Re: [OAUTH-WG] I-D Action: draft-ietf-oauth-jwsreq-21.txt

2020-05-01 Thread Torsten Lodderstedt
fore publishing? > >-- Mike > > From: Torsten Lodderstedt > Sent: Friday, May 1, 2020 2:37 AM > To: Mike Jones > Cc: John Bradley ; Nat Sakimura ; > oauth > Subject: Re: [OAUTH-WG] I-D Action: draft-ietf-oauth-jwsreq-21.txt

Re: [OAUTH-WG] I-D Action: draft-ietf-oauth-jwsreq-21.txt

2020-04-26 Thread Mike Jones
a request for early registration if it would be useful. -- Mike -Original Message- From: OAuth On Behalf Of Torsten Lodderstedt Sent: Sunday, April 26, 2020 8:17 AM To: Nat Sakimura ; John Bradley Cc: oauth Subject: Re: [OAUTH-WG] I-D Action: draft-ietf-oauth

Re: [OAUTH-WG] I-D Action: draft-ietf-oauth-jwsreq-21.txt

2020-04-26 Thread Torsten Lodderstedt
Hi Nat & John, I tried to find out how signing & encryption algorithms are determined in the JAR context. I just found this note in the history for -07: "Stopped talking about request_object_signing_alg” I assume you assume this is done via client registration parameters registered in

Re: [OAUTH-WG] I-D Action: draft-ietf-oauth-jwsreq-21.txt

2020-04-21 Thread Brian Campbell
I'd agree that Vladimir's proposed wording is more meaningful/helpful. On Mon, Apr 20, 2020 at 12:12 AM Vladimir Dzhuvinov wrote: > Nat, John, thanks for updating the JAR spec. I just reviewed it, in > particular the authz request and the security considerations sections. > Choosing to make

Re: [OAUTH-WG] I-D Action: draft-ietf-oauth-jwsreq-21.txt

2020-04-20 Thread Vladimir Dzhuvinov
Nat, John, thanks for updating the JAR spec. I just reviewed it, in particular the authz request and the security considerations sections. Choosing to make client_id (as top-level parameter) mandatory for all cases, even for those when it can be readily extracted from the JWT, makes the job of

[OAUTH-WG] I-D Action: draft-ietf-oauth-jwsreq-21.txt

2020-04-19 Thread internet-drafts
A New Internet-Draft is available from the on-line Internet-Drafts directories. This draft is a work item of the Web Authorization Protocol WG of the IETF. Title : The OAuth 2.0 Authorization Framework: JWT Secured Authorization Request (JAR) Authors : Nat