Hi Roman,
Thank you very much for the comments. We will incorporate them in the next 
revision.
Best,
Kristina

-----Original Message-----
From: OAuth <oauth-boun...@ietf.org> On Behalf Of Roman Danyliw
Sent: Monday, April 25, 2022 1:08 PM
To: oauth@ietf.org
Subject: [OAUTH-WG] AD Review of draft-ietf-oauth-jwk-thumbprint-uri-01

Hi!

I conducted an AD review of draft-ietf-oauth-jwk-thumbprint-uri-01.  Thanks for 
the work on this document. I have the following feedback which can be addressed 
with other IETF Last Call reviews.

** Section 4.  Editorial clarification on which field from the registry to use 
and error handling is below:  

OLD
   Hash algorithm identifiers used in JWK Thumbprint URIs are strings
   registered in the IANA "Named Information Hash Algorithm Registry"
   [IANA.Hash.Algorithms].

NEW
Hash algorithm identifiers used in JWK Thumbprint URIs MUST be values from the 
"Hash Name String" column in the IANA "Named Information Hash Algorithm 
Registry" [IANA.Hash.Algorithms].  JWK Thumbprint URIs with hash algorithm 
strings not found in this registry are considered invalid and the application 
using these thumbprints will need to define an appropriate error handling 
mechanism.

** From idnits:

  == The document doesn't use any RFC 2119 keywords, yet seems to have RFC
     2119 boilerplate text.

If the above isn't adopted, drop Section 2 since it doesn't appear to be needed.

Regards,
Roman

_______________________________________________
OAuth mailing list
OAuth@ietf.org
https://nam06.safelinks.protection.outlook.com/?url=https%3A%2F%2Fwww.ietf.org%2Fmailman%2Flistinfo%2Foauth&amp;data=05%7C01%7CKristina.Yasuda%40microsoft.com%7C469bf75e99ec425bd78808da286d75c4%7C72f988bf86f141af91ab2d7cd011db47%7C1%7C0%7C637866747863647551%7CUnknown%7CTWFpbGZsb3d8eyJWIjoiMC4wLjAwMDAiLCJQIjoiV2luMzIiLCJBTiI6Ik1haWwiLCJXVCI6Mn0%3D%7C3000%7C%7C%7C&amp;sdata=M2jHv5g9texb82YzgjMJtxDAfg9Pl032IyZAyb8xuYo%3D&amp;reserved=0

_______________________________________________
OAuth mailing list
OAuth@ietf.org
https://www.ietf.org/mailman/listinfo/oauth

Reply via email to