Re: [OAUTH-WG] draft-ietf-oauth-dpop-00 comments

2020-04-07 Thread Benjamin Kaduk
On Tue, Apr 07, 2020 at 03:31:09PM -0600, Brian Campbell wrote: > One of the primary motivations for the proof-of-possession mechanism of > DPoP being at the application layer was to hopefully enable implementation > and deployment by regular application developers. A lesson learned from the >

Re: [OAUTH-WG] draft-ietf-oauth-dpop-00 comments

2020-04-07 Thread Brian Campbell
One of the primary motivations for the proof-of-possession mechanism of DPoP being at the application layer was to hopefully enable implementation and deployment by regular application developers. A lesson learned from the difficulties and lack of adoption around Token Binding was that access to

[OAUTH-WG] Web Authorization Protocol (oauth) WG Virtual Meeting: 2020-05-11

2020-04-07 Thread IESG Secretary
The Web Authorization Protocol (oauth) Working Group will hold a virtual interim meeting on 2020-05-11 from 12:00 to 13:00 America/Toronto (16:00 to 17:00 UTC). Agenda: 1. Client Intermediary Metadata https://tools.ietf.org/html/draft-parecki-oauth-client-intermediary-metadata-00 2. Reciprocal

[OAUTH-WG] Web Authorization Protocol (oauth) WG Virtual Meeting: 2020-05-04

2020-04-07 Thread IESG Secretary
The Web Authorization Protocol (oauth) Working Group will hold a virtual interim meeting on 2020-05-04 from 12:00 to 13:00 America/Toronto (16:00 to 17:00 UTC). Agenda: 1. Demonstration of Proof-of-Possession at the Application Layer https://datatracker.ietf.org/doc/draft-ietf-oauth-dpop/ 2.

[OAUTH-WG] Web Authorization Protocol (oauth) WG Virtual Meeting: 2020-04-27

2020-04-07 Thread IESG Secretary
The Web Authorization Protocol (oauth) Working Group will hold a virtual interim meeting on 2020-04-27 from 12:00 to 13:00 America/Toronto (16:00 to 17:00 UTC). Agenda: 1. The OAuth 2.1 Authorization Framework https://datatracker.ietf.org/doc/draft-parecki-oauth-v2-1/ 2. JWT Response for OAuth

[OAUTH-WG] Web Authorization Protocol (oauth) WG Virtual Meeting: 2020-04-20

2020-04-07 Thread IESG Secretary
The Web Authorization Protocol (oauth) Working Group will hold a virtual interim meeting on 2020-04-20 from 12:00 to 13:00 America/Toronto (16:00 to 17:00 UTC). Agenda: 1. Pushed Authorization Requests https://datatracker.ietf.org/doc/draft-ietf-oauth-par/ 2. Rich Authorization Requests

[OAUTH-WG] Web Authorization Protocol (oauth) WG Virtual Meeting: 2020-04-13

2020-04-07 Thread IESG Secretary
The Web Authorization Protocol (oauth) Working Group will hold a virtual interim meeting on 2020-04-13 from 12:00 to 13:00 America/Toronto (16:00 to 17:00 UTC). Agenda: 1. Nested JWT https://www.ietf.org/archive/id/draft-yusef-oauth-nested-jwt-03.txt 2. JWT Profile for Access Tokens

[OAUTH-WG] Fwd: (Forward to others) Webex meeting invitation: OAuth WG Virtual Interim Meeting - May 11th

2020-04-07 Thread Rifaat Shekh-Yusef
BEGIN:VCALENDAR PRODID:-//Microsoft Corporation//Outlook 10.0 MIMEDIR//EN VERSION:2.0 METHOD:REQUEST BEGIN:VTIMEZONE TZID:America/New_York TZURL:http://tzurl.org/zoneinfo-outlook/America/New_York X-LIC-LOCATION:America/New_York BEGIN:DAYLIGHT TZOFFSETFROM:-0500 TZOFFSETTO:-0400 TZNAME:EDT

[OAUTH-WG] Fwd: (Forward to others) Webex meeting invitation: OAuth WG Virtual Interim Meeting - May 4th

2020-04-07 Thread Rifaat Shekh-Yusef
BEGIN:VCALENDAR PRODID:-//Microsoft Corporation//Outlook 10.0 MIMEDIR//EN VERSION:2.0 METHOD:REQUEST BEGIN:VTIMEZONE TZID:America/New_York TZURL:http://tzurl.org/zoneinfo-outlook/America/New_York X-LIC-LOCATION:America/New_York BEGIN:DAYLIGHT TZOFFSETFROM:-0500 TZOFFSETTO:-0400 TZNAME:EDT

[OAUTH-WG] Fwd: (Forward to others) Webex meeting invitation: OAuth WG Virtual Interim Meeting - April 27th

2020-04-07 Thread Rifaat Shekh-Yusef
BEGIN:VCALENDAR PRODID:-//Microsoft Corporation//Outlook 10.0 MIMEDIR//EN VERSION:2.0 METHOD:REQUEST BEGIN:VTIMEZONE TZID:America/New_York TZURL:http://tzurl.org/zoneinfo-outlook/America/New_York X-LIC-LOCATION:America/New_York BEGIN:DAYLIGHT TZOFFSETFROM:-0500 TZOFFSETTO:-0400 TZNAME:EDT

[OAUTH-WG] Fwd: (Forward to others) Webex meeting invitation: OAuth WG Virtual Interim Meeting - April 20th

2020-04-07 Thread Rifaat Shekh-Yusef
BEGIN:VCALENDAR PRODID:-//Microsoft Corporation//Outlook 10.0 MIMEDIR//EN VERSION:2.0 METHOD:REQUEST BEGIN:VTIMEZONE TZID:America/New_York TZURL:http://tzurl.org/zoneinfo-outlook/America/New_York X-LIC-LOCATION:America/New_York BEGIN:DAYLIGHT TZOFFSETFROM:-0500 TZOFFSETTO:-0400 TZNAME:EDT

[OAUTH-WG] Fwd: (Forward to others) Webex meeting invitation: OAuth WG Virtual Interim Meeting - April 13th

2020-04-07 Thread Rifaat Shekh-Yusef
BEGIN:VCALENDAR PRODID:-//Microsoft Corporation//Outlook 10.0 MIMEDIR//EN VERSION:2.0 METHOD:REQUEST BEGIN:VTIMEZONE TZID:America/New_York TZURL:http://tzurl.org/zoneinfo-outlook/America/New_York X-LIC-LOCATION:America/New_York BEGIN:DAYLIGHT TZOFFSETFROM:-0500 TZOFFSETTO:-0400 TZNAME:EDT

[OAUTH-WG] oauth - New Interim Meeting Request

2020-04-07 Thread IETF Meeting Session Request Tool
A new interim meeting request has just been submitted by Rifaat Shekh-Yusef. This request requires approval by the Area Director of the Security Area The meeting can be approved here: https://datatracker.ietf.org/meeting/interim/request/interim-2020-oauth-08

[OAUTH-WG] oauth - New Interim Meeting Request

2020-04-07 Thread IETF Meeting Session Request Tool
A new interim meeting request has just been submitted by Rifaat Shekh-Yusef. This request requires approval by the Area Director of the Security Area The meeting can be approved here: https://datatracker.ietf.org/meeting/interim/request/interim-2020-oauth-07

[OAUTH-WG] oauth - New Interim Meeting Request

2020-04-07 Thread IETF Meeting Session Request Tool
A new interim meeting request has just been submitted by Rifaat Shekh-Yusef. This request requires approval by the Area Director of the Security Area The meeting can be approved here: https://datatracker.ietf.org/meeting/interim/request/interim-2020-oauth-06

[OAUTH-WG] oauth - New Interim Meeting Request

2020-04-07 Thread IETF Meeting Session Request Tool
A new interim meeting request has just been submitted by Rifaat Shekh-Yusef. This request requires approval by the Area Director of the Security Area The meeting can be approved here: https://datatracker.ietf.org/meeting/interim/request/interim-2020-oauth-05

[OAUTH-WG] oauth - New Interim Meeting Request

2020-04-07 Thread IETF Meeting Session Request Tool
A new interim meeting request has just been submitted by Rifaat Shekh-Yusef. This request requires approval by the Area Director of the Security Area The meeting can be approved here: https://datatracker.ietf.org/meeting/interim/request/interim-2020-oauth-04

Re: [OAUTH-WG] oauth-browser-based-apps-05 - BFF

2020-04-07 Thread George Fletcher
Sorry to have missed the meeting. To your second point, I think we should provide guidance in this area. Currently section 6.2 requires all requests to be proxied via the application server. Should we add an additional section for the use case Vittorio mentions? Also there is no mention of