> Karl, > > I have been meaning to write to you since George Fletcher pointed me > at Mission-Bound Authorization on this list on 22 July. I said then > that I would treat it as primary related work in a revision of my own > draft and have not yet done so, which is my delay, not an oversight. > ICA is a better occasion than the one I was waiting for. > > The framing that interests me is your first sentence about the > absence: the user is not present at the hop, and redirecting to the > identity provider is not an option. That is the same observation I > started from and we have gone opposite directions with it. > > ICA answers it by having each boundary mint fresh, so no credential > travels and no component holds standing authority. I answer it by > requiring evidence produced at the moment of the action by a key the > invoking runtime cannot reach - which means my construction simply > fails in the case ICA is built for. If the user has gone offline > there is no proof to produce, and a profile that says "then refuse" > is not a solution to a continuation problem. > > So these are complementary rather than competing, and I think the > seam between them is worth naming. > > Your minting boundary establishes that this identity is a legitimate > continuation of that one. It does not establish, and does not claim > to, that the human agreed to what happens at the far end. Nor should > it - the human is absent by construction. But an agent continuing > work across four hops with correctly minted assertions at each is > still an agent whose original mandate said one thing and whose fourth > hop does another, and nothing in the chain refuses that. > > Two questions, both narrow and both about what ICA deliberately does > not carry rather than what it does. > > Does the minting boundary carry anything about what the original > authorization permitted - a scope, a constraint set, an action class - > or is the assertion purely about identity continuity? Your phrasing > "re-subjecting across a boundary as a mint rather than an attenuation" > reads as deliberate on this point, and I would rather understand the > choice than infer it. > > And where a chain of correctly minted assertions arrives at a > consequential action, is the receiving service expected to have any > independent evidence of authorization, or is the chain itself the > authorization? I am not suggesting ICA should answer that. I am > asking whether you see it as in scope. > > I ask because the second one is the layer I work on, and if ICA's > answer is "out of scope, and a separate artifact should carry it", > then the two compose cleanly and I would rather cite that than assume > it. If your answer is that the chain is sufficient, I would want to > understand why, because it is the case my draft exists to refuse. > > draft-yossif-psea, execution-time authorization evidence > https://datatracker.ietf.org/doc/draft-yossif-psea/ > > draft-yossif-agent-mandate-problem, the constraint set a human > signs before the agent acts - the T0 half of the same problem > https://datatracker.ietf.org/doc/draft-yossif-agent-mandate-problem/ > > The second is a problem statement with no mechanism proposed. If ICA > does carry constraint information across the mint, it may already > answer part of what that draft only states. > > Mohamad Khalil-Yossif
_______________________________________________ OAuth mailing list -- [email protected] To unsubscribe send an email to [email protected]
