Re: [OAUTH-WG] questions on Seamless OAuth 2.0 Client Assertion Grant

2018-11-13 Thread Omer Levi Hevroni
Ok, thanks for the clarification. Your point about a user with multiple devices is correct - but it is by design. The goal of this protocol is to allow device authentication - there is no information about the user. Therefore, there is also no way to associate devices to a user. It creates challeng

Re: [OAUTH-WG] questions on Seamless OAuth 2.0 Client Assertion Grant

2018-11-12 Thread Dick Hardt
I understand better, thanks! >From an OAuth perspective, this is a client credentials grant. You have added some other checks that may or may not help the security profile, but at the core, you have a private key on the device that is the primary credential, and is device oriented. FWIW: there ar

Re: [OAUTH-WG] questions on Seamless OAuth 2.0 Client Assertion Grant

2018-11-11 Thread Omer Levi Hevroni
Ok, let me try. At the company where I work, we have an app that is used by our users. We want to have a way to authenticate the requests from the application, without requiring the user to perform any interactive login flow. I described it more in-depth in the blog post - https://blog.solutotlv.c

Re: [OAUTH-WG] questions on Seamless OAuth 2.0 Client Assertion Grant

2018-11-08 Thread Dick Hardt
More detail on the scenario would help. On Fri, Nov 9, 2018 at 2:04 AM Omer Levi Hevroni wrote: > Yes, that is correct. > I'm sorry the confusion, I think this confusion is built into > oauth framework itself. > You understood well the scenario - I have an application running on an > untrusted d

Re: [OAUTH-WG] questions on Seamless OAuth 2.0 Client Assertion Grant

2018-11-08 Thread Omer Levi Hevroni
Yes, that is correct. I'm sorry the confusion, I think this confusion is built into oauth framework itself. You understood well the scenario - I have an application running on an untrusted device in an untrusted network. I looked for a way to authenticate the requests from the device to AS. Does it

[OAUTH-WG] questions on Seamless OAuth 2.0 Client Assertion Grant

2018-11-08 Thread Dick Hardt
Omar As promised, I have reviewed the ID[1] you posted. I'm confused in the Motivation by the references to authentication, as OAuth is about authorization. Perhaps you can post to the list the use case you are trying to solve for? I can infer aspects, but don't fully understand it. >From what I