Hello ACE,I have posted an update of our draft, please see the changelog for what has been updated.
I am in the middle of implementing this, and I'd encourage others to do so as well (https://bitbucket.org/lseitz/ace-java).
I would also welcome review comments, especially on the Client Token (CT) concept which is probably the most radical change wrt vanilla OAuth 2.0. I would like you to specially consider the following questions:
a.) Do you think the usecase for CT is valid? b.) Do you think CT is a reasonable solution for the usecase? (alternative solutions or suggestions for improvement are welcome)c.) Should the CT (or an alternative solution) be part of this draft or should it be a separate draft (or none at all)?
Regards, Ludwig -------- Forwarded Message -------- A new version of I-D, draft-ietf-ace-oauth-authz-05.txt has been successfully submitted by Ludwig Seitz and posted to the IETF repository. Name: draft-ietf-ace-oauth-authz Revision: 05 Title: Authentication and Authorization for Constrained Environments (ACE) Document date: 2017-02-03 Group: ace Pages: 62URL: https://www.ietf.org/internet-drafts/draft-ietf-ace-oauth-authz-05.txt
Status: https://datatracker.ietf.org/doc/draft-ietf-ace-oauth-authz/ Htmlized: https://tools.ietf.org/html/draft-ietf-ace-oauth-authz-05Diff: https://www.ietf.org/rfcdiff?url2=draft-ietf-ace-oauth-authz-05
Abstract: This specification defines a framework for authentication and authorization in Internet of Things (IoT) environments. The framework is based on a set of building blocks including OAuth 2.0 and CoAP, thus making a well-known and widely used authorization solution suitable for IoT devices. Existing specifications are used where possible, but where the constraints of IoT devices require it, extensions are added and profiles are defined. Please note that it may take a couple of minutes from the time of submission until the htmlized version and diff are available at tools.ietf.org. The IETF Secretariat
smime.p7s
Description: S/MIME Cryptographic Signature
_______________________________________________ Ace mailing list [email protected] https://www.ietf.org/mailman/listinfo/ace
