Re: [Ace] draft-ietf-ace-oauth-authz

2020-05-04 Thread Carsten Bormann
On 2020-05-05, at 06:54, Jim Schaad wrote: > > I have much the same problem. While a client could find an AS which would > authenticate the client, I don't know how the client would establish any > degree of trust in the AS which is going to give it tokens. Hence the four-corner model [1].

Re: [Ace] draft-ietf-ace-oauth-authz

2020-05-04 Thread Jim Schaad
I have much the same problem. While a client could find an AS which would authenticate the client, I don't know how the client would establish any degree of trust in the AS which is going to give it tokens. If you have already put a local public key for the AS into the client, then you might as

[Ace] Fwd: Reminder: Survey on planning for possible online IETF meetings

2020-05-04 Thread Daniel Migault
Hi, The IETF Executive Director and leadership need community input on how to handle virtual meetings. Please feel free to complete the survey. Thanks, Daniel -- Forwarded message - From: IETF Executive Director Date: Mon, May 4, 2020 at 3:04 AM Subject: Reminder: Survey on

[Ace] Multicast notifications for distributing public keys to other group members

2020-05-04 Thread Göran Selander
Dear CoRE and ACE, Apologies for cross-posting, this concerns the security for CoAP group communications (which is a CoRE draft) and the current specified method to retrieve public keys for group communication (which is an ACE draft). When a node joins a group [0] there is a need for group

Re: [Ace] [COSE] draft-raza-ace-cbor-certificates-04.txt

2020-05-04 Thread Göran Selander
Hi Laurence, and all, Thanks for providing a taxonomy. As mentioned, type 0 is clearly in the current draft COSE charter, and we see also the need for a representation of the X.509 profile in RFC 7925 which relieves constrained devices from implementing DER/ASN.1 encoding as well as

Re: [Ace] draft-ietf-ace-oauth-authz

2020-05-04 Thread Seitz Ludwig
Peter, Why not document what you invent in a draft? To me it would be a good starting point. /Ludwig From: Peter van der Stok Sent: den 4 maj 2020 09:15 To: Carsten Bormann Cc: Seitz Ludwig ; Jim Schaad ; peter van der Stok ; Ace Subject: Re: [Ace] draft-ietf-ace-oauth-authz Hi Carsten,

Re: [Ace] draft-ietf-ace-oauth-authz

2020-05-04 Thread Olaf Bergmann
Hi Peter, Peter van der Stok writes: > When I want to access an OCF device I can find its IP address through > service discovery (rfc7252 section 7) using an rt-value registered at > the IANA core parameters registry. For example, when I want to > initialize the AS I have to type in the IP

Re: [Ace] draft-ietf-ace-oauth-authz

2020-05-04 Thread Peter van der Stok
Hi Carsten, The imagination will not have finished its work in 10 yeras time if coap and the authorization will enjoy the success they merit. Also I don't see anybody being ready to start such a document the coming month. Do you see another document in which a first set of these registrations

Re: [Ace] draft-ietf-ace-oauth-authz

2020-05-04 Thread Carsten Bormann
On 2020-05-04, at 08:42, Seitz Ludwig wrote: > > For the sake of getting the document finished before I die of old age ;-) > would it be possible to specify this in a separate document? I think there may be multiple of these RT registrations, because the fact that a resource is part of an AS

Re: [Ace] draft-ietf-ace-oauth-authz

2020-05-04 Thread Seitz Ludwig
For the sake of getting the document finished before I die of old age ;-) would it be possible to specify this in a separate document? /Ludwig From: Ace On Behalf Of Peter van der Stok Sent: den 1 maj 2020 08:56 To: Jim Schaad Cc: consulta...@vanderstok.org; 'Ace' Subject: Re: [Ace]