> Karl,
> 
> I have been meaning to write to you since George Fletcher pointed me
> at Mission-Bound Authorization on this list on 22 July. I said then
> that I would treat it as primary related work in a revision of my own
> draft and have not yet done so, which is my delay, not an oversight.
> ICA is a better occasion than the one I was waiting for.
> 
> The framing that interests me is your first sentence about the
> absence: the user is not present at the hop, and redirecting to the
> identity provider is not an option. That is the same observation I
> started from and we have gone opposite directions with it.
> 
> ICA answers it by having each boundary mint fresh, so no credential
> travels and no component holds standing authority. I answer it by
> requiring evidence produced at the moment of the action by a key the
> invoking runtime cannot reach - which means my construction simply
> fails in the case ICA is built for. If the user has gone offline
> there is no proof to produce, and a profile that says "then refuse"
> is not a solution to a continuation problem.
> 
> So these are complementary rather than competing, and I think the
> seam between them is worth naming.
> 
> Your minting boundary establishes that this identity is a legitimate
> continuation of that one. It does not establish, and does not claim
> to, that the human agreed to what happens at the far end. Nor should
> it - the human is absent by construction. But an agent continuing
> work across four hops with correctly minted assertions at each is
> still an agent whose original mandate said one thing and whose fourth
> hop does another, and nothing in the chain refuses that.
> 
> Two questions, both narrow and both about what ICA deliberately does
> not carry rather than what it does.
> 
> Does the minting boundary carry anything about what the original
> authorization permitted - a scope, a constraint set, an action class -
> or is the assertion purely about identity continuity? Your phrasing
> "re-subjecting across a boundary as a mint rather than an attenuation"
> reads as deliberate on this point, and I would rather understand the
> choice than infer it.
> 
> And where a chain of correctly minted assertions arrives at a
> consequential action, is the receiving service expected to have any
> independent evidence of authorization, or is the chain itself the
> authorization? I am not suggesting ICA should answer that. I am
> asking whether you see it as in scope.
> 
> I ask because the second one is the layer I work on, and if ICA's
> answer is "out of scope, and a separate artifact should carry it",
> then the two compose cleanly and I would rather cite that than assume
> it. If your answer is that the chain is sufficient, I would want to
> understand why, because it is the case my draft exists to refuse.
> 
>   draft-yossif-psea, execution-time authorization evidence
>   https://datatracker.ietf.org/doc/draft-yossif-psea/
> 
>   draft-yossif-agent-mandate-problem, the constraint set a human
>   signs before the agent acts - the T0 half of the same problem
>   https://datatracker.ietf.org/doc/draft-yossif-agent-mandate-problem/
> 
> The second is a problem statement with no mechanism proposed. If ICA
> does carry constraint information across the mint, it may already
> answer part of what that draft only states.
> 
> Mohamad Khalil-Yossif



_______________________________________________
OAuth mailing list -- [email protected]
To unsubscribe send an email to [email protected]

Reply via email to