Skip to Content.
Sympa Menu

oidc-survey - Re: Fwd: Re: [mitreid-connect] token chaining ....

Subject: OIDC Survey Working Group

List archive

Re: Fwd: Re: [mitreid-connect] token chaining ....


Chronological Thread 
  • From: David Walker <>
  • To: <>
  • Subject: Re: Fwd: Re: [mitreid-connect] token chaining ....
  • Date: Thu, 12 Jan 2017 11:57:36 -0800
  • Authentication-results: spf=none (sender IP is ) ;
  • Ironport-phdr: 9a23:btvwlRK84LYywQGe9NmcpTZWNBhigK39O0sv0rFitYgeIvXxwZ3uMQTl6Ol3ixeRBMOAuq4C0LKd6vu4EUU7or+5+EgYd5JNUxJXwe43pCcHRPC/NEvgMfTxZDY7FskRHHVs/nW8LFQHUJ2mPw6arXK99yMdFQviPgRpOOv1BpTSj8Oq3Oyu5pHfeQtFiT6ybL9oIhi6sQrdutQYjId+N6081gbHrnxUdupM2GhmP0iTnxHy5sex+J5s7SFdsO8/+sBDTKv3Yb02QaRXAzo6PW814tbrtQTYQguU+nQcSGQWnQFWDAXD8Rr3Q43+sir+tup6xSmaIcj7Rq06VDi+86tmTgLjhSEaPDA77W7XkNR9gr9FrhKvpxJxwIDab4+aO/V8YqzdfMgXRWVdUstLUCJNHo2xYokJAuEcPehYtY79p14WoBWwHwasGuLvxSJVjXD2x6I61+chHh/c3Ac9GN8BrXrVo8/xNKcRT++11rLFzTTFb/NKxzj98o7IfQ49of2SR75/b9feyVQ2Gg7Dk16ep4vlPzaP2eQMtWiW9+tgWvyzi24psQ1xpSKvxsg0honMh4IV1krI+jtkz4YoI9CzVU11Yca8HZdNqy2XOJF6T8wgTm1ytis3yKcKtYO1cSUK0Jgr2hHSZ+Kdf4SW4h/uW/ydLDhliH5/fL+yhhC/+lW6xOLmTMm7ylNKozJFktbSsnAN0ATe5NCbR/V64kutxy+D2h7R5e1ZOEw0krHUJIA7zr43i5oTrV/MHijrmEXwkaCabF0k+vKv6+T7fLrpuoOcN45zigH4KKgundG/Afg8MggJWGib+v6w26Hk/U38WLlKj/s2nbfFsJ3COMgXuqG0DxVa34sh8RqyATWr3M4FkXQJLF9JYBeHgJLoO1HKLvD4F/C/g1G0nTh2yfHJJLnhApbTIXjZi7rhfLB961JCxwopy9BQ+Y5UBq8bLP3tR0DxqcTUDgUlPAys3+bnFNJ925sfWWKJHqCZN6bSsVqP5uIpOeWMY5UVuDnkJ/gi5v7hkGM2lUYGfam0x5sXdm63H/R9LkWdYHrsmcsBEXwUsgYkTezqjkGCXiBJZ3a0Qa08+i83BJi4AojeW4D+yICGiXO8H5FdI3tbEE6BAF/pcY6DXvILbmSVOMA3wRIeUr30Z4Y/1B3miwb+yLd9Zr7Y5SQctp/5/Nlz++DJkxwur3p5A9nLgDLFdH19gm5dH2x+56t4u0Eoklo=
  • Spamdiagnosticmetadata: NSPM
  • Spamdiagnosticoutput: 1:99

Very interesting, Steve.   Probably out of scope for our survey group, but here are some thoughts.

I notice that the newer RFC addresses impersonation, as well as delegation.  I wonder what the use case is that couldn't be satisfied with delegation, since, as far as I can tell, delegation is impersonation plus a record of who's impersonating.

David


On 01/12/2017 06:58 AM, Steven Carmody wrote:
Hi,

we were chatting about this sort of functionality on last friday's call ..... interesting

The MITRED OIDC/OAuth2 implementation is a very popular open source implementation. Justin seems to be the primary implementer.

The first rfc says in its abstract:

> This document provides a method for a resource server to present a
>    token that it has received from a client back to its authorization
>    server for the purposes of receiving a derivative token for use on
>    another resource server in order to chain together service requests.

That's what I'm looking for. But, that info rfc is long expired.

The second rfc is authored by the usual set of OAuth2 suspects, including Mike Jones, Tony Nadalin, John Bradley, etc. It re-introduces our old friend the STS from the WS protocols:

>  This specification defines a protocol for an HTTP- and JSON- based
>    Security Token Service (STS) by defining how to request and obtain
>    security tokens from OAuth 2.0 authorization servers, including
>    security tokens employing impersonation and delegation.

The second rfc is active, tho.


-------- Forwarded Message --------
Subject: Re: [mitreid-connect] token chaining ....
Date: Tue, 10 Jan 2017 14:03:17 -0500
From: Justin Richer
To: Steven Carmody
CC:

MITREid Connect currently implements this expired draft for token chaining:

https://tools.ietf.org/html/draft-richer-oauth-chain-00

The OAuth Working Group is currently working on something with similar (but much more complicated) functionality:
https://tools.ietf.org/html/draft-ietf-oauth-token-exchange-06

Nothing is published as an RFC yet.
 — Justin


On Jan 9, 2017, at 3:18 PM, Steven Carmody wrote:

Hi,

The MITRED documentation says that it supports token chaining -- but I'm
having trouble finding a current rfc that describes this
protocol/profile .... is there one ? Is there a description of what the
package supports for token chaining, and an example of how to use it ?

thanks !
_______________________________________________
mitreid-connect mailing list

http://mailman.mit.edu/mailman/listinfo/mitreid-connect


Attachment: signature.asc
Description: OpenPGP digital signature




Archive powered by MHonArc 2.6.19.

Top of Page