Re: [OAUTH-WG] [E] Re: Draft Proposal for a Cross Device Flow Security BCP

2022-10-26 Thread Hjelm, Bjorn
As an editorial note, the text referenced (section 5.2.4) by Joseph, "If FIDO2/WebAuthn support is not available, Channel Initiated Backchannel Authentication (CIBA) provides an alternative.." should reference "Client Initiated Backchannel Authentication (CIBA)". This reference is correct in the

Re: [OAUTH-WG] WGLC for Step-up Authentication

2022-10-26 Thread Jaimandeep Singh
Dear Rifaat, I respect your decision and wish all the best to the authors and members going forward. I would also like to bring to your kind attention that the discussions on Item No 5 which suggested inclusion of client app parameters in the signal flow could not be even started. I quote one of

[OAUTH-WG] Fine-grained Transactional Authorization (formerly RPC authorization)

2022-10-26 Thread Atul Tulshibagwale
Hi all, I've been posting periodically about an initiative that we hope to discuss during the IETF 115 sessions, which we are now calling Fine-grained Transactional Authorization (FTA). As a group of about 10-15 people, we have met a few times online, and arrived at this charter document for the

Re: [OAUTH-WG] WGLC for Step-up Authentication

2022-10-26 Thread Rifaat Shekh-Yusef
Jaimandeep, With the chair hat on, and as the shepherd for this document, I think that the authors addressed your comments in detail, and Warren provided you with some valuable responses. I do not see a need for any further discussion at this stage. The next step is the shepherd review, which

Re: [OAUTH-WG] Security Topics | Incorporate in-browser communication security considerations | PR53

2022-10-26 Thread Donna Chong Nee
Hi, thanks so much. Will take my time amending this with some help. Smart E11 On Thu, 27 Oct 2022, 02:16 Daniel Fett, wrote: > Hi Christian, > > thanks for bringing this to our attention! I think the recommendations in > the PR are very helpful and we will consider adding the text to the >

Re: [OAUTH-WG] Draft Proposal for a Cross Device Flow Security BCP

2022-10-26 Thread Pieter Kasselman
Thanks Joseph, those are good additions, thanks for pointing them out. I have opened issues to track both of them. -Original Message- From: Joseph Heenan Sent: Tuesday, October 25, 2022 11:49 AM To: Pieter Kasselman Cc: oauth@ietf.org; Daniel Fett ; Filip Skokan Subject: Re:

Re: [OAUTH-WG] Security Topics | Incorporate in-browser communication security considerations | PR53

2022-10-26 Thread Daniel Fett
Hi Christian, thanks for bringing this to our attention! I think the recommendations in the PR are very helpful and we will consider adding the text to the document. -Daniel Am 25.10.22 um 15:37 schrieb Christian Mainka: Hi, we would like to request the inclusion of _in-browser