Hi Roman, Thank you very much for the comments. We will incorporate them in the next revision. Best, Kristina
-----Original Message----- From: OAuth <oauth-boun...@ietf.org> On Behalf Of Roman Danyliw Sent: Monday, April 25, 2022 1:08 PM To: oauth@ietf.org Subject: [OAUTH-WG] AD Review of draft-ietf-oauth-jwk-thumbprint-uri-01 Hi! I conducted an AD review of draft-ietf-oauth-jwk-thumbprint-uri-01. Thanks for the work on this document. I have the following feedback which can be addressed with other IETF Last Call reviews. ** Section 4. Editorial clarification on which field from the registry to use and error handling is below: OLD Hash algorithm identifiers used in JWK Thumbprint URIs are strings registered in the IANA "Named Information Hash Algorithm Registry" [IANA.Hash.Algorithms]. NEW Hash algorithm identifiers used in JWK Thumbprint URIs MUST be values from the "Hash Name String" column in the IANA "Named Information Hash Algorithm Registry" [IANA.Hash.Algorithms]. JWK Thumbprint URIs with hash algorithm strings not found in this registry are considered invalid and the application using these thumbprints will need to define an appropriate error handling mechanism. ** From idnits: == The document doesn't use any RFC 2119 keywords, yet seems to have RFC 2119 boilerplate text. If the above isn't adopted, drop Section 2 since it doesn't appear to be needed. Regards, Roman _______________________________________________ OAuth mailing list OAuth@ietf.org https://nam06.safelinks.protection.outlook.com/?url=https%3A%2F%2Fwww.ietf.org%2Fmailman%2Flistinfo%2Foauth&data=05%7C01%7CKristina.Yasuda%40microsoft.com%7C469bf75e99ec425bd78808da286d75c4%7C72f988bf86f141af91ab2d7cd011db47%7C1%7C0%7C637866747863647551%7CUnknown%7CTWFpbGZsb3d8eyJWIjoiMC4wLjAwMDAiLCJQIjoiV2luMzIiLCJBTiI6Ik1haWwiLCJXVCI6Mn0%3D%7C3000%7C%7C%7C&sdata=M2jHv5g9texb82YzgjMJtxDAfg9Pl032IyZAyb8xuYo%3D&reserved=0 _______________________________________________ OAuth mailing list OAuth@ietf.org https://www.ietf.org/mailman/listinfo/oauth