>.mozaws.net/settings/panel/<wbr>emailpreferences/</a></div></div><br><d=
iv><strong>To: </strong>ekr-moz, ekr<br></div></div></div></div><br></div>
</blockquote></div><br></div>

--001a11416718fc6a32055ddca469--


From nobody Mon Nov 13 06:37:31 2017
Return-Path: <Andrei.Popov@microsoft.com>
X-Original-To: unbearable@ietfa.amsl.com
Delivered-To: unbearable@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id DFC7B124D37 for <unbearable@ietfa.amsl.com>; Mon, 13 Nov 2017 06:37:29 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.81
X-Spam-Level: 
X-Spam-Status: No, score=-2.81 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, HTML_MESSAGE=0.001, HTTPS_HTTP_MISMATCH=1.989, RCVD_IN_DNSWL_NONE=-0.0001, RCVD_IN_MSPIKE_H2=-2.8, SPF_PASS=-0.001, URIBL_BLOCKED=0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (1024-bit key) header.d=microsoft.com
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id 7sms17TWR3Zu for <unbearable@ietfa.amsl.com>; Mon, 13 Nov 2017 06:37:27 -0800 (PST)
Received: from NAM03-CO1-obe.outbound.protection.outlook.com (mail-co1nam03on0097.outbound.protection.outlook.com [104.47.40.97]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 20C16128CDC for <unbearable@ietf.org>; Mon, 13 Nov 2017 06:37:27 -0800 (PST)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=microsoft.com; s=selector1; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version; bh=NDYUkw3YxFuTyUOKqm6u1Ada6lBQMS0JtrxAArhYrEQ=; b=G4Jg9t5OuXThHN1ofsTgAAp3ghk3doUJfA2KohSyboqv67ejeWk4LhZ1rGff7hFlAs2TlPjbILXEsjZ/UN1fn0xNger2/vtbSC/3ah3rq3RyFRxt3psG3Y+A/XUxwSE+MmU7LkgjqYmyB1gXj00Vv/uL96gWlAxtEIkJrQ6pyaw=
Received: from CY4PR21MB0120.namprd21.prod.outlook.com (10.173.189.14) by CY4PR21MB0776.namprd21.prod.outlook.com (10.173.192.22) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_CBC_SHA384_P256) id 15.20.260.0; Mon, 13 Nov 2017 14:37:25 +0000
Received: from CY4PR21MB0120.namprd21.prod.outlook.com ([10.173.189.14]) by CY4PR21MB0120.namprd21.prod.outlook.com ([10.173.189.14]) with mapi id 15.20.0239.004; Mon, 13 Nov 2017 14:37:25 +0000
From: Andrei Popov <Andrei.Popov@microsoft.com>
To: Eric Rescorla <ekr@rtfm.com>, IETF Tokbind WG <unbearable@ietf.org>, "draft-ietf-tokbind-negotiation@tools.ietf.org" <draft-ietf-tokbind-negotiation@tools.ietf.org>
Thread-Topic: [Unbearable] AD Review: draft-ietf-tokbind-negotiation-09.txt
Thread-Index: AQHTP6bi1HjZQfs9hEKzAk/o21JpK6MSew+AgAAezVA=
Date: Mon, 13 Nov 2017 14:37:24 +0000
Message-ID: <CY4PR21MB012057579C1F371C80B66C628C2B0@CY4PR21MB0120.namprd21.prod.outlook.com>
References: <CABcZeBM6BYN3VoAmQafAm+gXn97e2RjgZKwJVuf6giK+Q_Q6og@mail.gmail.com> <CABcZeBNKRu81wGv4UKQL5JHzd3kCTEBF61pnety3aQgRCCGLSw@mail.gmail.com>
In-Reply-To: <CABcZeBNKRu81wGv4UKQL5JHzd3kCTEBF61pnety3aQgRCCGLSw@mail.gmail.com>
Accept-Language: en-US
Content-Language: en-US
X-MS-Has-Attach: 
X-MS-TNEF-Correlator: 
msip_labels: MSIP_Label_f42aa342-8706-4288-bd11-ebb85995028c_Enabled=True; MSIP_Label_f42aa342-8706-4288-bd11-ebb85995028c_SiteId=72f988bf-86f1-41af-91ab-2d7cd011db47; MSIP_Label_f42aa342-8706-4288-bd11-ebb85995028c_Owner=andreipo@microsoft.com;  MSIP_Label_f42aa342-8706-4288-bd11-ebb85995028c_SetDate=2017-11-13T14:37:32.1111107Z; MSIP_Label_f42aa342-8706-4288-bd11-ebb85995028c_Name=General; MSIP_Label_f42aa342-8706-4288-bd11-ebb85995028c_Application=Microsoft Azure Information Protection; MSIP_Label_f42aa342-8706-4288-bd11-ebb85995028c_Extended_MSFT_Method=Automatic; Sensitivity=General
x-originating-ip: [2001:67c:1232:144:9588:ba3e:2810:4148]
x-ms-publictraffictype: Email
x-microsoft-exchange-diagnostics: 1; CY4PR21MB0776; 6:IfMCKOTb8U/cDudbCSBvx1zAIkEzfv/t60QB9sfbuFAnpr1eOxXECF14XoznZY2Udi3jlePu2FjCB1xsUZhDHrjZh8u1mj485Tn9OQuBeMeBkftxlmNIPMari0pfywubwgeb5N5Eiqx7Wc+Mf5acVPb58S7ZIkUFkFdW3REdFHSit0rGVcsWxDE0IHM4p2SpoVVUxcEUlvbXnjB79MIQOGrTFvZgx3b2hQfwQIBFYXlB6iBJHurNSBxvvGr9o299a/yJws1JXpKWwmhDdV1im4UHfyO9mM9dS5QDPfB5acVZ6u5nPDqc3BpevLsrdt87YTDT7pZYXQ3p+jBvvmU3Bj6hhoODErmOKSs3e7jjE00=; 5:jh2N59KzpIZ14H/Y4q36BQ3F1GKiRt6X5ghLAKVTJ4UJdgJc8UDI9U6RfNMENacnVshJq+4MHZXl1ashbBD2gDwHjtHENsKRT5XSTNuBGHCsjWuV1RWKL07GeoEEYkD5M78PpL30fDk+uWSsEdYGAk3+DLUALTbwHWFj4tdSYu4=; 24:MjKKJpTZj+JRHMpDxHsa8KIQWMpAf4/bmtvYbRv2RsPcSLp4BvU6TZ0kzf5skyJ/pkO0M7kdedJSsU66yEuuJoAk3s/uptxP8S/3p8TRKns=; 7:VfbvrebMTSbh6ou9FgopHBu/WM4LUygLUNYQ1oz01zL1VSRUlrAr7GPP286PdMSGdu1HJ7FaIRm16m50Ql41uSesQLPH7Ph9blsoVjaPkYrkGnUKZMDtXKV7RwA4SGEDgQp5fy1NIAW7i22GiDh+7Li/9JV9F/RDVCS5oyW6EICXaxm07OvaTNn6ye/p/lWFNLXre00FNi7x+ZYsEmU9nzVTRXP/B26pmXfHOHKOMZCMv7H6l5Jc0NdYVWrmnd//
x-ms-exchange-antispam-srfa-diagnostics: SSOS;
x-ms-office365-filtering-correlation-id: 8016aef6-b721-4529-70f9-08d52aa40ed5
x-ms-office365-filtering-ht: Tenant
x-microsoft-antispam: UriScan:; BCL:0; PCL:0; RULEID:(22001)(4534020)(4602075)(4627115)(201703031133081)(201702281549075)(48565401081)(2017052603258); SRVR:CY4PR21MB0776; 
x-ms-traffictypediagnostic: CY4PR21MB0776:
authentication-results: spf=none (sender IP is ) smtp.mailfrom=Andrei.Popov@microsoft.com; 
x-microsoft-antispam-prvs: <CY4PR21MB0776C600293757586F5D94E18C2B0@CY4PR21MB0776.namprd21.prod.outlook.com>
x-exchange-antispam-report-test: UriScan:(158342451672863)(192374486261705)(189930954265078)(219752817060721)(21748063052155);
x-exchange-antispam-report-cfa-test: BCL:0; PCL:0; RULEID:(100000700101)(100105000095)(100000701101)(100105300095)(100000702101)(100105100095)(61425038)(6040450)(2401047)(5005006)(8121501046)(3002001)(10201501046)(3231022)(100000703101)(100105400095)(93006095)(93001095)(6055026)(61426038)(61427038)(6041248)(201703131423075)(201702281528075)(201703061421075)(201703061406153)(20161123560025)(20161123555025)(20161123564025)(20161123558100)(20161123562025)(6072148)(201708071742011)(100000704101)(100105200095)(100000705101)(100105500095); SRVR:CY4PR21MB0776; BCL:0; PCL:0; RULEID:(100000800101)(100110000095)(100000801101)(100110300095)(100000802101)(100110100095)(100000803101)(100110400095)(100000804101)(100110200095)(100000805101)(100110500095); SRVR:CY4PR21MB0776; 
x-forefront-prvs: 0490BBA1F0
x-forefront-antispam-report: SFV:NSPM; SFS:(10019020)(376002)(346002)(39860400002)(47760400005)(43544003)(189002)(24454002)(199003)(606006)(99286004)(790700001)(102836003)(6116002)(86362001)(86612001)(106356001)(2950100002)(230783001)(105586002)(10090500001)(7696004)(5660300001)(3280700002)(74316002)(2906002)(3660700001)(72206003)(97736004)(189998001)(7736002)(966005)(8990500004)(6246003)(54896002)(8676002)(81156014)(81166006)(9686003)(236005)(6306002)(53936002)(55016002)(33656002)(101416001)(19609705001)(2900100001)(25786009)(68736007)(2501003)(229853002)(10290500003)(110136005)(53546010)(50986999)(76176999)(54356999)(316002)(77096006)(6436002)(8936002)(6506006)(478600001)(14454004)(22452003); DIR:OUT; SFP:1102; SCL:1; SRVR:CY4PR21MB0776; H:CY4PR21MB0120.namprd21.prod.outlook.com; FPR:; SPF:None; PTR:InfoNoRecords;  MX:1; A:1; LANG:en; 
received-spf: None (protection.outlook.com: microsoft.com does not designate permitted sender hosts)
spamdiagnosticoutput: 1:99
spamdiagnosticmetadata: NSPM
Content-Type: multipart/alternative; boundary="_000_CY4PR21MB012057579C1F371C80B66C628C2B0CY4PR21MB0120namp_"
MIME-Version: 1.0
X-OriginatorOrg: microsoft.com
X-MS-Exchange-CrossTenant-Network-Message-Id: 8016aef6-b721-4529-70f9-08d52aa40ed5
X-MS-Exchange-CrossTenant-originalarrivaltime: 13 Nov 2017 14:37:24.7321 (UTC)
X-MS-Exchange-CrossTenant-fromentityheader: Hosted
X-MS-Exchange-CrossTenant-id: 72f988bf-86f1-41af-91ab-2d7cd011db47
X-MS-Exchange-Transport-CrossTenantHeadersStamped: CY4PR21MB0776
Archived-At: <https://mailarchive.ietf.org/arch/msg/unbearable/cKP2rWO3NDLuoImZKBTGq-s3NJk>
Subject: Re: [Unbearable] AD Review: draft-ietf-tokbind-negotiation-09.txt
X-BeenThere: unbearable@ietf.org
X-Mailman-Version: 2.1.22
Precedence: list
List-Id: "\"This list is for discussion of proposals for doing better than bearer tokens \(e.g. HTTP cookies, OAuth tokens etc.\) for web applications. The specific goal is chartering a WG focused on preventing security token export and replay attacks.\"" <unbearable.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/unbearable>, <mailto:unbearable-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/unbearable/>
List-Post: <mailto:unbearable@ietf.org>
List-Help: <mailto:unbearable-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/unbearable>, <mailto:unbearable-request@ietf.org?subject=subscribe>
X-List-Received-Date: Mon, 13 Nov 2017 14:37:30 -0000

--_000_CY4PR21MB012057579C1F371C80B66C628C2B0CY4PR21MB0120namp_
Content-Type: text/plain; charset="utf-8"
Content-Transfer-Encoding: base64

U291bmRzIGdvb2Q7IEnigJlsbCBtYWtlIHRoZSBzdWdnZXN0ZWQgY2hhbmdlcyBpbiBUQlBST1RP
IGFuZCBUQk5FR08gYWxvbmcgd2l0aCBhbnkgb3RoZXIgdXBkYXRlcyB0aGF0IG1heSByZXN1bHQg
ZnJvbSBMQy4NCg0KQ2hlZXJzLA0KDQpBbmRyZWkNCg0KRnJvbTogVW5iZWFyYWJsZSBbbWFpbHRv
OnVuYmVhcmFibGUtYm91bmNlc0BpZXRmLm9yZ10gT24gQmVoYWxmIE9mIEVyaWMgUmVzY29ybGEN
ClNlbnQ6IE1vbmRheSwgTm92ZW1iZXIgMTMsIDIwMTcgODo0NSBQTQ0KVG86IElFVEYgVG9rYmlu
ZCBXRyA8dW5iZWFyYWJsZUBpZXRmLm9yZz47IGRyYWZ0LWlldGYtdG9rYmluZC1uZWdvdGlhdGlv
bkB0b29scy5pZXRmLm9yZw0KU3ViamVjdDogUmU6IFtVbmJlYXJhYmxlXSBBRCBSZXZpZXc6IGRy
YWZ0LWlldGYtdG9rYmluZC1uZWdvdGlhdGlvbi0wOS50eHQNCg0KVGhlIG5ldyB2ZXJzaW9uIGlz
IGxvb2tpbmcgZ29vZC4gSSBoYXZlIHR3byBtaW5vciBjb21tZW50czoNCg0KLSBJIHN0aWxsIHRo
aW5rIGl0IHdvdWxkIGJlIGdvb2QgdG8gc2hhcnBlbiB0aGUgZGlzY3Vzc2lvbiBvZiB2ZXJzaW9u
IG5lZ290aWF0aW9uIGEgYml0Lg0KUGVyaGFwczogIk5vdGUgdGhhdCB0aGVyZSBpcyBubyB3YXkg
dG8gYWR2ZXJ0aXNlIGEgbWluaW11bSB2ZXJzaW9uLCBzbyBhIGNsaWVudA0KYWR2ZXJ0aXNpbmcg
dmVyc2lvbiBOIG11c3QgYmUgcHJlcGFyZWQgdG8gaGF2ZSB0aGUgc2VydmVyIHNlbGVjdCBhbnkg
b2xkZXINCnZlcnNpb247IGlmIGl0IGhhcyBhIG1pbmltdW0gYWNjZXB0YWJsZSB2ZXJzaW9uLCBp
dCBNVVNUIGNoZWNrIHRoZSByZXNwb25zZQ0KYWdhaW5zdCB0aGF0IGFuZCBnZW5lcmF0ZSBhbiBl
cnJvciBpZiB0aGUgdmVyc2lvbiBpcyB0b28gbG93Ig0KDQpTZWNvbmQ6DQoiUGxlYXNlIG5vdGUg
dGhhdCB0aGUgVG9rZW4gQmluZGluZyBwcm90b2NvbCB2ZXJzaW9uIGFuZCBrZXkNCiBwYXJhbWV0
ZXJzIGFyZSBuZWdvdGlhdGVkIGZvciBlYWNoIFRMUyBjb25uZWN0aW9uLCB3aGljaCBtZWFucyB0
aGF0Ig0KDQpZb3Ugc2hvdWxkIHJlbW92ZSAiUGxlYXNlIG5vdGUiIGJlY2F1c2UgdGhpcyBpc24n
dCBhbiBhc2lkZSwgaXQncyBhIG5ldyByZXF1aXJlbWVudC4NCg0KSSBoYXZlIHB1c2hlZCB0aGUg
SUVURiBMQyBidXR0b24sIHNvIGZlZWwgZnJlZSB0byBhZGRyZXNzIHRoZXNlIGxhdGVyLg0KDQot
RWtyDQoNCg0KDQoNCg0KDQpPbiBTdW4sIE9jdCA4LCAyMDE3IGF0IDM6NTkgQU0sIEVyaWMgUmVz
Y29ybGEgPGVrckBydGZtLmNvbTxtYWlsdG86ZWtyQHJ0Zm0uY29tPj4gd3JvdGU6DQoNCkEgcmlj
aCB2ZXJzaW9uIG9mIHRoaXMgcmV2aWV3IGNhbiBiZSBmb3VuZCBhdDoNCg0KaHR0cHM6Ly9tb3pw
aGFiLWlldGYuZGV2c3ZjZGV2Lm1vemF3cy5uZXQvRDQ4PGh0dHBzOi8vbmEwMS5zYWZlbGlua3Mu
cHJvdGVjdGlvbi5vdXRsb29rLmNvbS8/dXJsPWh0dHBzJTNBJTJGJTJGbW96cGhhYi1pZXRmLmRl
dnN2Y2Rldi5tb3phd3MubmV0JTJGRDQ4JmRhdGE9MDIlN0MwMSU3Q0FuZHJlaS5Qb3BvdiU0MG1p
Y3Jvc29mdC5jb20lN0NmMGE3MTQ3MjFmMmU0ZjhkNmZjZTA4ZDUyYTk0NmQxZCU3QzcyZjk4OGJm
ODZmMTQxYWY5MWFiMmQ3Y2QwMTFkYjQ3JTdDMSU3QzAlN0M2MzY0NjE3MzkzMzk3NjkxNDMmc2Rh
dGE9RDlIQ2l3U0pTOTNTblJpNnJTZnh1eUVXN1p6VnBtWjVHVnJKM3QlMkJqdTk0JTNEJnJlc2Vy
dmVkPTA+DQoxLiAgICAgIElmIHlvdSBtYWtlIGFuIGFjY291bnQgYW5kIGxvZ2luLCB5b3UgY2Fu
IHJlc3BvbmQgdG8gdGhlIGNvbW1lbnRzDQoNCmFuZCB3ZSBjYW4gdHJ5IHRvIHJlc29sdmUgdGhl
bSBiZWZvcmUgeW91IHByb2R1Y2UgYSBuZXcgZHJhZnQuDQoyLiAgICAgIFdoZW4geW91J3JlIHJl
YWR5IHRvIHByb2R1Y2UgYSBuZXcgZHJhZnQsIHlvdSBjYW4gZWl0aGVyIHVwbG9hZA0KDQppdCB0
byB0aGUgZHJhZnQgcmVwbyBvciBzZW5kIG1lIHRoZSBwcmUtZHJhZnQgYW5kIGVpdGhlciB3YXkg
SSdsbA0KdGFrZSBjYXJlIG9mIGdldHRpbmcgaXQgdXBsb2FkZWQgaGVyZSwgc28gd2UgY2FuIHNl
ZSBkaWZmcywgZXRjLg0KDQoNCklOTElORSBDT01NRU5UUw0KVmlldyBJbmxpbmU8aHR0cHM6Ly9u
YTAxLnNhZmVsaW5rcy5wcm90ZWN0aW9uLm91dGxvb2suY29tLz91cmw9aHR0cHMlM0ElMkYlMkZt
b3pwaGFiLWlldGYuZGV2c3ZjZGV2Lm1vemF3cy5uZXQlMkZENDclMjNpbmxpbmUtMzI2JmRhdGE9
MDIlN0MwMSU3Q0FuZHJlaS5Qb3BvdiU0MG1pY3Jvc29mdC5jb20lN0NmMGE3MTQ3MjFmMmU0Zjhk
NmZjZTA4ZDUyYTk0NmQxZCU3QzcyZjk4OGJmODZmMTQxYWY5MWFiMmQ3Y2QwMTFkYjQ3JTdDMSU3
QzAlN0M2MzY0NjE3MzkzMzk3NjkxNDMmc2RhdGE9QXdmaHUlMkZmcHZqa1J4VWh4VUdlVWVCWDVN
NDRyJTJGNlAxcG5ydUY1QVpESTglM0QmcmVzZXJ2ZWQ9MD5kcmFmdC1pZXRmLXRva2JpbmQtbmVn
b3RpYXRpb24udHh0OjEwMg0KdWludDggbWlub3I7DQp9IFByb3RvY29sVmVyc2lvbjsNCg0KeW91
IHNob3VsZCBub3RlIHRoYXQgdGhpcyBpcyB0YWtlbiBmcm9tIFJGQyA1MjQ2IG9yIHJlbmFtZSBp
dC4NCg0KVmlldyBJbmxpbmU8aHR0cHM6Ly9uYTAxLnNhZmVsaW5rcy5wcm90ZWN0aW9uLm91dGxv
b2suY29tLz91cmw9aHR0cHMlM0ElMkYlMkZtb3pwaGFiLWlldGYuZGV2c3ZjZGV2Lm1vemF3cy5u
ZXQlMkZENDclMjNpbmxpbmUtMzI3JmRhdGE9MDIlN0MwMSU3Q0FuZHJlaS5Qb3BvdiU0MG1pY3Jv
c29mdC5jb20lN0NmMGE3MTQ3MjFmMmU0ZjhkNmZjZTA4ZDUyYTk0NmQxZCU3QzcyZjk4OGJmODZm
MTQxYWY5MWFiMmQ3Y2QwMTFkYjQ3JTdDMSU3QzAlN0M2MzY0NjE3MzkzMzk3NjkxNDMmc2RhdGE9
bm13eXdnTkZNVFhLQzhpTllYU0pJWFRnbzdjNktldVVRYXpGbVZ0WWt1TSUzRCZyZXNlcnZlZD0w
PmRyYWZ0LWlldGYtdG9rYmluZC1uZWdvdGlhdGlvbi50eHQ6MTEwDQpQcm90b2NvbFZlcnNpb24g
dG9rZW5fYmluZGluZ192ZXJzaW9uOw0KVG9rZW5CaW5kaW5nS2V5UGFyYW1ldGVycyBrZXlfcGFy
YW1ldGVyc19saXN0PDEuLjJeOC0xPg0KfSBUb2tlbkJpbmRpbmdQYXJhbWV0ZXJzOw0KDQpUaGlz
IGlzIGtpbmQgb2YgaGFyZCB0byByZWFkIGJlY2F1c2UgeW91IGFyZSBqdXN0IGRlZmluaW5nIHRo
ZSBzaXplIG9mIHRoZSBlbnVtIGhlcmUgYW5kIHRoZW4geW91IGhhdmUgdGhlIGRlZmluaXRpb25z
IGluIHRoZSBvdGhlciBkcmFmdC4gSSB0aGluayB5b3Ugc2hvdWxkIGluc3RlYWQgY29weSB0aGUg
ZGVmaW5pdGlvbiBmcm9tIHRoZSBvdGhlciBkcmFmdCBhbmQgdGhlbiBoYXZlIGEgcG9pbnRlciwg
YmVjYXVzZSBhcyBpcyBpdCBsb29rcyBsaWtlIG5vIHZhbHVlcyBhcmUgZGVmaW5lZC4NCg0KVmll
dyBJbmxpbmU8aHR0cHM6Ly9uYTAxLnNhZmVsaW5rcy5wcm90ZWN0aW9uLm91dGxvb2suY29tLz91
cmw9aHR0cHMlM0ElMkYlMkZtb3pwaGFiLWlldGYuZGV2c3ZjZGV2Lm1vemF3cy5uZXQlMkZENDcl
MjNpbmxpbmUtMzI4JmRhdGE9MDIlN0MwMSU3Q0FuZHJlaS5Qb3BvdiU0MG1pY3Jvc29mdC5jb20l
N0NmMGE3MTQ3MjFmMmU0ZjhkNmZjZTA4ZDUyYTk0NmQxZCU3QzcyZjk4OGJmODZmMTQxYWY5MWFi
MmQ3Y2QwMTFkYjQ3JTdDMSU3QzAlN0M2MzY0NjE3MzkzMzk3NjkxNDMmc2RhdGE9JTJGV0VXM0lh
b0daMHZoWmp4cmR1TSUyRjI0VENBU0R4QUJuR3pGTTVtZ3REVlklM0QmcmVzZXJ2ZWQ9MD5kcmFm
dC1pZXRmLXRva2JpbmQtbmVnb3RpYXRpb24udHh0OjExNw0KY2xpZW50LiBbSS1ELmlldGYtdG9r
YmluZC1wcm90b2NvbF0gZGVzY3JpYmVzIHZlcnNpb24gezEsIDB9IG9mIHRoZQ0KcHJvdG9jb2wu
DQoNCkkgc2VlIHlvdSBhcmUgdXNpbmcgdGhlIFRMUyAxLjIgbmVnb3RpYXRpb24gc3RydWN0dXJl
cy4gWW91IHNob3VsZCBwcm9iYWJseSBhZGQgc29tZSB0ZXh0IHRvIG1ha2UgY2xlYXIgdGhhdCB0
aGlzIGltcGxpZXMgeW91IGFyZSBzdXBwb3J0aW5nIGFsbCBsb3dlciB2YWx1ZXMuDQoNClZpZXcg
SW5saW5lPGh0dHBzOi8vbmEwMS5zYWZlbGlua3MucHJvdGVjdGlvbi5vdXRsb29rLmNvbS8/dXJs
PWh0dHBzJTNBJTJGJTJGbW96cGhhYi1pZXRmLmRldnN2Y2Rldi5tb3phd3MubmV0JTJGRDQ3JTIz
aW5saW5lLTMyOSZkYXRhPTAyJTdDMDElN0NBbmRyZWkuUG9wb3YlNDBtaWNyb3NvZnQuY29tJTdD
ZjBhNzE0NzIxZjJlNGY4ZDZmY2UwOGQ1MmE5NDZkMWQlN0M3MmY5ODhiZjg2ZjE0MWFmOTFhYjJk
N2NkMDExZGI0NyU3QzElN0MwJTdDNjM2NDYxNzM5MzM5NzY5MTQzJnNkYXRhPWJhZ1BiY1B5STRN
JTJCalRSN2VuVTNVV0laVm10bW5HWjdtRGpSNTVQdVNvUSUzRCZyZXNlcnZlZD0wPmRyYWZ0LWll
dGYtdG9rYmluZC1uZWdvdGlhdGlvbi50eHQ6MTU4DQpwcm90b2NvbCB2ZXJzaW9uIG9mZmVyZWQg
YnkgdGhlIGNsaWVudCBpbiB0aGUgInRva2VuX2JpbmRpbmciDQpleHRlbnNpb24gYW5kIHRoZSBo
aWdoZXN0IHZlcnNpb24gc3VwcG9ydGVkIGJ5IHRoZSBzZXJ2ZXIuDQoNCkdpdmVuIG91ciBleHBl
cmllbmNlIHdpdGggVExTIG5lZ290aWF0aW9uLCB5b3UgcHJvYmFibHkgbmVlZCB0byBzdGF0ZSB2
ZXJ5IGNsZWFybHkgdGhhdCB5b3UgbmVlZCB0byBkbyBtaW4oY2xpZW50LCBzZXJ2ZXIpIHZlcnNp
b24gZXZlbiBpZiB0aGUgY2xpZW50IHZlcnNpb24gaXMgaGlnaGVyIHRoYW4geW91IGtub3cgYWJv
dXQuDQoNClZpZXcgSW5saW5lPGh0dHBzOi8vbmEwMS5zYWZlbGlua3MucHJvdGVjdGlvbi5vdXRs
b29rLmNvbS8/dXJsPWh0dHBzJTNBJTJGJTJGbW96cGhhYi1pZXRmLmRldnN2Y2Rldi5tb3phd3Mu
bmV0JTJGRDQ3JTIzaW5saW5lLTMzMCZkYXRhPTAyJTdDMDElN0NBbmRyZWkuUG9wb3YlNDBtaWNy
b3NvZnQuY29tJTdDZjBhNzE0NzIxZjJlNGY4ZDZmY2UwOGQ1MmE5NDZkMWQlN0M3MmY5ODhiZjg2
ZjE0MWFmOTFhYjJkN2NkMDExZGI0NyU3QzElN0MwJTdDNjM2NDYxNzM5MzM5NzY5MTQzJnNkYXRh
PTVmRzJLbVlxajZGMWE4TnFLMlpMc0pVTnBpZ2pYenUxZFhtTDdtMXFsJTJGZyUzRCZyZXNlcnZl
ZD0wPmRyYWZ0LWlldGYtdG9rYmluZC1uZWdvdGlhdGlvbi50eHQ6MTkzDQpleHRlbnNpb25zIGFy
ZSBub3QgbmVnb3RpYXRlZCAoc2VlIHNlY3VyaXR5IGNvbnNpZGVyYXRpb25zDQpzZWN0aW9uIGJl
bG93IGZvciBtb3JlIGRldGFpbHMpLg0KDQpJIHdvdWxkIHRlbmQgdG8gdGhpbmsgdGhhdCBzb21l
IG9mIHRoZXNlIHdvdWxkIGJlIGlsbGVnYWxfcGFyYW1ldGVyLg0KDQpWaWV3IElubGluZTxodHRw
czovL25hMDEuc2FmZWxpbmtzLnByb3RlY3Rpb24ub3V0bG9vay5jb20vP3VybD1odHRwcyUzQSUy
RiUyRm1venBoYWItaWV0Zi5kZXZzdmNkZXYubW96YXdzLm5ldCUyRkQ0NyUyM2lubGluZS0zMzEm
ZGF0YT0wMiU3QzAxJTdDQW5kcmVpLlBvcG92JTQwbWljcm9zb2Z0LmNvbSU3Q2YwYTcxNDcyMWYy
ZTRmOGQ2ZmNlMDhkNTJhOTQ2ZDFkJTdDNzJmOTg4YmY4NmYxNDFhZjkxYWIyZDdjZDAxMWRiNDcl
N0MxJTdDMCU3QzYzNjQ2MTczOTMzOTc2OTE0MyZzZGF0YT1qN0V1N2RYdnFzYjJURVNLOTJjVkNE
eHA1dGxnZDJnVERlZUg0MjB4RFlVJTNEJnJlc2VydmVkPTA+ZHJhZnQtaWV0Zi10b2tiaW5kLW5l
Z290aWF0aW9uLnR4dDoyMTANClBsZWFzZSBub3RlIHRoYXQgdGhlIFRva2VuIEJpbmRpbmcgcHJv
dG9jb2wgdmVyc2lvbiBhbmQga2V5DQpwYXJhbWV0ZXJzIGFyZSBuZWdvdGlhdGVkIGZvciBlYWNo
IFRMUyBjb25uZWN0aW9uLCB3aGljaCBtZWFucyB0aGF0DQoNCkkgd291bGQgcmVtb3ZlICJwbGVh
c2Ugbm90ZSIgaGVyZSwgYmVjYXVzZSB5b3UgYXJlbid0IHJlbWluZGluZyBwZW9wbGUsIHRoaXMg
aXMgYSBzZXBhcmF0ZSByZXF1aXJlbWVudC4NCg0KUkVQT1NJVE9SWQ0KcklFVEZSRVZJRVcgaWV0
Zi1yZXZpZXcNCg0KUkVWSVNJT04gREVUQUlMDQpodHRwczovL21venBoYWItaWV0Zi5kZXZzdmNk
ZXYubW96YXdzLm5ldC9ENDc8aHR0cHM6Ly9uYTAxLnNhZmVsaW5rcy5wcm90ZWN0aW9uLm91dGxv
b2suY29tLz91cmw9aHR0cHMlM0ElMkYlMkZtb3pwaGFiLWlldGYuZGV2c3ZjZGV2Lm1vemF3cy5u
ZXQlMkZENDcmZGF0YT0wMiU3QzAxJTdDQW5kcmVpLlBvcG92JTQwbWljcm9zb2Z0LmNvbSU3Q2Yw
YTcxNDcyMWYyZTRmOGQ2ZmNlMDhkNTJhOTQ2ZDFkJTdDNzJmOTg4YmY4NmYxNDFhZjkxYWIyZDdj
ZDAxMWRiNDclN0MxJTdDMCU3QzYzNjQ2MTczOTMzOTc2OTE0MyZzZGF0YT1NWjElMkJyamJVaUtt
UkY5OWt6VUlPQzRxTHFUZlVwZFNyVzIzYmZMMGsxdWslM0QmcmVzZXJ2ZWQ9MD4NCg0KRU1BSUwg
UFJFRkVSRU5DRVMNCmh0dHBzOi8vbW96cGhhYi1pZXRmLmRldnN2Y2Rldi5tb3phd3MubmV0L3Nl
dHRpbmdzL3BhbmVsL2VtYWlscHJlZmVyZW5jZXMvPGh0dHBzOi8vbmEwMS5zYWZlbGlua3MucHJv
dGVjdGlvbi5vdXRsb29rLmNvbS8/dXJsPWh0dHBzJTNBJTJGJTJGbW96cGhhYi1pZXRmLmRldnN2
Y2Rldi5tb3phd3MubmV0JTJGc2V0dGluZ3MlMkZwYW5lbCUyRmVtYWlscHJlZmVyZW5jZXMlMkYm
ZGF0YT0wMiU3QzAxJTdDQW5kcmVpLlBvcG92JTQwbWljcm9zb2Z0LmNvbSU3Q2YwYTcxNDcyMWYy
ZTRmOGQ2ZmNlMDhkNTJhOTQ2ZDFkJTdDNzJmOTg4YmY4NmYxNDFhZjkxYWIyZDdjZDAxMWRiNDcl
N0MxJTdDMCU3QzYzNjQ2MTczOTMzOTc2OTE0MyZzZGF0YT0lMkZUaGlDVnpRRldKMFlYdXhrUUxC
THFlbkVhRmZuTnJqYURpTzZBRTA4Rk0lM0QmcmVzZXJ2ZWQ9MD4NCg0KVG86IGVrci1tb3osIGVr
cg0KDQoNCg==

--_000_CY4PR21MB012057579C1F371C80B66C628C2B0CY4PR21MB0120namp_
Content-Type: text/html; charset="utf-8"
Content-Transfer-Encoding: base64

PGh0bWwgeG1sbnM6dj0idXJuOnNjaGVtYXMtbWljcm9zb2Z0LWNvbTp2bWwiIHhtbG5zOm89InVy
bjpzY2hlbWFzLW1pY3Jvc29mdC1jb206b2ZmaWNlOm9mZmljZSIgeG1sbnM6dz0idXJuOnNjaGVt
YXMtbWljcm9zb2Z0LWNvbTpvZmZpY2U6d29yZCIgeG1sbnM6bT0iaHR0cDovL3NjaGVtYXMubWlj
cm9zb2Z0LmNvbS9vZmZpY2UvMjAwNC8xMi9vbW1sIiB4bWxucz0iaHR0cDovL3d3dy53My5vcmcv
VFIvUkVDLWh0bWw0MCI+DQo8aGVhZD4NCjxtZXRhIGh0dHAtZXF1aXY9IkNvbnRlbnQtVHlwZSIg
Y29udGVudD0idGV4dC9odG1sOyBjaGFyc2V0PXV0Zi04Ij4NCjxtZXRhIG5hbWU9IkdlbmVyYXRv
ciIgY29udGVudD0iTWljcm9zb2Z0IFdvcmQgMTUgKGZpbHRlcmVkIG1lZGl1bSkiPg0KPHN0eWxl
PjwhLS0NCi8qIEZvbnQgRGVmaW5pdGlvbnMgKi8NCkBmb250LWZhY2UNCgl7Zm9udC1mYW1pbHk6
IkNhbWJyaWEgTWF0aCI7DQoJcGFub3NlLTE6MiA0IDUgMyA1IDQgNiAzIDIgNDt9DQpAZm9udC1m
YWNlDQoJe2ZvbnQtZmFtaWx5OkNhbGlicmk7DQoJcGFub3NlLTE6MiAxNSA1IDIgMiAyIDQgMyAy
IDQ7fQ0KQGZvbnQtZmFjZQ0KCXtmb250LWZhbWlseTpDb25zb2xhczsNCglwYW5vc2UtMToyIDEx
IDYgOSAyIDIgNCAzIDIgNDt9DQovKiBTdHlsZSBEZWZpbml0aW9ucyAqLw0KcC5Nc29Ob3JtYWws
IGxpLk1zb05vcm1hbCwgZGl2Lk1zb05vcm1hbA0KCXttYXJnaW46MGluOw0KCW1hcmdpbi1ib3R0
b206LjAwMDFwdDsNCglmb250LXNpemU6MTEuMHB0Ow0KCWZvbnQtZmFtaWx5OiJDYWxpYnJpIixz
YW5zLXNlcmlmO30NCmE6bGluaywgc3Bhbi5Nc29IeXBlcmxpbmsNCgl7bXNvLXN0eWxlLXByaW9y
aXR5Ojk5Ow0KCWNvbG9yOmJsdWU7DQoJdGV4dC1kZWNvcmF0aW9uOnVuZGVybGluZTt9DQphOnZp
c2l0ZWQsIHNwYW4uTXNvSHlwZXJsaW5rRm9sbG93ZWQNCgl7bXNvLXN0eWxlLXByaW9yaXR5Ojk5
Ow0KCWNvbG9yOnB1cnBsZTsNCgl0ZXh0LWRlY29yYXRpb246dW5kZXJsaW5lO30NCnAubXNvbm9y
bWFsMCwgbGkubXNvbm9ybWFsMCwgZGl2Lm1zb25vcm1hbDANCgl7bXNvLXN0eWxlLW5hbWU6bXNv
bm9ybWFsOw0KCW1zby1tYXJnaW4tdG9wLWFsdDphdXRvOw0KCW1hcmdpbi1yaWdodDowaW47DQoJ
bXNvLW1hcmdpbi1ib3R0b20tYWx0OmF1dG87DQoJbWFyZ2luLWxlZnQ6MGluOw0KCWZvbnQtc2l6
ZToxMS4wcHQ7DQoJZm9udC1mYW1pbHk6IkNhbGlicmkiLHNhbnMtc2VyaWY7fQ0Kc3Bhbi5FbWFp
bFN0eWxlMjANCgl7bXNvLXN0eWxlLXR5cGU6cGVyc29uYWwtcmVwbHk7DQoJZm9udC1mYW1pbHk6
IkNhbGlicmkiLHNhbnMtc2VyaWY7DQoJY29sb3I6d2luZG93dGV4dDt9DQouTXNvQ2hwRGVmYXVs
dA0KCXttc28tc3R5bGUtdHlwZTpleHBvcnQtb25seTsNCglmb250LWZhbWlseToiQ2FsaWJyaSIs
c2Fucy1zZXJpZjt9DQpAcGFnZSBXb3JkU2VjdGlvbjENCgl7c2l6ZTo4LjVpbiAxMS4waW47DQoJ
bWFyZ2luOjEuMGluIDEuMGluIDEuMGluIDEuMGluO30NCmRpdi5Xb3JkU2VjdGlvbjENCgl7cGFn
ZTpXb3JkU2VjdGlvbjE7fQ0KLyogTGlzdCBEZWZpbml0aW9ucyAqLw0KQGxpc3QgbDANCgl7bXNv
LWxpc3QtaWQ6Mzg0OTg0NDQ1Ow0KCW1zby1saXN0LXRlbXBsYXRlLWlkczotMjExNDY1MTA4Mjt9
DQpAbGlzdCBsMQ0KCXttc28tbGlzdC1pZDo5MjkwMDQ2MzQ7DQoJbXNvLWxpc3QtdGVtcGxhdGUt
aWRzOi0xODExNTQwNjE2O30NCkBsaXN0IGwxOmxldmVsMQ0KCXttc28tbGV2ZWwtc3RhcnQtYXQ6
MjsNCgltc28tbGV2ZWwtdGFiLXN0b3A6LjVpbjsNCgltc28tbGV2ZWwtbnVtYmVyLXBvc2l0aW9u
OmxlZnQ7DQoJdGV4dC1pbmRlbnQ6LS4yNWluO30NCm9sDQoJe21hcmdpbi1ib3R0b206MGluO30N
CnVsDQoJe21hcmdpbi1ib3R0b206MGluO30NCi0tPjwvc3R5bGU+PCEtLVtpZiBndGUgbXNvIDld
Pjx4bWw+DQo8bzpzaGFwZWRlZmF1bHRzIHY6ZXh0PSJlZGl0IiBzcGlkbWF4PSIxMDI2IiAvPg0K
PC94bWw+PCFbZW5kaWZdLS0+PCEtLVtpZiBndGUgbXNvIDldPjx4bWw+DQo8bzpzaGFwZWxheW91
dCB2OmV4dD0iZWRpdCI+DQo8bzppZG1hcCB2OmV4dD0iZWRpdCIgZGF0YT0iMSIgLz4NCjwvbzpz
aGFwZWxheW91dD48L3htbD48IVtlbmRpZl0tLT4NCjwvaGVhZD4NCjxib2R5IGxhbmc9IkVOLVVT
IiBsaW5rPSJibHVlIiB2bGluaz0icHVycGxlIj4NCjxkaXYgY2xhc3M9IldvcmRTZWN0aW9uMSI+
DQo8cCBjbGFzcz0iTXNvTm9ybWFsIj5Tb3VuZHMgZ29vZDsgSeKAmWxsIG1ha2UgdGhlIHN1Z2dl
c3RlZCBjaGFuZ2VzIGluIFRCUFJPVE8gYW5kIFRCTkVHTyBhbG9uZyB3aXRoIGFueSBvdGhlciB1
cGRhdGVzIHRoYXQgbWF5IHJlc3VsdCBmcm9tIExDLjxvOnA+PC9vOnA+PC9wPg0KPHAgY2xhc3M9
Ik1zb05vcm1hbCI+PGEgbmFtZT0iX01haWxFbmRDb21wb3NlIj48bzpwPiZuYnNwOzwvbzpwPjwv
YT48L3A+DQo8cCBjbGFzcz0iTXNvTm9ybWFsIj48c3BhbiBzdHlsZT0ibXNvLWJvb2ttYXJrOl9N
YWlsRW5kQ29tcG9zZSI+Q2hlZXJzLDxvOnA+PC9vOnA+PC9zcGFuPjwvcD4NCjxwIGNsYXNzPSJN
c29Ob3JtYWwiPjxzcGFuIHN0eWxlPSJtc28tYm9va21hcms6X01haWxFbmRDb21wb3NlIj48bzpw
PiZuYnNwOzwvbzpwPjwvc3Bhbj48L3A+DQo8cCBjbGFzcz0iTXNvTm9ybWFsIj48c3BhbiBzdHls
ZT0ibXNvLWJvb2ttYXJrOl9NYWlsRW5kQ29tcG9zZSI+QW5kcmVpPG86cD48L286cD48L3NwYW4+
PC9wPg0KPHAgY2xhc3M9Ik1zb05vcm1hbCI+PHNwYW4gc3R5bGU9Im1zby1ib29rbWFyazpfTWFp
bEVuZENvbXBvc2UiPjxvOnA+Jm5ic3A7PC9vOnA+PC9zcGFuPjwvcD4NCjxzcGFuIHN0eWxlPSJt
c28tYm9va21hcms6X01haWxFbmRDb21wb3NlIj48L3NwYW4+DQo8cCBjbGFzcz0iTXNvTm9ybWFs
Ij48Yj5Gcm9tOjwvYj4gVW5iZWFyYWJsZSBbbWFpbHRvOnVuYmVhcmFibGUtYm91bmNlc0BpZXRm
Lm9yZ10NCjxiPk9uIEJlaGFsZiBPZiA8L2I+RXJpYyBSZXNjb3JsYTxicj4NCjxiPlNlbnQ6PC9i
PiBNb25kYXksIE5vdmVtYmVyIDEzLCAyMDE3IDg6NDUgUE08YnI+DQo8Yj5Ubzo8L2I+IElFVEYg
VG9rYmluZCBXRyAmbHQ7dW5iZWFyYWJsZUBpZXRmLm9yZyZndDs7IGRyYWZ0LWlldGYtdG9rYmlu
ZC1uZWdvdGlhdGlvbkB0b29scy5pZXRmLm9yZzxicj4NCjxiPlN1YmplY3Q6PC9iPiBSZTogW1Vu
YmVhcmFibGVdIEFEIFJldmlldzogZHJhZnQtaWV0Zi10b2tiaW5kLW5lZ290aWF0aW9uLTA5LnR4
dDxvOnA+PC9vOnA+PC9wPg0KPHAgY2xhc3M9Ik1zb05vcm1hbCI+PG86cD4mbmJzcDs8L286cD48
L3A+DQo8ZGl2Pg0KPHAgY2xhc3M9Ik1zb05vcm1hbCI+VGhlIG5ldyB2ZXJzaW9uIGlzIGxvb2tp
bmcgZ29vZC4gSSBoYXZlIHR3byBtaW5vciBjb21tZW50czo8bzpwPjwvbzpwPjwvcD4NCjxkaXY+
DQo8cCBjbGFzcz0iTXNvTm9ybWFsIj48bzpwPiZuYnNwOzwvbzpwPjwvcD4NCjwvZGl2Pg0KPGRp
dj4NCjxwIGNsYXNzPSJNc29Ob3JtYWwiPi0gSSBzdGlsbCB0aGluayBpdCB3b3VsZCBiZSBnb29k
IHRvIHNoYXJwZW4gdGhlIGRpc2N1c3Npb24gb2YgdmVyc2lvbiBuZWdvdGlhdGlvbiBhIGJpdC48
bzpwPjwvbzpwPjwvcD4NCjwvZGl2Pg0KPGRpdj4NCjxwIGNsYXNzPSJNc29Ob3JtYWwiPlBlcmhh
cHM6ICZxdW90O05vdGUgdGhhdCB0aGVyZSBpcyBubyB3YXkgdG8gYWR2ZXJ0aXNlIGEgbWluaW11
bSB2ZXJzaW9uLCBzbyBhIGNsaWVudDxvOnA+PC9vOnA+PC9wPg0KPC9kaXY+DQo8ZGl2Pg0KPHAg
Y2xhc3M9Ik1zb05vcm1hbCI+YWR2ZXJ0aXNpbmcgdmVyc2lvbiBOIG11c3QgYmUgcHJlcGFyZWQg
dG8gaGF2ZSB0aGUgc2VydmVyIHNlbGVjdCBhbnkgb2xkZXI8bzpwPjwvbzpwPjwvcD4NCjwvZGl2
Pg0KPGRpdj4NCjxwIGNsYXNzPSJNc29Ob3JtYWwiPnZlcnNpb247IGlmIGl0IGhhcyBhIG1pbmlt
dW0gYWNjZXB0YWJsZSB2ZXJzaW9uLCBpdCBNVVNUIGNoZWNrIHRoZSByZXNwb25zZTxvOnA+PC9v
OnA+PC9wPg0KPC9kaXY+DQo8ZGl2Pg0KPHAgY2xhc3M9Ik1zb05vcm1hbCI+YWdhaW5zdCB0aGF0
IGFuZCBnZW5lcmF0ZSBhbiBlcnJvciBpZiB0aGUgdmVyc2lvbiBpcyB0b28gbG93JnF1b3Q7PG86
cD48L286cD48L3A+DQo8L2Rpdj4NCjxkaXY+DQo8cCBjbGFzcz0iTXNvTm9ybWFsIj48bzpwPiZu
YnNwOzwvbzpwPjwvcD4NCjwvZGl2Pg0KPGRpdj4NCjxwIGNsYXNzPSJNc29Ob3JtYWwiPlNlY29u
ZDo8bzpwPjwvbzpwPjwvcD4NCjwvZGl2Pg0KPGRpdj4NCjxwIGNsYXNzPSJNc29Ob3JtYWwiPiZx
dW90O1BsZWFzZSBub3RlIHRoYXQgdGhlIFRva2VuIEJpbmRpbmcgcHJvdG9jb2wgdmVyc2lvbiBh
bmQga2V5PG86cD48L286cD48L3A+DQo8L2Rpdj4NCjxkaXY+DQo8cCBjbGFzcz0iTXNvTm9ybWFs
Ij4mbmJzcDtwYXJhbWV0ZXJzIGFyZSBuZWdvdGlhdGVkIGZvciBlYWNoIFRMUyBjb25uZWN0aW9u
LCB3aGljaCBtZWFucyB0aGF0JnF1b3Q7PG86cD48L286cD48L3A+DQo8L2Rpdj4NCjxkaXY+DQo8
cCBjbGFzcz0iTXNvTm9ybWFsIj48bzpwPiZuYnNwOzwvbzpwPjwvcD4NCjwvZGl2Pg0KPGRpdj4N
CjxwIGNsYXNzPSJNc29Ob3JtYWwiPllvdSBzaG91bGQgcmVtb3ZlICZxdW90O1BsZWFzZSBub3Rl
JnF1b3Q7IGJlY2F1c2UgdGhpcyBpc24ndCBhbiBhc2lkZSwgaXQncyBhIG5ldyByZXF1aXJlbWVu
dC48bzpwPjwvbzpwPjwvcD4NCjwvZGl2Pg0KPGRpdj4NCjxwIGNsYXNzPSJNc29Ob3JtYWwiPjxv
OnA+Jm5ic3A7PC9vOnA+PC9wPg0KPC9kaXY+DQo8ZGl2Pg0KPHAgY2xhc3M9Ik1zb05vcm1hbCI+
SSBoYXZlIHB1c2hlZCB0aGUgSUVURiBMQyBidXR0b24sIHNvIGZlZWwgZnJlZSB0byBhZGRyZXNz
IHRoZXNlIGxhdGVyLjxvOnA+PC9vOnA+PC9wPg0KPC9kaXY+DQo8ZGl2Pg0KPHAgY2xhc3M9Ik1z
b05vcm1hbCI+PG86cD4mbmJzcDs8L286cD48L3A+DQo8L2Rpdj4NCjxkaXY+DQo8cCBjbGFzcz0i
TXNvTm9ybWFsIj4tRWtyPG86cD48L286cD48L3A+DQo8L2Rpdj4NCjxkaXY+DQo8cCBjbGFzcz0i
TXNvTm9ybWFsIj48bzpwPiZuYnNwOzwvbzpwPjwvcD4NCjwvZGl2Pg0KPGRpdj4NCjxwIGNsYXNz
PSJNc29Ob3JtYWwiPjxvOnA+Jm5ic3A7PC9vOnA+PC9wPg0KPC9kaXY+DQo8ZGl2Pg0KPHAgY2xh
c3M9Ik1zb05vcm1hbCI+PG86cD4mbmJzcDs8L286cD48L3A+DQo8L2Rpdj4NCjxkaXY+DQo8cCBj
bGFzcz0iTXNvTm9ybWFsIj48bzpwPiZuYnNwOzwvbzpwPjwvcD4NCjwvZGl2Pg0KPGRpdj4NCjxw
IGNsYXNzPSJNc29Ob3JtYWwiPjxvOnA+Jm5ic3A7PC9vOnA+PC9wPg0KPC9kaXY+DQo8L2Rpdj4N
CjxkaXY+DQo8cCBjbGFzcz0iTXNvTm9ybWFsIj48bzpwPiZuYnNwOzwvbzpwPjwvcD4NCjxkaXY+
DQo8cCBjbGFzcz0iTXNvTm9ybWFsIj5PbiBTdW4sIE9jdCA4LCAyMDE3IGF0IDM6NTkgQU0sIEVy
aWMgUmVzY29ybGEgJmx0OzxhIGhyZWY9Im1haWx0bzpla3JAcnRmbS5jb20iIHRhcmdldD0iX2Js
YW5rIj5la3JAcnRmbS5jb208L2E+Jmd0OyB3cm90ZTo8bzpwPjwvbzpwPjwvcD4NCjxibG9ja3F1
b3RlIHN0eWxlPSJib3JkZXI6bm9uZTtib3JkZXItbGVmdDpzb2xpZCAjQ0NDQ0NDIDEuMHB0O3Bh
ZGRpbmc6MGluIDBpbiAwaW4gNi4wcHQ7bWFyZ2luLWxlZnQ6NC44cHQ7bWFyZ2luLXJpZ2h0OjBp
biI+DQo8ZGl2Pg0KPGRpdj4NCjxwPjxzcGFuIHN0eWxlPSJmb250LXNpemU6OS41cHQiPkEgcmlj
aCB2ZXJzaW9uIG9mIHRoaXMgcmV2aWV3IGNhbiBiZSBmb3VuZCBhdDo8bzpwPjwvbzpwPjwvc3Bh
bj48L3A+DQo8cD48c3BhbiBzdHlsZT0iZm9udC1zaXplOjkuNXB0Ij48YSBocmVmPSJodHRwczov
L25hMDEuc2FmZWxpbmtzLnByb3RlY3Rpb24ub3V0bG9vay5jb20vP3VybD1odHRwcyUzQSUyRiUy
Rm1venBoYWItaWV0Zi5kZXZzdmNkZXYubW96YXdzLm5ldCUyRkQ0OCZhbXA7ZGF0YT0wMiU3QzAx
JTdDQW5kcmVpLlBvcG92JTQwbWljcm9zb2Z0LmNvbSU3Q2YwYTcxNDcyMWYyZTRmOGQ2ZmNlMDhk
NTJhOTQ2ZDFkJTdDNzJmOTg4YmY4NmYxNDFhZjkxYWIyZDdjZDAxMWRiNDclN0MxJTdDMCU3QzYz
NjQ2MTczOTMzOTc2OTE0MyZhbXA7c2RhdGE9RDlIQ2l3U0pTOTNTblJpNnJTZnh1eUVXN1p6VnBt
WjVHVnJKM3QlMkJqdTk0JTNEJmFtcDtyZXNlcnZlZD0wIiB0YXJnZXQ9Il9ibGFuayI+aHR0cHM6
Ly9tb3pwaGFiLWlldGYuZGV2c3ZjZGV2Lm1vemF3cy5uZXQvRDQ4PC9hPjxvOnA+PC9vOnA+PC9z
cGFuPjwvcD4NCjxwIGNsYXNzPSJNc29Ob3JtYWwiIHN0eWxlPSJtc28tbWFyZ2luLXRvcC1hbHQ6
YXV0bzttc28tbWFyZ2luLWJvdHRvbS1hbHQ6YXV0bzttYXJnaW4tbGVmdDo0Ny4yNXB0O3RleHQt
aW5kZW50Oi0uMjVpbjttc28tbGlzdDpsMCBsZXZlbDEgbGZvMSI+DQo8IVtpZiAhc3VwcG9ydExp
c3RzXT48c3BhbiBzdHlsZT0iZm9udC1zaXplOjkuNXB0Ij48c3BhbiBzdHlsZT0ibXNvLWxpc3Q6
SWdub3JlIj4xLjxzcGFuIHN0eWxlPSJmb250OjcuMHB0ICZxdW90O1RpbWVzIE5ldyBSb21hbiZx
dW90OyI+Jm5ic3A7Jm5ic3A7Jm5ic3A7Jm5ic3A7Jm5ic3A7DQo8L3NwYW4+PC9zcGFuPjwvc3Bh
bj48IVtlbmRpZl0+PHNwYW4gc3R5bGU9ImZvbnQtc2l6ZTo5LjVwdCI+SWYgeW91IG1ha2UgYW4g
YWNjb3VudCBhbmQgbG9naW4sIHlvdSBjYW4gcmVzcG9uZCB0byB0aGUgY29tbWVudHM8bzpwPjwv
bzpwPjwvc3Bhbj48L3A+DQo8cD48c3BhbiBzdHlsZT0iZm9udC1zaXplOjkuNXB0Ij5hbmQgd2Ug
Y2FuIHRyeSB0byByZXNvbHZlIHRoZW0gYmVmb3JlIHlvdSBwcm9kdWNlIGEgbmV3IGRyYWZ0Ljxv
OnA+PC9vOnA+PC9zcGFuPjwvcD4NCjxwIGNsYXNzPSJNc29Ob3JtYWwiIHN0eWxlPSJtc28tbWFy
Z2luLXRvcC1hbHQ6YXV0bzttc28tbWFyZ2luLWJvdHRvbS1hbHQ6YXV0bzttYXJnaW4tbGVmdDo0
Ny4yNXB0O3RleHQtaW5kZW50Oi0uMjVpbjttc28tbGlzdDpsMSBsZXZlbDEgbGZvMiI+DQo8IVtp
ZiAhc3VwcG9ydExpc3RzXT48c3BhbiBzdHlsZT0iZm9udC1zaXplOjkuNXB0Ij48c3BhbiBzdHls
ZT0ibXNvLWxpc3Q6SWdub3JlIj4yLjxzcGFuIHN0eWxlPSJmb250OjcuMHB0ICZxdW90O1RpbWVz
IE5ldyBSb21hbiZxdW90OyI+Jm5ic3A7Jm5ic3A7Jm5ic3A7Jm5ic3A7Jm5ic3A7DQo8L3NwYW4+
PC9zcGFuPjwvc3Bhbj48IVtlbmRpZl0+PHNwYW4gc3R5bGU9ImZvbnQtc2l6ZTo5LjVwdCI+V2hl
biB5b3UncmUgcmVhZHkgdG8gcHJvZHVjZSBhIG5ldyBkcmFmdCwgeW91IGNhbiBlaXRoZXIgdXBs
b2FkPG86cD48L286cD48L3NwYW4+PC9wPg0KPHA+PHNwYW4gc3R5bGU9ImZvbnQtc2l6ZTo5LjVw
dCI+aXQgdG8gdGhlIGRyYWZ0IHJlcG8gb3Igc2VuZCBtZSB0aGUgcHJlLWRyYWZ0IGFuZCBlaXRo
ZXIgd2F5IEknbGw8YnI+DQp0YWtlIGNhcmUgb2YgZ2V0dGluZyBpdCB1cGxvYWRlZCBoZXJlLCBz
byB3ZSBjYW4gc2VlIGRpZmZzLCBldGMuPG86cD48L286cD48L3NwYW4+PC9wPg0KPHA+PHNwYW4g
c3R5bGU9ImZvbnQtc2l6ZTo5LjVwdCI+PG86cD4mbmJzcDs8L286cD48L3NwYW4+PC9wPg0KPGRp
dj4NCjxwIGNsYXNzPSJNc29Ob3JtYWwiPjxzdHJvbmc+PHNwYW4gc3R5bGU9ImZvbnQtZmFtaWx5
OiZxdW90O0NhbGlicmkmcXVvdDssc2Fucy1zZXJpZiI+SU5MSU5FIENPTU1FTlRTPC9zcGFuPjwv
c3Ryb25nPjxvOnA+PC9vOnA+PC9wPg0KPGRpdj4NCjxkaXYgc3R5bGU9Im1hcmdpbi10b3A6NC41
cHQ7bWFyZ2luLWJvdHRvbTo5LjBwdCI+DQo8ZGl2IHN0eWxlPSJib3JkZXI6c29saWQgI0M3Q0NE
OSAxLjBwdDtwYWRkaW5nOjBpbiAwaW4gMGluIDBpbjtib3JkZXItcmFkaXVzOjNweCI+DQo8ZGl2
IHN0eWxlPSJib3JkZXI6c29saWQgI0UzRTRFOCAxLjBwdDtwYWRkaW5nOjBpbiAwaW4gMGluIDBp
biI+DQo8ZGl2Pg0KPHAgY2xhc3M9Ik1zb05vcm1hbCIgc3R5bGU9ImJhY2tncm91bmQ6I0VGRjJG
NCI+PHNwYW4gc3R5bGU9ImNvbG9yOiM3NDc3N0QiPjxhIGhyZWY9Imh0dHBzOi8vbmEwMS5zYWZl
bGlua3MucHJvdGVjdGlvbi5vdXRsb29rLmNvbS8/dXJsPWh0dHBzJTNBJTJGJTJGbW96cGhhYi1p
ZXRmLmRldnN2Y2Rldi5tb3phd3MubmV0JTJGRDQ3JTIzaW5saW5lLTMyNiZhbXA7ZGF0YT0wMiU3
QzAxJTdDQW5kcmVpLlBvcG92JTQwbWljcm9zb2Z0LmNvbSU3Q2YwYTcxNDcyMWYyZTRmOGQ2ZmNl
MDhkNTJhOTQ2ZDFkJTdDNzJmOTg4YmY4NmYxNDFhZjkxYWIyZDdjZDAxMWRiNDclN0MxJTdDMCU3
QzYzNjQ2MTczOTMzOTc2OTE0MyZhbXA7c2RhdGE9QXdmaHUlMkZmcHZqa1J4VWh4VUdlVWVCWDVN
NDRyJTJGNlAxcG5ydUY1QVpESTglM0QmYW1wO3Jlc2VydmVkPTAiIHRhcmdldD0iX2JsYW5rIj48
c3BhbiBzdHlsZT0idGV4dC1kZWNvcmF0aW9uOm5vbmUiPlZpZXcNCiBJbmxpbmU8L3NwYW4+PC9h
Pjwvc3Bhbj48Yj48c3BhbiBzdHlsZT0iY29sb3I6IzRCNEQ1MSI+ZHJhZnQtaWV0Zi10b2tiaW5k
LW5lZ290aWF0aW9uLnR4dDoxMDI8L3NwYW4+PC9iPjxzcGFuIHN0eWxlPSJjb2xvcjojNzQ3NzdE
Ij48bzpwPjwvbzpwPjwvc3Bhbj48L3A+DQo8L2Rpdj4NCjxkaXY+DQo8ZGl2IHN0eWxlPSJtYXJn
aW4tbGVmdDozLjBwdDttYXJnaW4tcmlnaHQ6My4wcHQ7YmFja2dyb3VuZDpyZ2JhKDE1MiwyMDcs
MjM1LDAuMzUpIj4NCjxwIGNsYXNzPSJNc29Ob3JtYWwiIHN0eWxlPSJsaW5lLWhlaWdodDoxMS4y
NXB0O2JhY2tncm91bmQ6I0Y3RjdGNyI+PHNwYW4gc3R5bGU9ImZvbnQtc2l6ZTo4LjVwdDtmb250
LWZhbWlseTpDb25zb2xhcyI+dWludDggbWlub3I7DQo8bzpwPjwvbzpwPjwvc3Bhbj48L3A+DQo8
L2Rpdj4NCjxkaXYgc3R5bGU9Im1hcmdpbi1sZWZ0OjMuMHB0O21hcmdpbi1yaWdodDozLjBwdDti
YWNrZ3JvdW5kOnJnYmEoMTUyLDIwNywyMzUsMC4zNSkiPg0KPHAgY2xhc3M9Ik1zb05vcm1hbCIg
c3R5bGU9ImxpbmUtaGVpZ2h0OjExLjI1cHQ7YmFja2dyb3VuZDojRjdGN0Y3Ij48c3BhbiBzdHls
ZT0iZm9udC1zaXplOjguNXB0O2ZvbnQtZmFtaWx5OkNvbnNvbGFzIj59IFByb3RvY29sVmVyc2lv
bjsNCjxvOnA+PC9vOnA+PC9zcGFuPjwvcD4NCjwvZGl2Pg0KPC9kaXY+DQo8L2Rpdj4NCjxkaXYg
c3R5bGU9Im1hcmdpbi10b3A6Ni4wcHQ7bWFyZ2luLWJvdHRvbTo2LjBwdCI+DQo8cCBzdHlsZT0i
bWFyZ2luOjYuMHB0Ij55b3Ugc2hvdWxkIG5vdGUgdGhhdCB0aGlzIGlzIHRha2VuIGZyb20gUkZD
IDUyNDYgb3IgcmVuYW1lIGl0LjxvOnA+PC9vOnA+PC9wPg0KPC9kaXY+DQo8L2Rpdj4NCjxwIGNs
YXNzPSJNc29Ob3JtYWwiPjxvOnA+Jm5ic3A7PC9vOnA+PC9wPg0KPGRpdiBzdHlsZT0iYm9yZGVy
OnNvbGlkICNDN0NDRDkgMS4wcHQ7cGFkZGluZzowaW4gMGluIDBpbiAwaW47Ym9yZGVyLXJhZGl1
czozcHgiPg0KPGRpdiBzdHlsZT0iYm9yZGVyOnNvbGlkICNFM0U0RTggMS4wcHQ7cGFkZGluZzow
aW4gMGluIDBpbiAwaW4iPg0KPGRpdj4NCjxwIGNsYXNzPSJNc29Ob3JtYWwiIHN0eWxlPSJiYWNr
Z3JvdW5kOiNFRkYyRjQiPjxzcGFuIHN0eWxlPSJjb2xvcjojNzQ3NzdEIj48YSBocmVmPSJodHRw
czovL25hMDEuc2FmZWxpbmtzLnByb3RlY3Rpb24ub3V0bG9vay5jb20vP3VybD1odHRwcyUzQSUy
RiUyRm1venBoYWItaWV0Zi5kZXZzdmNkZXYubW96YXdzLm5ldCUyRkQ0NyUyM2lubGluZS0zMjcm
YW1wO2RhdGE9MDIlN0MwMSU3Q0FuZHJlaS5Qb3BvdiU0MG1pY3Jvc29mdC5jb20lN0NmMGE3MTQ3
MjFmMmU0ZjhkNmZjZTA4ZDUyYTk0NmQxZCU3QzcyZjk4OGJmODZmMTQxYWY5MWFiMmQ3Y2QwMTFk
YjQ3JTdDMSU3QzAlN0M2MzY0NjE3MzkzMzk3NjkxNDMmYW1wO3NkYXRhPW5td3l3Z05GTVRYS0M4
aU5ZWFNKSVhUZ283YzZLZXVVUWF6Rm1WdFlrdU0lM0QmYW1wO3Jlc2VydmVkPTAiIHRhcmdldD0i
X2JsYW5rIj48c3BhbiBzdHlsZT0idGV4dC1kZWNvcmF0aW9uOm5vbmUiPlZpZXcNCiBJbmxpbmU8
L3NwYW4+PC9hPjwvc3Bhbj48Yj48c3BhbiBzdHlsZT0iY29sb3I6IzRCNEQ1MSI+ZHJhZnQtaWV0
Zi10b2tiaW5kLW5lZ290aWF0aW9uLnR4dDoxMTA8L3NwYW4+PC9iPjxzcGFuIHN0eWxlPSJjb2xv
cjojNzQ3NzdEIj48bzpwPjwvbzpwPjwvc3Bhbj48L3A+DQo8L2Rpdj4NCjxkaXY+DQo8ZGl2IHN0
eWxlPSJtYXJnaW4tbGVmdDozLjBwdDttYXJnaW4tcmlnaHQ6My4wcHQ7YmFja2dyb3VuZDpyZ2Jh
KDE1MiwyMDcsMjM1LDAuMzUpIj4NCjxwIGNsYXNzPSJNc29Ob3JtYWwiIHN0eWxlPSJsaW5lLWhl
aWdodDoxMS4yNXB0O2JhY2tncm91bmQ6I0Y3RjdGNyI+PHNwYW4gc3R5bGU9ImZvbnQtc2l6ZTo4
LjVwdDtmb250LWZhbWlseTpDb25zb2xhcyI+UHJvdG9jb2xWZXJzaW9uIHRva2VuX2JpbmRpbmdf
dmVyc2lvbjsNCjxvOnA+PC9vOnA+PC9zcGFuPjwvcD4NCjwvZGl2Pg0KPGRpdiBzdHlsZT0ibWFy
Z2luLWxlZnQ6My4wcHQ7bWFyZ2luLXJpZ2h0OjMuMHB0O2JhY2tncm91bmQ6cmdiYSgxNTIsMjA3
LDIzNSwwLjM1KSI+DQo8cCBjbGFzcz0iTXNvTm9ybWFsIiBzdHlsZT0ibGluZS1oZWlnaHQ6MTEu
MjVwdDtiYWNrZ3JvdW5kOiNGN0Y3RjciPjxzcGFuIHN0eWxlPSJmb250LXNpemU6OC41cHQ7Zm9u
dC1mYW1pbHk6Q29uc29sYXMiPlRva2VuQmluZGluZ0tleVBhcmFtZXRlcnMga2V5X3BhcmFtZXRl
cnNfbGlzdCZsdDsxLi4yXjgtMSZndDsNCjxvOnA+PC9vOnA+PC9zcGFuPjwvcD4NCjwvZGl2Pg0K
PGRpdiBzdHlsZT0ibWFyZ2luLWxlZnQ6My4wcHQ7bWFyZ2luLXJpZ2h0OjMuMHB0O2JhY2tncm91
bmQ6cmdiYSgxNTIsMjA3LDIzNSwwLjM1KSI+DQo8cCBjbGFzcz0iTXNvTm9ybWFsIiBzdHlsZT0i
bGluZS1oZWlnaHQ6MTEuMjVwdDtiYWNrZ3JvdW5kOiNGN0Y3RjciPjxzcGFuIHN0eWxlPSJmb250
LXNpemU6OC41cHQ7Zm9udC1mYW1pbHk6Q29uc29sYXMiPn0gVG9rZW5CaW5kaW5nUGFyYW1ldGVy
czsNCjxvOnA+PC9vOnA+PC9zcGFuPjwvcD4NCjwvZGl2Pg0KPC9kaXY+DQo8L2Rpdj4NCjxkaXYg
c3R5bGU9Im1hcmdpbi10b3A6Ni4wcHQ7bWFyZ2luLWJvdHRvbTo2LjBwdCI+DQo8cCBzdHlsZT0i
bWFyZ2luOjYuMHB0Ij5UaGlzIGlzIGtpbmQgb2YgaGFyZCB0byByZWFkIGJlY2F1c2UgeW91IGFy
ZSBqdXN0IGRlZmluaW5nIHRoZSBzaXplIG9mIHRoZSBlbnVtIGhlcmUgYW5kIHRoZW4geW91IGhh
dmUgdGhlIGRlZmluaXRpb25zIGluIHRoZSBvdGhlciBkcmFmdC4gSSB0aGluayB5b3Ugc2hvdWxk
IGluc3RlYWQgY29weSB0aGUgZGVmaW5pdGlvbiBmcm9tIHRoZSBvdGhlciBkcmFmdCBhbmQgdGhl
biBoYXZlIGEgcG9pbnRlciwgYmVjYXVzZQ0KIGFzIGlzIGl0IGxvb2tzIGxpa2Ugbm8gdmFsdWVz
IGFyZSBkZWZpbmVkLjxvOnA+PC9vOnA+PC9wPg0KPC9kaXY+DQo8L2Rpdj4NCjxwIGNsYXNzPSJN
c29Ob3JtYWwiPjxvOnA+Jm5ic3A7PC9vOnA+PC9wPg0KPGRpdiBzdHlsZT0iYm9yZGVyOnNvbGlk
ICNDN0NDRDkgMS4wcHQ7cGFkZGluZzowaW4gMGluIDBpbiAwaW47Ym9yZGVyLXJhZGl1czozcHgi
Pg0KPGRpdiBzdHlsZT0iYm9yZGVyOnNvbGlkICNFM0U0RTggMS4wcHQ7cGFkZGluZzowaW4gMGlu
IDBpbiAwaW4iPg0KPGRpdj4NCjxwIGNsYXNzPSJNc29Ob3JtYWwiIHN0eWxlPSJiYWNrZ3JvdW5k
OiNFRkYyRjQiPjxzcGFuIHN0eWxlPSJjb2xvcjojNzQ3NzdEIj48YSBocmVmPSJodHRwczovL25h
MDEuc2FmZWxpbmtzLnByb3RlY3Rpb24ub3V0bG9vay5jb20vP3VybD1odHRwcyUzQSUyRiUyRm1v
enBoYWItaWV0Zi5kZXZzdmNkZXYubW96YXdzLm5ldCUyRkQ0NyUyM2lubGluZS0zMjgmYW1wO2Rh
dGE9MDIlN0MwMSU3Q0FuZHJlaS5Qb3BvdiU0MG1pY3Jvc29mdC5jb20lN0NmMGE3MTQ3MjFmMmU0
ZjhkNmZjZTA4ZDUyYTk0NmQxZCU3QzcyZjk4OGJmODZmMTQxYWY5MWFiMmQ3Y2QwMTFkYjQ3JTdD
MSU3QzAlN0M2MzY0NjE3MzkzMzk3NjkxNDMmYW1wO3NkYXRhPSUyRldFVzNJYW9HWjB2aFpqeHJk
dU0lMkYyNFRDQVNEeEFCbkd6Rk01bWd0RFZZJTNEJmFtcDtyZXNlcnZlZD0wIiB0YXJnZXQ9Il9i
bGFuayI+PHNwYW4gc3R5bGU9InRleHQtZGVjb3JhdGlvbjpub25lIj5WaWV3DQogSW5saW5lPC9z
cGFuPjwvYT48L3NwYW4+PGI+PHNwYW4gc3R5bGU9ImNvbG9yOiM0QjRENTEiPmRyYWZ0LWlldGYt
dG9rYmluZC1uZWdvdGlhdGlvbi50eHQ6MTE3PC9zcGFuPjwvYj48c3BhbiBzdHlsZT0iY29sb3I6
Izc0Nzc3RCI+PG86cD48L286cD48L3NwYW4+PC9wPg0KPC9kaXY+DQo8ZGl2Pg0KPGRpdiBzdHls
ZT0ibWFyZ2luLWxlZnQ6My4wcHQ7bWFyZ2luLXJpZ2h0OjMuMHB0O2JhY2tncm91bmQ6cmdiYSgx
NTIsMjA3LDIzNSwwLjM1KSI+DQo8cCBjbGFzcz0iTXNvTm9ybWFsIiBzdHlsZT0ibGluZS1oZWln
aHQ6MTEuMjVwdDtiYWNrZ3JvdW5kOiNGN0Y3RjciPjxzcGFuIHN0eWxlPSJmb250LXNpemU6OC41
cHQ7Zm9udC1mYW1pbHk6Q29uc29sYXMiPmNsaWVudC4gW0ktRC5pZXRmLXRva2JpbmQtcHJvdG9j
b2xdIGRlc2NyaWJlcyB2ZXJzaW9uIHsxLCAwfSBvZiB0aGUNCjxvOnA+PC9vOnA+PC9zcGFuPjwv
cD4NCjwvZGl2Pg0KPGRpdiBzdHlsZT0ibWFyZ2luLWxlZnQ6My4wcHQ7bWFyZ2luLXJpZ2h0OjMu
MHB0O2JhY2tncm91bmQ6cmdiYSgxNTIsMjA3LDIzNSwwLjM1KSI+DQo8cCBjbGFzcz0iTXNvTm9y
bWFsIiBzdHlsZT0ibGluZS1oZWlnaHQ6MTEuMjVwdDtiYWNrZ3JvdW5kOiNGN0Y3RjciPjxzcGFu
IHN0eWxlPSJmb250LXNpemU6OC41cHQ7Zm9udC1mYW1pbHk6Q29uc29sYXMiPnByb3RvY29sLg0K
PG86cD48L286cD48L3NwYW4+PC9wPg0KPC9kaXY+DQo8L2Rpdj4NCjwvZGl2Pg0KPGRpdiBzdHls
ZT0ibWFyZ2luLXRvcDo2LjBwdDttYXJnaW4tYm90dG9tOjYuMHB0Ij4NCjxwIHN0eWxlPSJtYXJn
aW46Ni4wcHQiPkkgc2VlIHlvdSBhcmUgdXNpbmcgdGhlIFRMUyAxLjIgbmVnb3RpYXRpb24gc3Ry
dWN0dXJlcy4gWW91IHNob3VsZCBwcm9iYWJseSBhZGQgc29tZSB0ZXh0IHRvIG1ha2UgY2xlYXIg
dGhhdCB0aGlzIGltcGxpZXMgeW91IGFyZSBzdXBwb3J0aW5nIGFsbCBsb3dlciB2YWx1ZXMuPG86
cD48L286cD48L3A+DQo8L2Rpdj4NCjwvZGl2Pg0KPHAgY2xhc3M9Ik1zb05vcm1hbCI+PG86cD4m
bmJzcDs8L286cD48L3A+DQo8ZGl2IHN0eWxlPSJib3JkZXI6c29saWQgI0M3Q0NEOSAxLjBwdDtw
YWRkaW5nOjBpbiAwaW4gMGluIDBpbjtib3JkZXItcmFkaXVzOjNweCI+DQo8ZGl2IHN0eWxlPSJi
b3JkZXI6c29saWQgI0UzRTRFOCAxLjBwdDtwYWRkaW5nOjBpbiAwaW4gMGluIDBpbiI+DQo8ZGl2
Pg0KPHAgY2xhc3M9Ik1zb05vcm1hbCIgc3R5bGU9ImJhY2tncm91bmQ6I0VGRjJGNCI+PHNwYW4g
c3R5bGU9ImNvbG9yOiM3NDc3N0QiPjxhIGhyZWY9Imh0dHBzOi8vbmEwMS5zYWZlbGlua3MucHJv
dGVjdGlvbi5vdXRsb29rLmNvbS8/dXJsPWh0dHBzJTNBJTJGJTJGbW96cGhhYi1pZXRmLmRldnN2
Y2Rldi5tb3phd3MubmV0JTJGRDQ3JTIzaW5saW5lLTMyOSZhbXA7ZGF0YT0wMiU3QzAxJTdDQW5k
cmVpLlBvcG92JTQwbWljcm9zb2Z0LmNvbSU3Q2YwYTcxNDcyMWYyZTRmOGQ2ZmNlMDhkNTJhOTQ2
ZDFkJTdDNzJmOTg4YmY4NmYxNDFhZjkxYWIyZDdjZDAxMWRiNDclN0MxJTdDMCU3QzYzNjQ2MTcz
OTMzOTc2OTE0MyZhbXA7c2RhdGE9YmFnUGJjUHlJNE0lMkJqVFI3ZW5VM1VXSVpWbXRtbkdaN21E
alI1NVB1U29RJTNEJmFtcDtyZXNlcnZlZD0wIiB0YXJnZXQ9Il9ibGFuayI+PHNwYW4gc3R5bGU9
InRleHQtZGVjb3JhdGlvbjpub25lIj5WaWV3DQogSW5saW5lPC9zcGFuPjwvYT48L3NwYW4+PGI+
PHNwYW4gc3R5bGU9ImNvbG9yOiM0QjRENTEiPmRyYWZ0LWlldGYtdG9rYmluZC1uZWdvdGlhdGlv
bi50eHQ6MTU4PC9zcGFuPjwvYj48c3BhbiBzdHlsZT0iY29sb3I6Izc0Nzc3RCI+PG86cD48L286
cD48L3NwYW4+PC9wPg0KPC9kaXY+DQo8ZGl2Pg0KPGRpdiBzdHlsZT0ibWFyZ2luLWxlZnQ6My4w
cHQ7bWFyZ2luLXJpZ2h0OjMuMHB0O2JhY2tncm91bmQ6cmdiYSgxNTIsMjA3LDIzNSwwLjM1KSI+
DQo8cCBjbGFzcz0iTXNvTm9ybWFsIiBzdHlsZT0ibGluZS1oZWlnaHQ6MTEuMjVwdDtiYWNrZ3Jv
dW5kOiNGN0Y3RjciPjxzcGFuIHN0eWxlPSJmb250LXNpemU6OC41cHQ7Zm9udC1mYW1pbHk6Q29u
c29sYXMiPnByb3RvY29sIHZlcnNpb24gb2ZmZXJlZCBieSB0aGUgY2xpZW50IGluIHRoZSAmcXVv
dDt0b2tlbl9iaW5kaW5nJnF1b3Q7DQo8bzpwPjwvbzpwPjwvc3Bhbj48L3A+DQo8L2Rpdj4NCjxk
aXYgc3R5bGU9Im1hcmdpbi1sZWZ0OjMuMHB0O21hcmdpbi1yaWdodDozLjBwdDtiYWNrZ3JvdW5k
OnJnYmEoMTUyLDIwNywyMzUsMC4zNSkiPg0KPHAgY2xhc3M9Ik1zb05vcm1hbCIgc3R5bGU9Imxp
bmUtaGVpZ2h0OjExLjI1cHQ7YmFja2dyb3VuZDojRjdGN0Y3Ij48c3BhbiBzdHlsZT0iZm9udC1z
aXplOjguNXB0O2ZvbnQtZmFtaWx5OkNvbnNvbGFzIj5leHRlbnNpb24gYW5kIHRoZSBoaWdoZXN0
IHZlcnNpb24gc3VwcG9ydGVkIGJ5IHRoZSBzZXJ2ZXIuDQo8bzpwPjwvbzpwPjwvc3Bhbj48L3A+
DQo8L2Rpdj4NCjwvZGl2Pg0KPC9kaXY+DQo8ZGl2IHN0eWxlPSJtYXJnaW4tdG9wOjYuMHB0O21h
cmdpbi1ib3R0b206Ni4wcHQiPg0KPHAgc3R5bGU9Im1hcmdpbjo2LjBwdCI+R2l2ZW4gb3VyIGV4
cGVyaWVuY2Ugd2l0aCBUTFMgbmVnb3RpYXRpb24sIHlvdSBwcm9iYWJseSBuZWVkIHRvIHN0YXRl
IHZlcnkgY2xlYXJseSB0aGF0IHlvdSBuZWVkIHRvIGRvIG1pbihjbGllbnQsIHNlcnZlcikgdmVy
c2lvbiBldmVuIGlmIHRoZSBjbGllbnQgdmVyc2lvbiBpcyBoaWdoZXIgdGhhbiB5b3Uga25vdyBh
Ym91dC48bzpwPjwvbzpwPjwvcD4NCjwvZGl2Pg0KPC9kaXY+DQo8cCBjbGFzcz0iTXNvTm9ybWFs
Ij48bzpwPiZuYnNwOzwvbzpwPjwvcD4NCjxkaXYgc3R5bGU9ImJvcmRlcjpzb2xpZCAjQzdDQ0Q5
IDEuMHB0O3BhZGRpbmc6MGluIDBpbiAwaW4gMGluO2JvcmRlci1yYWRpdXM6M3B4Ij4NCjxkaXYg
c3R5bGU9ImJvcmRlcjpzb2xpZCAjRTNFNEU4IDEuMHB0O3BhZGRpbmc6MGluIDBpbiAwaW4gMGlu
Ij4NCjxkaXY+DQo8cCBjbGFzcz0iTXNvTm9ybWFsIiBzdHlsZT0iYmFja2dyb3VuZDojRUZGMkY0
Ij48c3BhbiBzdHlsZT0iY29sb3I6Izc0Nzc3RCI+PGEgaHJlZj0iaHR0cHM6Ly9uYTAxLnNhZmVs
aW5rcy5wcm90ZWN0aW9uLm91dGxvb2suY29tLz91cmw9aHR0cHMlM0ElMkYlMkZtb3pwaGFiLWll
dGYuZGV2c3ZjZGV2Lm1vemF3cy5uZXQlMkZENDclMjNpbmxpbmUtMzMwJmFtcDtkYXRhPTAyJTdD
MDElN0NBbmRyZWkuUG9wb3YlNDBtaWNyb3NvZnQuY29tJTdDZjBhNzE0NzIxZjJlNGY4ZDZmY2Uw
OGQ1MmE5NDZkMWQlN0M3MmY5ODhiZjg2ZjE0MWFmOTFhYjJkN2NkMDExZGI0NyU3QzElN0MwJTdD
NjM2NDYxNzM5MzM5NzY5MTQzJmFtcDtzZGF0YT01ZkcyS21ZcWo2RjFhOE5xSzJaTHNKVU5waWdq
WHp1MWRYbUw3bTFxbCUyRmclM0QmYW1wO3Jlc2VydmVkPTAiIHRhcmdldD0iX2JsYW5rIj48c3Bh
biBzdHlsZT0idGV4dC1kZWNvcmF0aW9uOm5vbmUiPlZpZXcNCiBJbmxpbmU8L3NwYW4+PC9hPjwv
c3Bhbj48Yj48c3BhbiBzdHlsZT0iY29sb3I6IzRCNEQ1MSI+ZHJhZnQtaWV0Zi10b2tiaW5kLW5l
Z290aWF0aW9uLnR4dDoxOTM8L3NwYW4+PC9iPjxzcGFuIHN0eWxlPSJjb2xvcjojNzQ3NzdEIj48
bzpwPjwvbzpwPjwvc3Bhbj48L3A+DQo8L2Rpdj4NCjxkaXY+DQo8ZGl2IHN0eWxlPSJtYXJnaW4t
bGVmdDozLjBwdDttYXJnaW4tcmlnaHQ6My4wcHQ7YmFja2dyb3VuZDpyZ2JhKDE1MiwyMDcsMjM1
LDAuMzUpIj4NCjxwIGNsYXNzPSJNc29Ob3JtYWwiIHN0eWxlPSJsaW5lLWhlaWdodDoxMS4yNXB0
O2JhY2tncm91bmQ6I0Y3RjdGNyI+PHNwYW4gc3R5bGU9ImZvbnQtc2l6ZTo4LjVwdDtmb250LWZh
bWlseTpDb25zb2xhcyI+ZXh0ZW5zaW9ucyBhcmUgbm90IG5lZ290aWF0ZWQgKHNlZSBzZWN1cml0
eSBjb25zaWRlcmF0aW9ucw0KPG86cD48L286cD48L3NwYW4+PC9wPg0KPC9kaXY+DQo8ZGl2IHN0
eWxlPSJtYXJnaW4tbGVmdDozLjBwdDttYXJnaW4tcmlnaHQ6My4wcHQ7YmFja2dyb3VuZDpyZ2Jh
KDE1MiwyMDcsMjM1LDAuMzUpIj4NCjxwIGNsYXNzPSJNc29Ob3JtYWwiIHN0eWxlPSJsaW5lLWhl
aWdodDoxMS4yNXB0O2JhY2tncm91bmQ6I0Y3RjdGNyI+PHNwYW4gc3R5bGU9ImZvbnQtc2l6ZTo4
LjVwdDtmb250LWZhbWlseTpDb25zb2xhcyI+c2VjdGlvbiBiZWxvdyBmb3IgbW9yZSBkZXRhaWxz
KS4NCjxvOnA+PC9vOnA+PC9zcGFuPjwvcD4NCjwvZGl2Pg0KPC9kaXY+DQo8L2Rpdj4NCjxkaXYg
c3R5bGU9Im1hcmdpbi10b3A6Ni4wcHQ7bWFyZ2luLWJvdHRvbTo2LjBwdCI+DQo8cCBzdHlsZT0i
bWFyZ2luOjYuMHB0Ij5JIHdvdWxkIHRlbmQgdG8gdGhpbmsgdGhhdCBzb21lIG9mIHRoZXNlIHdv
dWxkIGJlIGlsbGVnYWxfcGFyYW1ldGVyLjxvOnA+PC9vOnA+PC9wPg0KPC9kaXY+DQo8L2Rpdj4N
CjxwIGNsYXNzPSJNc29Ob3JtYWwiPjxvOnA+Jm5ic3A7PC9vOnA+PC9wPg0KPGRpdiBzdHlsZT0i
Ym9yZGVyOnNvbGlkICNDN0NDRDkgMS4wcHQ7cGFkZGluZzowaW4gMGluIDBpbiAwaW47Ym9yZGVy
LXJhZGl1czozcHgiPg0KPGRpdiBzdHlsZT0iYm9yZGVyOnNvbGlkICNFM0U0RTggMS4wcHQ7cGFk
ZGluZzowaW4gMGluIDBpbiAwaW4iPg0KPGRpdj4NCjxwIGNsYXNzPSJNc29Ob3JtYWwiIHN0eWxl
PSJiYWNrZ3JvdW5kOiNFRkYyRjQiPjxzcGFuIHN0eWxlPSJjb2xvcjojNzQ3NzdEIj48YSBocmVm
PSJodHRwczovL25hMDEuc2FmZWxpbmtzLnByb3RlY3Rpb24ub3V0bG9vay5jb20vP3VybD1odHRw
cyUzQSUyRiUyRm1venBoYWItaWV0Zi5kZXZzdmNkZXYubW96YXdzLm5ldCUyRkQ0NyUyM2lubGlu
ZS0zMzEmYW1wO2RhdGE9MDIlN0MwMSU3Q0FuZHJlaS5Qb3BvdiU0MG1pY3Jvc29mdC5jb20lN0Nm
MGE3MTQ3MjFmMmU0ZjhkNmZjZTA4ZDUyYTk0NmQxZCU3QzcyZjk4OGJmODZmMTQxYWY5MWFiMmQ3
Y2QwMTFkYjQ3JTdDMSU3QzAlN0M2MzY0NjE3MzkzMzk3NjkxNDMmYW1wO3NkYXRhPWo3RXU3ZFh2
cXNiMlRFU0s5MmNWQ0R4cDV0bGdkMmdURGVlSDQyMHhEWVUlM0QmYW1wO3Jlc2VydmVkPTAiIHRh
cmdldD0iX2JsYW5rIj48c3BhbiBzdHlsZT0idGV4dC1kZWNvcmF0aW9uOm5vbmUiPlZpZXcNCiBJ
bmxpbmU8L3NwYW4+PC9hPjwvc3Bhbj48Yj48c3BhbiBzdHlsZT0iY29sb3I6IzRCNEQ1MSI+ZHJh
ZnQtaWV0Zi10b2tiaW5kLW5lZ290aWF0aW9uLnR4dDoyMTA8L3NwYW4+PC9iPjxzcGFuIHN0eWxl
PSJjb2xvcjojNzQ3NzdEIj48bzpwPjwvbzpwPjwvc3Bhbj48L3A+DQo8L2Rpdj4NCjxkaXY+DQo8
ZGl2IHN0eWxlPSJtYXJnaW4tbGVmdDozLjBwdDttYXJnaW4tcmlnaHQ6My4wcHQ7YmFja2dyb3Vu
ZDpyZ2JhKDE1MiwyMDcsMjM1LDAuMzUpIj4NCjxwIGNsYXNzPSJNc29Ob3JtYWwiIHN0eWxlPSJs
aW5lLWhlaWdodDoxMS4yNXB0O2JhY2tncm91bmQ6I0Y3RjdGNyI+PHNwYW4gc3R5bGU9ImZvbnQt
c2l6ZTo4LjVwdDtmb250LWZhbWlseTpDb25zb2xhcyI+UGxlYXNlIG5vdGUgdGhhdCB0aGUgVG9r
ZW4gQmluZGluZyBwcm90b2NvbCB2ZXJzaW9uIGFuZCBrZXkNCjxvOnA+PC9vOnA+PC9zcGFuPjwv
cD4NCjwvZGl2Pg0KPGRpdiBzdHlsZT0ibWFyZ2luLWxlZnQ6My4wcHQ7bWFyZ2luLXJpZ2h0OjMu
MHB0O2JhY2tncm91bmQ6cmdiYSgxNTIsMjA3LDIzNSwwLjM1KSI+DQo8cCBjbGFzcz0iTXNvTm9y
bWFsIiBzdHlsZT0ibGluZS1oZWlnaHQ6MTEuMjVwdDtiYWNrZ3JvdW5kOiNGN0Y3RjciPjxzcGFu
IHN0eWxlPSJmb250LXNpemU6OC41cHQ7Zm9udC1mYW1pbHk6Q29uc29sYXMiPnBhcmFtZXRlcnMg
YXJlIG5lZ290aWF0ZWQgZm9yIGVhY2ggVExTIGNvbm5lY3Rpb24sIHdoaWNoIG1lYW5zIHRoYXQN
CjxvOnA+PC9vOnA+PC9zcGFuPjwvcD4NCjwvZGl2Pg0KPC9kaXY+DQo8L2Rpdj4NCjxkaXYgc3R5
bGU9Im1hcmdpbi10b3A6Ni4wcHQ7bWFyZ2luLWJvdHRvbTo2LjBwdCI+DQo8cCBzdHlsZT0ibWFy
Z2luOjYuMHB0Ij5JIHdvdWxkIHJlbW92ZSAmcXVvdDtwbGVhc2Ugbm90ZSZxdW90OyBoZXJlLCBi
ZWNhdXNlIHlvdSBhcmVuJ3QgcmVtaW5kaW5nIHBlb3BsZSwgdGhpcyBpcyBhIHNlcGFyYXRlIHJl
cXVpcmVtZW50LjxvOnA+PC9vOnA+PC9wPg0KPC9kaXY+DQo8L2Rpdj4NCjwvZGl2Pg0KPC9kaXY+
DQo8L2Rpdj4NCjxkaXY+DQo8ZGl2Pg0KPHAgY2xhc3M9Ik1zb05vcm1hbCI+PG86cD4mbmJzcDs8
L286cD48L3A+DQo8ZGl2Pg0KPHAgY2xhc3M9Ik1zb05vcm1hbCI+PHN0cm9uZz48c3BhbiBzdHls
ZT0iZm9udC1mYW1pbHk6JnF1b3Q7Q2FsaWJyaSZxdW90OyxzYW5zLXNlcmlmIj5SRVBPU0lUT1JZ
PC9zcGFuPjwvc3Ryb25nPjxvOnA+PC9vOnA+PC9wPg0KPGRpdj4NCjxkaXY+DQo8cCBjbGFzcz0i
TXNvTm9ybWFsIj5ySUVURlJFVklFVyBpZXRmLXJldmlldzxvOnA+PC9vOnA+PC9wPg0KPC9kaXY+
DQo8L2Rpdj4NCjwvZGl2Pg0KPHAgY2xhc3M9Ik1zb05vcm1hbCI+PG86cD4mbmJzcDs8L286cD48
L3A+DQo8ZGl2Pg0KPHAgY2xhc3M9Ik1zb05vcm1hbCI+PHN0cm9uZz48c3BhbiBzdHlsZT0iZm9u
dC1mYW1pbHk6JnF1b3Q7Q2FsaWJyaSZxdW90OyxzYW5zLXNlcmlmIj5SRVZJU0lPTiBERVRBSUw8
L3NwYW4+PC9zdHJvbmc+PG86cD48L286cD48L3A+DQo8ZGl2Pg0KPHAgY2xhc3M9Ik1zb05vcm1h
bCI+PGEgaHJlZj0iaHR0cHM6Ly9uYTAxLnNhZmVsaW5rcy5wcm90ZWN0aW9uLm91dGxvb2suY29t
Lz91cmw9aHR0cHMlM0ElMkYlMkZtb3pwaGFiLWlldGYuZGV2c3ZjZGV2Lm1vemF3cy5uZXQlMkZE
NDcmYW1wO2RhdGE9MDIlN0MwMSU3Q0FuZHJlaS5Qb3BvdiU0MG1pY3Jvc29mdC5jb20lN0NmMGE3
MTQ3MjFmMmU0ZjhkNmZjZTA4ZDUyYTk0NmQxZCU3QzcyZjk4OGJmODZmMTQxYWY5MWFiMmQ3Y2Qw
MTFkYjQ3JTdDMSU3QzAlN0M2MzY0NjE3MzkzMzk3NjkxNDMmYW1wO3NkYXRhPU1aMSUyQnJqYlVp
S21SRjk5a3pVSU9DNHFMcVRmVXBkU3JXMjNiZkwwazF1ayUzRCZhbXA7cmVzZXJ2ZWQ9MCIgdGFy
Z2V0PSJfYmxhbmsiPmh0dHBzOi8vbW96cGhhYi1pZXRmLmRldnN2Y2Rldi5tb3phd3MubmV0L0Q0
NzwvYT48bzpwPjwvbzpwPjwvcD4NCjwvZGl2Pg0KPC9kaXY+DQo8cCBjbGFzcz0iTXNvTm9ybWFs
Ij48bzpwPiZuYnNwOzwvbzpwPjwvcD4NCjxkaXY+DQo8cCBjbGFzcz0iTXNvTm9ybWFsIj48c3Ry
b25nPjxzcGFuIHN0eWxlPSJmb250LWZhbWlseTomcXVvdDtDYWxpYnJpJnF1b3Q7LHNhbnMtc2Vy
aWYiPkVNQUlMIFBSRUZFUkVOQ0VTPC9zcGFuPjwvc3Ryb25nPjxvOnA+PC9vOnA+PC9wPg0KPGRp
dj4NCjxwIGNsYXNzPSJNc29Ob3JtYWwiPjxhIGhyZWY9Imh0dHBzOi8vbmEwMS5zYWZlbGlua3Mu
cHJvdGVjdGlvbi5vdXRsb29rLmNvbS8/dXJsPWh0dHBzJTNBJTJGJTJGbW96cGhhYi1pZXRmLmRl
dnN2Y2Rldi5tb3phd3MubmV0JTJGc2V0dGluZ3MlMkZwYW5lbCUyRmVtYWlscHJlZmVyZW5jZXMl
MkYmYW1wO2RhdGE9MDIlN0MwMSU3Q0FuZHJlaS5Qb3BvdiU0MG1pY3Jvc29mdC5jb20lN0NmMGE3
MTQ3MjFmMmU0ZjhkNmZjZTA4ZDUyYTk0NmQxZCU3QzcyZjk4OGJmODZmMTQxYWY5MWFiMmQ3Y2Qw
MTFkYjQ3JTdDMSU3QzAlN0M2MzY0NjE3MzkzMzk3NjkxNDMmYW1wO3NkYXRhPSUyRlRoaUNWelFG
V0owWVh1eGtRTEJMcWVuRWFGZm5OcmphRGlPNkFFMDhGTSUzRCZhbXA7cmVzZXJ2ZWQ9MCIgdGFy
Z2V0PSJfYmxhbmsiPmh0dHBzOi8vbW96cGhhYi1pZXRmLmRldnN2Y2Rldi5tb3phd3MubmV0L3Nl
dHRpbmdzL3BhbmVsL2VtYWlscHJlZmVyZW5jZXMvPC9hPjxvOnA+PC9vOnA+PC9wPg0KPC9kaXY+
DQo8L2Rpdj4NCjxwIGNsYXNzPSJNc29Ob3JtYWwiPjxvOnA+Jm5ic3A7PC9vOnA+PC9wPg0KPGRp
dj4NCjxwIGNsYXNzPSJNc29Ob3JtYWwiPjxzdHJvbmc+PHNwYW4gc3R5bGU9ImZvbnQtZmFtaWx5
OiZxdW90O0NhbGlicmkmcXVvdDssc2Fucy1zZXJpZiI+VG86IDwvc3Bhbj4NCjwvc3Ryb25nPmVr
ci1tb3osIGVrcjxvOnA+PC9vOnA+PC9wPg0KPC9kaXY+DQo8L2Rpdj4NCjwvZGl2Pg0KPC9kaXY+
DQo8cCBjbGFzcz0iTXNvTm9ybWFsIj48bzpwPiZuYnNwOzwvbzpwPjwvcD4NCjwvZGl2Pg0KPC9i
bG9ja3F1b3RlPg0KPC9kaXY+DQo8cCBjbGFzcz0iTXNvTm9ybWFsIj48bzpwPiZuYnNwOzwvbzpw
PjwvcD4NCjwvZGl2Pg0KPC9kaXY+DQo8L2JvZHk+DQo8L2h0bWw+DQo=

--_000_CY4PR21MB012057579C1F371C80B66C628C2B0CY4PR21MB0120namp_--


From nobody Mon Nov 13 15:02:02 2017
Return-Path: <iesg-secretary@ietf.org>
X-Original-To: unbearable@ietf.org
Delivered-To: unbearable@ietfa.amsl.com
Received: from ietfa.amsl.com (localhost [IPv6:::1]) by ietfa.amsl.com (Postfix) with ESMTP id 7F685120724; Mon, 13 Nov 2017 15:01:50 -0800 (PST)
MIME-Version: 1.0
Content-Type: text/plain; charset="utf-8"
Content-Transfer-Encoding: 7bit
From: The IESG <iesg-secretary@ietf.org>
To: "IETF-Announce" <ietf-announce@ietf.org>
X-Test-IDTracker: no
X-IETF-IDTracker: 6.65.1
Auto-Submitted: auto-generated
Precedence: bulk
CC: ekr@rtfm.com, John Bradley <ve7jtb@ve7jtb.com>, unbearable@ietf.org, draft-ietf-tokbind-protocol@ietf.org, ve7jtb@ve7jtb.com, tokbind-chairs@ietf.org
Reply-To: ietf@ietf.org
Sender: <iesg-secretary@ietf.org>
MIME-Version: 1.0
Content-Type: text/plain; charset="utf-8"
Content-Transfer-Encoding: 7bit
Message-ID: <151061411047.6041.13432163942672955613.idtracker@ietfa.amsl.com>
Date: Mon, 13 Nov 2017 15:01:50 -0800
Archived-At: <https://mailarchive.ietf.org/arch/msg/unbearable/JQ0n4j_6f4MI6ZqUznfoDsDsGvI>
Subject: [Unbearable] Last Call: <draft-ietf-tokbind-protocol-16.txt> (The Token Binding Protocol Version 1.0) to Proposed Standard
X-BeenThere: unbearable@ietf.org
X-Mailman-Version: 2.1.22
List-Id: "\"This list is for discussion of proposals for doing better than bearer tokens \(e.g. HTTP cookies, OAuth tokens etc.\) for web applications. The specific goal is chartering a WG focused on preventing security token export and replay attacks.\"" <unbearable.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/unbearable>, <mailto:unbearable-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/unbearable/>
List-Post: <mailto:unbearable@ietf.org>
List-Help: <mailto:unbearable-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/unbearable>, <mailto:unbearable-request@ietf.org?subject=subscribe>
X-List-Received-Date: Mon, 13 Nov 2017 23:01:51 -0000

The IESG has received a request from the Token Binding WG (tokbind) to
consider the following document: - 'The Token Binding Protocol Version 1.0'
  <draft-ietf-tokbind-protocol-16.txt> as Proposed Standard

The IESG plans to make a decision in the next few weeks, and solicits final
comments on this action. Please send substantive comments to the
ietf@ietf.org mailing lists by 2017-11-27. Exceptionally, comments may be
sent to iesg@ietf.org instead. In either case, please retain the beginning of
the Subject line to allow automated sorting.

Abstract


   This document specifies Version 1.0 of the Token Binding protocol.
   The Token Binding protocol allows client/server applications to
   create long-lived, uniquely identifiable TLS bindings spanning
   multiple TLS sessions and connections.  Applications are then enabled
   to cryptographically bind security tokens to the TLS layer,
   preventing token export and replay attacks.  To protect privacy, the
   Token Binding identifiers are only conveyed over TLS and can be reset
   by the user at any time.




The file can be obtained via
https://datatracker.ietf.org/doc/draft-ietf-tokbind-protocol/

IESG discussion can be tracked via
https://datatracker.ietf.org/doc/draft-ietf-tokbind-protocol/ballot/


No IPR declarations have been submitted directly on this I-D.





From nobody Mon Nov 13 15:02:55 2017
Return-Path: <iesg-secretary@ietf.org>
X-Original-To: unbearable@ietf.org
Delivered-To: unbearable@ietfa.amsl.com
Received: from ietfa.amsl.com (localhost [IPv6:::1]) by ietfa.amsl.com (Postfix) with ESMTP id E113F127369; Mon, 13 Nov 2017 15:02:47 -0800 (PST)
MIME-Version: 1.0
Content-Type: text/plain; charset="utf-8"
Content-Transfer-Encoding: 7bit
From: The IESG <iesg-secretary@ietf.org>
To: "IETF-Announce" <ietf-announce@ietf.org>
X-Test-IDTracker: no
X-IETF-IDTracker: 6.65.1
Auto-Submitted: auto-generated
Precedence: bulk
CC: ekr@rtfm.com, John Bradley <ve7jtb@ve7jtb.com>, unbearable@ietf.org, tokbind-chairs@ietf.org, ve7jtb@ve7jtb.com, draft-ietf-tokbind-negotiation@ietf.org
Reply-To: ietf@ietf.org
Sender: <iesg-secretary@ietf.org>
MIME-Version: 1.0
Content-Type: text/plain; charset="utf-8"
Content-Transfer-Encoding: 7bit
Message-ID: <151061416791.5985.561262309681299774.idtracker@ietfa.amsl.com>
Date: Mon, 13 Nov 2017 15:02:47 -0800
Archived-At: <https://mailarchive.ietf.org/arch/msg/unbearable/pm42YqBxvaVpDGPhGCSNX9z2TPA>
Subject: [Unbearable] Last Call: <draft-ietf-tokbind-negotiation-10.txt> (Transport Layer Security (TLS) Extension for Token Binding Protocol Negotiation) to Proposed Standard
X-BeenThere: unbearable@ietf.org
X-Mailman-Version: 2.1.22
List-Id: "\"This list is for discussion of proposals for doing better than bearer tokens \(e.g. HTTP cookies, OAuth tokens etc.\) for web applications. The specific goal is chartering a WG focused on preventing security token export and replay attacks.\"" <unbearable.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/unbearable>, <mailto:unbearable-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/unbearable/>
List-Post: <mailto:unbearable@ietf.org>
List-Help: <mailto:unbearable-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/unbearable>, <mailto:unbearable-request@ietf.org?subject=subscribe>
X-List-Received-Date: Mon, 13 Nov 2017 23:02:48 -0000

The IESG has received a request from the Token Binding WG (tokbind) to
consider the following document: - 'Transport Layer Security (TLS) Extension
for Token Binding Protocol
   Negotiation'
  <draft-ietf-tokbind-negotiation-10.txt> as Proposed Standard

The IESG plans to make a decision in the next few weeks, and solicits final
comments on this action. Please send substantive comments to the
ietf@ietf.org mailing lists by 2017-11-27. Exceptionally, comments may be
sent to iesg@ietf.org instead. In either case, please retain the beginning of
the Subject line to allow automated sorting.

Abstract


   This document specifies a Transport Layer Security (TLS) extension
   for the negotiation of Token Binding protocol version and key
   parameters.




The file can be obtained via
https://datatracker.ietf.org/doc/draft-ietf-tokbind-negotiation/

IESG discussion can be tracked via
https://datatracker.ietf.org/doc/draft-ietf-tokbind-negotiation/ballot/


No IPR declarations have been submitted directly on this I-D.





From nobody Mon Nov 13 17:48:47 2017
Return-Path: <ietf-secretariat-reply@ietf.org>
X-Original-To: unbearable@ietf.org
Delivered-To: unbearable@ietfa.amsl.com
Received: from ietfa.amsl.com (localhost [IPv6:::1]) by ietfa.amsl.com (Postfix) with ESMTP id DE45F1295A0 for <unbearable@ietf.org>; Mon, 13 Nov 2017 17:48:44 -0800 (PST)
MIME-Version: 1.0
Content-Type: text/plain; charset="utf-8"
Content-Transfer-Encoding: 7bit
To: <unbearable@ietf.org>
X-Test-IDTracker: no
X-IETF-IDTracker: 6.65.1
Auto-Submitted: auto-generated
Precedence: bulk
Message-ID: <151062412490.5973.5292329468893600796.idtracker@ietfa.amsl.com>
Date: Mon, 13 Nov 2017 17:48:44 -0800
From: IETF Secretariat <ietf-secretariat-reply@ietf.org>
Archived-At: <https://mailarchive.ietf.org/arch/msg/unbearable/8U46sHeui89qAgj1i2boDcKgQMQ>
Subject: [Unbearable] Milestones changed for tokbind WG
X-BeenThere: unbearable@ietf.org
X-Mailman-Version: 2.1.22
List-Id: "\"This list is for discussion of proposals for doing better than bearer tokens \(e.g. HTTP cookies, OAuth tokens etc.\) for web applications. The specific goal is chartering a WG focused on preventing security token export and replay attacks.\"" <unbearable.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/unbearable>, <mailto:unbearable-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/unbearable/>
List-Post: <mailto:unbearable@ietf.org>
List-Help: <mailto:unbearable-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/unbearable>, <mailto:unbearable-request@ietf.org?subject=subscribe>
X-List-Received-Date: Tue, 14 Nov 2017 01:48:45 -0000

Changed milestone "TLS extension for Token Binding as WG document", set state
to active from review, accepting new milestone.

Changed milestone "HTTPS Token Binding to IESG.", set due date to December
2017 from December 2015.

Changed milestone "Token Binding Protocol v1.0 to IESG.", set due date to
December 2017 from December 2015.

URL: https://datatracker.ietf.org/wg/tokbind/about/


From nobody Mon Nov 13 22:23:36 2017
Return-Path: <leifj@sunet.se>
X-Original-To: unbearable@ietfa.amsl.com
Delivered-To: unbearable@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 2F70C124D6C for <unbearable@ietfa.amsl.com>; Mon, 13 Nov 2017 22:23:32 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.901
X-Spam-Level: 
X-Spam-Status: No, score=-1.901 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, RCVD_IN_DNSWL_NONE=-0.0001, SPF_PASS=-0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (2048-bit key) header.d=sunet-se.20150623.gappssmtp.com
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id VcIUmhRsDbc0 for <unbearable@ietfa.amsl.com>; Mon, 13 Nov 2017 22:23:29 -0800 (PST)
Received: from mail-pg0-x235.google.com (mail-pg0-x235.google.com [IPv6:2607:f8b0:400e:c05::235]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 4CFDD128656 for <unbearable@ietf.org>; Mon, 13 Nov 2017 22:23:28 -0800 (PST)
Received: by mail-pg0-x235.google.com with SMTP id s2so14591089pge.10 for <unbearable@ietf.org>; Mon, 13 Nov 2017 22:23:28 -0800 (PST)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=sunet-se.20150623.gappssmtp.com; s=20150623; h=to:from:subject:message-id:date:user-agent:mime-version :content-language:content-transfer-encoding; bh=ttHaHydE3TwdqTxL3Dv5aaMH36tdQFrOOluOPH4OSnw=; b=j2hl2xvnRpP3FRB5kdpjmV8yTsxjrbYnp19OSK8ZXHHqvpHAUtMBwt+UB9o9UwOpYv Gtd7lPGUt7FadG4VYp/4EzRv3oLont6grLk3mRjWC4buK/6KpDE7OaJUwwndjIs1VZ7W FMn49ZbPR7vKQm8j+SSO5fBSHFO4QEYLfk7Txt43ViLn/9XE9RknNB2z1tzYES/b48Wm /NmARs41mx8wtK/k08pR3gxaGY6hCNQpfPp18yS6RPMSuIE3pX3kSg/VhtJWJVrdpAXq CJCB/2etHSIzAp7HdxN7y2GoeYAngss7ymF2i7APRrLqguz/4dOjM95bhG05xzCV+ruq Nw6Q==
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20161025; h=x-gm-message-state:to:from:subject:message-id:date:user-agent :mime-version:content-language:content-transfer-encoding; bh=ttHaHydE3TwdqTxL3Dv5aaMH36tdQFrOOluOPH4OSnw=; b=D1+HwKhQPDNeRW4BEwVNki4HTcpWFTiEo/Hr6ScpCkX7KI5Qwx6adq1MoggAz+yZm7 FoSdnjfkKN15kpzXqERHPKeYlJC3DcizkmWCQZzRQ1oCjWLmk+TBZ5cBQITMUu1tRh/y e78dYwO5m7Lef/32RV7UZMSL3sT+Z3qXPubhULDEABzk8HR3h9MLR/NzGDnv5UwoBim+ iLAZMx8qO4wmlmBGNRJzskEX0xunmVpdHyVQVJ1T6Wkhg+HZ5y2QVJAKTAEnmhuw71ef o9BjGXsPJHNbRzIGfbi7aiJIIupLB5uMMZ3F2CWgmd18WSY/k2yxAFhS9LDiDGhTmVPn nejw==
X-Gm-Message-State: AJaThX7ADY7V6C+Mtp2K6JUHvp9OTLwAXecsBhCqyiUWKUWP2P6hWzh/ ooooY0NSlf8USoGV/SOD5z9MFY2liCs=
X-Google-Smtp-Source: AGs4zMbYDQ8UaBPVBUTCHzGd1EZwvsPe0PgKrHpJQVr2b4H/h4dClOMibivRqxsHYGb0tKnMaao7Kw==
X-Received: by 10.84.211.79 with SMTP id b73mr11204204pli.116.1510640608196; Mon, 13 Nov 2017 22:23:28 -0800 (PST)
Received: from ?IPv6:2001:67c:370:128:418a:5b2a:53f5:49b? ([2001:67c:370:128:418a:5b2a:53f5:49b]) by smtp.gmail.com with ESMTPSA id s65sm37708672pfj.81.2017.11.13.22.23.26 for <unbearable@ietf.org> (version=TLS1_2 cipher=ECDHE-RSA-AES128-GCM-SHA256 bits=128/128); Mon, 13 Nov 2017 22:23:27 -0800 (PST)
To: IETF Tokbind WG <unbearable@ietf.org>
From: Leif Johansson <leifj@sunet.se>
Message-ID: <1a6a44a7-4984-e52c-af62-3876fdbe4d44@sunet.se>
Date: Tue, 14 Nov 2017 07:23:25 +0100
User-Agent: Mozilla/5.0 (X11; Linux x86_64; rv:52.0) Gecko/20100101 Thunderbird/52.4.0
MIME-Version: 1.0
Content-Type: text/plain; charset=utf-8
Content-Language: en-US
Content-Transfer-Encoding: 7bit
Archived-At: <https://mailarchive.ietf.org/arch/msg/unbearable/tZ38ykvjt_1oWTc2PnivLI2iPT0>
Subject: [Unbearable] wg adoption of draft-nharper-tokbind-tls13-00
X-BeenThere: unbearable@ietf.org
X-Mailman-Version: 2.1.22
Precedence: list
List-Id: "\"This list is for discussion of proposals for doing better than bearer tokens \(e.g. HTTP cookies, OAuth tokens etc.\) for web applications. The specific goal is chartering a WG focused on preventing security token export and replay attacks.\"" <unbearable.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/unbearable>, <mailto:unbearable-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/unbearable/>
List-Post: <mailto:unbearable@ietf.org>
List-Help: <mailto:unbearable-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/unbearable>, <mailto:unbearable-request@ietf.org?subject=subscribe>
X-List-Received-Date: Tue, 14 Nov 2017 06:23:33 -0000

In Singapore there was strong consensus for adopting
draft-nharper-tokbind-tls13-00 as a WG document. Unless
anyone protests here, draft-ietf-tokbind-tls13-00 will
be published in a few days.

	Cheers Leif


From nobody Tue Nov 14 17:43:37 2017
Return-Path: <bounce+3a3868.40f-unbearable=ietf.org@github.com>
X-Original-To: unbearable@ietfa.amsl.com
Delivered-To: unbearable@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 4DA1E12940A for <unbearable@ietfa.amsl.com>; Tue, 14 Nov 2017 10:25:23 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.9
X-Spam-Level: 
X-Spam-Status: No, score=-1.9 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, HEADER_FROM_DIFFERENT_DOMAINS=0.001, RCVD_IN_DNSWL_NONE=-0.0001, SPF_PASS=-0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (1024-bit key) header.d=github.com
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id TAOwjG7g8pdP for <unbearable@ietfa.amsl.com>; Tue, 14 Nov 2017 10:25:21 -0800 (PST)
Received: from m69-169.mailgun.net (m69-169.mailgun.net [166.78.69.169]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 7996A128B38 for <unbearable@ietf.org>; Tue, 14 Nov 2017 10:25:21 -0800 (PST)
DKIM-Signature: a=rsa-sha256; v=1; c=relaxed/relaxed; d=github.com; q=dns/txt;  s=mailo; t=1510683920; h=Content-Transfer-Encoding: Content-Type: Mime-Version: Subject: Message-ID: To: Reply-To: From: Date: Sender; bh=Ed5MgGWPaNCevjOCflKTtIpOqoddNt4fJlrGVIF+RG4=; b=dIiltkupq1XHfz+ZYgoZ/I2PUkgGmSC5Wb2GzkJBZsOh3Q9H1G/1LA1PKpKt7Kfrp1t0iOLJ WcUwvQQbkTrX+X1j5FgZ8Q7JFvnSpNKyQ7cj7KROowiNktgGovECSS8cQgqhwR+mfVntJbH4 /+Kv5QSk1p7WAJWSShpbpshiYgk=
Sender: dirk=balfanz.net@github.com
X-Mailgun-Sending-Ip: 166.78.69.169
X-Mailgun-Sid: WyIzMTNlNyIsICJ1bmJlYXJhYmxlQGlldGYub3JnIiwgIjQwZiJd
Received: from github.com (Unknown [192.30.252.35]) by mxa.mailgun.org with ESMTP id 5a0b350e.7fe368080720-smtp-out-n02; Tue, 14 Nov 2017 18:25:18 -0000 (UTC)
Date: Tue, 14 Nov 2017 10:25:17 -0800
From: balfanz <dirk@balfanz.net>
Reply-To: balfanz <dirk@balfanz.net>
To: unbearable@ietf.org
Message-ID: <5a0b350d88203_6743f7dff0dfc34686aa@hookshot-fe-92cdb05.cp1-iad.github.net.mail>
Mime-Version: 1.0
Content-Type: multipart/mixed; boundary="--==_mimepart_5a0b350d87ef4_6743f7dff0dfc34685e0"; charset=UTF-8
Content-Transfer-Encoding: 7bit
Archived-At: <https://mailarchive.ietf.org/arch/msg/unbearable/ZwDpAyGjsDsu4-Izhw0wdjs2q_I>
X-Mailman-Approved-At: Tue, 14 Nov 2017 17:43:36 -0800
Subject: [Unbearable] [TokenBinding/Internet-Drafts] 633587: Adding fed sign-on considerations to Security Cons...
X-BeenThere: unbearable@ietf.org
X-Mailman-Version: 2.1.22
Precedence: list
List-Id: "\"This list is for discussion of proposals for doing better than bearer tokens \(e.g. HTTP cookies, OAuth tokens etc.\) for web applications. The specific goal is chartering a WG focused on preventing security token export and replay attacks.\"" <unbearable.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/unbearable>, <mailto:unbearable-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/unbearable/>
List-Post: <mailto:unbearable@ietf.org>
List-Help: <mailto:unbearable-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/unbearable>, <mailto:unbearable-request@ietf.org?subject=subscribe>
X-List-Received-Date: Tue, 14 Nov 2017 18:25:23 -0000

----==_mimepart_5a0b350d87ef4_6743f7dff0dfc34685e0
Content-Type: text/plain;
 charset=UTF-8
Content-Transfer-Encoding: 7bit

  Branch: refs/heads/master
  Home:   https://github.com/TokenBinding/Internet-Drafts
  Commit: 6335877da2a0d39be8b5f17f62911ba2acdac7f2
      https://github.com/TokenBinding/Internet-Drafts/commit/6335877da2a0d39be8b5f17f62911ba2acdac7f2
  Author: balfanz <dirk@balfanz.net>
  Date:   2017-11-14 (Tue, 14 Nov 2017)

  Changed paths:
    M draft-ietf-tokbind-https-10.xml

  Log Message:
  -----------
  Adding fed sign-on considerations to Security Considerations sections.


  Commit: d97f889cd1c94faa59533f23600c4d3005b56325
      https://github.com/TokenBinding/Internet-Drafts/commit/d97f889cd1c94faa59533f23600c4d3005b56325
  Author: balfanz <dirk@balfanz.net>
  Date:   2017-11-14 (Tue, 14 Nov 2017)

  Changed paths:
    R draft-ietf-tokbind-https-10.xml
    A draft-ietf-tokbind-https-11.xml

  Log Message:
  -----------
  creating v11 of draft-ietf-tokbind-https


Compare: https://github.com/TokenBinding/Internet-Drafts/compare/7b18d47daf8f...d97f889cd1c9
----==_mimepart_5a0b350d87ef4_6743f7dff0dfc34685e0--


From nobody Tue Nov 14 17:43:42 2017
Return-Path: <bounces+848413-28b5-unbearable=ietf.org@sgmail.github.com>
X-Original-To: unbearable@ietfa.amsl.com
Delivered-To: unbearable@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 149FF1200CF for <unbearable@ietfa.amsl.com>; Tue, 14 Nov 2017 17:39:31 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -3.395
X-Spam-Level: 
X-Spam-Status: No, score=-3.395 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, HTML_IMAGE_ONLY_28=1.404, HTML_MESSAGE=0.001, RCVD_IN_MSPIKE_H2=-2.8, SPF_PASS=-0.001, URIBL_BLOCKED=0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (1024-bit key) header.d=github.com
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id rw7YhExqUKR4 for <unbearable@ietfa.amsl.com>; Tue, 14 Nov 2017 17:39:29 -0800 (PST)
Received: from o6.sgmail.github.com (o6.sgmail.github.com [192.254.113.101]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 19702129478 for <unbearable@ietf.org>; Tue, 14 Nov 2017 17:39:02 -0800 (PST)
DKIM-Signature: v=1; a=rsa-sha1; c=relaxed/relaxed; d=github.com;  h=from:reply-to:to:cc:subject:mime-version:content-type:content-transfer-encoding:list-id:list-archive:list-post:list-unsubscribe; s=s20150108; bh=rE6j5I/rWN5R8Zz7inZo6Xaj134=; b=jrjNpfB1Jzp4f1RW kphr+cEq3iTJ4xq6EdMyCHLLb+xqdm97mRUCDfszXUb62823v+5B3tDeY86/9Psi gJbBxig4YkHz7q3xYlv2qaTJQIsP20gvWkvW8RwZ/El5OQHMC3TDZKVBRF1sbuK0 8JZj8VcuFKPkEO/1hW5maiVGMQo=
Received: by filter0932p1mdw1.sendgrid.net with SMTP id filter0932p1mdw1-2191-5A0B9AB5-A 2017-11-15 01:39:01.167088321 +0000 UTC
Received: from github-smtp2b-ext-cp1-prd.iad.github.net (github-smtp2b-ext-cp1-prd.iad.github.net [192.30.253.17]) by ismtpd0006p1iad1.sendgrid.net (SG) with ESMTP id ICBJK95FS4O4vh5bwllYxg for <unbearable@ietf.org>; Wed, 15 Nov 2017 01:39:01.111 +0000 (UTC)
Date: Wed, 15 Nov 2017 01:39:01 +0000 (UTC)
From: Nick Harper <notifications@github.com>
Reply-To: TokenBinding/Internet-Drafts <reply+011c274f44126fdf29dfb3d2c1757e0fa7d79f7bbfbb60a292cf0000000116235cb592a169ce1054fb73@reply.github.com>
To: TokenBinding/Internet-Drafts <Internet-Drafts@noreply.github.com>
Cc: Subscribed <subscribed@noreply.github.com>
Message-ID: <TokenBinding/Internet-Drafts/pull/99@github.com>
Mime-Version: 1.0
Content-Type: multipart/alternative; boundary="--==_mimepart_5a0b9ab5225e_acb3f80bf28cf3870833"; charset=UTF-8
Content-Transfer-Encoding: 7bit
Precedence: list
X-GitHub-Sender: nharper
X-GitHub-Recipient: unbearable-ML
X-GitHub-Reason: subscribed
X-Auto-Response-Suppress: All
X-GitHub-Recipient-Address: unbearable@ietf.org
tracking: 
X-SG-EID: 9Yqp9dCIIwZxB0MVAPExrXlt7a4/46ALD9aG/N3UOYrn4L094Zq915vTolWkxSZAi5tgwISkbtlOmO 2QmnjgBlylwn1Jo4dLzU3fiacmxO/T+28b3AYtIWbevFBusWcNEjSzFchVRtrXE7NVAqjP3jM7yapz 3JvXInULIrZu4uEE4LUjUW/KJWF8g3dxvNePIP1z/aKsH/Zr+fBj29Ag/BBtCF5ArQ/k7Z8mKhOZKu c=
Archived-At: <https://mailarchive.ietf.org/arch/msg/unbearable/MeMogKGshkzaz5qDWzqT4LzOCVg>
X-Mailman-Approved-At: Tue, 14 Nov 2017 17:43:36 -0800
Subject: [Unbearable] [TokenBinding/Internet-Drafts] Remove Nick Harper from acknowledgements in HTTPSTB (#99)
X-BeenThere: unbearable@ietf.org
X-Mailman-Version: 2.1.22
List-Id: "\"This list is for discussion of proposals for doing better than bearer tokens \(e.g. HTTP cookies, OAuth tokens etc.\) for web applications. The specific goal is chartering a WG focused on preventing security token export and replay attacks.\"" <unbearable.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/unbearable>, <mailto:unbearable-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/unbearable/>
List-Post: <mailto:unbearable@ietf.org>
List-Help: <mailto:unbearable-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/unbearable>, <mailto:unbearable-request@ietf.org?subject=subscribe>
X-List-Received-Date: Wed, 15 Nov 2017 01:39:31 -0000

----==_mimepart_5a0b9ab5225e_acb3f80bf28cf3870833
Content-Type: text/plain;
 charset=UTF-8
Content-Transfer-Encoding: 7bit

I figure I don't need to be in the acknowledgements if I'm an author.
You can view, comment on, or merge this pull request online at:

  https://github.com/TokenBinding/Internet-Drafts/pull/99

-- Commit Summary --

  * Remove Nick Harper from acknowledgements in HTTPSTB

-- File Changes --

    M draft-ietf-tokbind-https-11.xml (4)

-- Patch Links --

https://github.com/TokenBinding/Internet-Drafts/pull/99.patch
https://github.com/TokenBinding/Internet-Drafts/pull/99.diff

-- 
You are receiving this because you are subscribed to this thread.
Reply to this email directly or view it on GitHub:
https://github.com/TokenBinding/Internet-Drafts/pull/99

----==_mimepart_5a0b9ab5225e_acb3f80bf28cf3870833
Content-Type: text/html;
 charset=UTF-8
Content-Transfer-Encoding: 7bit

<p>I figure I don't need to be in the acknowledgements if I'm an author.</p>

<hr>

<h4>You can view, comment on, or merge this pull request online at:</h4>
<p>&nbsp;&nbsp;<a href='https://github.com/TokenBinding/Internet-Drafts/pull/99'>https://github.com/TokenBinding/Internet-Drafts/pull/99</a></p>

<h4>Commit Summary</h4>
<ul>
  <li>Remove Nick Harper from acknowledgements in HTTPSTB</li>
</ul>

<h4>File Changes</h4>
<ul>
  <li>
    <strong>M</strong>
    <a href="https://github.com/TokenBinding/Internet-Drafts/pull/99/files#diff-0">draft-ietf-tokbind-https-11.xml</a>
    (4)
  </li>
</ul>

<h4>Patch Links:</h4>
<ul>
  <li><a href='https://github.com/TokenBinding/Internet-Drafts/pull/99.patch'>https://github.com/TokenBinding/Internet-Drafts/pull/99.patch</a></li>
  <li><a href='https://github.com/TokenBinding/Internet-Drafts/pull/99.diff'>https://github.com/TokenBinding/Internet-Drafts/pull/99.diff</a></li>
</ul>

<p style="font-size:small;-webkit-text-size-adjust:none;color:#666;">&mdash;<br />You are receiving this because you are subscribed to this thread.<br />Reply to this email directly, <a href="https://github.com/TokenBinding/Internet-Drafts/pull/99">view it on GitHub</a>, or <a href="https://github.com/notifications/unsubscribe-auth/ARwnTyJifdqUUvT43ZCmkU5u5tyxsNTVks5s2kC1gaJpZM4QeQ1M">mute the thread</a>.<img alt="" height="1" src="https://github.com/notifications/beacon/ARwnTww0bF4A66jzEo4dVFsgMJwjnS2qks5s2kC1gaJpZM4QeQ1M.gif" width="1" /></p>
<div itemscope itemtype="http://schema.org/EmailMessage">
<div itemprop="action" itemscope itemtype="http://schema.org/ViewAction">
  <link itemprop="url" href="https://github.com/TokenBinding/Internet-Drafts/pull/99"></link>
  <meta itemprop="name" content="View Pull Request"></meta>
</div>
<meta itemprop="description" content="View this Pull Request on GitHub"></meta>
</div>

<script type="application/json" data-scope="inboxmarkup">{"api_version":"1.0","publisher":{"api_key":"05dde50f1d1a384dd78767c55493e4bb","name":"GitHub"},"entity":{"external_key":"github/TokenBinding/Internet-Drafts","title":"TokenBinding/Internet-Drafts","subtitle":"GitHub repository","main_image_url":"https://cloud.githubusercontent.com/assets/143418/17495839/a5054eac-5d88-11e6-95fc-7290892c7bb5.png","avatar_image_url":"https://cloud.githubusercontent.com/assets/143418/15842166/7c72db34-2c0b-11e6-9aed-b52498112777.png","action":{"name":"Open in GitHub","url":"https://github.com/TokenBinding/Internet-Drafts"}},"updates":{"snippets":[{"icon":"DESCRIPTION","message":"Remove Nick Harper from acknowledgements in HTTPSTB (#99)"}],"action":{"name":"View Pull Request","url":"https://github.com/TokenBinding/Internet-Drafts/pull/99"}}}</script>

----==_mimepart_5a0b9ab5225e_acb3f80bf28cf3870833--


From nobody Wed Nov 15 14:30:20 2017
Return-Path: <internet-drafts@ietf.org>
X-Original-To: unbearable@ietf.org
Delivered-To: unbearable@ietfa.amsl.com
Received: from ietfa.amsl.com (localhost [IPv6:::1]) by ietfa.amsl.com (Postfix) with ESMTP id 0C8BB128959; Wed, 15 Nov 2017 14:30:14 -0800 (PST)
MIME-Version: 1.0
Content-Type: text/plain; charset="utf-8"
Content-Transfer-Encoding: 8bit
From: internet-drafts@ietf.org
To: <i-d-announce@ietf.org>
Cc: unbearable@ietf.org
X-Test-IDTracker: no
X-IETF-IDTracker: 6.66.0
Auto-Submitted: auto-generated
Precedence: bulk
Message-ID: <151078501401.28116.971879104787590644@ietfa.amsl.com>
Date: Wed, 15 Nov 2017 14:30:14 -0800
Archived-At: <https://mailarchive.ietf.org/arch/msg/unbearable/V3JJ_ZebU_n8b0aXELHyicxYovI>
Subject: [Unbearable] I-D Action: draft-ietf-tokbind-https-11.txt
X-BeenThere: unbearable@ietf.org
X-Mailman-Version: 2.1.22
List-Id: "\"This list is for discussion of proposals for doing better than bearer tokens \(e.g. HTTP cookies, OAuth tokens etc.\) for web applications. The specific goal is chartering a WG focused on preventing security token export and replay attacks.\"" <unbearable.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/unbearable>, <mailto:unbearable-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/unbearable/>
List-Post: <mailto:unbearable@ietf.org>
List-Help: <mailto:unbearable-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/unbearable>, <mailto:unbearable-request@ietf.org?subject=subscribe>
X-List-Received-Date: Wed, 15 Nov 2017 22:30:14 -0000

A New Internet-Draft is available from the on-line Internet-Drafts directories.
This draft is a work item of the Token Binding WG of the IETF.

        Title           : Token Binding over HTTP
        Authors         : Andrei Popov
                          Magnus Nyström
                          Dirk Balfanz
                          Adam Langley
                          Nick Harper
                          Jeff Hodges
	Filename        : draft-ietf-tokbind-https-11.txt
	Pages           : 23
	Date            : 2017-11-15

Abstract:
   This document describes a collection of mechanisms that allow HTTP
   servers to cryptographically bind security tokens (such as cookies
   and OAuth tokens) to TLS connections.

   We describe both first-party and federated scenarios.  In a first-
   party scenario, an HTTP server is able to cryptographically bind the
   security tokens it issues to a client, and which the client
   subsequently returns to the server, to the TLS connection between the
   client and server.  Such bound security tokens are protected from
   misuse since the server can generally detect if they are replayed
   inappropriately, e.g., over other TLS connections.

   Federated token bindings, on the other hand, allow servers to
   cryptographically bind security tokens to a TLS connection that the
   client has with a different server than the one issuing the token.

   This Internet-Draft is a companion document to The Token Binding
   Protocol.


The IETF datatracker status page for this draft is:
https://datatracker.ietf.org/doc/draft-ietf-tokbind-https/

There are also htmlized versions available at:
https://tools.ietf.org/html/draft-ietf-tokbind-https-11
https://datatracker.ietf.org/doc/html/draft-ietf-tokbind-https-11

A diff from the previous version is available at:
https://www.ietf.org/rfcdiff?url2=draft-ietf-tokbind-https-11


Please note that it may take a couple of minutes from the time of submission
until the htmlized version and diff are available at tools.ietf.org.

Internet-Drafts are also available by anonymous FTP at:
ftp://ftp.ietf.org/internet-drafts/


From nobody Wed Nov 15 18:40:45 2017
Return-Path: <Jeff.Hodges@kingsmountain.com>
X-Original-To: unbearable@ietfa.amsl.com
Delivered-To: unbearable@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 33263126DFB for <unbearable@ietfa.amsl.com>; Wed, 15 Nov 2017 18:40:44 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.921
X-Spam-Level: 
X-Spam-Status: No, score=-1.921 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, RCVD_IN_DNSWL_NONE=-0.0001, RCVD_IN_MSPIKE_H3=-0.01, RCVD_IN_MSPIKE_WL=-0.01, SPF_PASS=-0.001] autolearn=ham autolearn_force=no
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id PvMeQGPU0GK6 for <unbearable@ietfa.amsl.com>; Wed, 15 Nov 2017 18:40:42 -0800 (PST)
Received: from qproxy5-pub.mail.unifiedlayer.com (qproxy5-pub.mail.unifiedlayer.com [69.89.21.30]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 120CB120227 for <unbearable@ietf.org>; Wed, 15 Nov 2017 18:40:42 -0800 (PST)
Received: from cmgw2 (unknown [10.0.90.83]) by qproxy5.mail.unifiedlayer.com (Postfix) with ESMTP id A608A6AE27 for <unbearable@ietf.org>; Wed, 15 Nov 2017 19:40:41 -0700 (MST)
Received: from box514.bluehost.com ([74.220.219.114]) by cmgw2 with  id aSgd1w00W2UhLwi01Sggky; Wed, 15 Nov 2017 19:40:41 -0700
X-Authority-Analysis: v=2.2 cv=dZfw5Tfe c=1 sm=1 tr=0 a=9W6Fsu4pMcyimqnCr1W0/w==:117 a=9W6Fsu4pMcyimqnCr1W0/w==:17 a=IkcTkHD0fZMA:10 a=sC3jslCIGhcA:10 a=48vgC7mUAAAA:8 a=5IsXbjgYAAAA:8 a=yMhMjlubAAAA:8 a=1XWaLZrsAAAA:8 a=qI-sqkvjAAAA:8 a=N_DkT1jQxOtiqeY3FuwA:9 a=QEXdDO2ut3YA:10 a=vhBUhgpoTRMA:10 a=tGV61vUrzvQA:10 a=2HW1KCYWM_4A:10 a=_6cCrZ3FNcsA:10 a=w1C3t2QeGrPiZgrLijVG:22 a=RR2nPHISKLg-FD_FhCoU:22
Received: from dhcp-8b7b.meeting.ietf.org ([31.133.139.123]:56975) by box514.bluehost.com with esmtpsa (TLSv1.2:ECDHE-RSA-AES128-GCM-SHA256:128) (Exim 4.87) (envelope-from <Jeff.Hodges@KingsMountain.com>) id 1eFA6X-000yhW-CT for unbearable@ietf.org; Wed, 15 Nov 2017 19:40:37 -0700
To: IETF TokBind WG <unbearable@ietf.org>
From: =JeffH <Jeff.Hodges@KingsMountain.com>
Message-ID: <f273a44d-b8a5-8a2f-a5d4-0a5da9abfe91@KingsMountain.com>
Date: Thu, 16 Nov 2017 10:40:31 +0800
User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10.12; rv:52.0) Gecko/20100101 Thunderbird/52.4.0
MIME-Version: 1.0
Content-Type: text/plain; charset=utf-8; format=flowed
Content-Language: en-US
Content-Transfer-Encoding: 8bit
X-AntiAbuse: This header was added to track abuse, please include it with any abuse report
X-AntiAbuse: Primary Hostname - box514.bluehost.com
X-AntiAbuse: Original Domain - ietf.org
X-AntiAbuse: Originator/Caller UID/GID - [47 12] / [47 12]
X-AntiAbuse: Sender Address Domain - KingsMountain.com
X-BWhitelist: no
X-Source-IP: 31.133.139.123
X-Exim-ID: 1eFA6X-000yhW-CT
X-Source: 
X-Source-Args: 
X-Source-Dir: 
X-Source-Sender: dhcp-8b7b.meeting.ietf.org [31.133.139.123]:56975
X-Source-Auth: jeff.hodges+kingsmountain.com
X-Email-Count: 1
X-Source-Cap: a2luZ3Ntb3U7a2luZ3Ntb3U7Ym94NTE0LmJsdWVob3N0LmNvbQ==
X-Local-Domain: no
Archived-At: <https://mailarchive.ietf.org/arch/msg/unbearable/UDxyNQwEdUGw0-aQTPaKiYH3hQM>
Subject: [Unbearable] FWD: Status of draft-ietf-tokbind-https
X-BeenThere: unbearable@ietf.org
X-Mailman-Version: 2.1.22
Precedence: list
List-Id: "\"This list is for discussion of proposals for doing better than bearer tokens \(e.g. HTTP cookies, OAuth tokens etc.\) for web applications. The specific goal is chartering a WG focused on preventing security token export and replay attacks.\"" <unbearable.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/unbearable>, <mailto:unbearable-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/unbearable/>
List-Post: <mailto:unbearable@ietf.org>
List-Help: <mailto:unbearable-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/unbearable>, <mailto:unbearable-request@ietf.org?subject=subscribe>
X-List-Received-Date: Thu, 16 Nov 2017 02:40:44 -0000

[ I'm posting to the list a thread EKR had earlier this week with 
draft-ietf-tokbind-https editors.  this thread is the reason for the 
recent PR:
[TokenBinding/Internet-Drafts] 633587: Adding fed sign-on considerations 
to Security Cons...,
<https://www.ietf.org/mail-archive/web/unbearable/current/msg01507.html>

..and the publishing of -tokbind-https-11:

<https://www.ietf.org/mail-archive/web/unbearable/current/msg01509.html>

Am fwd'g this, and reply(s), w/EKR's and editors' permission...

]


From: Eric Rescorla <ekr@rtfm.com>
Date: Monday, November 13, 2017 at 9:00 PM
To: "draft-ietf-tokbind-https@tools.ietf.org" 
<draft-ietf-tokbind-https@tools.ietf.org>, "tokbind-chairs@ietf.org" 
<tokbind-chairs@ietf.org>
Subject: Status of draft-ietf-tokbind-https
Resent-From: <alias-bounces@ietf.org>, Eric Rescorla <ekr@rtfm.com>
Resent-To: <andreipo@microsoft.com>, <mnystrom@microsoft.com>, Dirk 
Balfanz <balfanz@google.com>, Adam Langley <agl@google.com>, 
<nharper@google.com>, Jeff Hodges <Jeff.Hodges@PayPal.com>, 
<draft-ietf-tokbind-https@ietf.org>
Resent-Date: Monday, November 13, 2017 at 9:00 PM

Hi folks,

I have made a first pass through this document and while I have some
comments it appears generally sound. My one concern is the complexity
of the federated version. It's complicated enough that it's not obviously
secure and I don't know how much analysis there has been of it.


One thing I noticed that is a bit concerning is a potential way for an
attacker to get a confused token. As I understand it, the objective of
the flow is for the client to get a token which he can provide to the
Token Consumer that has in it the TBID for the key which he will use
to do a provided token binding to the Token Consumer. However, the
Token Provider's notion of who the TC is (the audience) usually comes
from some kind of redirect argument.

Specifically, consider the case where Alice is for some reason trying
to authenticate to the attacker, you can then get the following flow:


Alice                        Attacker                  Token Provider

Request ------------------------>

<-------------  Redirect to TP w/
Include-Referred-Token-Binding-ID:true
Audience identity = Victim

GET ---------------------------------------------------------->
EBTMS([K_tp, provided_binding],
       [K_attacker, referred_binding])
Audience identity = Victim

<-------------------------------------------------------- Token


So at this point, the Provider issues a token he thinks is for
the Victim but actually has the TBID for the attacker. I don't
see how to make this an attack, but it seems like it has the TP
being confused and (if the token has an audience value in it)
a token which is confused too, which doesn't seem ideal. Am I
wrong about this?


Anyway, my question really is: how can we make sure we have reasonable
confidence that this piece of token binding is secure? How much
analysis has there been? is there anything I can read? Or do we
just have whatever is in the draft?

Happy to sync up before the session tomorrow if that's useful

Thanks,
-Ekr


From nobody Wed Nov 15 18:42:21 2017
Return-Path: <Jeff.Hodges@kingsmountain.com>
X-Original-To: unbearable@ietfa.amsl.com
Delivered-To: unbearable@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 2830E126DFB for <unbearable@ietfa.amsl.com>; Wed, 15 Nov 2017 18:42:20 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.921
X-Spam-Level: 
X-Spam-Status: No, score=-1.921 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, RCVD_IN_DNSWL_NONE=-0.0001, RCVD_IN_MSPIKE_H3=-0.01, RCVD_IN_MSPIKE_WL=-0.01, SPF_PASS=-0.001] autolearn=ham autolearn_force=no
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id NNkzs33KDXuH for <unbearable@ietfa.amsl.com>; Wed, 15 Nov 2017 18:42:18 -0800 (PST)
Received: from qproxy5-pub.mail.unifiedlayer.com (qproxy5-pub.mail.unifiedlayer.com [69.89.21.30]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id A88F3126CC4 for <unbearable@ietf.org>; Wed, 15 Nov 2017 18:42:18 -0800 (PST)
Received: from cmgw4 (unknown [10.0.90.85]) by qproxy5.mail.unifiedlayer.com (Postfix) with ESMTP id 5F7FE6AD66 for <unbearable@ietf.org>; Wed, 15 Nov 2017 19:42:18 -0700 (MST)
Received: from box514.bluehost.com ([74.220.219.114]) by cmgw4 with  id aSiE1w00A2UhLwi01SiHg7; Wed, 15 Nov 2017 19:42:18 -0700
X-Authority-Analysis: v=2.2 cv=JNNLi4Cb c=1 sm=1 tr=0 a=9W6Fsu4pMcyimqnCr1W0/w==:117 a=9W6Fsu4pMcyimqnCr1W0/w==:17 a=IkcTkHD0fZMA:10 a=sC3jslCIGhcA:10 a=5IsXbjgYAAAA:8 a=48vgC7mUAAAA:8 a=yMhMjlubAAAA:8 a=1XWaLZrsAAAA:8 a=qI-sqkvjAAAA:8 a=jHZcg3eliQUGabWl4-EA:9 a=u5y99PvpAtivChGq:21 a=bfOvsgzaF8XuCIBY:21 a=QEXdDO2ut3YA:10 a=RR2nPHISKLg-FD_FhCoU:22 a=w1C3t2QeGrPiZgrLijVG:22
Received: from dhcp-8b7b.meeting.ietf.org ([31.133.139.123]:56992) by box514.bluehost.com with esmtpsa (TLSv1.2:ECDHE-RSA-AES128-GCM-SHA256:128) (Exim 4.87) (envelope-from <Jeff.Hodges@KingsMountain.com>) id 1eFA85-000zlw-Ue for unbearable@ietf.org; Wed, 15 Nov 2017 19:42:14 -0700
From: =JeffH <Jeff.Hodges@KingsMountain.com>
To: IETF TokBind WG <unbearable@ietf.org>
Message-ID: <36e949a4-b4cf-2848-0474-f163e8d7b861@KingsMountain.com>
Date: Thu, 16 Nov 2017 10:42:10 +0800
User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10.12; rv:52.0) Gecko/20100101 Thunderbird/52.4.0
MIME-Version: 1.0
Content-Type: text/plain; charset=utf-8; format=flowed
Content-Language: en-US
Content-Transfer-Encoding: 7bit
X-AntiAbuse: This header was added to track abuse, please include it with any abuse report
X-AntiAbuse: Primary Hostname - box514.bluehost.com
X-AntiAbuse: Original Domain - ietf.org
X-AntiAbuse: Originator/Caller UID/GID - [47 12] / [47 12]
X-AntiAbuse: Sender Address Domain - KingsMountain.com
X-BWhitelist: no
X-Source-IP: 31.133.139.123
X-Exim-ID: 1eFA85-000zlw-Ue
X-Source: 
X-Source-Args: 
X-Source-Dir: 
X-Source-Sender: dhcp-8b7b.meeting.ietf.org [31.133.139.123]:56992
X-Source-Auth: jeff.hodges+kingsmountain.com
X-Email-Count: 2
X-Source-Cap: a2luZ3Ntb3U7a2luZ3Ntb3U7Ym94NTE0LmJsdWVob3N0LmNvbQ==
X-Local-Domain: no
Archived-At: <https://mailarchive.ietf.org/arch/msg/unbearable/SuymQ0UekxcrA1FpGMiFEn-ndCU>
Subject: Re: [Unbearable] FWD: Status of draft-ietf-tokbind-https
X-BeenThere: unbearable@ietf.org
X-Mailman-Version: 2.1.22
Precedence: list
List-Id: "\"This list is for discussion of proposals for doing better than bearer tokens \(e.g. HTTP cookies, OAuth tokens etc.\) for web applications. The specific goal is chartering a WG focused on preventing security token export and replay attacks.\"" <unbearable.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/unbearable>, <mailto:unbearable-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/unbearable/>
List-Post: <mailto:unbearable@ietf.org>
List-Help: <mailto:unbearable-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/unbearable>, <mailto:unbearable-request@ietf.org?subject=subscribe>
X-List-Received-Date: Thu, 16 Nov 2017 02:42:20 -0000

From: Leif Johansson <leifj@sunet.se>
Date: Monday, November 13, 2017 at 9:10 PM
To: Eric Rescorla <ekr@rtfm.com>, 
"draft-ietf-tokbind-https@tools.ietf.org" 
<draft-ietf-tokbind-https@tools.ietf.org>, "tokbind-chairs@ietf.org" 
<tokbind-chairs@ietf.org>
Subject: Re: Status of draft-ietf-tokbind-https
Resent-From: <alias-bounces@ietf.org>, Leif Johansson <leifj@sunet.se>
Resent-To: <andreipo@microsoft.com>, <mnystrom@microsoft.com>, Dirk 
Balfanz <balfanz@google.com>, Adam Langley <agl@google.com>, 
<nharper@google.com>, Jeff Hodges <Jeff.Hodges@PayPal.com>, 
<draft-ietf-tokbind-https@ietf.org>
Resent-Date: Monday, November 13, 2017 at 9:10 PM

 > On 2017-11-13 14:00, Eric Rescorla wrote:
 > Hi folks,
 > I have made a first pass through this document and while I have some
 > comments it appears generally sound. My one concern is the complexity
 > of the federated version. It's complicated enough that it's not obviously
 > secure and I don't know how much analysis there has been of it.



Have we gotten a secdir review yet? I confess I haven't seen one yet but
I may have missed something...

 > One thing I noticed that is a bit concerning is a potential way for an
 > attacker to get a confused token. As I understand it, the objective of
 > the flow is for the client to get a token which he can provide to the
 > Token Consumer that has in it the TBID for the key which he will use
 > to do a provided token binding to the Token Consumer. However, the
 > Token Provider's notion of who the TC is (the audience) usually comes
 > from some kind of redirect argument.
 > Specifically, consider the case where Alice is for some reason trying
 > to authenticate to the attacker, you can then get the following flow:
 > Alice                        Attacker                  Token Provider
 > Request ------------------------>
 > <-------------  Redirect to TP w/
 > Include-Referred-Token-Binding-ID:true
 > Audience identity = Victim
 > GET ---------------------------------------------------------->
 > EBTMS([K_tp, provided_binding],
 >       [K_attacker, referred_binding])
 > Audience identity = Victim
 > <-------------------------------------------------------- Token
 > So at this point, the Provider issues a token he thinks is for
 > the Victim but actually has the TBID for the attacker. I don't
 > see how to make this an attack, but it seems like it has the TP
 > being confused and (if the token has an audience value in it)
 > a token which is confused too, which doesn't seem ideal. Am I
 > wrong about this?
 > Anyway, my question really is: how can we make sure we have reasonable
 > confidence that this piece of token binding is secure? How much
 > analysis has there been? is there anything I can read? Or do we
 > just have whatever is in the draft?
 > Happy to sync up before the session tomorrow if that's useful
 > Thanks,
 > -Ekr

I don't have anything pressing in the morning. Happy to meet up
to talk about this. JB, Nick and Brian is here but I haven't
seen any of the key folks behind the core protocol yet.

	Cheers Leif



From nobody Wed Nov 15 18:50:32 2017
Return-Path: <Jeff.Hodges@kingsmountain.com>
X-Original-To: unbearable@ietfa.amsl.com
Delivered-To: unbearable@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 1A8F312943B for <unbearable@ietfa.amsl.com>; Wed, 15 Nov 2017 18:50:28 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -4.701
X-Spam-Level: 
X-Spam-Status: No, score=-4.701 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, RCVD_IN_DNSWL_NONE=-0.0001, RCVD_IN_MSPIKE_H2=-2.8, SPF_PASS=-0.001] autolearn=ham autolearn_force=no
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id BnB-lNWOpCkw for <unbearable@ietfa.amsl.com>; Wed, 15 Nov 2017 18:50:24 -0800 (PST)
Received: from qproxy2.mail.unifiedlayer.com (qproxy2-pub.mail.unifiedlayer.com [69.89.16.161]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id AE106129407 for <unbearable@ietf.org>; Wed, 15 Nov 2017 18:50:24 -0800 (PST)
Received: from cmgw2 (unknown [10.0.90.83]) by qproxy2.mail.unifiedlayer.com (Postfix) with ESMTP id 5F9F635953 for <unbearable@ietf.org>; Wed, 15 Nov 2017 19:50:24 -0700 (MST)
Received: from box514.bluehost.com ([74.220.219.114]) by cmgw2 with  id aSqM1w0072UhLwi01SqQgv; Wed, 15 Nov 2017 19:50:24 -0700
X-Authority-Analysis: v=2.2 cv=dZfw5Tfe c=1 sm=1 tr=0 a=9W6Fsu4pMcyimqnCr1W0/w==:117 a=9W6Fsu4pMcyimqnCr1W0/w==:17 a=IkcTkHD0fZMA:10 a=sC3jslCIGhcA:10 a=5IsXbjgYAAAA:8 a=48vgC7mUAAAA:8 a=yMhMjlubAAAA:8 a=1XWaLZrsAAAA:8 a=qI-sqkvjAAAA:8 a=N-NeutNGwVsVvx_QPwEA:9 a=jBLKuy5OahpGKs3f:21 a=uY1B84mOzwPW9m-F:21 a=QEXdDO2ut3YA:10 a=RR2nPHISKLg-FD_FhCoU:22 a=w1C3t2QeGrPiZgrLijVG:22
Received: from dhcp-8b7b.meeting.ietf.org ([31.133.139.123]:57195) by box514.bluehost.com with esmtpsa (TLSv1.2:ECDHE-RSA-AES128-GCM-SHA256:128) (Exim 4.87) (envelope-from <Jeff.Hodges@KingsMountain.com>) id 1eFAFx-0013Oc-1i for unbearable@ietf.org; Wed, 15 Nov 2017 19:50:21 -0700
To: IETF TokBind WG <unbearable@ietf.org>
From: =JeffH <Jeff.Hodges@KingsMountain.com>
Message-ID: <8c824f3f-2eee-3209-1325-06b4fc65602f@KingsMountain.com>
Date: Thu, 16 Nov 2017 10:50:15 +0800
User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10.12; rv:52.0) Gecko/20100101 Thunderbird/52.4.0
MIME-Version: 1.0
Content-Type: text/plain; charset=utf-8; format=flowed
Content-Language: en-US
Content-Transfer-Encoding: 7bit
X-AntiAbuse: This header was added to track abuse, please include it with any abuse report
X-AntiAbuse: Primary Hostname - box514.bluehost.com
X-AntiAbuse: Original Domain - ietf.org
X-AntiAbuse: Originator/Caller UID/GID - [47 12] / [47 12]
X-AntiAbuse: Sender Address Domain - KingsMountain.com
X-BWhitelist: no
X-Source-IP: 31.133.139.123
X-Exim-ID: 1eFAFx-0013Oc-1i
X-Source: 
X-Source-Args: 
X-Source-Dir: 
X-Source-Sender: dhcp-8b7b.meeting.ietf.org [31.133.139.123]:57195
X-Source-Auth: jeff.hodges+kingsmountain.com
X-Email-Count: 3
X-Source-Cap: a2luZ3Ntb3U7a2luZ3Ntb3U7Ym94NTE0LmJsdWVob3N0LmNvbQ==
X-Local-Domain: no
Archived-At: <https://mailarchive.ietf.org/arch/msg/unbearable/hvKpvpnZHoW0A6dbtzfeVoW0ilA>
Subject: Re: [Unbearable] FWD: Status of draft-ietf-tokbind-https
X-BeenThere: unbearable@ietf.org
X-Mailman-Version: 2.1.22
Precedence: list
List-Id: "\"This list is for discussion of proposals for doing better than bearer tokens \(e.g. HTTP cookies, OAuth tokens etc.\) for web applications. The specific goal is chartering a WG focused on preventing security token export and replay attacks.\"" <unbearable.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/unbearable>, <mailto:unbearable-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/unbearable/>
List-Post: <mailto:unbearable@ietf.org>
List-Help: <mailto:unbearable-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/unbearable>, <mailto:unbearable-request@ietf.org?subject=subscribe>
X-List-Received-Date: Thu, 16 Nov 2017 02:50:28 -0000

From: Eric Rescorla <ekr@rtfm.com>
Date: Monday, November 13, 2017 at 9:12 PM
To: Leif Johansson <leifj@sunet.se>
Cc: "draft-ietf-tokbind-https@tools.ietf.org" 
<draft-ietf-tokbind-https@tools.ietf.org>, "tokbind-chairs@ietf.org" 
<tokbind-chairs@ietf.org>
Subject: Re: Status of draft-ietf-tokbind-https
Resent-From: <alias-bounces@ietf.org>, Eric Rescorla <ekr@rtfm.com>
Resent-To: <andreipo@microsoft.com>, <mnystrom@microsoft.com>, Dirk 
Balfanz <balfanz@google.com>, Adam Langley <agl@google.com>, 
<nharper@google.com>, Jeff Hodges <Jeff.Hodges@PayPal.com>, 
<draft-ietf-tokbind-https@ietf.org>
Resent-Date: Monday, November 13, 2017 at 9:13 PM


 > On Mon, Nov 13, 2017 at 9:10 PM, Leif Johansson <leifj@sunet.se> wrote:
 > On 2017-11-13 14:00, Eric Rescorla wrote:
 >> Hi folks,
 >>
 >> I have made a first pass through this document and while I have some
 >> comments it appears generally sound. My one concern is the complexity
 >> of the federated version. It's complicated enough that it's not 
obviously
 >> secure and I don't know how much analysis there has been of it.
 >
 > Have we gotten a secdir review yet? I confess I haven't seen one yet but
 > I may have missed something...

No, I don't think so, but generally I wouldn't expect that thorough a 
review from that, at least not at the level of real protocol analysis.

-Ekr



From nobody Wed Nov 15 18:52:18 2017
Return-Path: <Jeff.Hodges@kingsmountain.com>
X-Original-To: unbearable@ietfa.amsl.com
Delivered-To: unbearable@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id BBA3512940E for <unbearable@ietfa.amsl.com>; Wed, 15 Nov 2017 18:52:13 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -4.701
X-Spam-Level: 
X-Spam-Status: No, score=-4.701 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, RCVD_IN_DNSWL_NONE=-0.0001, RCVD_IN_MSPIKE_H2=-2.8, SPF_PASS=-0.001] autolearn=ham autolearn_force=no
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id PTkxbxp16Qd1 for <unbearable@ietfa.amsl.com>; Wed, 15 Nov 2017 18:52:12 -0800 (PST)
Received: from qproxy1-pub.mail.unifiedlayer.com (qproxy1-pub.mail.unifiedlayer.com [173.254.64.10]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id F2F33128954 for <unbearable@ietf.org>; Wed, 15 Nov 2017 18:52:11 -0800 (PST)
Received: from CMOut01 (unknown [10.0.90.82]) by qproxy1.mail.unifiedlayer.com (Postfix) with ESMTP id 3A48D120475 for <unbearable@ietf.org>; Wed, 15 Nov 2017 19:51:27 -0700 (MST)
Received: from box514.bluehost.com ([74.220.219.114]) by CMOut01 with  id aSrQ1w0042UhLwi01SrTF8; Wed, 15 Nov 2017 19:51:27 -0700
X-Authority-Analysis: v=2.2 cv=K4VSJ2eI c=1 sm=1 tr=0 a=9W6Fsu4pMcyimqnCr1W0/w==:117 a=9W6Fsu4pMcyimqnCr1W0/w==:17 a=IkcTkHD0fZMA:10 a=sC3jslCIGhcA:10 a=yMhMjlubAAAA:8 a=5IsXbjgYAAAA:8 a=1XWaLZrsAAAA:8 a=48vgC7mUAAAA:8 a=qI-sqkvjAAAA:8 a=so3EvALKwebfFulFyOwA:9 a=QEXdDO2ut3YA:10 a=RR2nPHISKLg-FD_FhCoU:22 a=w1C3t2QeGrPiZgrLijVG:22
Received: from dhcp-8b7b.meeting.ietf.org ([31.133.139.123]:57208) by box514.bluehost.com with esmtpsa (TLSv1.2:ECDHE-RSA-AES128-GCM-SHA256:128) (Exim 4.87) (envelope-from <Jeff.Hodges@KingsMountain.com>) id 1eFAGx-0013tb-R9 for unbearable@ietf.org; Wed, 15 Nov 2017 19:51:24 -0700
To: IETF TokBind WG <unbearable@ietf.org>
From: =JeffH <Jeff.Hodges@KingsMountain.com>
Message-ID: <15f89604-8327-b43e-e788-00d18180b234@KingsMountain.com>
Date: Thu, 16 Nov 2017 10:51:21 +0800
User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10.12; rv:52.0) Gecko/20100101 Thunderbird/52.4.0
MIME-Version: 1.0
Content-Type: text/plain; charset=utf-8; format=flowed
Content-Language: en-US
Content-Transfer-Encoding: 8bit
X-AntiAbuse: This header was added to track abuse, please include it with any abuse report
X-AntiAbuse: Primary Hostname - box514.bluehost.com
X-AntiAbuse: Original Domain - ietf.org
X-AntiAbuse: Originator/Caller UID/GID - [47 12] / [47 12]
X-AntiAbuse: Sender Address Domain - KingsMountain.com
X-BWhitelist: no
X-Source-IP: 31.133.139.123
X-Exim-ID: 1eFAGx-0013tb-R9
X-Source: 
X-Source-Args: 
X-Source-Dir: 
X-Source-Sender: dhcp-8b7b.meeting.ietf.org [31.133.139.123]:57208
X-Source-Auth: jeff.hodges+kingsmountain.com
X-Email-Count: 4
X-Source-Cap: a2luZ3Ntb3U7a2luZ3Ntb3U7Ym94NTE0LmJsdWVob3N0LmNvbQ==
X-Local-Domain: no
Archived-At: <https://mailarchive.ietf.org/arch/msg/unbearable/XMuAumDhLOn2w2_0JF_IBPYuPyc>
Subject: Re: [Unbearable] FWD: Status of draft-ietf-tokbind-https
X-BeenThere: unbearable@ietf.org
X-Mailman-Version: 2.1.22
Precedence: list
List-Id: "\"This list is for discussion of proposals for doing better than bearer tokens \(e.g. HTTP cookies, OAuth tokens etc.\) for web applications. The specific goal is chartering a WG focused on preventing security token export and replay attacks.\"" <unbearable.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/unbearable>, <mailto:unbearable-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/unbearable/>
List-Post: <mailto:unbearable@ietf.org>
List-Help: <mailto:unbearable-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/unbearable>, <mailto:unbearable-request@ietf.org?subject=subscribe>
X-List-Received-Date: Thu, 16 Nov 2017 02:52:14 -0000

From: Andrei Popov <Andrei.Popov@microsoft.com>
Date: Monday, November 13, 2017 at 10:50 PM
To: Eric Rescorla <ekr@rtfm.com>, Leif Johansson <leifj@sunet.se>, Vinod 
Anupam <vanupam@google.com>
Cc: "draft-ietf-tokbind-https@tools.ietf.org" 
<draft-ietf-tokbind-https@tools.ietf.org>, "tokbind-chairs@ietf.org" 
<tokbind-chairs@ietf.org>
Subject: RE: Status of draft-ietf-tokbind-https
Resent-From: <alias-bounces@ietf.org>, Andrei Popov 
<Andrei.Popov@microsoft.com>
Resent-To: <andreipo@microsoft.com>, <mnystrom@microsoft.com>, Dirk 
Balfanz <balfanz@google.com>, Adam Langley <agl@google.com>, 
<nharper@google.com>, Jeff Hodges <Jeff.Hodges@PayPal.com>, 
<draft-ietf-tokbind-https@ietf.org>
Resent-Date: Tuesday, November 14, 2017 at 12:23 AM

I’m available in the morning; unfortunately, Dirk is not here, but 
Anupam can represent him.

Regarding the attack, it is not quite clear to me:
Even assuming the TP is willing to issue a token for Alice to connect to 
the Attacker (which probably means the Attacker is a server known to the 
TP), this token will be bound to the TB key Alice has created for use 
with the attacker.
So the attacker cannot use this token to impersonate Alice to another 
server (without also stealing the corresponding private key).
Or am I missing something?

What time should we meet tomorrow?

Cheers,

Andrei


From nobody Wed Nov 15 18:53:37 2017
Return-Path: <Jeff.Hodges@kingsmountain.com>
X-Original-To: unbearable@ietfa.amsl.com
Delivered-To: unbearable@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id C5026129421 for <unbearable@ietfa.amsl.com>; Wed, 15 Nov 2017 18:53:35 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -4.701
X-Spam-Level: 
X-Spam-Status: No, score=-4.701 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, RCVD_IN_DNSWL_NONE=-0.0001, RCVD_IN_MSPIKE_H2=-2.8, SPF_PASS=-0.001] autolearn=ham autolearn_force=no
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id BPBnFVZoMgKZ for <unbearable@ietfa.amsl.com>; Wed, 15 Nov 2017 18:53:34 -0800 (PST)
Received: from qproxy2.mail.unifiedlayer.com (qproxy2-pub.mail.unifiedlayer.com [69.89.16.161]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 77F74129413 for <unbearable@ietf.org>; Wed, 15 Nov 2017 18:53:34 -0800 (PST)
Received: from cmgw3 (unknown [10.0.90.84]) by qproxy2.mail.unifiedlayer.com (Postfix) with ESMTP id 265DC3572C for <unbearable@ietf.org>; Wed, 15 Nov 2017 19:53:34 -0700 (MST)
Received: from box514.bluehost.com ([74.220.219.114]) by cmgw3 with  id aStW1w00a2UhLwi01StZXa; Wed, 15 Nov 2017 19:53:34 -0700
X-Authority-Analysis: v=2.2 cv=H76r+6Qi c=1 sm=1 tr=0 a=9W6Fsu4pMcyimqnCr1W0/w==:117 a=9W6Fsu4pMcyimqnCr1W0/w==:17 a=IkcTkHD0fZMA:10 a=sC3jslCIGhcA:10 a=5IsXbjgYAAAA:8 a=yMhMjlubAAAA:8 a=1XWaLZrsAAAA:8 a=48vgC7mUAAAA:8 a=qI-sqkvjAAAA:8 a=vCMV7FptvruRoYsDdpYA:9 a=QEXdDO2ut3YA:10 a=RR2nPHISKLg-FD_FhCoU:22 a=w1C3t2QeGrPiZgrLijVG:22
Received: from dhcp-8b7b.meeting.ietf.org ([31.133.139.123]:57257) by box514.bluehost.com with esmtpsa (TLSv1.2:ECDHE-RSA-AES128-GCM-SHA256:128) (Exim 4.87) (envelope-from <Jeff.Hodges@KingsMountain.com>) id 1eFAJ0-0014xb-Ke for unbearable@ietf.org; Wed, 15 Nov 2017 19:53:30 -0700
To: IETF TokBind WG <unbearable@ietf.org>
From: =JeffH <Jeff.Hodges@KingsMountain.com>
Message-ID: <241701af-c2a8-e288-7f9c-297ddc687e91@KingsMountain.com>
Date: Thu, 16 Nov 2017 10:53:26 +0800
User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10.12; rv:52.0) Gecko/20100101 Thunderbird/52.4.0
MIME-Version: 1.0
Content-Type: text/plain; charset=utf-8; format=flowed
Content-Language: en-US
Content-Transfer-Encoding: 8bit
X-AntiAbuse: This header was added to track abuse, please include it with any abuse report
X-AntiAbuse: Primary Hostname - box514.bluehost.com
X-AntiAbuse: Original Domain - ietf.org
X-AntiAbuse: Originator/Caller UID/GID - [47 12] / [47 12]
X-AntiAbuse: Sender Address Domain - KingsMountain.com
X-BWhitelist: no
X-Source-IP: 31.133.139.123
X-Exim-ID: 1eFAJ0-0014xb-Ke
X-Source: 
X-Source-Args: 
X-Source-Dir: 
X-Source-Sender: dhcp-8b7b.meeting.ietf.org [31.133.139.123]:57257
X-Source-Auth: jeff.hodges+kingsmountain.com
X-Email-Count: 5
X-Source-Cap: a2luZ3Ntb3U7a2luZ3Ntb3U7Ym94NTE0LmJsdWVob3N0LmNvbQ==
X-Local-Domain: no
Archived-At: <https://mailarchive.ietf.org/arch/msg/unbearable/kzHfNHVVgzHiGDgd3MF2wTGCcvY>
Subject: Re: [Unbearable] FWD: Status of draft-ietf-tokbind-https
X-BeenThere: unbearable@ietf.org
X-Mailman-Version: 2.1.22
Precedence: list
List-Id: "\"This list is for discussion of proposals for doing better than bearer tokens \(e.g. HTTP cookies, OAuth tokens etc.\) for web applications. The specific goal is chartering a WG focused on preventing security token export and replay attacks.\"" <unbearable.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/unbearable>, <mailto:unbearable-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/unbearable/>
List-Post: <mailto:unbearable@ietf.org>
List-Help: <mailto:unbearable-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/unbearable>, <mailto:unbearable-request@ietf.org?subject=subscribe>
X-List-Received-Date: Thu, 16 Nov 2017 02:53:36 -0000

From: Eric Rescorla <ekr@rtfm.com>
Date: Tuesday, November 14, 2017 at 4:11 AM
To: Andrei Popov <Andrei.Popov@microsoft.com>
Cc: Leif Johansson <leifj@sunet.se>, Vinod Anupam <vanupam@google.com>, 
"draft-ietf-tokbind-https@tools.ietf.org" 
<draft-ietf-tokbind-https@tools.ietf.org>, "tokbind-chairs@ietf.org" 
<tokbind-chairs@ietf.org>
Subject: Re: Status of draft-ietf-tokbind-https
Resent-From: <alias-bounces@ietf.org>, Eric Rescorla <ekr@rtfm.com>
Resent-To: <andreipo@microsoft.com>, <mnystrom@microsoft.com>, Dirk 
Balfanz <balfanz@google.com>, Adam Langley <agl@google.com>, 
<nharper@google.com>, Jeff Hodges <Jeff.Hodges@PayPal.com>, 
<draft-ietf-tokbind-https@ietf.org>
Resent-Date: Tuesday, November 14, 2017 at 4:12 AM


On Mon, Nov 13, 2017 at 2:50 PM, Andrei Popov 
<Andrei.Popov@microsoft.com> wrote:> I’m available in the morning; 
unfortunately, Dirk is not here, b>
 > Anupam can represent him.
 >
 > Regarding the attack, it is not quite clear to me: Even assuming the
 > TP is willing to issue a token for Alice to connect to the Attacker
 > (which probably means the Attacker is a server known to the TP), this
 > token will be bound to the TB key Alice has created for use with the
 > attacker.
 >
 > So the attacker cannot use this token to impersonate Alice to another
 > server (without also stealing the corresponding private key). Or am I
 > missing something?

I don't think so. I agree it's not an attack, it's just creating a 
confused token. I just worry whenever we have a protocol which allows 
this kind of confusion that either (a) we can turn it into an attack or 
(b) there's some other way to create confusion that is an attack.

-Ekr




From nobody Wed Nov 15 18:54:55 2017
Return-Path: <Jeff.Hodges@kingsmountain.com>
X-Original-To: unbearable@ietfa.amsl.com
Delivered-To: unbearable@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id A6350129407 for <unbearable@ietfa.amsl.com>; Wed, 15 Nov 2017 18:54:53 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.921
X-Spam-Level: 
X-Spam-Status: No, score=-1.921 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, RCVD_IN_DNSWL_NONE=-0.0001, RCVD_IN_MSPIKE_H3=-0.01, RCVD_IN_MSPIKE_WL=-0.01, SPF_PASS=-0.001] autolearn=ham autolearn_force=no
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id BHxKOKe2g3Zu for <unbearable@ietfa.amsl.com>; Wed, 15 Nov 2017 18:54:52 -0800 (PST)
Received: from qproxy4-pub.mail.unifiedlayer.com (qproxy4-pub.mail.unifiedlayer.com [66.147.248.250]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 2149D126CC4 for <unbearable@ietf.org>; Wed, 15 Nov 2017 18:54:52 -0800 (PST)
Received: from cmgw3 (unknown [10.0.90.84]) by qproxy4.mail.unifiedlayer.com (Postfix) with ESMTP id C03BDA0267 for <unbearable@ietf.org>; Wed, 15 Nov 2017 19:54:51 -0700 (MST)
Received: from box514.bluehost.com ([74.220.219.114]) by cmgw3 with  id aSuo1w00E2UhLwi01Sur6N; Wed, 15 Nov 2017 19:54:51 -0700
X-Authority-Analysis: v=2.2 cv=H76r+6Qi c=1 sm=1 tr=0 a=9W6Fsu4pMcyimqnCr1W0/w==:117 a=9W6Fsu4pMcyimqnCr1W0/w==:17 a=IkcTkHD0fZMA:10 a=sC3jslCIGhcA:10 a=qI-sqkvjAAAA:8 a=5IsXbjgYAAAA:8 a=48vgC7mUAAAA:8 a=pGLkceISAAAA:8 a=Ae6wU8TBUcR5Byg_2mwA:9 a=QEXdDO2ut3YA:10 a=RR2nPHISKLg-FD_FhCoU:22 a=w1C3t2QeGrPiZgrLijVG:22
Received: from dhcp-8b7b.meeting.ietf.org ([31.133.139.123]:57274) by box514.bluehost.com with esmtpsa (TLSv1.2:ECDHE-RSA-AES128-GCM-SHA256:128) (Exim 4.87) (envelope-from <Jeff.Hodges@KingsMountain.com>) id 1eFAKG-0015Vb-Fh for unbearable@ietf.org; Wed, 15 Nov 2017 19:54:48 -0700
To: IETF TokBind WG <unbearable@ietf.org>
From: =JeffH <Jeff.Hodges@KingsMountain.com>
Message-ID: <386d6154-c7bc-a10c-0ffa-43b1b65bebf6@KingsMountain.com>
Date: Thu, 16 Nov 2017 10:54:45 +0800
User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10.12; rv:52.0) Gecko/20100101 Thunderbird/52.4.0
MIME-Version: 1.0
Content-Type: text/plain; charset=utf-8; format=flowed
Content-Language: en-US
Content-Transfer-Encoding: 8bit
X-AntiAbuse: This header was added to track abuse, please include it with any abuse report
X-AntiAbuse: Primary Hostname - box514.bluehost.com
X-AntiAbuse: Original Domain - ietf.org
X-AntiAbuse: Originator/Caller UID/GID - [47 12] / [47 12]
X-AntiAbuse: Sender Address Domain - KingsMountain.com
X-BWhitelist: no
X-Source-IP: 31.133.139.123
X-Exim-ID: 1eFAKG-0015Vb-Fh
X-Source: 
X-Source-Args: 
X-Source-Dir: 
X-Source-Sender: dhcp-8b7b.meeting.ietf.org [31.133.139.123]:57274
X-Source-Auth: jeff.hodges+kingsmountain.com
X-Email-Count: 6
X-Source-Cap: a2luZ3Ntb3U7a2luZ3Ntb3U7Ym94NTE0LmJsdWVob3N0LmNvbQ==
X-Local-Domain: no
Archived-At: <https://mailarchive.ietf.org/arch/msg/unbearable/zcwN7GyCMwTZZlOppN6y8cjejj4>
Subject: Re: [Unbearable] FWD: Status of draft-ietf-tokbind-https
X-BeenThere: unbearable@ietf.org
X-Mailman-Version: 2.1.22
Precedence: list
List-Id: "\"This list is for discussion of proposals for doing better than bearer tokens \(e.g. HTTP cookies, OAuth tokens etc.\) for web applications. The specific goal is chartering a WG focused on preventing security token export and replay attacks.\"" <unbearable.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/unbearable>, <mailto:unbearable-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/unbearable/>
List-Post: <mailto:unbearable@ietf.org>
List-Help: <mailto:unbearable-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/unbearable>, <mailto:unbearable-request@ietf.org?subject=subscribe>
X-List-Received-Date: Thu, 16 Nov 2017 02:54:53 -0000

From: Jeff Hodges <jeff.hodges@paypal.com>
Date: Tuesday, November 14, 2017 at 1:26 PM
To: Eric Rescorla <ekr@rtfm.com>, 
"draft-ietf-tokbind-https@tools.ietf.org" 
<draft-ietf-tokbind-https@tools.ietf.org>, "tokbind-chairs@ietf.org" 
<tokbind-chairs@ietf.org>
Cc: "Jeff Hodges (phone & @kingsmountain)" <netwerkeddude@gmail.com>
Subject: Re: Status of draft-ietf-tokbind-https

thanks for the question EKR. I did not see this until during the first 
session this morning.

did you folks discuss and are there notes?

In any case seems to me that the below should have gone to unbearable@ 
such that everyone can consider it. probably ought to be sent there with 
any conclusions y'all reached in any case.

I also do not see an attack here, but agree that the attacker would 
ostensibly end up with a security token ("token" in EKR's diagram below) 
having an audience not matching the TBID included in the sec token. 
However, the audience is a notion of the federation protocol, not of 
token binding. So actually obtaining a sec token with an incorrect 
audience depends upon characteristics of the fed protocol and its 
implementation.  I suppose one could argue that we ought to add to 
draft-ietf-tokbind-https' sec cons an explicit admonition that one's fed 
protocol implementation really needs to be correct, otherwise one might 
issue such "confused tokens".  We do have fairly detailed sec analysis 
in sections 7.3 and 7.4, the latter of which is wrt fed protocols. I 
/think/ this issue is at least implicitly addressed in there, but do not 
have fine-tooth-comb time right now. something to perhaps do, tho.
	
thanks,

=JeffH



From nobody Wed Nov 15 19:01:49 2017
Return-Path: <Jeff.Hodges@kingsmountain.com>
X-Original-To: unbearable@ietfa.amsl.com
Delivered-To: unbearable@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 43C42126CC4 for <unbearable@ietfa.amsl.com>; Wed, 15 Nov 2017 19:01:47 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -4.701
X-Spam-Level: 
X-Spam-Status: No, score=-4.701 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, RCVD_IN_DNSWL_NONE=-0.0001, RCVD_IN_MSPIKE_H2=-2.8, SPF_PASS=-0.001] autolearn=ham autolearn_force=no
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id s0kVOHcJInTv for <unbearable@ietfa.amsl.com>; Wed, 15 Nov 2017 19:01:45 -0800 (PST)
Received: from qproxy1-pub.mail.unifiedlayer.com (qproxy1-pub.mail.unifiedlayer.com [173.254.64.10]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 4CFB2124BE8 for <unbearable@ietf.org>; Wed, 15 Nov 2017 19:01:45 -0800 (PST)
Received: from CMOut01 (unknown [10.0.90.82]) by qproxy1.mail.unifiedlayer.com (Postfix) with ESMTP id 329021201E0 for <unbearable@ietf.org>; Wed, 15 Nov 2017 20:01:44 -0700 (MST)
Received: from box514.bluehost.com ([74.220.219.114]) by CMOut01 with  id aT1h1w0082UhLwi01T1kYU; Wed, 15 Nov 2017 20:01:44 -0700
X-Authority-Analysis: v=2.2 cv=K4VSJ2eI c=1 sm=1 tr=0 a=9W6Fsu4pMcyimqnCr1W0/w==:117 a=9W6Fsu4pMcyimqnCr1W0/w==:17 a=IkcTkHD0fZMA:10 a=sC3jslCIGhcA:10 a=5IsXbjgYAAAA:8 a=yMhMjlubAAAA:8 a=1XWaLZrsAAAA:8 a=48vgC7mUAAAA:8 a=qI-sqkvjAAAA:8 a=1nf8GrLKyDivVUu9rZgA:9 a=QEXdDO2ut3YA:10 a=RR2nPHISKLg-FD_FhCoU:22 a=w1C3t2QeGrPiZgrLijVG:22
Received: from dhcp-8b7b.meeting.ietf.org ([31.133.139.123]:57357) by box514.bluehost.com with esmtpsa (TLSv1.2:ECDHE-RSA-AES128-GCM-SHA256:128) (Exim 4.87) (envelope-from <Jeff.Hodges@KingsMountain.com>) id 1eFAQu-0018Z4-TL for unbearable@ietf.org; Wed, 15 Nov 2017 20:01:41 -0700
To: IETF TokBind WG <unbearable@ietf.org>
From: =JeffH <Jeff.Hodges@KingsMountain.com>
Message-ID: <85f012f0-0b38-971f-c2ae-7d6b0d486c5f@KingsMountain.com>
Date: Thu, 16 Nov 2017 11:01:36 +0800
User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10.12; rv:52.0) Gecko/20100101 Thunderbird/52.4.0
MIME-Version: 1.0
Content-Type: text/plain; charset=utf-8; format=flowed
Content-Language: en-US
Content-Transfer-Encoding: 8bit
X-AntiAbuse: This header was added to track abuse, please include it with any abuse report
X-AntiAbuse: Primary Hostname - box514.bluehost.com
X-AntiAbuse: Original Domain - ietf.org
X-AntiAbuse: Originator/Caller UID/GID - [47 12] / [47 12]
X-AntiAbuse: Sender Address Domain - KingsMountain.com
X-BWhitelist: no
X-Source-IP: 31.133.139.123
X-Exim-ID: 1eFAQu-0018Z4-TL
X-Source: 
X-Source-Args: 
X-Source-Dir: 
X-Source-Sender: dhcp-8b7b.meeting.ietf.org [31.133.139.123]:57357
X-Source-Auth: jeff.hodges+kingsmountain.com
X-Email-Count: 1
X-Source-Cap: a2luZ3Ntb3U7a2luZ3Ntb3U7Ym94NTE0LmJsdWVob3N0LmNvbQ==
X-Local-Domain: no
Archived-At: <https://mailarchive.ietf.org/arch/msg/unbearable/RLWdsP3EgcYFrDtoOQM0vHpDwV4>
Subject: Re: [Unbearable] FWD: Status of draft-ietf-tokbind-https
X-BeenThere: unbearable@ietf.org
X-Mailman-Version: 2.1.22
Precedence: list
List-Id: "\"This list is for discussion of proposals for doing better than bearer tokens \(e.g. HTTP cookies, OAuth tokens etc.\) for web applications. The specific goal is chartering a WG focused on preventing security token export and replay attacks.\"" <unbearable.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/unbearable>, <mailto:unbearable-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/unbearable/>
List-Post: <mailto:unbearable@ietf.org>
List-Help: <mailto:unbearable-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/unbearable>, <mailto:unbearable-request@ietf.org?subject=subscribe>
X-List-Received-Date: Thu, 16 Nov 2017 03:01:47 -0000

From: Eric Rescorla <ekr@rtfm.com>
Date: Thursday, November 16, 2017 at 8:07 AM
To: Andrei Popov <Andrei.Popov@microsoft.com>
Cc: Leif Johansson <leifj@sunet.se>, Vinod Anupam <vanupam@google.com>, 
"draft-ietf-tokbind-https@tools.ietf.org" 
<draft-ietf-tokbind-https@tools.ietf.org>, "tokbind-chairs@ietf.org" 
<tokbind-chairs@ietf.org>, Dirk Balfanz <balfanz@google.com>
Subject: Re: Status of draft-ietf-tokbind-https
Resent-From: <alias-bounces@ietf.org>, Eric Rescorla <ekr@rtfm.com>
Resent-To: <andreipo@microsoft.com>, <mnystrom@microsoft.com>, Dirk 
Balfanz <balfanz@google.com>, Adam Langley <agl@google.com>, 
<nharper@google.com>, Jeff Hodges <Jeff.Hodges@PayPal.com>, 
<draft-ietf-tokbind-https@ietf.org>
Resent-Date: Thursday, November 16, 2017 at 8:08 AM

Thanks. As you can imagine, this week is terrible, but I should be able 
to finish my read-through next week.

-Ekr


On Thu, Nov 16, 2017 at 7:56 AM, Andrei Popov 
<Andrei.Popov@microsoft.com> wrote:
Hi Eric,

Dirk has uploaded HTTPSTB-11 with additional language at the end of 
section 7.4 “ Securing Federated Sign-On Protocols”:

“Note that the presence of Token Binding does not relieve the Token
    Provider and Token Consumer from performing various checks to ensure
    the security of clients during federated sign-on protocols.  These
    include the following:

    o  The Token Provider should not issue tokens to Token Consumers that
       have been shown to act maliciously.  To aid in this, the
       federation protocol should identify the Token Consumer to the
       Token Provider (e.g., through OAuth client IDs or similar
       mechanisms), and the Token Provider should ensure that tokens are
       indeed issued to the Token Consumer identified in the token
       request (e.g., by verifying that the redirect URI is associated
       with the OAuth client ID.)

    o  The Token Consumer should verify that the tokens were issued for
       it, and not some other token consumer.  To aid in this, the
       federation protocol should include an audience parameter in the
       token response, or apply equivalent mechanisms (the implicit OAuth
       flow requires Token Consumers to identify themselves when they
       exchange OAuth authorization codes for OAuth refresh tokens,
       leaving it up to the Token Provider to verify that the OAuth
       authorization was delivered to the correct Token Consumer).“

Cheers,

Andrei


From nobody Wed Nov 15 19:29:08 2017
Return-Path: <Jeff.Hodges@kingsmountain.com>
X-Original-To: unbearable@ietfa.amsl.com
Delivered-To: unbearable@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id A2D21129482 for <unbearable@ietfa.amsl.com>; Wed, 15 Nov 2017 19:28:57 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -3.908
X-Spam-Level: 
X-Spam-Status: No, score=-3.908 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, RCVD_IN_MSPIKE_H2=-2.8, RDNS_NONE=0.793, SPF_PASS=-0.001] autolearn=ham autolearn_force=no
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id ibcGTVncKVk1 for <unbearable@ietfa.amsl.com>; Wed, 15 Nov 2017 19:28:56 -0800 (PST)
Received: from qproxy6-pub.mail.unifiedlayer.com (unknown [69.89.23.12]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id E3F99124BE8 for <unbearable@ietf.org>; Wed, 15 Nov 2017 19:28:55 -0800 (PST)
Received: from CMOut01 (unknown [10.0.90.82]) by qproxy6.mail.unifiedlayer.com (Postfix) with ESMTP id 906C714058F for <unbearable@ietf.org>; Wed, 15 Nov 2017 20:28:55 -0700 (MST)
Received: from box514.bluehost.com ([74.220.219.114]) by CMOut01 with  id aTUs1w00B2UhLwi01TUvXC; Wed, 15 Nov 2017 20:28:55 -0700
X-Authority-Analysis: v=2.2 cv=K4VSJ2eI c=1 sm=1 tr=0 a=9W6Fsu4pMcyimqnCr1W0/w==:117 a=9W6Fsu4pMcyimqnCr1W0/w==:17 a=IkcTkHD0fZMA:10 a=sC3jslCIGhcA:10 a=48vgC7mUAAAA:8 a=9agrKkvSGwkZelEvQrYA:9 a=KljnBhELFtFfIRu4:21 a=2r9hc6O_niGuJnHF:21 a=QEXdDO2ut3YA:10 a=rKrVYePj7rwA:10 a=w1C3t2QeGrPiZgrLijVG:22
Received: from dhcp-8b7b.meeting.ietf.org ([31.133.139.123]:57685) by box514.bluehost.com with esmtpsa (TLSv1.2:ECDHE-RSA-AES128-GCM-SHA256:128) (Exim 4.87) (envelope-from <Jeff.Hodges@KingsMountain.com>) id 1eFArE-001Kkk-8v for unbearable@ietf.org; Wed, 15 Nov 2017 20:28:52 -0700
To: IETF TokBind WG <unbearable@ietf.org>
From: =JeffH <Jeff.Hodges@KingsMountain.com>
Message-ID: <d965818c-5ea7-d88b-d731-f4adee3d0bcc@KingsMountain.com>
Date: Thu, 16 Nov 2017 11:28:49 +0800
User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10.12; rv:52.0) Gecko/20100101 Thunderbird/52.4.0
MIME-Version: 1.0
Content-Type: text/plain; charset=utf-8; format=flowed
Content-Language: en-US
Content-Transfer-Encoding: 7bit
X-AntiAbuse: This header was added to track abuse, please include it with any abuse report
X-AntiAbuse: Primary Hostname - box514.bluehost.com
X-AntiAbuse: Original Domain - ietf.org
X-AntiAbuse: Originator/Caller UID/GID - [47 12] / [47 12]
X-AntiAbuse: Sender Address Domain - KingsMountain.com
X-BWhitelist: no
X-Source-IP: 31.133.139.123
X-Exim-ID: 1eFArE-001Kkk-8v
X-Source: 
X-Source-Args: 
X-Source-Dir: 
X-Source-Sender: dhcp-8b7b.meeting.ietf.org [31.133.139.123]:57685
X-Source-Auth: jeff.hodges+kingsmountain.com
X-Email-Count: 3
X-Source-Cap: a2luZ3Ntb3U7a2luZ3Ntb3U7Ym94NTE0LmJsdWVob3N0LmNvbQ==
X-Local-Domain: no
Archived-At: <https://mailarchive.ietf.org/arch/msg/unbearable/TjODxfllm1gmYtqAgUjN5YhVypc>
Subject: [Unbearable] fyi: [saag] Tokbind ietf100
X-BeenThere: unbearable@ietf.org
X-Mailman-Version: 2.1.22
Precedence: list
List-Id: "\"This list is for discussion of proposals for doing better than bearer tokens \(e.g. HTTP cookies, OAuth tokens etc.\) for web applications. The specific goal is chartering a WG focused on preventing security token export and replay attacks.\"" <unbearable.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/unbearable>, <mailto:unbearable-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/unbearable/>
List-Post: <mailto:unbearable@ietf.org>
List-Help: <mailto:unbearable-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/unbearable>, <mailto:unbearable-request@ietf.org?subject=subscribe>
X-List-Received-Date: Thu, 16 Nov 2017 03:28:58 -0000

From: saag <saag-bounces@ietf.org> on behalf of Leif Johansson 
<leifj@mnt.se>
Date: Thursday, November 16, 2017 at 10:57 AM
To: IETF SAAG <saag@ietf.org>
Subject: [saag] Tokbind ietf100


The WG met on Tuesday. The core documents are all getting ready for 
publication. The WG adopted a document describing token binding for TLS 
1.3 and also made progress on the proxy & tls terminators document.

Leif & John
_______________________________________________
saag mailing list
saag@ietf.org
https://www.ietf.org/mailman/listinfo/saag


From nobody Tue Nov 21 23:50:39 2017
Return-Path: <internet-drafts@ietf.org>
X-Original-To: unbearable@ietf.org
Delivered-To: unbearable@ietfa.amsl.com
Received: from ietfa.amsl.com (localhost [IPv6:::1]) by ietfa.amsl.com (Postfix) with ESMTP id 7DDD3127B5A; Tue, 21 Nov 2017 23:50:32 -0800 (PST)
MIME-Version: 1.0
Content-Type: text/plain; charset="utf-8"
Content-Transfer-Encoding: 7bit
From: internet-drafts@ietf.org
To: <i-d-announce@ietf.org>
Cc: unbearable@ietf.org
X-Test-IDTracker: no
X-IETF-IDTracker: 6.66.0
Auto-Submitted: auto-generated
Precedence: bulk
Message-ID: <151133703246.13319.7634966594942310640@ietfa.amsl.com>
Date: Tue, 21 Nov 2017 23:50:32 -0800
Archived-At: <https://mailarchive.ietf.org/arch/msg/unbearable/dLXH_wW0eb528kIv7qQwAnfy2EY>
Subject: [Unbearable] I-D Action: draft-ietf-tokbind-tls13-00.txt
X-BeenThere: unbearable@ietf.org
X-Mailman-Version: 2.1.22
List-Id: "\"This list is for discussion of proposals for doing better than bearer tokens \(e.g. HTTP cookies, OAuth tokens etc.\) for web applications. The specific goal is chartering a WG focused on preventing security token export and replay attacks.\"" <unbearable.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/unbearable>, <mailto:unbearable-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/unbearable/>
List-Post: <mailto:unbearable@ietf.org>
List-Help: <mailto:unbearable-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/unbearable>, <mailto:unbearable-request@ietf.org?subject=subscribe>
X-List-Received-Date: Wed, 22 Nov 2017 07:50:32 -0000

A New Internet-Draft is available from the on-line Internet-Drafts directories.
This draft is a work item of the Token Binding WG of the IETF.

        Title           : Token Binding for Transport Layer Security (TLS) Version 1.3 Connections
        Author          : Nick Harper
	Filename        : draft-ietf-tokbind-tls13-00.txt
	Pages           : 4
	Date            : 2017-11-21

Abstract:
   Negotiation of the Token Binding protocol is only defined for
   Transport Layer Security (TLS) versions 1.2 and earlier.  Token
   Binding users may wish to use it with TLS 1.3; this document defines
   a backwards compatible way to negotiate Token Binding on TLS 1.3
   connections.


The IETF datatracker status page for this draft is:
https://datatracker.ietf.org/doc/draft-ietf-tokbind-tls13/

There are also htmlized versions available at:
https://tools.ietf.org/html/draft-ietf-tokbind-tls13-00
https://datatracker.ietf.org/doc/html/draft-ietf-tokbind-tls13-00


Please note that it may take a couple of minutes from the time of submission
until the htmlized version and diff are available at tools.ietf.org.

Internet-Drafts are also available by anonymous FTP at:
ftp://ftp.ietf.org/internet-drafts/


From nobody Fri Nov 24 11:19:41 2017
Return-Path: <ynir.ietf@gmail.com>
X-Original-To: unbearable@ietf.org
Delivered-To: unbearable@ietfa.amsl.com
Received: from ietfa.amsl.com (localhost [IPv6:::1]) by ietfa.amsl.com (Postfix) with ESMTP id B226C1293D6; Fri, 24 Nov 2017 11:19:25 -0800 (PST)
MIME-Version: 1.0
Content-Type: text/plain; charset="utf-8"
Content-Transfer-Encoding: 7bit
From: Yoav Nir <ynir.ietf@gmail.com>
To: <secdir@ietf.org>
Cc: draft-ietf-tokbind-protocol.all@ietf.org, unbearable@ietf.org, ietf@ietf.org
X-Test-IDTracker: no
X-IETF-IDTracker: 6.66.0
Auto-Submitted: auto-generated
Precedence: bulk
Message-ID: <151155116566.9001.9710010900094084736@ietfa.amsl.com>
Date: Fri, 24 Nov 2017 11:19:25 -0800
Archived-At: <https://mailarchive.ietf.org/arch/msg/unbearable/dbhh2hz-lxm_RhiU8ByEmIFGyek>
Subject: [Unbearable] Secdir last call review of draft-ietf-tokbind-protocol-16
X-BeenThere: unbearable@ietf.org
X-Mailman-Version: 2.1.22
List-Id: "\"This list is for discussion of proposals for doing better than bearer tokens \(e.g. HTTP cookies, OAuth tokens etc.\) for web applications. The specific goal is chartering a WG focused on preventing security token export and replay attacks.\"" <unbearable.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/unbearable>, <mailto:unbearable-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/unbearable/>
List-Post: <mailto:unbearable@ietf.org>
List-Help: <mailto:unbearable-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/unbearable>, <mailto:unbearable-request@ietf.org?subject=subscribe>
X-List-Received-Date: Fri, 24 Nov 2017 19:19:26 -0000

Reviewer: Yoav Nir
Review result: Ready

The document seems ready with two minor editorial nits:

1. The first sentence is as follows:
  Often, servers generate various security tokens (e.g.  HTTP cookies, OAuth
  [RFC6749] tokens) If you reference the OAuth RFC, you should also reference
  the HTTP cookie RFC (RFC 6265)

2. The term "bound token" appears in section 2 without any definition. Perhaps
add something like "An application token contained in a token binding message
is called a bound token"

Other than that, the document is well written and the security issues are dealt
with well in sections 4 and 5 as well as the security considerations section
(7).


From nobody Wed Nov 29 10:08:41 2017
Return-Path: <bounce+3a3868.40f-unbearable=ietf.org@github.com>
X-Original-To: unbearable@ietfa.amsl.com
Delivered-To: unbearable@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id B1BC2124D85 for <unbearable@ietfa.amsl.com>; Wed, 29 Nov 2017 10:08:39 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.9
X-Spam-Level: 
X-Spam-Status: No, score=-1.9 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, HEADER_FROM_DIFFERENT_DOMAINS=0.001, RCVD_IN_DNSWL_NONE=-0.0001, SPF_PASS=-0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (1024-bit key) header.d=github.com
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id a-4c84euPOos for <unbearable@ietfa.amsl.com>; Wed, 29 Nov 2017 10:08:36 -0800 (PST)
Received: from m71-131.mailgun.net (m71-131.mailgun.net [166.78.71.131]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id B87C91288A9 for <unbearable@ietf.org>; Wed, 29 Nov 2017 10:08:36 -0800 (PST)
DKIM-Signature: a=rsa-sha256; v=1; c=relaxed/relaxed; d=github.com; q=dns/txt;  s=mailo; t=1511978915; h=Content-Transfer-Encoding: Content-Type: Mime-Version: Subject: Message-ID: To: Reply-To: From: Date: Sender; bh=7bjoScxx3MMGInvQUoPv7Yhz8/8OnFIq2h57JPqHbuk=; b=tF8I/x6rIEJrhQqkYaAI5VwktbUPcGXMnwImWLckaha2LzuVIy6OpDDE8FdI5m1yZIYFPCwX vQnukacwkvypQ1HuktVVML423OzHMlGq46+I32Che/PtU8Zd4Sky93wzGj3HX4LGTNG88Btx y4q2eGn77SvHo507nciUtEOXj/8=
Sender: dirk=balfanz.net@github.com
X-Mailgun-Sending-Ip: 166.78.71.131
X-Mailgun-Sid: WyIzMTNlNyIsICJ1bmJlYXJhYmxlQGlldGYub3JnIiwgIjQwZiJd
Received: from github.com (Unknown [192.30.252.40]) by mxa.mailgun.org with ESMTP id 5a1ef76d.7f26987bdfc0-smtp-out-n03; Wed, 29 Nov 2017 18:07:41 -0000 (UTC)
Date: Wed, 29 Nov 2017 10:07:40 -0800
From: balfanz <dirk@balfanz.net>
Reply-To: balfanz <dirk@balfanz.net>
To: unbearable@ietf.org
Message-ID: <5a1ef76c33a13_15da3fcb1388fc34120074@hookshot-fe6-cp1-prd.iad.github.net.mail>
Mime-Version: 1.0
Content-Type: multipart/mixed; boundary="--==_mimepart_5a1ef76c33527_15da3fcb1388fc34119970"; charset=UTF-8
Content-Transfer-Encoding: 7bit
Archived-At: <https://mailarchive.ietf.org/arch/msg/unbearable/3P2oTHdMIPL5QCr14L9VyEBWV7c>
Subject: [Unbearable] [TokenBinding/Internet-Drafts] b10996: Updated README
X-BeenThere: unbearable@ietf.org
X-Mailman-Version: 2.1.22
Precedence: list
List-Id: "\"This list is for discussion of proposals for doing better than bearer tokens \(e.g. HTTP cookies, OAuth tokens etc.\) for web applications. The specific goal is chartering a WG focused on preventing security token export and replay attacks.\"" <unbearable.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/unbearable>, <mailto:unbearable-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/unbearable/>
List-Post: <mailto:unbearable@ietf.org>
List-Help: <mailto:unbearable-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/unbearable>, <mailto:unbearable-request@ietf.org?subject=subscribe>
X-List-Received-Date: Wed, 29 Nov 2017 18:08:40 -0000

----==_mimepart_5a1ef76c33527_15da3fcb1388fc34119970
Content-Type: text/plain;
 charset=UTF-8
Content-Transfer-Encoding: 7bit

  Branch: refs/heads/master
  Home:   https://github.com/TokenBinding/Internet-Drafts
  Commit: b10996b6da65f9aee06634bcf43fef36b51cf3de
      https://github.com/TokenBinding/Internet-Drafts/commit/b10996b6da65f9aee06634bcf43fef36b51cf3de
  Author: balfanz <dirk@balfanz.net>
  Date:   2017-11-29 (Wed, 29 Nov 2017)

  Changed paths:
    M README.md

  Log Message:
  -----------
  Updated README

bumped version of httpstb to 11



----==_mimepart_5a1ef76c33527_15da3fcb1388fc34119970--


From nobody Thu Nov 30 14:35:27 2017
Return-Path: <bounces+848413-28b5-unbearable=ietf.org@sgmail.github.com>
X-Original-To: unbearable@ietfa.amsl.com
Delivered-To: unbearable@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 5C0A5126B72 for <unbearable@ietfa.amsl.com>; Wed, 29 Nov 2017 09:28:31 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -0.474
X-Spam-Level: 
X-Spam-Status: No, score=-0.474 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, HTML_IMAGE_ONLY_20=1.546, HTML_MESSAGE=0.001, RCVD_IN_MSPIKE_H3=-0.01, RCVD_IN_MSPIKE_WL=-0.01, SPF_PASS=-0.001] autolearn=no autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (1024-bit key) header.d=github.com
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id XgJT0Z6mhvXr for <unbearable@ietfa.amsl.com>; Wed, 29 Nov 2017 09:28:30 -0800 (PST)
Received: from o10.sgmail.github.com (o10.sgmail.github.com [167.89.101.201]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 28676120726 for <unbearable@ietf.org>; Wed, 29 Nov 2017 09:28:30 -0800 (PST)
DKIM-Signature: v=1; a=rsa-sha1; c=relaxed/relaxed; d=github.com;  h=from:reply-to:to:cc:subject:mime-version:content-type:content-transfer-encoding:list-id:list-archive:list-post:list-unsubscribe; s=s20150108; bh=XtH5Dqf3lq6x4mWNBnEJxB1b2u4=; b=DsTa+fermOxHcrup VQBWWV8RZvNVb7evKvOJ4maNjuSEDzq5F5eb6wStPhWap4k+LQSWpmNBfAQIO6xP EJFkNbTEyLsB2tmKNSyz4plzSUNlb3i2zB517f23JHiRhZbc7JlJNZ2tIOlnCMJl ImBt20GCIXxmUguLvy4T5mQoahQ=
Received: by filter0202p1las1.sendgrid.net with SMTP id filter0202p1las1-18668-5A1EEE3C-3A 2017-11-29 17:28:28.846042023 +0000 UTC
Received: from github-smtp2b-ext-cp1-prd.iad.github.net (github-smtp2b-ext-cp1-prd.iad.github.net [192.30.253.17]) by ismtpd0015p1iad2.sendgrid.net (SG) with ESMTP id 96mOJ3-qQradsrBpxTTROg for <unbearable@ietf.org>; Wed, 29 Nov 2017 17:28:28.858 +0000 (UTC)
Date: Wed, 29 Nov 2017 17:28:28 +0000 (UTC)
From: balfanz <notifications@github.com>
Reply-To: TokenBinding/Internet-Drafts <reply+011c274fb44b16097f49aac75c29dc18158a0efbf4dd3ef092cf000000011636b03c92a169ce108f864e@reply.github.com>
To: TokenBinding/Internet-Drafts <Internet-Drafts@noreply.github.com>
Cc: Subscribed <subscribed@noreply.github.com>
Message-ID: <TokenBinding/Internet-Drafts/issues/100@github.com>
Mime-Version: 1.0
Content-Type: multipart/alternative; boundary="--==_mimepart_5a1eee3ca396a_713b3fb72598ef38945b0"; charset=UTF-8
Content-Transfer-Encoding: 7bit
Precedence: list
X-GitHub-Sender: balfanz
X-GitHub-Recipient: unbearable-ML
X-GitHub-Reason: subscribed
X-Auto-Response-Suppress: All
X-GitHub-Recipient-Address: unbearable@ietf.org
tracking: 
X-SG-EID: 9Yqp9dCIIwZxB0MVAPExrXlt7a4/46ALD9aG/N3UOYpvPsDO9ZPlRSLQuWr9xYzUGFTkYVcoEeECHk FeDwdpzjbIJW0+WfME7pxVsmXH+6u4XJQjbaODXnPrOicWJy9rOxxFxB9E2GthMU9Z/J9JbXtQUpjr A2JPQOiN82rqfO0+u7CWsBSg1URIf5fQ7BIpK1sBwK/3pF6RoNrO+RcyCA==
Archived-At: <https://mailarchive.ietf.org/arch/msg/unbearable/_En2zu2bz0vXkXyWmGobLQ4c5iU>
X-Mailman-Approved-At: Thu, 30 Nov 2017 14:35:26 -0800
Subject: [Unbearable] [TokenBinding/Internet-Drafts] Cite RFC 2818 (#100)
X-BeenThere: unbearable@ietf.org
X-Mailman-Version: 2.1.22
List-Id: "\"This list is for discussion of proposals for doing better than bearer tokens \(e.g. HTTP cookies, OAuth tokens etc.\) for web applications. The specific goal is chartering a WG focused on preventing security token export and replay attacks.\"" <unbearable.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/unbearable>, <mailto:unbearable-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/unbearable/>
List-Post: <mailto:unbearable@ietf.org>
List-Help: <mailto:unbearable-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/unbearable>, <mailto:unbearable-request@ietf.org?subject=subscribe>
X-List-Received-Date: Wed, 29 Nov 2017 17:28:31 -0000

----==_mimepart_5a1eee3ca396a_713b3fb72598ef38945b0
Content-Type: text/plain;
 charset=UTF-8
Content-Transfer-Encoding: 7bit

Cite RFC 2818 when referring to HTTP over TLS in HTTPSTB.

-- 
You are receiving this because you are subscribed to this thread.
Reply to this email directly or view it on GitHub:
https://github.com/TokenBinding/Internet-Drafts/issues/100
----==_mimepart_5a1eee3ca396a_713b3fb72598ef38945b0
Content-Type: text/html;
 charset=UTF-8
Content-Transfer-Encoding: 7bit

<p>Cite RFC 2818 when referring to HTTP over TLS in HTTPSTB.</p>

<p style="font-size:small;-webkit-text-size-adjust:none;color:#666;">&mdash;<br />You are receiving this because you are subscribed to this thread.<br />Reply to this email directly, <a href="https://github.com/TokenBinding/Internet-Drafts/issues/100">view it on GitHub</a>, or <a href="https://github.com/notifications/unsubscribe-auth/ARwnT5r2HIdEKq5P3GnuANLFHStZfHUHks5s7ZQ8gaJpZM4QvV1Z">mute the thread</a>.<img alt="" height="1" src="https://github.com/notifications/beacon/ARwnT9_TYdYqjhusWR4Sicx4R8qWTl_Qks5s7ZQ8gaJpZM4QvV1Z.gif" width="1" /></p>
<div itemscope itemtype="http://schema.org/EmailMessage">
<div itemprop="action" itemscope itemtype="http://schema.org/ViewAction">
  <link itemprop="url" href="https://github.com/TokenBinding/Internet-Drafts/issues/100"></link>
  <meta itemprop="name" content="View Issue"></meta>
</div>
<meta itemprop="description" content="View this Issue on GitHub"></meta>
</div>

<script type="application/json" data-scope="inboxmarkup">{"api_version":"1.0","publisher":{"api_key":"05dde50f1d1a384dd78767c55493e4bb","name":"GitHub"},"entity":{"external_key":"github/TokenBinding/Internet-Drafts","title":"TokenBinding/Internet-Drafts","subtitle":"GitHub repository","main_image_url":"https://cloud.githubusercontent.com/assets/143418/17495839/a5054eac-5d88-11e6-95fc-7290892c7bb5.png","avatar_image_url":"https://cloud.githubusercontent.com/assets/143418/15842166/7c72db34-2c0b-11e6-9aed-b52498112777.png","action":{"name":"Open in GitHub","url":"https://github.com/TokenBinding/Internet-Drafts"}},"updates":{"snippets":[{"icon":"DESCRIPTION","message":"Cite RFC 2818 (#100)"}],"action":{"name":"View Issue","url":"https://github.com/TokenBinding/Internet-Drafts/issues/100"}}}</script>
----==_mimepart_5a1eee3ca396a_713b3fb72598ef38945b0--


From nobody Thu Nov 30 14:35:33 2017
Return-Path: <bounces+848413-28b5-unbearable=ietf.org@sgmail.github.com>
X-Original-To: unbearable@ietfa.amsl.com
Delivered-To: unbearable@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 7255C1288A9 for <unbearable@ietfa.amsl.com>; Wed, 29 Nov 2017 10:01:46 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -0.474
X-Spam-Level: 
X-Spam-Status: No, score=-0.474 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, HTML_IMAGE_ONLY_20=1.546, HTML_MESSAGE=0.001, RCVD_IN_MSPIKE_H3=-0.01, RCVD_IN_MSPIKE_WL=-0.01, SPF_PASS=-0.001] autolearn=no autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (1024-bit key) header.d=github.com
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id VhoxBC9Mqi1c for <unbearable@ietfa.amsl.com>; Wed, 29 Nov 2017 10:01:40 -0800 (PST)
Received: from o1.sgmail.github.com (o1.sgmail.github.com [192.254.114.176]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 8AA36126CC4 for <unbearable@ietf.org>; Wed, 29 Nov 2017 10:01:40 -0800 (PST)
DKIM-Signature: v=1; a=rsa-sha1; c=relaxed/relaxed; d=github.com;  h=from:reply-to:to:cc:subject:mime-version:content-type:content-transfer-encoding:list-id:list-archive:list-post:list-unsubscribe; s=s20150108; bh=EF3CXMCKBEved3wA6TuEgC16g6s=; b=jfel/luQWI83GHgt axRZwicFlU2D4sVtKVY9oZy0IgAas39PIx6euR5JjpqTVGJODTBOoe2phDDYDOQI H8H59ZknKMB8NrUYRJT/5ZRdMrStSDMLP5BF7yxuuoAD5pUkEpr7Q1b1ARXzc3Bs w5aU5braJMEDerKxRKcfZSQ9eKQ=
Received: by filter0608p1las1.sendgrid.net with SMTP id filter0608p1las1-26915-5A1EF603-A 2017-11-29 18:01:39.32686927 +0000 UTC
Received: from github-smtp2b-ext-cp1-prd.iad.github.net (github-smtp2b-ext-cp1-prd.iad.github.net [192.30.253.17]) by ismtpd0022p1iad2.sendgrid.net (SG) with ESMTP id pX8zNnMtRoiBfwJ14PEG2A for <unbearable@ietf.org>; Wed, 29 Nov 2017 18:01:39.379 +0000 (UTC)
Date: Wed, 29 Nov 2017 18:01:39 +0000 (UTC)
From: balfanz <notifications@github.com>
Reply-To: TokenBinding/Internet-Drafts <reply+011c274fe19043fd79f7974f54f431730459ecbda66dcfb092cf000000011636b80392a169ce108faed2@reply.github.com>
To: TokenBinding/Internet-Drafts <Internet-Drafts@noreply.github.com>
Cc: Subscribed <subscribed@noreply.github.com>
Message-ID: <TokenBinding/Internet-Drafts/issues/101@github.com>
Mime-Version: 1.0
Content-Type: multipart/alternative; boundary="--==_mimepart_5a1ef60327621_7bcc3f974ce00f3829526c"; charset=UTF-8
Content-Transfer-Encoding: 7bit
Precedence: list
X-GitHub-Sender: balfanz
X-GitHub-Recipient: unbearable-ML
X-GitHub-Reason: subscribed
X-Auto-Response-Suppress: All
X-GitHub-Recipient-Address: unbearable@ietf.org
tracking: 
X-SG-EID: 9Yqp9dCIIwZxB0MVAPExrXlt7a4/46ALD9aG/N3UOYq4wScwOtE6OqhHtV9UTz1scz//4tG9LX3Hhc T+QLEiFKAY+UiQHRZSVehUqzmC29XYO3z5PVaQ+oCgKDrBqLukiUXZjF15+rTQBkYnHMs3pZ+Nfm4s bIel0jgi4su9CXl7JZMqQx+/7jIv32HamKYFGJ2Tq5WFWRdBHwg/2laQDQ==
Archived-At: <https://mailarchive.ietf.org/arch/msg/unbearable/_xe5yI8EXdv7DUyOlVKOiOdzbB8>
X-Mailman-Approved-At: Thu, 30 Nov 2017 14:35:26 -0800
Subject: [Unbearable] [TokenBinding/Internet-Drafts] Use real examples in HTTPSTB (#101)
X-BeenThere: unbearable@ietf.org
X-Mailman-Version: 2.1.22
List-Id: "\"This list is for discussion of proposals for doing better than bearer tokens \(e.g. HTTP cookies, OAuth tokens etc.\) for web applications. The specific goal is chartering a WG focused on preventing security token export and replay attacks.\"" <unbearable.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/unbearable>, <mailto:unbearable-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/unbearable/>
List-Post: <mailto:unbearable@ietf.org>
List-Help: <mailto:unbearable-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/unbearable>, <mailto:unbearable-request@ietf.org?subject=subscribe>
X-List-Received-Date: Wed, 29 Nov 2017 18:01:46 -0000

----==_mimepart_5a1ef60327621_7bcc3f974ce00f3829526c
Content-Type: text/plain;
 charset=UTF-8
Content-Transfer-Encoding: 7bit

Instead of saying something like 
```
Sec-Token-Binding: <base64url-encoded TokenBindingMessage>
```
we should use a real example of a token binding header.

-- 
You are receiving this because you are subscribed to this thread.
Reply to this email directly or view it on GitHub:
https://github.com/TokenBinding/Internet-Drafts/issues/101
----==_mimepart_5a1ef60327621_7bcc3f974ce00f3829526c
Content-Type: text/html;
 charset=UTF-8
Content-Transfer-Encoding: 7bit

<p>Instead of saying something like</p>
<pre><code>Sec-Token-Binding: &lt;base64url-encoded TokenBindingMessage&gt;
</code></pre>
<p>we should use a real example of a token binding header.</p>

<p style="font-size:small;-webkit-text-size-adjust:none;color:#666;">&mdash;<br />You are receiving this because you are subscribed to this thread.<br />Reply to this email directly, <a href="https://github.com/TokenBinding/Internet-Drafts/issues/101">view it on GitHub</a>, or <a href="https://github.com/notifications/unsubscribe-auth/ARwnT_zCYxaWGe47TrCxF6azbjLgPYubks5s7ZwDgaJpZM4QvYwN">mute the thread</a>.<img alt="" height="1" src="https://github.com/notifications/beacon/ARwnT03LJq4gpriKiAwJjJ96Xmpzl_XNks5s7ZwDgaJpZM4QvYwN.gif" width="1" /></p>
<div itemscope itemtype="http://schema.org/EmailMessage">
<div itemprop="action" itemscope itemtype="http://schema.org/ViewAction">
  <link itemprop="url" href="https://github.com/TokenBinding/Internet-Drafts/issues/101"></link>
  <meta itemprop="name" content="View Issue"></meta>
</div>
<meta itemprop="description" content="View this Issue on GitHub"></meta>
</div>

<script type="application/json" data-scope="inboxmarkup">{"api_version":"1.0","publisher":{"api_key":"05dde50f1d1a384dd78767c55493e4bb","name":"GitHub"},"entity":{"external_key":"github/TokenBinding/Internet-Drafts","title":"TokenBinding/Internet-Drafts","subtitle":"GitHub repository","main_image_url":"https://cloud.githubusercontent.com/assets/143418/17495839/a5054eac-5d88-11e6-95fc-7290892c7bb5.png","avatar_image_url":"https://cloud.githubusercontent.com/assets/143418/15842166/7c72db34-2c0b-11e6-9aed-b52498112777.png","action":{"name":"Open in GitHub","url":"https://github.com/TokenBinding/Internet-Drafts"}},"updates":{"snippets":[{"icon":"DESCRIPTION","message":"Use real examples in HTTPSTB (#101)"}],"action":{"name":"View Issue","url":"https://github.com/TokenBinding/Internet-Drafts/issues/101"}}}</script>
----==_mimepart_5a1ef60327621_7bcc3f974ce00f3829526c--


From nobody Thu Nov 30 14:35:38 2017
Return-Path: <bounces+848413-28b5-unbearable=ietf.org@sgmail.github.com>
X-Original-To: unbearable@ietfa.amsl.com
Delivered-To: unbearable@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 1D6191289B5 for <unbearable@ietfa.amsl.com>; Wed, 29 Nov 2017 10:08:50 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -3.182
X-Spam-Level: 
X-Spam-Status: No, score=-3.182 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, HTML_IMAGE_ONLY_24=1.618, HTML_MESSAGE=0.001, RCVD_IN_MSPIKE_H2=-2.8, SPF_PASS=-0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (1024-bit key) header.d=github.com
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id ZvOiWlPSPYLJ for <unbearable@ietfa.amsl.com>; Wed, 29 Nov 2017 10:08:49 -0800 (PST)
Received: from o6.sgmail.github.com (o6.sgmail.github.com [192.254.113.101]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id A9719124D85 for <unbearable@ietf.org>; Wed, 29 Nov 2017 10:08:48 -0800 (PST)
DKIM-Signature: v=1; a=rsa-sha1; c=relaxed/relaxed; d=github.com;  h=from:reply-to:to:cc:in-reply-to:references:subject:mime-version:content-type:content-transfer-encoding:list-id:list-archive:list-post:list-unsubscribe; s=s20150108; bh=6oEkRcsWaOE0hD7QgffaK/L13nc=; b=bwLFkrHX97mievFV cz9kBcZc2gbYkAehMGx5Egsu1D2IjUHz0nkbZHpNxJistOsfgq0kQcZVMNWhCk4f yyAccZ8+RSYy4GP8S5X4K3PncIEBWornWIJALAAHmfj+BxgvUibAlw9NQfGA9O2K iHyu8PhpIRczYvztsczs5vq5pSs=
Received: by filter0618p1las1.sendgrid.net with SMTP id filter0618p1las1-8878-5A1EF77A-26 2017-11-29 18:07:54.888462144 +0000 UTC
Received: from github-smtp2a-ext-cp1-prd.iad.github.net (github-smtp2a-ext-cp1-prd.iad.github.net [192.30.253.16]) by ismtpd0004p1iad2.sendgrid.net (SG) with ESMTP id lA3gs0npT1iybqJobK5cHA for <unbearable@ietf.org>; Wed, 29 Nov 2017 18:07:54.800 +0000 (UTC)
Date: Wed, 29 Nov 2017 18:07:55 +0000 (UTC)
From: Brian Campbell <notifications@github.com>
Reply-To: TokenBinding/Internet-Drafts <reply+011c274f0d070e8f280df6a114d08e28fab29300b379af0192cf000000011636b97a92a169ce108faed2@reply.github.com>
To: TokenBinding/Internet-Drafts <Internet-Drafts@noreply.github.com>
Cc: Subscribed <subscribed@noreply.github.com>
Message-ID: <TokenBinding/Internet-Drafts/issues/101/347946134@github.com>
In-Reply-To: <TokenBinding/Internet-Drafts/issues/101@github.com>
References: <TokenBinding/Internet-Drafts/issues/101@github.com>
Mime-Version: 1.0
Content-Type: multipart/alternative; boundary="--==_mimepart_5a1ef77ab5dc6_5cac3fe32c39cf341089d0"; charset=UTF-8
Content-Transfer-Encoding: 7bit
Precedence: list
X-GitHub-Sender: b---c
X-GitHub-Recipient: unbearable-ML
X-GitHub-Reason: subscribed
X-Auto-Response-Suppress: All
X-GitHub-Recipient-Address: unbearable@ietf.org
tracking: 
X-SG-EID: 9Yqp9dCIIwZxB0MVAPExrXlt7a4/46ALD9aG/N3UOYoN7F7U9Y36/p4iuLIUdcXlKLd6pEbsaRycNY du69O/ySQZdJPigki2x0aBHyuvPuH+lKyPmJl1sib23qhEzeTxM8uRvseh9DrSbclTRJopZZZK5CbD 17yMNUcW03uQ2675nn1IxwPGHWZ8PQ3BSVUHdoJRC3QOxLe31SlsKpwn+7YzDgnteMphIck+8yUeHX 8=
Archived-At: <https://mailarchive.ietf.org/arch/msg/unbearable/TkYUUUz1ae9BnKfQbfrUvjOdF7o>
X-Mailman-Approved-At: Thu, 30 Nov 2017 14:35:26 -0800
Subject: Re: [Unbearable] [TokenBinding/Internet-Drafts] Use real examples in HTTPSTB (#101)
X-BeenThere: unbearable@ietf.org
X-Mailman-Version: 2.1.22
List-Id: "\"This list is for discussion of proposals for doing better than bearer tokens \(e.g. HTTP cookies, OAuth tokens etc.\) for web applications. The specific goal is chartering a WG focused on preventing security token export and replay attacks.\"" <unbearable.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/unbearable>, <mailto:unbearable-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/unbearable/>
List-Post: <mailto:unbearable@ietf.org>
List-Help: <mailto:unbearable-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/unbearable>, <mailto:unbearable-request@ietf.org?subject=subscribe>
X-List-Received-Date: Wed, 29 Nov 2017 18:08:50 -0000

----==_mimepart_5a1ef77ab5dc6_5cac3fe32c39cf341089d0
Content-Type: text/plain;
 charset=UTF-8
Content-Transfer-Encoding: 7bit

https://tools.ietf.org/html/draft-ietf-tokbind-ttrp-01#section-2.3.1 has one you can use, if you like

-- 
You are receiving this because you are subscribed to this thread.
Reply to this email directly or view it on GitHub:
https://github.com/TokenBinding/Internet-Drafts/issues/101#issuecomment-347946134
----==_mimepart_5a1ef77ab5dc6_5cac3fe32c39cf341089d0
Content-Type: text/html;
 charset=UTF-8
Content-Transfer-Encoding: 7bit

<p><a href="https://tools.ietf.org/html/draft-ietf-tokbind-ttrp-01#section-2.3.1" rel="nofollow">https://tools.ietf.org/html/draft-ietf-tokbind-ttrp-01#section-2.3.1</a> has one you can use, if you like</p>

<p style="font-size:small;-webkit-text-size-adjust:none;color:#666;">&mdash;<br />You are receiving this because you are subscribed to this thread.<br />Reply to this email directly, <a href="https://github.com/TokenBinding/Internet-Drafts/issues/101#issuecomment-347946134">view it on GitHub</a>, or <a href="https://github.com/notifications/unsubscribe-auth/ARwnT4JMRJfOidqXfehPWN5W03q1YcbTks5s7Z16gaJpZM4QvYwN">mute the thread</a>.<img alt="" height="1" src="https://github.com/notifications/beacon/ARwnTw7V3__3vkQpx4N3UxiqAhQ-2ppJks5s7Z16gaJpZM4QvYwN.gif" width="1" /></p>
<div itemscope itemtype="http://schema.org/EmailMessage">
<div itemprop="action" itemscope itemtype="http://schema.org/ViewAction">
  <link itemprop="url" href="https://github.com/TokenBinding/Internet-Drafts/issues/101#issuecomment-347946134"></link>
  <meta itemprop="name" content="View Issue"></meta>
</div>
<meta itemprop="description" content="View this Issue on GitHub"></meta>
</div>

<script type="application/json" data-scope="inboxmarkup">{"api_version":"1.0","publisher":{"api_key":"05dde50f1d1a384dd78767c55493e4bb","name":"GitHub"},"entity":{"external_key":"github/TokenBinding/Internet-Drafts","title":"TokenBinding/Internet-Drafts","subtitle":"GitHub repository","main_image_url":"https://cloud.githubusercontent.com/assets/143418/17495839/a5054eac-5d88-11e6-95fc-7290892c7bb5.png","avatar_image_url":"https://cloud.githubusercontent.com/assets/143418/15842166/7c72db34-2c0b-11e6-9aed-b52498112777.png","action":{"name":"Open in GitHub","url":"https://github.com/TokenBinding/Internet-Drafts"}},"updates":{"snippets":[{"icon":"PERSON","message":"@b---c in #101: https://tools.ietf.org/html/draft-ietf-tokbind-ttrp-01#section-2.3.1 has one you can use, if you like"}],"action":{"name":"View Issue","url":"https://github.com/TokenBinding/Internet-Drafts/issues/101#issuecomment-347946134"}}}</script>
----==_mimepart_5a1ef77ab5dc6_5cac3fe32c39cf341089d0--


From nobody Thu Nov 30 22:56:31 2017
Return-Path: <jouni.nospam@gmail.com>
X-Original-To: unbearable@ietf.org
Delivered-To: unbearable@ietfa.amsl.com
Received: from ietfa.amsl.com (localhost [IPv6:::1]) by ietfa.amsl.com (Postfix) with ESMTP id 93DBD127863; Thu, 30 Nov 2017 22:56:19 -0800 (PST)
MIME-Version: 1.0
Content-Type: text/plain; charset="utf-8"
Content-Transfer-Encoding: 7bit
From: Jouni Korhonen <jouni.nospam@gmail.com>
To: <gen-art@ietf.org>
Cc: draft-ietf-tokbind-protocol.all@ietf.org, unbearable@ietf.org, ietf@ietf.org
X-Test-IDTracker: no
X-IETF-IDTracker: 6.66.0
Auto-Submitted: auto-generated
Precedence: bulk
Message-ID: <151211137956.11945.3926284036867947678@ietfa.amsl.com>
Date: Thu, 30 Nov 2017 22:56:19 -0800
Archived-At: <https://mailarchive.ietf.org/arch/msg/unbearable/ZU9EPIuADzJCa8mc6WWzpSH9Zic>
Subject: [Unbearable] Genart last call review of draft-ietf-tokbind-protocol-16
X-BeenThere: unbearable@ietf.org
X-Mailman-Version: 2.1.22
List-Id: "\"This list is for discussion of proposals for doing better than bearer tokens \(e.g. HTTP cookies, OAuth tokens etc.\) for web applications. The specific goal is chartering a WG focused on preventing security token export and replay attacks.\"" <unbearable.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/unbearable>, <mailto:unbearable-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/unbearable/>
List-Post: <mailto:unbearable@ietf.org>
List-Help: <mailto:unbearable-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/unbearable>, <mailto:unbearable-request@ietf.org?subject=subscribe>
X-List-Received-Date: Fri, 01 Dec 2017 06:56:20 -0000

Reviewer: Jouni Korhonen
Review result: Ready

I am the assigned Gen-ART reviewer for this draft. The General Area
Review Team (Gen-ART) reviews all IETF documents being processed
by the IESG for the IETF Chair.  Please treat these comments just
like any other last call comments.

For more information, please see the FAQ at

<https://trac.ietf.org/trac/gen/wiki/GenArtfaq>.

Document: draft-ietf-tokbind-protocol-??
Reviewer: Jouni Korhonen
Review Date: 2017-11-30
IETF LC End Date: 2017-11-27
IESG Telechat date: Not scheduled for a telechat

Summary: Ready to go. I am not an expert on this field thus my review was
rather superficial. Reading the document through did not raise any alarms.

Major issues: None spotted.

Minor issues: None.

Nits/editorial comments:  IDnist result was good (outdated references are
non-issues).


