Re: Add "oauth-authorization-resource" attribute?

Michael Sweet via ipp <[email protected]>
Newsgroups gmane.ietf.ipp
Message-ID <[email protected]>
Smith,

I still need to finish updating the wiki for the last meeting's minutes... Anywsyd...

> On Nov 7, 2022, at 9:46 PM, Kennedy, Smith (Wireless & IPP Standards) <[email protected]> wrote:
> 
> That sounds right - I couldn't remember how this played out and it doesn't seem to be covered in the wiki page.
> 
> However, I'm worried about that conclusion. If we advise that the Client supplies the "printer-uri" value as the resource identifier, wouldn't this mean that the Authentication Service needs to know the printer's current URI? That could be in the .local domain which isn't really any more useful or verifiable than a printer-uuid value. (Obviously how the printer and Authentication Service talk to one another is outside our scope of concern but that would affect whether the printer could register its URI with the Authentication Service.)
> 
> It seems like we could define the attribute but then provide guidance for how best to use it?

OK, so the subject of a "canonical" printer URI was something I've brought up as well.

From a standards-perspective the printer advertises its supported URIs, security mechanisms, and authentication methods, so the printer-uri-supported/uri-authentication-supported/uri-security-supported trio and printer/system-xri-supported collection attributes will indicate which URIs to use and which URIs support OAuth.

From a security standpoint, the same authentication and security (encryption) methods should be used/supported for all URIs, otherwise you are just creating "back doors".  For interoperability you  don't want to create a situation where a Client is confused about the URI, authentication, or security that it should use.

All that said, I don't think we can design or recommend a configuration where a Client can discover a Printer via mDNS, use a .local hostname, *and* use a cloud/remote OAuth authorization server with token exchange since there is no way to ensure that the printer-uri is globally unique.

________________________
Michael Sweet

_______________________________________________
ipp mailing list
[email protected]
https://www.pwg.org/mailman/listinfo/ipp
signature.asc (application/pgp-signature, 833 B)
-----BEGIN PGP SIGNATURE-----

iQIzBAEBCAAdFiEEkIbDzcZsP1Y8+PQFvmfHXsgfMkQFAmNqPS8ACgkQvmfHXsgf
MkSHAQ//YJcZIdII/QPlXI+c1/XgkQ1XN7lEcHdZgrO1WdrfXgYu1OnydkpyTntM
L5hwId5BsTY+nTVeNFz846g5W4MV/FsOyVESzDMlKIqWLn0a79LAmaxHKmdvtyZa
7CVX9CQDEKgnhjAB5NibFnybzLGBy55bNc3JnEmaTYBQW7GXHkNcPbLuHowAOVIN
e9Gr2oVn7Xj1gYi3ba81ZzOKa12Cr28AcBznYY+vSPIBoOoFIac4E4kh5EVkb7tV
8JfAgXxkQcADW29WYY9Hp3+RZidYpamq7ir5bWyfyCjccN96r6GWJ2uWILXimZXe
Js8pVA8ot7UUEpBWUS6YpcJqleLWSCe5sGGghsZ8ssodBgnYpz+WVpBhaitjvrMf
SXtmb2M/hizcAH13WSaE9oaLPsBAwEeMkPQx7xIwufpIxTf8AuAZxz/QWr+INwY7
fgVUiE6ga+8Pbu/YeJtSAJn9grr+c56/lfopEy9pHvxCm7EC9w9vxyTQzP5I9wZW
60OVqJfrKpqgoC8ae0op0g56CVY5yAtWPErLAwhVLjbMzUVL2A0aHriTWv0RGDC5
r6ccVnV8PdAw8f8RyCzW+V3q0HBYVX+DyYqXP6tLcxnDBY8m8nJQOaVvS2TTwssL
lwn82jMBRA+F4e4fVnt2HyDS2KxK7n+oOdcj3cP3S5nvKOrDFC8=
=FZvc
-----END PGP SIGNATURE-----
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.