Re: [OAUTH-WG] Publication has been requested for draft-ietf-oauth-device-flow-07

2018-01-05 Thread Hollenbeck, Scott
> -Original Message- > From: OAuth [mailto:oauth-boun...@ietf.org] On Behalf Of Rifaat Shekh- > Yusef > Sent: Friday, January 05, 2018 12:30 PM > To: e...@rtfm.com > Cc: oauth@ietf.org; iesg-secret...@ietf.org; oauth-cha...@ietf.org > Subject: [EXTERNAL] [OAUTH-WG] Publication has been requ

Re: [OAUTH-WG] OAuth 2.0 Device Flow LC Comment (and OpenID Connect)

2018-01-03 Thread Hollenbeck, Scott
From: William Denniss [mailto:wdenn...@google.com] Sent: Tuesday, January 02, 2018 5:38 PM To: Hollenbeck, Scott Cc: oauth@ietf.org Subject: [EXTERNAL] Re: [OAUTH-WG] OAuth 2.0 Device Flow LC Comment (and OpenID Connect) On Mon, Nov 27, 2017 at 6:32 AM Hollenbeck, Scott mailto:shollenb

Re: [OAUTH-WG] WGLC for OAuth 2.0 Device Flow for Browserless and Input Constrained Devices

2018-01-02 Thread Hollenbeck, Scott
On Jan 2, 2018, at 4:08 PM, William Denniss mailto:wdenn...@google.com>> wrote: On Fri, Dec 15, 2017 at 11:12 PM, Vladimir Dzhuvinov mailto:vladi...@connect2id.com>> wrote: On 15/12/17 00:43, William Denniss wrote: > On Fri, Dec 8, 2017 at 11:42 AM, Vladimir Dzhuvinov > mailto:vladi...@connec

[OAUTH-WG] OAuth 2.0 Device Flow LC Comment (and OpenID Connect)

2017-11-27 Thread Hollenbeck, Scott
I have reviewed draft-ietf-oauth-device-flow-07. Just one comment regarding Section 5.1: Would it be possible to suggest some minimally acceptable entropy value? The text says "The user code SHOULD have enough entropy that when combined with rate limiting makes a brute-force attack infeasible",

Re: [OAUTH-WG] oauth with command line clients

2017-06-12 Thread Hollenbeck, Scott
From: OAuth [mailto:oauth-boun...@ietf.org] On Behalf Of Bill Burke Sent: Monday, June 12, 2017 9:23 AM To: Aaron Parecki Cc: OAuth WG Subject: [EXTERNAL] Re: [OAUTH-WG] oauth with command line clients I've read about these techniques, but, its just not a good user experience. I'm thinking m

Re: [OAUTH-WG] Identity Provider Interop Testing?

2016-09-27 Thread Hollenbeck, Scott
Thanks, Nat. Scott From: Nat Sakimura [mailto:sakim...@gmail.com] Sent: Tuesday, September 27, 2016 10:03 AM To: Hollenbeck, Scott; Justin Richer; oauth@ietf.org Subject: Re: [OAUTH-WG] Identity Provider Interop Testing? There is an interop list which does not have IPR requirement. The IPR

Re: [OAUTH-WG] Identity Provider Interop Testing?

2016-09-19 Thread Hollenbeck, Scott
> -Original Message- > From: OAuth [mailto:oauth-boun...@ietf.org] On Behalf Of Justin Richer > Sent: Monday, September 19, 2016 9:35 AM > To: oauth@ietf.org > Subject: Re: [OAUTH-WG] Identity Provider Interop Testing? > > You're better off contacting the OpenID Connect working group and t

[OAUTH-WG] Identity Provider Interop Testing?

2016-09-19 Thread Hollenbeck, Scott
I'm looking to do some OpenID Connect interoperability testing with someone who has implemented an identity provider. I have a relying party implementation that's been tested with Microsoft Hotmail and Google Gmail. I'd like to add support for at least one more IDP. Can anyone help? Scott

Re: [OAUTH-WG] Cross-Area Review Request for RDAP Authentication

2016-04-06 Thread Hollenbeck, Scott
: OAuth [mailto:oauth-boun...@ietf.org] On Behalf Of Hollenbeck, > Scott > Sent: Tuesday, January 19, 2016 9:40 AM > To: 'OAuth@ietf.org' > Subject: Re: [OAUTH-WG] Cross-Area Review Request for RDAP > Authentication > > > -Original Message- > > From:

Re: [OAUTH-WG] Cross-Area Review Request for RDAP Authentication

2016-01-19 Thread Hollenbeck, Scott
> -Original Message- > From: Hollenbeck, Scott > Sent: Monday, January 11, 2016 8:31 AM > To: OAuth@ietf.org > Subject: Cross-Area Review Request for RDAP Authentication > > I'd like to ask folks who are more familiar with OAuth than I am to > please re

[OAUTH-WG] Cross-Area Review Request for RDAP Authentication

2016-01-11 Thread Hollenbeck, Scott
I'd like to ask folks who are more familiar with OAuth than I am to please review an I-D I've written that describes an approach to using OpenID Connect with the Registration Data Access Protocol (RDAP, a product of the WEIRDS WG). Those of you who are familiar with WHOIS will understand the mot

[OAUTH-WG] Federated Authentication for RDAP

2015-03-23 Thread Hollenbeck, Scott
I was going to ask this question during the just-concluded WG session at IETF-92, but with a full agenda and little time I thought it might be better to ask this question on-list. The Registration Data Access Protocol (RDAP, a work product of the WEIRDS WG) uses a RESTful web service to access