Re: [OAUTH-WG] JWT Token on-behalf of Use case

2015-07-07 Thread Sam Hartman
Speaking as someone who is reasonably familiar with Kerberos and the general concepts involved, I find both Microsoft/Kerberos technology ((constrained delegation/protocol transition) and the ws-trust text horribly confusing and would recommend against all of the above as examples of clarity.

Re: [OAUTH-WG] JWT Token on-behalf of Use case

2015-07-07 Thread Kathleen Moriarty
I'm just catching up on this tread, but would appreciate an in-room discussion on this topic that doesn't assume the adopted draft has the agreed upon approach as I am not reading that there is consensus on that approach in this thread at all. Could we see presentations on Mike's draft and

Re: [OAUTH-WG] JWT Token on-behalf of Use case

2015-07-07 Thread Justin Richer
Kathleen, I agree that Brian’s approach covers the use case that drove my original draft and effectively subsumes my approach. My standing contention with the document as it stands is and has always been that it’s lacking a general syntactical approach and it isn’t very OAuth-y. I would love

Re: [OAUTH-WG] JWT Token on-behalf of Use case

2015-07-07 Thread Mike Jones
] On Behalf Of Justin Richer Sent: Tuesday, July 07, 2015 12:52 PM To: Kathleen Moriarty Cc: oauth@ietf.org Subject: Re: [OAUTH-WG] JWT Token on-behalf of Use case Kathleen, I agree that Brian’s approach covers the use case that drove my original draft and effectively subsumes my approach. My

Re: [OAUTH-WG] JWT Token on-behalf of Use case

2015-07-07 Thread Kathleen Moriarty
On Tue, Jul 7, 2015 at 3:43 PM, Kathleen Moriarty kathleen.moriarty.i...@gmail.com wrote: I'm just catching up on this tread, but would appreciate an in-room discussion on this topic that doesn't assume the adopted draft has the agreed upon approach as I am not reading that there is consensus

Re: [OAUTH-WG] JWT Token on-behalf of Use case

2015-07-06 Thread Sergey Beryozkin
] *On Behalf Of *Vivek Biswas -T (vibiswas - XORIANT CORPORATION at Cisco) *Sent:* Thursday, June 25, 2015 2:20 PM *To:* OAuth@ietf.org mailto:OAuth@ietf.org *Subject:* [OAUTH-WG] JWT Token on-behalf

Re: [OAUTH-WG] JWT Token on-behalf of Use case

2015-07-06 Thread Brian Campbell
-T (vibiswas - XORIANT CORPORATION at Cisco) *Sent:* Thursday, June 25, 2015 2:20 PM *To:* OAuth@ietf.org mailto:OAuth@ietf.org *Subject:* [OAUTH-WG] JWT Token on-behalf of Use case Hi All

Re: [OAUTH-WG] JWT Token on-behalf of Use case

2015-07-06 Thread Anthony Nadalin
...@ietf.org] On Behalf Of Brian Campbell Sent: Monday, July 6, 2015 11:29 AM To: Mike Jones michael.jo...@microsoft.com Cc: oauth oauth@ietf.org Subject: Re: [OAUTH-WG] JWT Token on-behalf of Use case Stating specific action items resulting from the ad-hoc meeting in Dallas like that suggests some clear

Re: [OAUTH-WG] JWT Token on-behalf of Use case

2015-07-06 Thread John Bradley
, 2015 11:29 AM To: Mike Jones michael.jo...@microsoft.com Cc: oauth oauth@ietf.org Subject: Re: [OAUTH-WG] JWT Token on-behalf of Use case Stating specific action items resulting from the ad-hoc meeting in Dallas like that suggests some clear consensus was reached, which is not at all

Re: [OAUTH-WG] JWT Token on-behalf of Use case

2015-07-06 Thread Phil Hunt
: OAuth [mailto:oauth-boun...@ietf.org] On Behalf Of Brian Campbell Sent: Monday, July 6, 2015 11:29 AM To: Mike Jones michael.jo...@microsoft.com Cc: oauth oauth@ietf.org Subject: Re: [OAUTH-WG] JWT Token on-behalf of Use case Stating specific action items resulting from the ad-hoc meeting

Re: [OAUTH-WG] JWT Token on-behalf of Use case

2015-07-06 Thread Brian Campbell
*Subject:* Re: [OAUTH-WG] JWT Token on-behalf of Use case Stating specific action items resulting from the ad-hoc meeting in Dallas like that suggests some clear consensus was reached, which is not at all the case. As I recall, several of us argued past one another for an hour or so and decided

Re: [OAUTH-WG] JWT Token on-behalf of Use case

2015-07-06 Thread Mike Jones
Campbell Cc: oauth Subject: Re: [OAUTH-WG] JWT Token on-behalf of Use case Yes unfortunately we haven’t made any progress on this since accepting Mike’s first draft. His proposal is basically for a new endpoint while Brian tired to fit it into the existing token endpoint. I think draft-ietf

Re: [OAUTH-WG] JWT Token on-behalf of Use case

2015-07-06 Thread John Bradley
Campbell Cc: oauth Subject: Re: [OAUTH-WG] JWT Token on-behalf of Use case Yes unfortunately we haven’t made any progress on this since accepting Mike’s first draft. His proposal is basically for a new endpoint while Brian tired to fit it into the existing token endpoint. I think draft-ietf

Re: [OAUTH-WG] JWT Token on-behalf of Use case

2015-07-06 Thread Brian Campbell
: OAuth [mailto:oauth-boun...@ietf.org] On Behalf Of John Bradley Sent: Monday, July 06, 2015 8:13 AM To: Brian Campbell Cc: oauth Subject: Re: [OAUTH-WG] JWT Token on-behalf of Use case Yes unfortunately we haven’t made any progress on this since accepting Mike’s first draft. His proposal

Re: [OAUTH-WG] JWT Token on-behalf of Use case

2015-07-06 Thread Mike Jones
Bradley; oauth Subject: Re: [OAUTH-WG] JWT Token on-behalf of Use case Stating specific action items resulting from the ad-hoc meeting in Dallas like that suggests some clear consensus was reached, which is not at all the case. As I recall, several of us argued past one another for an hour or so

Re: [OAUTH-WG] JWT Token on-behalf of Use case

2015-07-06 Thread Justin Richer
:* Monday, July 6, 2015 11:29 AM *To:* Mike Jones michael.jo...@microsoft.com mailto:michael.jo...@microsoft.com *Cc:* oauth oauth@ietf.org mailto:oauth@ietf.org *Subject:* Re: [OAUTH-WG] JWT Token on-behalf of Use case Stating specific action items resulting from the ad-hoc meeting in Dallas like

Re: [OAUTH-WG] JWT Token on-behalf of Use case

2015-07-06 Thread Anthony Nadalin
...@microsoft.com; oauth oauth@ietf.org Subject: Re: [OAUTH-WG] JWT Token on-behalf of Use case A natural usage of act-as or impersonationhttp://www.oxforddictionaries.com/us/definition/american_english/impersonate would suggest, to many people anyway, that the way you just used the terms is reversed. The bold

Re: [OAUTH-WG] JWT Token on-behalf of Use case

2015-07-06 Thread John Bradley
, -- Mike From: Brian Campbell [mailto:bcampb...@pingidentity.com] Sent: Monday, July 06, 2015 11:29 AM To: Mike Jones Cc: John Bradley; oauth Subject: Re: [OAUTH-WG] JWT Token on-behalf of Use case Stating specific action items resulting from the ad-hoc meeting in Dallas like that suggests

Re: [OAUTH-WG] JWT Token on-behalf of Use case

2015-07-06 Thread Brian Campbell
] *Sent:* Monday, July 6, 2015 2:33 PM *To:* Anthony Nadalin tony...@microsoft.com *Cc:* Mike Jones michael.jo...@microsoft.com; oauth oauth@ietf.org *Subject:* Re: [OAUTH-WG] JWT Token on-behalf of Use case A natural usage of act-as or impersonation http://www.oxforddictionaries.com/us

Re: [OAUTH-WG] JWT Token on-behalf of Use case

2015-07-06 Thread John Bradley
) *Sent:* Thursday, June 25, 2015 2:20 PM *To:* OAuth@ietf.org mailto:OAuth@ietf.org *Subject:* [OAUTH-WG] JWT Token on-behalf of Use case Hi All, I am looking to solve a use-case similar

Re: [OAUTH-WG] JWT Token on-behalf of Use case

2015-07-01 Thread Anthony Nadalin
] On Behalf Of Justin Richer Sent: Wednesday, July 1, 2015 5:18 AM To: oauth@ietf.org Subject: Re: [OAUTH-WG] JWT Token on-behalf of Use case As it's written right now, it's a translation of some WS-* concepts into JWT format. It's not really OAuth-y (since the client has to understand the token format

Re: [OAUTH-WG] JWT Token on-behalf of Use case

2015-07-01 Thread Sergey Beryozkin
Of *Vivek Biswas -T (vibiswas - XORIANT CORPORATION at Cisco) *Sent:* Thursday, June 25, 2015 2:20 PM *To:* OAuth@ietf.org *Subject:* [OAUTH-WG] JWT Token on-behalf of Use case Hi All, I am looking to solve a use-case similar to WS-Security On-Behalf-Of http://docs.oasis-open.org/ws-sx/ws

Re: [OAUTH-WG] JWT Token on-behalf of Use case

2015-07-01 Thread Sergey Beryozkin
PM *To:* OAuth@ietf.org *Subject:* [OAUTH-WG] JWT Token on-behalf of Use case Hi All, I am looking to solve a use-case similar to WS-Security On-Behalf-Of http://docs.oasis-open.org/ws-sx/ws-trust/v1.4/errata01/os/ws-trust-1.4-errata01-os-complete.html#_Toc325658980 with OAuth JWT Token

Re: [OAUTH-WG] JWT Token on-behalf of Use case

2015-07-01 Thread Justin Richer
Biswas -T (vibiswas - XORIANT CORPORATION at Cisco) *Sent:* Thursday, June 25, 2015 2:20 PM *To:* OAuth@ietf.org *Subject:* [OAUTH-WG] JWT Token on-behalf of Use case Hi All, I am looking to solve a use-case similar to WS-Security On-Behalf-Of http://docs.oasis-open.org/ws-sx/ws-trust/v1.4/errata01

Re: [OAUTH-WG] JWT Token on-behalf of Use case

2015-07-01 Thread Brian Campbell
- XORIANT CORPORATION at Cisco) *Sent:* Thursday, June 25, 2015 2:20 PM *To:* OAuth@ietf.org *Subject:* [OAUTH-WG] JWT Token on-behalf of Use case Hi All, I am looking to solve a use-case similar to WS-Security On-Behalf-Of http://docs.oasis-open.org/ws-sx/ws-trust/v1.4/errata01/os/ws

Re: [OAUTH-WG] JWT Token on-behalf of Use case

2015-07-01 Thread Phil Hunt
-exchange-01 is about. Cheers, -- Mike *From:*OAuth [mailto:oauth-boun...@ietf.org] *On Behalf Of *Vivek Biswas -T (vibiswas - XORIANT CORPORATION at Cisco) *Sent:* Thursday, June 25, 2015 2:20 PM *To:* OAuth@ietf.org *Subject:* [OAUTH-WG] JWT Token on-behalf of Use case Hi All

Re: [OAUTH-WG] JWT Token on-behalf of Use case

2015-06-30 Thread Sergey Beryozkin
] JWT Token on-behalf of Use case Hi All, I am looking to solve a use-case similar to WS-Security On-Behalf-Of http://docs.oasis-open.org/ws-sx/ws-trust/v1.4/errata01/os/ws-trust-1.4-errata01-os-complete.html#_Toc325658980 with OAuth JWT Token. Is there a standard claim which we can define

[OAUTH-WG] JWT Token on-behalf of Use case

2015-06-25 Thread Vivek Biswas -T (vibiswas - XORIANT CORPORATION at Cisco)
Hi All, I am looking to solve a use-case similar to WS-Security On-Behalf-Ofhttp://docs.oasis-open.org/ws-sx/ws-trust/v1.4/errata01/os/ws-trust-1.4-errata01-os-complete.html#_Toc325658980 with OAuth JWT Token. Is there a standard claim which we can define within the OAuth JWT which denote

Re: [OAUTH-WG] JWT Token on-behalf of Use case

2015-06-25 Thread Mike Jones
Biswas -T (vibiswas - XORIANT CORPORATION at Cisco) Sent: Thursday, June 25, 2015 2:20 PM To: OAuth@ietf.org Subject: [OAUTH-WG] JWT Token on-behalf of Use case Hi All, I am looking to solve a use-case similar to WS-Security On-Behalf-Ofhttp://docs.oasis-open.org/ws-sx/ws-trust/v1.4/errata01/os