Hannes requested that some folks read through the assertion drafts and give 
feedback in light of the upcoming shepherd review.

[1] http://datatracker.ietf.org/doc/draft-ietf-oauth-assertions/
[2] http://datatracker.ietf.org/doc/draft-ietf-oauth-saml2-bearer/
[3] http://datatracker.ietf.org/doc/draft-ietf-oauth-jwt-bearer/

I can't speak to the security considerations or advisability of these drafts, 
but as far as the documents go I think they are well-organized, consistent 
(internally and across all 3 documents) and straightforward.

A few comments:

[1] Section 4.2.1 says in passing that it is an error condition "if more than 
one client authentication mechanism is used". If this is a true requirement / 
error state I think it should be called out more strongly. Perhaps 4.2 should 
say at the top that "Other client authentication mechanisms MUST NOT be used in 
conjunction with an assertion".

If so, [2] 3.2 and [3] 3.2 should also indicate that additional client 
credentials MUST NOT be used in addition to the assertion for Client 
Authentication.

[3] Section 2.2 first sentence: "client authentication grant" should just be 
"client authentication".

--Amanda Anganes
_______________________________________________
OAuth mailing list
[email protected]
https://www.ietf.org/mailman/listinfo/oauth

Reply via email to