In preparation for IETF 90 in Toronto<http://www.ietf.org/meeting/90/>, I've 
updated the OAuth Token Exchange draft to allow JWTs to be unsigned in cases 
where the trust model permits it.  This draft also incorporates some of the 
review feedback received on the -00 draft.  (Because I believe it deserves more 
working group discussion to determine the right resolutions, John Bradley's 
terminology feedback was not yet addressed.  This would be a good topic to 
discuss in Toronto.)

This specification is available at:

*        http://tools.ietf.org/html/draft-jones-oauth-token-exchange-01

An HTML formatted version is also available at:

*        http://self-issued.info/docs/draft-jones-oauth-token-exchange-01.html

                                                            -- Mike

P.S.  I also posted this note at http://self-issued.info/?p=1252 and as 
@selfissued.

_______________________________________________
OAuth mailing list
[email protected]
https://www.ietf.org/mailman/listinfo/oauth

Reply via email to