[OAUTH-WG] Re: Product Support for RFC8414 well-known URIs

2024-07-04 Thread Michael Jones
I'm aware of many production deployments of authorization server metadata that, for the issuer https://example.com/tenants/tenant123 use the OpenID Connect .well-known path formulation https://example.com/tenants/tenant123/.well-known/openid-configuration and none that use https://example.com/

[OAUTH-WG] Shepherd Review for OAuth 2.0 Protected Resource Metadata draft

2024-07-04 Thread Rifaat Shekh-Yusef
Mike, Phil, Aaron, The following is my shepherd review for OAuth 2.0 Protected Resource Metadata https://www.ietf.org/archive/id/draft-ietf-oauth-resource-metadata-05.html *Comments/Questions* 5.4. Compatibility with other authentication methods Would this not open the door for potential downg