[OAUTH-WG] (no subject)

2020-01-20 Thread Schlampa Schlampa
___ OAuth mailing list OAuth@ietf.org https://www.ietf.org/mailman/listinfo/oauth

[OAUTH-WG] (no subject)

2020-01-20 Thread Schlampa Schlampa
https://adguard.com/de/versions/android/release.html?utm_source=android_medium=activity_about_campaign=versionhistory ___ OAuth mailing list OAuth@ietf.org https://www.ietf.org/mailman/listinfo/oauth

Re: [OAUTH-WG] [UNVERIFIED SENDER] OAuth Topics for Vancouver

2020-01-20 Thread Richard Backman, Annabelle
To be honest I’m somewhat taken aback by this reaction. The request was for time to discuss an alternative PoP mechanism face-to-face. This is a topic which has come up in the context of other work (e.g., DPoP) at several recent IETF meetings, including the last one in Singapore. While I

Re: [OAUTH-WG] [UNVERIFIED SENDER] OAuth Topics for Vancouver

2020-01-20 Thread Rob Cordes
Hi Annabelle, Sure TLS is not th one size fits all but if you swap out Client Y signs / authenticates message A to recipient X by: Client Y uses TLS for authentication of the source (itself), integrity of data / communications and even confidentiality (not really needed in our HTTP

[OAUTH-WG] (no subject)

2020-01-20 Thread Schlampa Schlampa
___ OAuth mailing list OAuth@ietf.org https://www.ietf.org/mailman/listinfo/oauth

Re: [OAUTH-WG] Question for encrypted POP Key

2020-01-20 Thread Jim Schaad
Never mind, I just saw the answer. -Original Message- From: Jim Schaad Sent: Monday, January 20, 2020 10:57 AM To: 'draft-ietf-oauth-proof-of-possess...@ietf.org' Cc: 'oauth' Subject: Question for encrypted POP Key I am trying to deal with some of the various confirmation methods for

[OAUTH-WG] Question for encrypted POP Key

2020-01-20 Thread Jim Schaad
I am trying to deal with some of the various confirmation methods for a POP token. The question that I have is about the format of the JOSE Encrypted value to be used. The document has an example of a compact serialization for this concept, it does not have an example of a JSON serialization.

Re: [OAUTH-WG] OAuth Topics for Vancouver

2020-01-20 Thread Rob Cordes
Hi, Sorry for me answering in this direct manner instead of via the OAUTH mailing list or so. I would like to point a practical issue out wrt the HTTP signature spec. I have got practical experience with the spec through my work for ING in our PSD2 (European electronic banking scheme)

[OAUTH-WG] HTTP Signing

2020-01-20 Thread Justin Richer
As many of you know, Annabelle and I have put forward a general-purpose HTTP Signing specification in the HTTP Working Group, at least initially based on the old Cavage signatures spec that’s been used in the wild. We expect a number of important changes to happen as it goes through the

Re: [OAUTH-WG] OAuth Topics for Vancouver

2020-01-20 Thread Aaron Parecki
I would like to discuss the Browser app BCP as well as the new draft which got bumped from the agenda in Singapore: https://tools.ietf.org/id/draft-parecki-oauth-client-intermediary-metadata Aaron Parecki aaronparecki.com On Mon, Jan 20, 2020 at 7:34 AM Rifaat Shekh-Yusef wrote: > All,

Re: [OAUTH-WG] OAuth Topics for Vancouver

2020-01-20 Thread Torsten Lodderstedt
Hi Rifaat, I would like to present draft-ietf-oauth-par, draft-lodderstedt-oauth-rar, and draft-ietf-oauth-jwt-introspection-response (if we did not manage to move it forward by then). best regards, Torsten. > On 20. Jan 2020, at 16:32, Rifaat Shekh-Yusef wrote: > > All, > > Please, let

Re: [OAUTH-WG] OAuth Topics for Vancouver

2020-01-20 Thread Daniel Fett
Hi! I would like to discuss DPoP, the Security BCP, and give a brief update about the activities at the FAPI working group. -Daniel Am 20.01.20 um 16:32 schrieb Rifaat Shekh-Yusef: > All, > > Please, let us know if you have any topics that you would like to > present and discuss in Vancouver. >

[OAUTH-WG] OAuth Topics for Vancouver

2020-01-20 Thread Rifaat Shekh-Yusef
All, Please, let us know if you have any topics that you would like to present and discuss in Vancouver. Regards, Rifaat & Hannes ___ OAuth mailing list OAuth@ietf.org https://www.ietf.org/mailman/listinfo/oauth