Re: [OAUTH-WG] Error Responses in JWT Profile for OAuth 2.0 Access Tokens

2020-03-30 Thread Karl McGuinness
breaks interop. I think there is a real need to define resource owner authentication assurance interoperability for access tokens, but I fear this may require its own spec. -Karl Karl McGuinness Chief Product Architect www.okta.com<http://www.okta.com/> On Mar 25, 2020, at 12:59 PM, vitto

Re: [OAUTH-WG] MTLS vs. DPOP

2019-05-07 Thread Karl McGuinness
ially with OpenSSL bindings 1) https://medium.com/@vaneek/using-mutual-tls-authentication-in-a-serverless-world-3afd19a6fe70 -Karl On May 7, 2019, at 11:17 AM, Torsten Lodderstedt mailto:tors...@lodderstedt.net>> wrote: Am 07.05.2019 um 20:09 schrieb Karl McGuinness mailto:kmcguinn.

Re: [OAUTH-WG] MTLS vs. DPOP

2019-05-07 Thread Karl McGuinness
mTLS has significant challenges at scale in a multi-tenant SaaS deployment on public clouds using modern edge technologies/services. Applications are increasingly being built using Function-as-a-Service/ephemeral workloads as well. Additional complexity increases if you also want to support "b

Re: [OAUTH-WG] draft-bertocci-oauth-access-token-jwt-00

2019-05-06 Thread Karl McGuinness
On Mon, May 6, 2019 at 12:16 PM Vladimir Dzhuvinov > mailto:vladi...@connect2id.com>> > wrote: > >> On 06/05/2019 20:32, Vittorio Bertocci wrote: >>> To that end, *Karl MCGuinness suggested that we include >>> grant_type as a return claim, which the RS could use to the