Re: [OAUTH-WG] Secdir last call review of draft-ietf-oauth-dpop-12

2023-01-20 Thread Brian Campbell
Thanks for the review Benjamin! Specific replies are inline below. On Fri, Jan 20, 2023 at 2:20 PM Benjamin Schwartz via Datatracker < nore...@ietf.org> wrote: > Reviewer: Benjamin Schwartz > Review result: Ready > > This is a very mature, carefully drafted specification. > Appreciate that.

[OAUTH-WG] Fwd: I-D Action: draft-ietf-oauth-dpop-13.txt

2023-01-20 Thread Brian Campbell
This -13 revision just has some very minor updates for a few things noticed during IETF last call. -- Forwarded message - From: Date: Fri, Jan 20, 2023 at 2:19 PM Subject: [OAUTH-WG] I-D Action: draft-ietf-oauth-dpop-13.txt To: Cc: A New Internet-Draft is available from the

[OAUTH-WG] Secdir last call review of draft-ietf-oauth-dpop-12

2023-01-20 Thread Benjamin Schwartz via Datatracker
Reviewer: Benjamin Schwartz Review result: Ready This is a very mature, carefully drafted specification. Question: Under Dynamic Client Registration, do we need a mechanism for the client learn the required signature algorithms? In general, there is no discussion of how mutually acceptable

[OAUTH-WG] I-D Action: draft-ietf-oauth-dpop-13.txt

2023-01-20 Thread internet-drafts
A New Internet-Draft is available from the on-line Internet-Drafts directories. This draft is a work item of the Web Authorization Protocol WG of the IETF. Title : OAuth 2.0 Demonstrating Proof-of-Possession at the Application Layer (DPoP) Authors : Daniel

Re: [OAUTH-WG] [IANA #1264432] expert review for draft-ietf-oauth-dpop (http-fields)

2023-01-20 Thread Ryan Ridenour
On Fri, Jan 20, 2023, 3:03 PM Neil Madden wrote: > > > On 20 Jan 2023, at 18:47, Brian Campbell 40pingidentity@dmarc.ietf.org> wrote: > > > Hi Mark, > > Thanks for the review and feedback. I am aware of HTTP Structured Fields > and certainly see value in it - even using it in some other

Re: [OAUTH-WG] [IANA #1264432] expert review for draft-ietf-oauth-dpop (http-fields)

2023-01-20 Thread Neil Madden
On 20 Jan 2023, at 18:47, Brian Campbell wrote:Hi Mark,Thanks for the review and feedback. I am aware of HTTP Structured Fields and certainly see value in it - even using it in some other work in which I'm involved. However, I'm unsure of its fit or utility for this draft. With that said, I've

Re: [OAUTH-WG] [IANA #1264432] expert review for draft-ietf-oauth-dpop (http-fields)

2023-01-20 Thread Brian Campbell
Hi Mark, Thanks for the review and feedback. I am aware of HTTP Structured Fields and certainly see value in it - even using it in some other work in which I'm involved. However, I'm unsure of its fit or utility for this draft. With that said, I've tried to reply more specifically to your

Re: [OAUTH-WG] Implementations - OAuth 2.0 Step-up Authentication Challenge Protocol

2023-01-20 Thread Rifaat Shekh-Yusef
Thanks Brock! I added this implementation to the shepherd writeup. Regards, Rifaat On Fri, Jan 20, 2023 at 12:29 AM Vittorio Bertocci < vittorio.berto...@auth0.com> wrote: > Wonderful, thanks Brock! > > On Thu, Jan 19, 2023 at 14:55 Brock Allen wrote: > >> *This message originated outside