Re: [OAUTH-WG] Ted Lemon's No Objection on draft-ietf-oauth-json-web-token-27: (with COMMENT)

2014-10-06 Thread Mike Jones
> -Original Message- > From: Ted Lemon [mailto:ted.le...@nominum.com] > Sent: Monday, October 06, 2014 12:49 PM > To: Mike Jones > Cc: The IESG; oauth-cha...@tools.ietf.org; draft-ietf-oauth-json-web- > to...@tools.ietf.org; oauth@ietf.org > Subject: Re: Ted Lemon's No Objection on draft-ie

Re: [OAUTH-WG] Stephen Farrell's Discuss on draft-ietf-oauth-json-web-token-27: (with DISCUSS and COMMENT)

2014-10-06 Thread Mike Jones
Thanks for tracking all of this Stephen. Responses inline below... > -Original Message- > From: Stephen Farrell [mailto:stephen.farr...@cs.tcd.ie] > Sent: Monday, October 06, 2014 2:43 PM > To: Mike Jones; The IESG > Cc: oauth-cha...@tools.ietf.org; draft-ietf-oauth-json-web- > to...@tool

Re: [OAUTH-WG] Stephen Farrell's Discuss on draft-ietf-oauth-json-web-token-27: (with DISCUSS and COMMENT)

2014-10-06 Thread John Bradley
While my personal preference is to not release PII as part of authentication, We do have people demanding attributes in SAML and Connect at LoA 2+ for identity resolution at the relying party. https://www.idmanagement.gov/sites/default/files/documents/FICAM_TFS_ATOS.pdf (see Appendix A) JWT is

Re: [OAUTH-WG] Stephen Farrell's Discuss on draft-ietf-oauth-json-web-token-27: (with DISCUSS and COMMENT)

2014-10-06 Thread Stephen Farrell
Hi Mike, On 06/10/14 08:54, Mike Jones wrote: > Thanks for your review, Stephen. I've added the working group to the > thread so they're aware of your comments. > >> -Original Message- From: Stephen Farrell >> [mailto:stephen.farr...@cs.tcd.ie] Sent: Thursday, October 02, 2014 >> 5:03 A

Re: [OAUTH-WG] Ted Lemon's No Objection on draft-ietf-oauth-json-web-token-27: (with COMMENT)

2014-10-06 Thread Ted Lemon
On Oct 6, 2014, at 3:54 AM, Mike Jones wrote: > Sometimes authenticated encryption alone is good enough without requiring a > signature. Different applications will have different requirements. So > while this section discussion the applicable considerations, the working > group felt that it

Re: [OAUTH-WG] Secdir Review of draft-ietf-oauth-jwt-bearer-10

2014-10-06 Thread Mike Jones
Thanks for your review, Radia. I've added the working group to the thread so that they're aware of your comments. > From: Radia Perlman [mailto:radiaperl...@gmail.com] > Sent: Monday, September 29, 2014 4:46 PM > To: sec...@ietf.org; The IESG; draft-ietf-oauth-jwt-bearer@tools.ietf.org > Su

Re: [OAUTH-WG] Richard Barnes' Discuss on draft-ietf-oauth-json-web-token-27: (with DISCUSS and COMMENT)

2014-10-06 Thread Mike Jones
Thanks for your review, Richard. My responses are inline below... > -Original Message- > From: OAuth [mailto:oauth-boun...@ietf.org] On Behalf Of Richard Barnes > Sent: Wednesday, October 01, 2014 7:57 PM > To: The IESG > Cc: oauth-cha...@tools.ietf.org; oauth@ietf.org; draft-ietf-oauth-j

Re: [OAUTH-WG] Gen-ART Last Call review of draft-ietf-oauth-saml2-bearer-21

2014-10-06 Thread Mike Jones
Thanks for your review, Meral. I've added the working group to this thread so that they're aware of your comments. > From: Meral Shirazipour [mailto:meral.shirazip...@ericsson.com] > Sent: Monday, September 29, 2014 12:40 AM > To: draft-ietf-oauth-saml2-bearer@tools.ietf.org; gen-...@ietf.o

Re: [OAUTH-WG] Last Call review of draft-ietf-oauth-saml2-bearer-21

2014-10-06 Thread Mike Jones
Thanks for your review, Tom. I've added the working group to this thread so they're aware of your comment. > -Original Message- > From: Tom Taylor [mailto:tom.taylor.s...@gmail.com] > Sent: Sunday, September 28, 2014 8:33 PM > To: ops-...@ietf.org; draft-ietf-oauth-saml2-bearer@tools

Re: [OAUTH-WG] Ted Lemon's No Objection on draft-ietf-oauth-json-web-token-27: (with COMMENT)

2014-10-06 Thread Mike Jones
Thanks for your review, Ted. I'm adding the working group to the thread so they're aware of your comments. > -Original Message- > From: Ted Lemon [mailto:ted.le...@nominum.com] > Sent: Thursday, October 02, 2014 6:58 AM > To: The IESG > Cc: oauth-cha...@tools.ietf.org; draft-ietf-oauth-j

Re: [OAUTH-WG] Stephen Farrell's Discuss on draft-ietf-oauth-json-web-token-27: (with DISCUSS and COMMENT)

2014-10-06 Thread Mike Jones
Thanks for your review, Stephen. I've added the working group to the thread so they're aware of your comments. > -Original Message- > From: Stephen Farrell [mailto:stephen.farr...@cs.tcd.ie] > Sent: Thursday, October 02, 2014 5:03 AM > To: The IESG > Cc: oauth-cha...@tools.ietf.org; draf