> Karl,
> 
> Nothing to correct. The three-layer split is right, and the sentence I
> would have argued with — PSEA at the hop where the human is present,
> ICA at the hop where they are not — is one I wrote myself, so I will
> leave it standing.
> 
> Open item 9 is where I can be useful, and I think it turns on a
> distinction that is easy to lose because both halves are called
> "testable".
> 
> A representation carried in the envelope and evaluated by the
> receiving authorization server is testable by that server. That is
> useful and it is probably what ICA should carry: scopes are the
> natural form, since scopes are what the receiving server already
> evaluates, and it needs nothing a mint does not already know.
> 
> What it does not give you is a representation a third party can check
> after the fact. The evaluation is performed by a party inside the
> trust boundary the ceiling exists to constrain — the receiving domain
> is bounded by the ceiling and is also the one applying it. A relying
> party that trusts neither the identity provider nor the receiving
> domain cannot re-run the check. That is not hypothetical: a regulator
> reconstructing a decision, a card issuer in a chargeback, a
> counterparty in a dispute. All three arrive after the fact and none of
> them can ask the receiving server to do it again.
> 
> The two are not in tension and they want different things.
> 
> The narrow suggestion: alongside whatever representation the envelope
> carries for evaluation, carry a commitment to it — a digest over a
> canonical form of the ceiling, bound into the assertion. It changes no
> evaluation, adds no field a mint has to understand, and costs a hash.
> What it buys is that a later artifact can reference the exact ceiling
> in force at establishment without ICA having to define what a ceiling
> contains, or take a position on whether it is scopes or an
> authorization detail.
> 
> The reason to want the commitment separate from the representation is
> the one my own draft turns on. A ceiling the identity provider
> computes and the receiving server evaluates establishes what those two
> agreed. It does not establish what the human agreed, because neither
> of them is the human. Keeping the commitment canonical and
> recomputable is what lets an artifact from the layer that does speak
> for the human point at the same bytes.
> 
> So the form matters more than the content. If item 9 resolves toward
> something a third party can recompute over canonical bytes, the layers
> join. If it resolves toward a policy-bound representation only, they
> do not, and the authorization layer has to carry its own copy of the
> ceiling — duplication, and somewhere for the two to drift.
> 
> That is a preference about encoding rather than about scope, and it
> does not ask ICA to carry anything it would not carry anyway.
> 
> On Mission-Bound: I owe you a proper read rather than another
> paragraph. draft-yossif-agent-mandate-problem states requirements and
> deliberately proposes no mechanism, so if Mission-Bound meets them it
> belongs there as related work rather than as an alternative. That
> revision is held on an unrelated question in RATS; when it moves, that
> is the change it carries.
> 
> Mohamad Khalil-Yossif
> 
>   draft-yossif-psea
>   https://datatracker.ietf.org/doc/draft-yossif-psea/
>   draft-yossif-agent-mandate-problem
>   https://datatracker.ietf.org/doc/draft-yossif-agent-mandate-problem/
>   draft-yossif-enrollment-problem
>   https://datatracker.ietf.org/doc/draft-yossif-enrollment-problem/



_______________________________________________
OAuth mailing list -- [email protected]
To unsubscribe send an email to [email protected]

Reply via email to