> Meiling, all,
> 
> I have posted contributed text to issue #15 (Intent Confirmation
> for Critical/Irreversible Actions), covering the three Next Actions
> listed there: the mapping to existing use cases, the requirements
> this scenario adds, and a gap analysis.
> 
> https://github.com/Maisy-ML/Agent-Authorization-Use-Cases/issues/15
> 
> Two points from it are worth surfacing on the list rather than
> leaving in the issue.
> 
> First, the scenario adds a requirement that issue #11 does not
> currently state. Execution-time evidence must be distinguishable
> from post-hoc ratification. A confirmation record produced after
> the effect has cleared is a different artifact with different
> evidentiary weight, and a signature alone does not separate them.
> If the catalogue is going to state requirements for this class, I
> think that one belongs in the set.
> 
> Second, and more important for the document as a whole: every
> candidate mechanism discussed in this space verifies a signature
> against a key and then treats that key as standing for a person.
> What enrollment must guarantee for that step to hold is not stated
> in any current draft. The gap is inherited by whichever mechanism
> the group eventually selects, so it is a catalogue-level concern
> rather than a property of any one proposal. I have written it up
> as a problem statement with requirements and no mechanism:
> 
> https://datatracker.ietf.org/doc/draft-yossif-enrollment-problem/
> 
> The ex-ante counterpart, on binding executed parameters to a
> constraint set the human actually signed, is here:
> 
> https://datatracker.ietf.org/doc/draft-yossif-agent-mandate-problem/
> 
> Happy to write either up in the catalogue's gap format if that is
> more useful than a citation.
> 
> Mohamad Khalil-Yossif



_______________________________________________
OAuth mailing list -- [email protected]
To unsubscribe send an email to [email protected]

Reply via email to