[OAUTH-WG] Barry Leiba's No Objection on draft-ietf-oauth-assertions-17: (with COMMENT)

2014-10-14 Thread Barry Leiba
Barry Leiba has entered the following ballot position for draft-ietf-oauth-assertions-17: No Objection When responding, please keep the subject line intact and reply to all email addresses included in the To and CC lines. (Feel free to cut this introductory paragraph, however.) Please refer to h

[OAUTH-WG] Pete Resnick's No Objection on draft-ietf-oauth-jwt-bearer-10: (with COMMENT)

2014-10-14 Thread Pete Resnick
Pete Resnick has entered the following ballot position for draft-ietf-oauth-jwt-bearer-10: No Objection When responding, please keep the subject line intact and reply to all email addresses included in the To and CC lines. (Feel free to cut this introductory paragraph, however.) Please refer to

[OAUTH-WG] Pete Resnick's No Objection on draft-ietf-oauth-saml2-bearer-21: (with COMMENT)

2014-10-14 Thread Pete Resnick
Pete Resnick has entered the following ballot position for draft-ietf-oauth-saml2-bearer-21: No Objection When responding, please keep the subject line intact and reply to all email addresses included in the To and CC lines. (Feel free to cut this introductory paragraph, however.) Please refer t

[OAUTH-WG] Pete Resnick's No Objection on draft-ietf-oauth-assertions-17: (with COMMENT)

2014-10-14 Thread Pete Resnick
Pete Resnick has entered the following ballot position for draft-ietf-oauth-assertions-17: No Objection When responding, please keep the subject line intact and reply to all email addresses included in the To and CC lines. (Feel free to cut this introductory paragraph, however.) Please refer to

Re: [OAUTH-WG] [kitten] I-D Action: draft-ietf-kitten-sasl-oauth-16.txt

2014-10-14 Thread Richer, Justin P.
I agree with Phil on this one (hey, it happens!): this is a classic example of having one piece of software and many instances of it talking to many different service providers. Each of those pairings is going to need to agree on a client ID, and one would hope a client secret or equivalent. It'

Re: [OAUTH-WG] Ted Lemon's No Objection on draft-ietf-oauth-json-web-token-27: (with COMMENT)

2014-10-14 Thread Ted Lemon
On Oct 14, 2014, at 7:53 AM, Mike Jones wrote: > The proposed resolution below has been applied to the -28 draft. Thanks! ___ OAuth mailing list OAuth@ietf.org https://www.ietf.org/mailman/listinfo/oauth

Re: [OAUTH-WG] Richard Barnes' Discuss on draft-ietf-oauth-json-web-token-27: (with DISCUSS and COMMENT)

2014-10-14 Thread Mike Jones
The proposed resolution below has been incorporated in the -28 draft. Hopefully you can clear your DISCUSS on that basis. Thanks again, -- Mike > -Original Message- > From: OAuth [mailto:oauth-boun...@ietf.org] On Behalf Of

Re: [OAUTH-WG] Ted Lemon's No Objection on draft-ietf-oauth-json-web-token-27: (with COMMENT)

2014-10-14 Thread Mike Jones
The proposed resolution below has been applied to the -28 draft. Thanks again, -- Mike > -Original Message- > From: OAuth [mailto:oauth-boun...@ietf.org] On Behalf Of Mike Jones > Sent: Tuesday, October 07, 2014 6:06 PM > To:

Re: [OAUTH-WG] Stephen Farrell's Discuss on draft-ietf-oauth-json-web-token-27: (with DISCUSS and COMMENT)

2014-10-14 Thread Mike Jones
The proposed resolutions below have been included in the -28 draft. Hopefully you'll be able to clear your DISCUSSes on that basis. The String Comparison Rules in Section 7.3 have been expanded to talk about when the application may need canonicalization rules.

Re: [OAUTH-WG] Barry Leiba's Discuss on draft-ietf-oauth-json-web-token-27: (with DISCUSS and COMMENT)

2014-10-14 Thread Mike Jones
The proposed resolutions have been applied to the -28 draft. Hopefully this will enable to clear your DISCUSSes. Thanks again for the careful read! -- Mike > -Original Message- > From: OAuth [mailto:oauth-boun...@ietf.org] On Behalf Of Mike Jones > Sent:

Re: [OAUTH-WG] Alissa Cooper's Discuss on draft-ietf-oauth-json-web-token-27: (with DISCUSS)

2014-10-14 Thread Mike Jones
These resolutions have been incorporated in the -28 draft. Thanks again for your review. -- Mike From: Kathleen Moriarty [mailto:kathleen.moriarty.i...@gmail.com] Sent: Thursday, October 02, 2014 8:21 AM To: Mike Jones Cc: Alissa Coope

[OAUTH-WG] FW: JOSE -34 and JWT -28 drafts addressing IESG review comments

2014-10-14 Thread Mike Jones
From: Mike Jones Sent: Tuesday, October 14, 2014 5:39 AM To: j...@ietf.org Subject: JOSE -34 and JWT -28 drafts addressing IESG review comments Updated JOSE and JWT specifications have been published that address the IESG review comments received. The one set of normative changes was to change

[OAUTH-WG] I-D Action: draft-ietf-oauth-json-web-token-28.txt

2014-10-14 Thread internet-drafts
A New Internet-Draft is available from the on-line Internet-Drafts directories. This draft is a work item of the Web Authorization Protocol Working Group of the IETF. Title : JSON Web Token (JWT) Authors : Michael B. Jones John Bradley

Re: [OAUTH-WG] Blackhat US: OAuth Talk

2014-10-14 Thread Antonio Sanso
hi Hannes, thanks for the link. It is interesting. Said that I think the attack shown there are a bit “academic” and do not reflect the real life situation. Moreover it still mention the MAC flow when AFAIK the OAuth working group decided to deviate from it. IMHO the majority of real life attack

Re: [OAUTH-WG] New Version Notification for draft-hunt-oauth-v2-user-a4c-05.txt

2014-10-14 Thread Sergey Beryozkin
Sorry for the noise, On 14/10/14 10:25, Sergey Beryozkin wrote: Hi Phil, All, Thanks for your positive feedback and further comments below. My goal was really about trying to make a clear picture in my mind about what OIDC is with respect to OAuth2, and specifically supporting the point about OI

[OAUTH-WG] SPOP - code verifier requirements

2014-10-14 Thread Nat Sakimura
In his mail, Mike asked whether code verifier is a value that is sendable without trnasformation as a http parameter value, or if it needs to be % encoded when it is being sent. We have several options here: 1) Require that the code verifier to be a base64url encoded string of a binary rand

Re: [OAUTH-WG] New Version Notification for draft-hunt-oauth-v2-user-a4c-05.txt

2014-10-14 Thread Sergey Beryozkin
Hi Phil, All, Thanks for your positive feedback and further comments below. My goal was really about trying to make a clear picture in my mind about what OIDC is with respect to OAuth2, and specifically supporting the point about OIDC not being just OAuth2. As such, the idea of a specific OID

[OAUTH-WG] Define a server capaiblity discovery parameter? (was: Re: OAuth SPOP Detailed Review)

2014-10-14 Thread Nat Sakimura
In his mail, Hannes suggested to include more explicit reference to a feature in the OpenID Connect Discovery spec in section 3.1. My response to it was that we could define a parameter here and ask the implementers to implement it. Questions remains whether we want to define it here or leave i

Re: [OAUTH-WG] Review draft-ietf-oauth-spop-00

2014-10-14 Thread Nat Sakimura
Hi Eduardo, I have accepted all the "Suggestions" in the forthcoming version. You can see my private editing copy at https://bitbucket.org/Nat/oauth-spop/commits/f0f8599 to see how it has been incorporated. Best, Nat On Wed, 03 Sep 2014 01:57:31 -0600 Eduardo Gueiros wrote: > -BEGI