Re: removing keygen from HTML
Harry Halpin <[email protected]> Mon, 30 May 2016 22:04:03 -1000
| Newsgroups | gmane.org.w3c.tag |
|---|---|
| Message-ID | <CAE1ny+5R3n3G2E4u9hjdcvbNKc0MD4i2i3JBDws7DVoe2jJTMQ@mail.gmail.com> |
--001a114670ccfdc6c005341ed09b Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: quoted-printable On Mon, May 30, 2016 at 6:36 AM, Graham Leggett <[email protected]> wrote: > On 30 May 2016, at 4:14 PM, Harry Halpin <[email protected]> wrote: > > > Some folks are using <keygen>, although I think everyone has been > notified of the upcoming deprecation quite a while ago and so hopefully a= re > preparing for a post-<keygen> world if they use client certs in the brows= er > outside of TLS (such as for authentication). One deployment, MIT is worki= ng > to moving to OpenID with Duo two-factor. > > > > It has been requested not to remove it until the replacement is ready, > and I think WebAuthn fulfils the requirements in a way that is coherent > with the Web Security Model. > > I urge the working group to engage the crypto community and let the crypt= o > community decide on what is or isn=E2=80=99t a replacement for keygen. No= =E2=80=9Cproxy > auth=E2=80=9D based system like OpenID is able to replace the capabilitie= s of > client certificates. > I think you are confusing authorization with authentication. Authorization is done by OpenID. MIT uses two-factor authentication (mandatory by June 15), and will likely move to Web Authentication when the code is in browsers. Any other legacy deployments of client certificates for authentication should probably also start working on upgrading their systems to use another authentication protocol. The argument for holding till October is that by then the organizations using client certificates for authentication could upgrade to the Web Authentication API. The crypto community is already engaged in FIDO and Web Authentication and the general work has gone through the peer review process (see publications by Dirk Balfanz, etc.). Although if you find any more cryptographers or security experts, it would be great if they would join the Working Group as an Invited Experts. I do not know anyone from the cryptographic or security community that would support keeping <keygen>. Indeed, the default response from the security/crypto community would be to drop <keygen> due to legacy usage of MD5 and violation of security boundaries (SOP). > > > Here's the WebAuthn schedule - so thus, one-factor cryptographic > authentication should be working across most browsers later in the year, = as > early as October. So far, the Working Group has been moving very fast. > > I would also urge the working group to treat any attempt at rushing this > issue with a significant amount of skepticism. > Note that the general scheme has been under development for several years before the Working Group so the Web Authentication Working Group is not rushing. The general scheme is used internally at Google and many other large organizations, so it makes sense to make it more widely available. cheers, harry > > Regards, > Graham > =E2=80=94 > > --001a114670ccfdc6c005341ed09b Content-Type: text/html; charset=UTF-8 Content-Transfer-Encoding: quoted-printable <div dir=3D"ltr"><br><div class=3D"gmail_extra"><br><div class=3D"gmail_quo= te">On Mon, May 30, 2016 at 6:36 AM, Graham Leggett <span dir=3D"ltr"><<= a href=3D"mailto:[email protected]" target=3D"_blank">[email protected]</a>&g= t;</span> wrote:<br><blockquote class=3D"gmail_quote" style=3D"margin:0 0 0= .8ex;border-left:1px #ccc solid;padding-left:1ex"><span>On 30 May 2016, at= 4:14 PM, Harry Halpin <<a href=3D"mailto:[email protected]" target=3D= "_blank">[email protected]</a>> wrote:<br> <br> > Some folks are using <keygen>, although I think everyone has bee= n notified of the upcoming deprecation quite a while ago and so hopefully a= re preparing for a post-<keygen> world if they use client certs in th= e browser outside of TLS (such as for authentication). One deployment, MIT = is working to moving to OpenID with Duo two-factor.<br> ><br> > It has been requested not to remove it until the replacement is ready,= and I think WebAuthn fulfils the requirements in a way that is coherent wi= th the Web Security Model.<br> <br> </span>I urge the working group to engage the crypto community and let the = crypto community decide on what is or isn=E2=80=99t a replacement for keyge= n. No =E2=80=9Cproxy auth=E2=80=9D based system like OpenID is able to repl= ace the capabilities of client certificates.<br></blockquote><div><br></div= ><div>I think you are confusing authorization with authentication. Authoriz= ation is done by OpenID. MIT uses two-factor authentication (mandatory by J= une 15), and will likely move to Web Authentication when the code is in bro= wsers. Any other legacy deployments of client certificates for authenticati= on should probably also start working on upgrading their systems to use ano= ther authentication protocol. The argument for holding till October is that= by then the organizations using client certificates for authentication cou= ld upgrade to the Web Authentication API.=C2=A0 <br></div><div>=C2=A0</div>= <div>The crypto community is already engaged in FIDO and Web Authentication= and the general work has gone through the peer review process (see publica= tions by Dirk Balfanz, etc.). Although if you find any more cryptographers = or security experts, it would be great if they would join the Working Group= as an Invited Experts.<br><br></div><div>I do not know anyone from the cry= ptographic or security community that would support keeping <keygen>.= Indeed, the default response from the security/crypto community would be t= o drop <keygen> due to legacy usage of MD5 and violation of security = boundaries (SOP). <br></div><div><br>=C2=A0<br></div><blockquote class=3D"g= mail_quote" style=3D"margin:0 0 0 .8ex;border-left:1px #ccc solid;padding-l= eft:1ex"> <span><br> > Here's the WebAuthn schedule - so thus, one-factor cryptographic a= uthentication should be working across most browsers later in the year, as = early as October. So far, the Working Group has been moving very fast.<br> <br> </span>I would also urge the working group to treat any attempt at rushing = this issue with a significant amount of skepticism.<br></blockquote><div><b= r></div><div><br>Note that the general scheme has been under development fo= r several years before the Working Group so the Web Authentication Working = Group is not rushing. The general scheme is used internally at Google and m= any other large organizations, so it makes sense to make it more widely ava= ilable. <br><br></div><div>=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0 cheer= s,<br></div><div>=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2= =A0=C2=A0=C2=A0 harry<br><br></div><div><br>=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0= =C2=A0=C2=A0 <br><br><br>=C2=A0<br></div><blockquote class=3D"gmail_quote" = style=3D"margin:0 0 0 .8ex;border-left:1px #ccc solid;padding-left:1ex"> <br> Regards,<br> Graham<br> =E2=80=94<br> <br> </blockquote></div><br></div></div> --001a114670ccfdc6c005341ed09b--