[OAUTH-WG] AD Review of http://datatracker.ietf.org/doc/draft-ietf-oauth-saml2-bearer

2014-07-15 Thread Kathleen Moriarty
Hello, I just finished my review of http://datatracker.ietf.org/doc/draft-ietf-oauth-saml2-bearer. The draft looks great, thank you for all of your efforts on it! I did notice that there were no privacy considerations pointing back to RFC6973, could that text be added? The draft came after the

Re: [OAUTH-WG] Dynamic Client Registration: IPR Confirmation

2014-07-15 Thread Mike Jones
So that the working group has concrete language to consider, propose the following language to the OAuth Dynamic Client Registration specification: Portions of this specification are derived from the OpenID Connect Dynamic Registration [OpenID.Registration] specification. This was done so that

Re: [OAUTH-WG] Shepherd Writeup for Dynamic Client Registration Draft

2014-07-15 Thread Justin Richer
I've implemented the core dynamic registration draft and the management protocol draft (including read, update, and delete), both client side and server side, in MITREid Connect: https://github.com/mitreid-connect/OpenID-Connect-Java-Spring-Server We've been running this code in production at

Re: [OAUTH-WG] Shepherd Writeup for Dynamic Client Registration Draft

2014-07-15 Thread Edmund Jay
It is from the OpenID Connect spec, but I believe the OpenID Connect spec is similar enough that it is compliant with the OAuth version. From: Anthony Nadalin To: Edmund Jay ; Hannes Tschofenig ; "oauth@ietf.org" Sent: Tuesday, July 15, 2014 12:04 PM Subject

Re: [OAUTH-WG] Shepherd Writeup for Dynamic Client Registration Draft

2014-07-15 Thread Anthony Nadalin
Is your implementation from the OpenID Connect specification of from the IETF specification From: OAuth [mailto:oauth-boun...@ietf.org] On Behalf Of Edmund Jay Sent: Tuesday, July 15, 2014 11:01 AM To: Hannes Tschofenig; oauth@ietf.org Subject: Re: [OAUTH-WG] Shepherd Writeup for Dynamic Client R

Re: [OAUTH-WG] Shepherd Writeup for Dynamic Client Registration Draft

2014-07-15 Thread Edmund Jay
I've implemented registration as part of OpenID Connect. server - https://connect.openid4.us/abop client - https://connect.openid4.us/abrp From: Hannes Tschofenig To: "oauth@ietf.org" Sent: Tuesday, July 8, 2014 5:46 AM Subject: [OAUTH-WG] Shepherd Writeup f

[OAUTH-WG] OAuth Proof-of-Possession Work

2014-07-15 Thread Hannes Tschofenig
Hi all, Kathleen just confirmed the milestone update and as part of our work on the security part (which we called "proof-of-possession"). We replaced one milestone (containing one document, namely the MAC token spec) with one milestone for the proof-of-possession work (now containing a number of

[OAUTH-WG] Final Agenda for the IETF#90 OAuth Meeting

2014-07-15 Thread Hannes Tschofenig
** Please send us slides as soon as possible ** Web Authorization Protocol (OAuth) -- THURSDAY, July 24, 2014 1520-1720 EDT Manitoba (MM) - Welcome & Agenda Bashing (Chairs, 10min) (includes status update of the current WG documents in IESG processing) - Dynam

[OAUTH-WG] OAuth Use Cases

2014-07-15 Thread Hannes Tschofenig
Hi all, due to lack of interest and progress we deleted the 'OAuth use case' document from the milestone list (after consultation with our area director). Text with relevant use cases will be copied to the working group Wiki page. The text is not lost. We would like to thank the original authors