Re: [OAUTH-WG] HTTP Message Signing and OAuth PoP

2021-05-05 Thread Rifaat Shekh-Yusef
I have requested a session for this coming Monday, May 10th @ 12:00 pm ET. An announcement should be coming soon. Regards, Rifaat On Wed, May 5, 2021 at 7:54 AM Rifaat Shekh-Yusef wrote: > Would this coming Monday, May 10th @ 12:00 pm ET, work for you? > > Regards, > Rifaat > > > On Mon, May

Re: [OAUTH-WG] HTTP Message Signing and OAuth PoP

2021-05-05 Thread Rifaat Shekh-Yusef
Would this coming Monday, May 10th @ 12:00 pm ET, work for you? Regards, Rifaat On Mon, May 3, 2021 at 8:59 AM Justin Richer wrote: > Hi Rifaat, > > If you’d like to keep the current mondays-at-noon-ET schedule I can > support that. Any Monday this month would work for me, and I’ve reached ou

Re: [OAUTH-WG] HTTP Message Signing and OAuth PoP

2021-05-03 Thread Justin Richer
Hi Rifaat, If you’d like to keep the current mondays-at-noon-ET schedule I can support that. Any Monday this month would work for me, and I’ve reached out to Annabelle so hopefully she can join as well. I don’t know if I’d be able to have the rewrite of the OAuth PoP draft in hand by any of tho

Re: [OAUTH-WG] HTTP Message Signing and OAuth PoP

2021-04-29 Thread Rifaat Shekh-Yusef
Hi Justin, Thanks for the update on this, We would be happy to schedule an interim meeting to discuss this. Do you have a date in mind? Regards, Rifaat & Hannes On Thu, Apr 29, 2021 at 11:34 AM Justin Richer wrote: > Many of you will remember an old draft that I was the editor of that > d

Re: [OAUTH-WG] HTTP Message Signing and OAuth PoP

2021-04-29 Thread Phillip Hunt
Justin Thanks for this. I am pleased the HTTPbis group took this up. It is a multi-WG issue that needs their expertise. I look forward to reading the new draft. Cheers, Phil > On Apr 29, 2021, at 8:34 AM, Justin Richer wrote: > > Many of you will remember an old draft that I was the edito

[OAUTH-WG] HTTP Message Signing and OAuth PoP

2021-04-29 Thread Justin Richer
Many of you will remember an old draft that I was the editor of that defined OAuth proof of possession methods using HTTP Message Signing. When writing that draft I invented my own scheme because there wasn’t an existing HTTP message signature standard that was robust enough for our use cases. I