Hannes requested that some folks read through the assertion drafts and give feedback in light of the upcoming shepherd review.
[1] http://datatracker.ietf.org/doc/draft-ietf-oauth-assertions/ [2] http://datatracker.ietf.org/doc/draft-ietf-oauth-saml2-bearer/ [3] http://datatracker.ietf.org/doc/draft-ietf-oauth-jwt-bearer/ I can't speak to the security considerations or advisability of these drafts, but as far as the documents go I think they are well-organized, consistent (internally and across all 3 documents) and straightforward. A few comments: [1] Section 4.2.1 says in passing that it is an error condition "if more than one client authentication mechanism is used". If this is a true requirement / error state I think it should be called out more strongly. Perhaps 4.2 should say at the top that "Other client authentication mechanisms MUST NOT be used in conjunction with an assertion". If so, [2] 3.2 and [3] 3.2 should also indicate that additional client credentials MUST NOT be used in addition to the assertion for Client Authentication. [3] Section 2.2 first sentence: "client authentication grant" should just be "client authentication". --Amanda Anganes
_______________________________________________ OAuth mailing list [email protected] https://www.ietf.org/mailman/listinfo/oauth
