Re: [OAUTH-WG] Resource Indicators Implementations

2019-01-14 Thread Hannes Tschofenig
We implement the resource indicator as part of our Pelion Secure Device Access (SDA) product. Here is the link: https://cloud.mbed.com/docs/v1.2/device-management/secure-device-access.html From: OAuth On Behalf Of Rifaat Shekh-Yusef Sent: Freitag, 4. Januar 2019 16:39 To: oauth Subject:

[OAUTH-WG] Presentation slots at IETF 104

2019-01-14 Thread Hannes Tschofenig
Hi all, If you are planning to give a presentation at IETF#104 please drop us an email. We started planning for the meeting already. Ciao Hannes & Rifaat IMPORTANT NOTICE: The contents of this email and any attachments are confidential and may also be privileged. If you are not the intended

[OAUTH-WG] Updated "OAuth WG Virtual Office Hours" Conference Bridge

2019-01-14 Thread Hannes Tschofenig
Hi all, Please update your meeting invite for the "OAuth WG Virtual Office Hours" conference call. Ciao Hannes & Rifaat IMPORTANT NOTICE: The contents of this email and any attachments are confidential and may also be privileged. If you are not the intended recipient, please notify the sender

Re: [OAUTH-WG] MTLS and in-browser clients using the token endpoint

2019-01-14 Thread Brian Campbell
No, my testing was not via XHR/fetch. Just direct request from the browser. I was making the assumption (maybe foolishly) that it wouldn't impact behavior because it's all at the network layer. I saw that Firefox setting but left the default (at least for my install), which was not to autopick.

Re: [OAUTH-WG] MTLS and in-browser clients using the token endpoint

2019-01-14 Thread Brian Campbell
Trying to summarize things somewhat here and focus in hopefully towards some decision. There's basically an idea on the table to add an AS metadata parameter to the draft-ietf-oauth-mtls doc that would be a JSON object which contains endpoints that a client doing MTLS would use rather than the