Hi Charles,

Thanks for your review.

I replied to your question at 
https://github.com/oauth-wg/draft-ietf-oauth-rfc8725bis/issues/65#issuecomment-5296310358.

In short, I believe there are reasons to leave this as is.

                                Thanks,
                                -- Mike

-----Original Message-----
From: Charles Eckel (eckelcu) <[email protected]>
Sent: Friday, August 14, 2026 7:04 AM
To: Yaron Sheffer <[email protected]>
Cc: The IESG <[email protected]>; [email protected]; 
[email protected]; [email protected]; [email protected]
Subject: Re: Charles Eckel's No Objection on draft-ietf-oauth-rfc8725bis-09: 
(with COMMENT)

Hi Yaron,

I appreciate your consideration of my comment.

Thanks,
Charles

On Aug 14, 2026, at 12:50 AM, Yaron Sheffer <[email protected]> wrote:

Thank you Charles for your review!

Opened https://github.com/oauth-wg/draft-ietf-oauth-rfc8725bis/issues/65

Best,
   Yaron

------ Original Message ------
From "Charles Eckel via Datatracker" <[email protected]> To "The IESG" 
<[email protected]> Cc [email protected]; 
[email protected]; [email protected]; [email protected] 
Date 13/08/2026 21:06:44 Subject Charles Eckel's No Objection on 
draft-ietf-oauth-rfc8725bis-09: (with COMMENT)

Charles Eckel has entered the following ballot position for
draft-ietf-oauth-rfc8725bis-09: No Objection

When responding, please keep the subject line intact and reply to all email 
addresses included in the To and CC lines. (Feel free to cut this introductory 
paragraph, however.)


Please refer to 
https://www.ietf.org/about/groups/iesg/statements/handling-ballot-positions/
for more information about how to handle DISCUSS and COMMENT positions.


The document, along with other ballot positions, can be found here:
https://datatracker.ietf.org/doc/draft-ietf-oauth-rfc8725bis/



----------------------------------------------------------------------
COMMENT:
----------------------------------------------------------------------

Thanks to Valery Smyslov for the ARTART review and to the authors for 
addressing the points raised.

## Comments

### Section 3.11, RECOMMENDED vs REQUIRED use of "typ"

681        Explicit typing is RECOMMENDED for new uses of JWTs, because without
682        it, mutually exclusive validation rules are harder to enforce and
683        cross-JWT confusion becomes more likely.

Is there a specific reason the "typ" requirement is "RECOMMENDED" rather than 
"REQUIRED" for new uses of JWTs?




_______________________________________________
OAuth mailing list -- [email protected]
To unsubscribe send an email to [email protected]

Reply via email to