On 2017-02-24 22:58, John Bradley wrote:
I updated the references but haven't made any other changes.

I had some questions about it so though it was worth keeping alive
at-least for discussion.

There have been some other questions and proposed changes.

I will take a look through them and see if what may be worth updating.

John B.

Question about the 'aud' parameter: Wouldn't it be useful to allow other values than URIs for that one?

One could easily imagine a group identifier as value of that field, where the RS internally resolves whether it is part of that group and therefore the target audience of that token.



Ludwig Seitz, PhD
Security Lab, RISE ICT/SICS
Phone +46(0)70-349 92 51

