Hi Charles, Thanks for your review.
I replied to your question at https://github.com/oauth-wg/draft-ietf-oauth-rfc8725bis/issues/65#issuecomment-5296310358. In short, I believe there are reasons to leave this as is. Thanks, -- Mike -----Original Message----- From: Charles Eckel (eckelcu) <[email protected]> Sent: Friday, August 14, 2026 7:04 AM To: Yaron Sheffer <[email protected]> Cc: The IESG <[email protected]>; [email protected]; [email protected]; [email protected]; [email protected] Subject: Re: Charles Eckel's No Objection on draft-ietf-oauth-rfc8725bis-09: (with COMMENT) Hi Yaron, I appreciate your consideration of my comment. Thanks, Charles On Aug 14, 2026, at 12:50 AM, Yaron Sheffer <[email protected]> wrote: Thank you Charles for your review! Opened https://github.com/oauth-wg/draft-ietf-oauth-rfc8725bis/issues/65 Best, Yaron ------ Original Message ------ From "Charles Eckel via Datatracker" <[email protected]> To "The IESG" <[email protected]> Cc [email protected]; [email protected]; [email protected]; [email protected] Date 13/08/2026 21:06:44 Subject Charles Eckel's No Objection on draft-ietf-oauth-rfc8725bis-09: (with COMMENT) Charles Eckel has entered the following ballot position for draft-ietf-oauth-rfc8725bis-09: No Objection When responding, please keep the subject line intact and reply to all email addresses included in the To and CC lines. (Feel free to cut this introductory paragraph, however.) Please refer to https://www.ietf.org/about/groups/iesg/statements/handling-ballot-positions/ for more information about how to handle DISCUSS and COMMENT positions. The document, along with other ballot positions, can be found here: https://datatracker.ietf.org/doc/draft-ietf-oauth-rfc8725bis/ ---------------------------------------------------------------------- COMMENT: ---------------------------------------------------------------------- Thanks to Valery Smyslov for the ARTART review and to the authors for addressing the points raised. ## Comments ### Section 3.11, RECOMMENDED vs REQUIRED use of "typ" 681 Explicit typing is RECOMMENDED for new uses of JWTs, because without 682 it, mutually exclusive validation rules are harder to enforce and 683 cross-JWT confusion becomes more likely. Is there a specific reason the "typ" requirement is "RECOMMENDED" rather than "REQUIRED" for new uses of JWTs? _______________________________________________ OAuth mailing list -- [email protected] To unsubscribe send an email to [email protected]
