> Meiling, all, > > I have posted contributed text to issue #15 (Intent Confirmation > for Critical/Irreversible Actions), covering the three Next Actions > listed there: the mapping to existing use cases, the requirements > this scenario adds, and a gap analysis. > > https://github.com/Maisy-ML/Agent-Authorization-Use-Cases/issues/15 > > Two points from it are worth surfacing on the list rather than > leaving in the issue. > > First, the scenario adds a requirement that issue #11 does not > currently state. Execution-time evidence must be distinguishable > from post-hoc ratification. A confirmation record produced after > the effect has cleared is a different artifact with different > evidentiary weight, and a signature alone does not separate them. > If the catalogue is going to state requirements for this class, I > think that one belongs in the set. > > Second, and more important for the document as a whole: every > candidate mechanism discussed in this space verifies a signature > against a key and then treats that key as standing for a person. > What enrollment must guarantee for that step to hold is not stated > in any current draft. The gap is inherited by whichever mechanism > the group eventually selects, so it is a catalogue-level concern > rather than a property of any one proposal. I have written it up > as a problem statement with requirements and no mechanism: > > https://datatracker.ietf.org/doc/draft-yossif-enrollment-problem/ > > The ex-ante counterpart, on binding executed parameters to a > constraint set the human actually signed, is here: > > https://datatracker.ietf.org/doc/draft-yossif-agent-mandate-problem/ > > Happy to write either up in the catalogue's gap format if that is > more useful than a citation. > > Mohamad Khalil-Yossif
_______________________________________________ OAuth mailing list -- [email protected] To unsubscribe send an email to [email protected]
