Re: [OAUTH-WG] JWT: add "iss" and "aud" to Reserved Header Parameter Names in JWE

2013-07-14 Thread Dick Hardt
nt:* Wednesday, May 29, 2013 8:48 AM > *To:* Anthony Nadalin > *Cc:* O Auth WG > > *Subject:* Re: [OAUTH-WG] JWT: add "iss" and "aud" to Reserved Header > Parameter Names in JWE > > ** ** > > Yes, there could be privacy issues, and we can d

Re: [OAUTH-WG] JWT: add "iss" and "aud" to Reserved Header Parameter Names in JWE

2013-07-14 Thread Mike Jones
e JWT." -- Mike From: oauth-boun...@ietf.org [mailto:oauth-boun...@ietf.org] On Behalf Of Dick Hardt Sent: Wednesday, May 29, 2013 8:48 AM To: Anthony Nadalin Cc: O Auth WG Subject: Re: [OAUTH-WG] JWT: add "iss" and "aud" to Reserved Heade

Re: [OAUTH-WG] JWT: add "iss" and "aud" to Reserved Header Parameter Names in JWE

2013-05-29 Thread Dick Hardt
rypted payload > > ** ** > > *From:* oauth-boun...@ietf.org [mailto:oauth-boun...@ietf.org] *On Behalf > Of *Dick Hardt > *Sent:* Tuesday, May 28, 2013 9:34 AM > *To:* O Auth WG > *Subject:* Re: [OAUTH-WG] JWT: add "iss" and "aud" to Reserved Header >

Re: [OAUTH-WG] JWT: add "iss" and "aud" to Reserved Header Parameter Names in JWE

2013-05-29 Thread Anthony Nadalin
So there could be privacy issues on why I would not want the ISS or AUD outside the encrypted payload From: oauth-boun...@ietf.org [mailto:oauth-boun...@ietf.org] On Behalf Of Dick Hardt Sent: Tuesday, May 28, 2013 9:34 AM To: O Auth WG Subject: Re: [OAUTH-WG] JWT: add "iss" an

Re: [OAUTH-WG] JWT: add "iss" and "aud" to Reserved Header Parameter Names in JWE

2013-05-28 Thread Dick Hardt
Following up on this topic ... On Wed, May 1, 2013 at 2:12 PM, Dick Hardt wrote: > "iss" and "aud" would be optional parameters in a JWE. These parameters > are in the payload, but since it is encrypted, the payload must be > decrypted before they can be read. Some times knowing these parameter

Re: [OAUTH-WG] JWT: add "iss" and "aud" to Reserved Header Parameter Names in JWE

2013-05-01 Thread Dick Hardt
; > -- Mike > > -Original Message- > From: oauth-boun...@ietf.org [mailto:oauth-boun...@ietf.org] On Behalf Of > Dick Hardt > Sent: Wednesday, May 01, 2013 2:12 PM > To: O Auth WG > Subject: [OAUTH-WG] JWT: add "iss" and "aud&

Re: [OAUTH-WG] JWT: add "iss" and "aud" to Reserved Header Parameter Names in JWE

2013-05-01 Thread Mike Jones
-- Mike -Original Message- From: oauth-boun...@ietf.org [mailto:oauth-boun...@ietf.org] On Behalf Of Dick Hardt Sent: Wednesday, May 01, 2013 2:12 PM To: O Auth WG Subject: [OAUTH-WG] JWT: add "iss" and "aud" to Reserved Header Parameter Names in JWE "iss&quo

[OAUTH-WG] JWT: add "iss" and "aud" to Reserved Header Parameter Names in JWE

2013-05-01 Thread Dick Hardt
"iss" and "aud" would be optional parameters in a JWE. These parameters are in the payload, but since it is encrypted, the payload must be decrypted before they can be read. Some times knowing these parameters is required to be able to decrypt the payload … These would be additions to 9.3.1 in