Re: [OAUTH-WG] Secdir last call review of draft-ietf-oauth-access-token-jwt-11

2021-02-24 Thread Joseph Salowey
On Sat, Feb 20, 2021 at 12:42 AM Vittorio Bertocci < vittorio.berto...@auth0.com> wrote: > Thank you Joseph for your comments! > > [Joe] Thanks for your response, comments inline below: > > 1. (Editorial) What is the relationship between this document and RFC > 7523. > > They are using JWT

Re: [OAUTH-WG] Secdir last call review of draft-ietf-oauth-access-token-jwt-11

2021-02-20 Thread Vittorio Bertocci
Thank you Joseph for your comments! > 1. (Editorial) What is the relationship between this document and RFC 7523. > They are using JWT for different purposes, but I think it would be useful to >clarify this in the introduction. Good point, I agree it would be good to preempt doubts on

[OAUTH-WG] Secdir last call review of draft-ietf-oauth-access-token-jwt-11

2021-02-07 Thread Joseph Salowey via Datatracker
Reviewer: Joseph Salowey Review result: Has Issues I have reviewed this document as part of the security directorate's ongoing effort to review all IETF documents being processed by the IESG. These comments were written primarily for the benefit of the security area directors. Document editors