Re: [OAUTH-WG] Assertion flow and token bootstrapping

2010-06-15 Thread Eran Hammer-Lahav
framework for obtaining an access token. EHL From: oauth-boun...@ietf.org [mailto:oauth-boun...@ietf.org] On Behalf Of Lisa Dusseault Sent: Wednesday, June 02, 2010 10:33 AM To: oauth Subject: [OAUTH-WG] Assertion flow and token bootstrapping I've been trying to understand the use case

Re: [OAUTH-WG] Assertion flow and token bootstrapping

2010-06-07 Thread Thomas Hardjono
[mailto:oauth-boun...@ietf.org] On Behalf Of Dick Hardt Sent: Friday, June 04, 2010 9:59 PM To: Luke Shepard Cc: oauth@ietf.org Subject: Re: [OAUTH-WG] Assertion flow and token bootstrapping because we use it On 2010-06-04, at 6:40 PM, Luke Shepard wrote: Why? On Jun 4, 2010, at 4:41 PM

Re: [OAUTH-WG] Assertion flow and token bootstrapping

2010-06-07 Thread Dick Hardt
/ __ -Original Message- From: oauth-boun...@ietf.org [mailto:oauth-boun...@ietf.org] On Behalf Of Dick Hardt Sent: Friday, June 04, 2010 9:59 PM To: Luke Shepard Cc: oauth@ietf.org Subject: Re: [OAUTH-WG] Assertion flow and token bootstrapping because we use it On 2010-06-04, at 6

Re: [OAUTH-WG] Assertion flow and token bootstrapping

2010-06-07 Thread Thomas Hardjono
[mailto:dick.ha...@gmail.com] Sent: Sunday, June 06, 2010 8:10 PM To: Thomas Hardjono Cc: oauth@ietf.org Subject: Re: [OAUTH-WG] Assertion flow and token bootstrapping I hope so. On 2010-06-06, at 3:22 PM, Thomas Hardjono wrote: Apologies for another newbie question: is the design-intention

Re: [OAUTH-WG] Assertion flow and token bootstrapping

2010-06-04 Thread Brian Campbell
On Thu, Jun 3, 2010 at 9:20 AM, Peter Saint-Andre stpe...@stpeter.im wrote: At least for the assertion flow, that's definitely true. At the interim meeting we had some discussion about perhaps pulling the assertion flow out of the base spec and into a separate document. Perhaps that's the

Re: [OAUTH-WG] Assertion flow and token bootstrapping

2010-06-04 Thread Torsten Lodderstedt
+1 Am 04.06.2010 23:38, schrieb Brian Campbell: On Thu, Jun 3, 2010 at 9:20 AM, Peter Saint-Andrestpe...@stpeter.im wrote: At least for the assertion flow, that's definitely true. At the interim meeting we had some discussion about perhaps pulling the assertion flow out of the base spec

Re: [OAUTH-WG] Assertion flow and token bootstrapping

2010-06-04 Thread Patrick Harding
+1 Sent from my iPhone On Jun 4, 2010, at 5:38 PM, Brian Campbell bcampb...@pingidentity.com wrote: On Thu, Jun 3, 2010 at 9:20 AM, Peter Saint-Andre stpe...@stpeter.im wrote: At least for the assertion flow, that's definitely true. At the interim meeting we had some discussion about

Re: [OAUTH-WG] Assertion flow and token bootstrapping

2010-06-04 Thread Luke Shepard
Why? On Jun 4, 2010, at 4:41 PM, Patrick Harding wrote: +1 Sent from my iPhone On Jun 4, 2010, at 5:38 PM, Brian Campbell bcampb...@pingidentity.com wrote: On Thu, Jun 3, 2010 at 9:20 AM, Peter Saint-Andre stpe...@stpeter.im wrote: At least for the assertion flow, that's

Re: [OAUTH-WG] Assertion flow and token bootstrapping

2010-06-04 Thread Dick Hardt
because we use it On 2010-06-04, at 6:40 PM, Luke Shepard wrote: Why? On Jun 4, 2010, at 4:41 PM, Patrick Harding wrote: +1 Sent from my iPhone On Jun 4, 2010, at 5:38 PM, Brian Campbell bcampb...@pingidentity.com wrote: On Thu, Jun 3, 2010 at 9:20 AM, Peter Saint-Andre

Re: [OAUTH-WG] Assertion flow and token bootstrapping

2010-06-03 Thread Peter Saint-Andre
On 6/3/10 8:54 AM, Thomas Hardjono wrote: PS. Compared to the details of RFC4120 and even to the old ISAKMP in the IETF, the current OAuth2.0 draft-05 spec appear to be a high-level framework that needs to be instantiated/profiled. At least for the assertion flow, that's definitely true. At

Re: [OAUTH-WG] Assertion flow and token bootstrapping

2010-06-03 Thread Paul Madsen
that needs to be instantiated/profiled. /thomas/ __ -From: Dick Hardt [mailto:dick.ha...@gmail.com] -Sent: Thursday, June 03, 2010 1:51 AM To: Brian Campbell Cc: Thomas Hardjono; oauth Subject: Re: [OAUTH-WG] Assertion flow and token bootstrapping

Re: [OAUTH-WG] Assertion flow and token bootstrapping

2010-06-03 Thread Dick Hardt
On 2010-06-03, at 7:54 AM, Thomas Hardjono wrote: Dick, Brian, Thanks for the clarification. - Is the Assertion Flow designed only for the STS, or can it be used with other identity providers (non-WSS). It can be used with any tokens. I use the STS term to clarify the design pattern.

Re: [OAUTH-WG] Assertion flow and token bootstrapping

2010-06-03 Thread Dick Hardt
On 2010-06-03, at 8:20 AM, Peter Saint-Andre wrote: On 6/3/10 8:54 AM, Thomas Hardjono wrote: PS. Compared to the details of RFC4120 and even to the old ISAKMP in the IETF, the current OAuth2.0 draft-05 spec appear to be a high-level framework that needs to be instantiated/profiled. At

[OAUTH-WG] Assertion flow and token bootstrapping

2010-06-02 Thread Lisa Dusseault
I've been trying to understand the use case for the assertion flow ( http://tools.ietf.org/html/draft-ietf-oauth-v2-05#section-3.10) . Conversely, I have a use case for bootstrapping, and I'm trying to understand if the assertion flow is the right flow for that use case. The bootstrapping use

Re: [OAUTH-WG] Assertion flow and token bootstrapping

2010-06-02 Thread Thomas Hardjono
...@ietf.org [mailto:oauth-boun...@ietf.org] On Behalf Of Lisa Dusseault Sent: Wednesday, June 02, 2010 1:33 PM To: oauth Subject: [OAUTH-WG] Assertion flow and token bootstrapping I've been trying to understand the use case for the assertion flow (http://tools.ietf.org/html/draft-ietf-oauth-v2-05

Re: [OAUTH-WG] Assertion flow and token bootstrapping

2010-06-02 Thread Brian Campbell
[mailto:oauth-boun...@ietf.org] On Behalf Of Lisa Dusseault Sent: Wednesday, June 02, 2010 1:33 PM To: oauth Subject: [OAUTH-WG] Assertion flow and token bootstrapping I've been trying to understand the use case for the assertion flow (http://tools.ietf.org/html/draft-ietf-oauth-v2-05

Re: [OAUTH-WG] Assertion flow and token bootstrapping

2010-06-02 Thread Dick Hardt
, June 02, 2010 1:33 PM To: oauth Subject: [OAUTH-WG] Assertion flow and token bootstrapping I've been trying to understand the use case for the assertion flow (http://tools.ietf.org/html/draft-ietf-oauth-v2-05#section-3.10) . Conversely, I have a use case for bootstrapping, and I'm