Re: [OAUTH-WG] Rechartering OAuth: New Charter Text

2016-01-15 Thread Phil Hunt (IDM)
Hannes I would like to propose a brief presentation on "events". While this might not end up being oauth wg activity, I think a lot of attendees may be interested. We might make this one of those if we have time topics. Phil > On Jan 15, 2016, at 12:15, Hannes Tschofenig > wrote: > > Hi B

[OAUTH-WG] Rechartering OAuth: New Charter Text

2016-01-15 Thread Hannes Tschofenig
Hi Barry, as discussed today I am forwarding you the new charter text for the OAuth working group. In parallel to the IESG processing this re-chartering request we will run a call for adoption to also update the milestone list at the same time. Ciao Hannes & Derek -- Ch

Re: [OAUTH-WG] IETF 95 - Buenos Aires

2016-01-15 Thread Brian Campbell
Speaking for myself but I suspect others might be in the same boat - I'd love to see some additional time beyond the official meeting made available to try and make more progress on the open work in OAuth. But the week before IETF in a different country (even if it's only a 19h bus ride) just isn't

Re: [OAUTH-WG] IETF 95 - Buenos Aires

2016-01-15 Thread John Bradley
Paul if you are interested there is something more your speed. http://www.eldertreks.com/tour/ETTD000364 > On Jan 15, 2016, at 9:50 AM, Paul Madsen wrote: > > John, could you not supply a donkey to carry Hannes' luggage? or is it a BYOD > instance? >

Re: [OAUTH-WG] IETF 95 - Buenos Aires

2016-01-15 Thread John Bradley
For the direct route I would take a llama as the pack animal. I could arrange one , but it would need to be returned for the deposit. I don’t know of anyone with one way llama rentals. (he could purchase it outright and eat it in BA I suppose.) I am willing to provide reasonable support, but

Re: [OAUTH-WG] IETF 95 - Buenos Aires

2016-01-15 Thread Paul Madsen
John, could you not supply a donkey to carry Hannes' luggage? or is it a BYOD instance? On 1/15/16 9:33 AM, John Bradley wrote: It is about a 13day walk with a really big hill (Andies) that he would need to get over. If he came a week early and had a water carrier he might make it depending

Re: [OAUTH-WG] Question about RFC 7622 (Token Introspection)

2016-01-15 Thread John Bradley
Currently the canonical form of RFC is ASCII and there is a external tool that tries to do HTML markup on the ascii version. When authoring something that works in english may well not get the right HTML markup. The Authors do there best but there is no way to fix by editing the HTML as a reaso

Re: [OAUTH-WG] IETF 95 - Buenos Aires

2016-01-15 Thread John Bradley
PS it is about a 19h senic bus ride over the Andies taking a not direct route via Mendoza, for anyone wanting a bus option. I am planing to fly myself. Lots of flights on the domestic airlines. John B. On Jan 15, 2016 9:33 AM, "John Bradley" wrote: > It is about a 13day walk with a really big

Re: [OAUTH-WG] IETF 95 - Buenos Aires

2016-01-15 Thread John Bradley
It is about a 13day walk with a really big hill (Andies) that he would need to get over. If he came a week early and had a water carrier he might make it depending on route. I would not dare him on it! I am not going to be his water carrier! On Jan 15, 2016 9:25 AM, "Klaas Wierenga (kwiereng)" w

Re: [OAUTH-WG] IETF 95 - Buenos Aires

2016-01-15 Thread Klaas Wierenga (kwiereng)
No, Hannes wants to run from Santiago to Buenos Aires ;-) Sent from my iPhone On 15 Jan 2016, at 15:22, John Bradley mailto:ve7...@ve7jtb.com>> wrote: The Friday is available. We can find space if there is interest. I was expecting you to be doing some 100k wine run on the Friday. John B.

Re: [OAUTH-WG] IETF 95 - Buenos Aires

2016-01-15 Thread John Bradley
The Friday is available. We can find space if there is interest. I was expecting you to be doing some 100k wine run on the Friday. John B. On Jan 15, 2016 9:11 AM, "Hannes Tschofenig" wrote: > Would it make sense to add an OAuth day to the OpenID Summit to prepare > the IETF meeting, to play a

Re: [OAUTH-WG] Question about RFC 7622 (Token Introspection)

2016-01-15 Thread Buhake Sindi
Hi, Was just reading the specification (RFC 7662) and the following link "breaks" Chapter 2.3 2.3 . Error Response If the protected resource uses OAuth 2.0 client credentials to authenticate to the introspection endpoint and its credentia

Re: [OAUTH-WG] Question about RFC 7622 (Token Introspection)

2016-01-15 Thread Sergey Beryozkin
Ouch, you are right, sorry for the confusion, Thanks, Sergey On 15/01/16 14:13, Buhake Sindi wrote: Hi, Are you not mistaking this with RFC 7662? :-) Kind Regards, Buhake Sindi On 15 Jan 2016 12:34, "Sergey Beryozkin" mailto:sberyoz...@gmail.com>> wrote: Hi All, I'm reviewing RFC 76

Re: [OAUTH-WG] Question about RFC 7622 (Token Introspection)

2016-01-15 Thread Buhake Sindi
Hi, Are you not mistaking this with RFC 7662? :-) Kind Regards, Buhake Sindi On 15 Jan 2016 12:34, "Sergey Beryozkin" wrote: > Hi All, > > I'm reviewing RFC 7622 as we are going ahead with implementing it. > I have a question: > > 1. Token Hint in the introspection request. > The spec mentions

Re: [OAUTH-WG] IETF 95 - Buenos Aires

2016-01-15 Thread Hannes Tschofenig
Would it make sense to add an OAuth day to the OpenID Summit to prepare the IETF meeting, to play around with code, etc? On 01/15/2016 01:58 PM, John Bradley wrote: > Yes I am going. > > The University of Chile and RedHat are sponsoring a one day OpenID Summit on > Mar 31. > > I will send the r

Re: [OAUTH-WG] Question about RFC 7622 (Token Introspection)

2016-01-15 Thread Sergey Beryozkin
Hi John Thanks, looks like it was a last minute change because Introduction does not explain why would clients want to use the introspection endpoint to effectively 'unwrap' the opaque token representations. I have another question. How to report the expiry time in cases when the tokens do n

Re: [OAUTH-WG] Question about RFC 7622 (Token Introspection)

2016-01-15 Thread John Bradley
Some people wanted the client to be able to use introspection. The ability to pass a refresh token is a legacy of that.A RS would never have a refresh token unless it is acting as a client. That is correct. John B. > On Jan 15, 2016, at 5:34 AM, Sergey Beryozkin wrote: > > Hi All, > > I

Re: [OAUTH-WG] IETF 95 - Buenos Aires

2016-01-15 Thread John Bradley
Yes in Santiago Chile a short flight or long drive to Buenos Ares. It is the Thursday prior to the IETF so that people have time to visit my Parcella and go on wine tours etc before heading to BA on Sunday. http://www.tripadvisor.com/Attraction_Review-g1136527-d8504544-Reviews-Maipo_Valley_Wine_T

Re: [OAUTH-WG] IETF 95 - Buenos Aires

2016-01-15 Thread Nat Sakimura
That's in Chile? 2016年1月15日(金) 21:58 John Bradley : > Yes I am going. > > The University of Chile and RedHat are sponsoring a one day OpenID Summit > on Mar 31. > > I will send the registration info to the list once we have it up. > > Anyone interested should email myself or Rolando who is cc’d on

Re: [OAUTH-WG] IETF 95 - Buenos Aires

2016-01-15 Thread John Bradley
Yes I am going. The University of Chile and RedHat are sponsoring a one day OpenID Summit on Mar 31. I will send the registration info to the list once we have it up. Anyone interested should email myself or Rolando who is cc’d on this. John B. > On Jan 15, 2016, at 6:08 AM, Hannes Tschofenig

Re: [OAUTH-WG] IETF 95 - Buenos Aires

2016-01-15 Thread Nat Sakimura
I plan to attend. =nat via iPhone 2016/01/15 20:08、Hannes Tschofenig のメッセージ: > Hi all, > > I have just requested a 2 hour meeting slot for the next IETF meeting in > Buenos Aires. > > It would be good to know whether you are planning to attend the upcoming > IETF meeting. Please drop me a pr

[OAUTH-WG] IETF 95 - Buenos Aires

2016-01-15 Thread Hannes Tschofenig
Hi all, I have just requested a 2 hour meeting slot for the next IETF meeting in Buenos Aires. It would be good to know whether you are planning to attend the upcoming IETF meeting. Please drop me a private mail to tell me your plans. Ciao Hannes signature.asc Description: OpenPGP digital sig

[OAUTH-WG] Question about RFC 7622 (Token Introspection)

2016-01-15 Thread Sergey Beryozkin
Hi All, I'm reviewing RFC 7622 as we are going ahead with implementing it. I have a question: 1. Token Hint in the introspection request. The spec mentions 'refresh_token' as one of the possible values. But a protected resource does not see a refresh token (ever ?), it is Access Token service