Re: [OAUTH-WG] Hashing passwords for "password" grant type

2010-09-10 Thread Yutaka OIWA
oring the passwords in plain > text in the database anyway. Anybody else dealing with a similar issue? > > Aaron > > > > > _______ > OAuth mailing list > OAuth@ietf.org > https://www.ietf.org/mailman/listinfo/oauth -- 大岩 寛 Yutaka Oiwa 独立行政法人 産業技術総合研究所

Re: [OAUTH-WG] Open Issues: Group Survey (respond by 5/13)

2010-05-11 Thread Yutaka OIWA
tools.ietf.org/html/draft-oiwa-http-mutualauth-06>. I designed it mainly considering Browser-based authentication, but I do not limit its possible uses to Browsers. Feedbacks from other possible usage area, if possible, is much appreciated. -- Yutaka OIWA, Ph.D.

Re: [OAUTH-WG] Open Issues: Group Survey (respond by 5/13)

2010-05-11 Thread Yutaka OIWA
gle-octet forcibly). # "Authorization: Basic 5SyeOuUsng==". You can see there is only # 7 octets (for 6 Japanese characters + a colon) after decoding BASE64. -- Yutaka OIWA, Ph.D. Research Scientist Research Center for Informat

[OAUTH-WG] HTTP auth issues, in Anaheim

2010-03-19 Thread Yutaka OIWA
rd to discussing issues there. Cheers, -- Yutaka OIWA, Ph.D. Research Scientist Research Center for Information Security (RCIS) National Institute of Advanced Industrial Science and Technology (AIST) Mail addr

Re: [OAUTH-WG] draft-oiwa-http-mutualauth-06

2010-02-26 Thread Yutaka OIWA
g it to several parts, e.g. introduction, general HTTP extensions and Mutual authentication. I am currently planning to do it after the harmonization above. -- Yutaka OIWA, Ph.D. Research Scientist Research Center fo

Re: [OAUTH-WG] Authentication-Info Header

2010-01-21 Thread Yutaka Oiwa
ror information (ours has a 1-bit flag in WWW-Authenticate to distinguish between password mismatch and key expiration, on which client behavior differs). I'm interested if we also have a similar need which is not realized now. -- Yutaka OIWA, Ph.D. Research Sci