[OAUTH-WG] OAuth Security Workshop Call for Proposals

2019-01-11 Thread Torsten Lodderstedt
Hi all, the Call for Proposal for the 4th OAuth Security Workshop is out! https://sec.uni-stuttgart.de/events/osw2019 Please propose a session! kind regards, Torsten. smime.p7s Description: S/MIME cryptographic signature ___ OAuth mailing list OAuth

Re: [OAUTH-WG] MTLS and in-browser clients using the token endpoint

2019-01-11 Thread David Waite
> On Jan 11, 2019, at 3:32 AM, Neil Madden wrote: > > On 9 Jan 2019, at 05:54, David Waite wrote: >> >>> On Dec 28, 2018, at 3:55 PM, Brian Campbell >>> wrote: >>> >> >> >>> All of that is meant as an explanation of sorts to say that I think that >>> things are actually okay enough as i

Re: [OAUTH-WG] Benjamin Kaduk's Discuss on draft-ietf-oauth-token-exchange-16: (with DISCUSS and COMMENT)

2019-01-11 Thread Mike Jones
I would advocate requesting early registration for urn:ietf:params:oauth:grant-type:token-exchange. -- Mike -Original Message- From: Benjamin Kaduk Sent: Friday, January 11, 2019 8:13 AM To: Brian Campbell Cc: The IESG ; oauth ; draft-ietf-oauth-token-

Re: [OAUTH-WG] Benjamin Kaduk's Discuss on draft-ietf-oauth-token-exchange-16: (with DISCUSS and COMMENT)

2019-01-11 Thread Benjamin Kaduk
I also apologize for the slow response (I gave Brian a unicast heads-up earlier) -- between vacation, the holidays, and a death in a the family I was away from email for quite some time. On Tue, Dec 04, 2018 at 02:54:36PM -0700, Brian Campbell wrote: > I apologize for the slow response, Ben. I was

Re: [OAUTH-WG] MTLS and in-browser clients using the token endpoint

2019-01-11 Thread Filip Skokan
307 indeed seems doable, similar to a discovery namespace it requires the client software to be prepared for this and follow the redirect in that case, but in David’s case it doesn’t require the client to “know” it is bound to a device wide policy. The client just assumes it has no form of authenti

Re: [OAUTH-WG] MTLS and in-browser clients using the token endpoint

2019-01-11 Thread Neil Madden
On 9 Jan 2019, at 05:54, David Waite wrote: > >> On Dec 28, 2018, at 3:55 PM, Brian Campbell >> wrote: >> > > >> All of that is meant as an explanation of sorts to say that I think that >> things are actually okay enough as is and that I'd like to retract the >> proposal I'd previously mad