Re: [OAUTH-WG] OAuth Milestone Update and Rechartering

2014-05-15 Thread Brian Campbell
ype. > > We're still dealing with ws-federation passive profile in saml dominated > world. The oauth working group shouldn't repeat that sin. > > -cmort > > > On Wed, May 14, 2014 at 2:40 PM, Anthony Nadalin wrote: > >> There are folks that are not implement

Re: [OAUTH-WG] OAuth Milestone Update and Rechartering

2014-05-15 Thread Brian Campbell
"I had personally requested the OIDC community about six months ago to describe some minimal subset which we could all reasonably implement. I was told that the specification was "locked down" and fully debugged and so on, so no changes could be made. Imagine my surprise to find that in the final

Re: [OAUTH-WG] OAuth Milestone Update and Rechartering

2014-05-15 Thread Anthony Nadalin
Where is the confusion ? From: OAuth [mailto:oauth-boun...@ietf.org] On Behalf Of John Bradley Sent: Wednesday, May 14, 2014 10:59 AM To: Brian Campbell Cc: oauth@ietf.org Subject: Re: [OAUTH-WG] OAuth Milestone Update and Rechartering I know a number of people implementing http

Re: [OAUTH-WG] OAuth Milestone Update and Rechartering

2014-05-14 Thread Phil Hunt
ns of this already >>> and much interest >>> >>> >>> >>> From: OAuth [mailto:oauth-boun...@ietf.org] On Behalf Of Phil Hunt >>> Sent: Wednesday, May 14, 2014 8:32 AM >>> To: Brian Campbell >>> Cc: oauth@ietf.org >>>

Re: [OAUTH-WG] OAuth Milestone Update and Rechartering

2014-05-14 Thread Chuck Mortimore
gt; Regards, > Anil > > On 05/14/2014 10:47 AM, Anthony Nadalin wrote: > > I agree with Phil on this one, there are implementations of this already > and much interest > > > > *From:* OAuth [mailto:oauth-boun...@ietf.org ] *On > Behalf Of *Phil Hunt > *Sent:* Wed

Re: [OAUTH-WG] OAuth Milestone Update and Rechartering

2014-05-14 Thread Prateek Mishra
oauth-boun...@ietf.org] *On Behalf Of *Phil Hunt *Sent:* Wednesday, May 14, 2014 8:32 AM *To:* Brian Campbell *Cc:* oauth@ietf.org *Subject:* Re: [OAUTH-WG] OAuth Milestone Update and Rechartering On the contrary. I and others are interested. We are waiting for the charter to pick up the work. Regard

Re: [OAUTH-WG] OAuth Milestone Update and Rechartering

2014-05-14 Thread Chuck Mortimore
e > connect everwhere as it’s over kill where we only need a the functionality > of a4c. > > > > *From:* Chuck Mortimore [mailto:cmortim...@salesforce.com] > *Sent:* Wednesday, May 14, 2014 9:39 AM > *To:* Anthony Nadalin > *Cc:* Phil Hunt; Brian Campbell; oauth@ietf.org > >

Re: [OAUTH-WG] OAuth Milestone Update and Rechartering

2014-05-14 Thread Brian Campbell
wrote: > Please list the implementstions > > > > *From:* OAuth [mailto:oauth-boun...@ietf.org] *On Behalf Of *John Bradley > *Sent:* Wednesday, May 14, 2014 10:59 AM > > *To:* Brian Campbell > *Cc:* oauth@ietf.org > *Subject:* Re: [OAUTH-WG] OAuth Milestone Update and

Re: [OAUTH-WG] OAuth Milestone Update and Rechartering

2014-05-14 Thread John Bradley
> > To: Brian Campbell > Cc: oauth@ietf.org > Subject: Re: [OAUTH-WG] OAuth Milestone Update and Rechartering > > > > I know a number of people implementing > > > > > http://tools.ietf.org/html/draft-sakimura-oauth-tcse-03 > > > > Havi

Re: [OAUTH-WG] OAuth Milestone Update and Rechartering

2014-05-14 Thread Anthony Nadalin
a4c. From: Chuck Mortimore [mailto:cmortim...@salesforce.com] Sent: Wednesday, May 14, 2014 9:39 AM To: Anthony Nadalin Cc: Phil Hunt; Brian Campbell; oauth@ietf.org Subject: Re: [OAUTH-WG] OAuth Milestone Update and Rechartering Can you point to one publicly available or publicly documented

Re: [OAUTH-WG] OAuth Milestone Update and Rechartering

2014-05-14 Thread Anthony Nadalin
Please list the implementstions From: OAuth [mailto:oauth-boun...@ietf.org] On Behalf Of John Bradley Sent: Wednesday, May 14, 2014 10:59 AM To: Brian Campbell Cc: oauth@ietf.org Subject: Re: [OAUTH-WG] OAuth Milestone Update and Rechartering I know a number of people implementing http

Re: [OAUTH-WG] OAuth Milestone Update and Rechartering

2014-05-14 Thread John Bradley
I know a number of people implementing > http://tools.ietf.org/html/draft-sakimura-oauth-tcse-03 Having it on a RFC track may make sense. I remain to be convinced that a4c ads anything other than confusion. If the WG wants to take it up it should be aligned with Connect. I think there are m

Re: [OAUTH-WG] OAuth Milestone Update and Rechartering

2014-05-14 Thread Paul Madsen
Phil, neither is Connect an authentication mechanism, it (and SAML, WS-fed etc) is also a 'method for providing end-user authentication information to client applications' We don't need a Connect-- paul On 5/14/14, 1:29 PM, Phil Hunt wrote: This is not an authentication mechanism - it is a met

Re: [OAUTH-WG] OAuth Milestone Update and Rechartering

2014-05-14 Thread Chuck Mortimore
Would still love to hear you answer _why_ "the IETF needs a draft that enables and provides user authentication information to clients." Would still love to see Tony point to the existing a4c implementations. On Wed, May 14, 2014 at 10:29 AM, Phil Hunt wrote: > This is not an authentication

Re: [OAUTH-WG] OAuth Milestone Update and Rechartering

2014-05-14 Thread Phil Hunt
This is not an authentication mechanism - it is a method for providing end-user authentication information to client applications. I will publish a revised draft shortly. Phil @independentid www.independentid.com phil.h...@oracle.com On May 14, 2014, at 10:23 AM, George Fletcher wrote: >

Re: [OAUTH-WG] OAuth Milestone Update and Rechartering

2014-05-14 Thread Anil Saldhana
: [OAUTH-WG] OAuth Milestone Update and Rechartering On the contrary. I and others are interested. We are waiting for the charter to pick up the work. Regardless there will be a new draft shortly. Phil On May 14, 2014, at 5:24, Brian Campbell <mailto:bcampb...@pingidentity.com>> wrote

Re: [OAUTH-WG] OAuth Milestone Update and Rechartering

2014-05-14 Thread George Fletcher
I also would like to see the WG not focus on another authentication mechanism and instead look at work like Brian suggested. Thanks, George On 5/14/14, 11:41 AM, Chuck Mortimore wrote: Agree with Brian and Justin here. Work is already covered in Connect - cmort On May 14, 2014, at 8:39 AM,

Re: [OAUTH-WG] OAuth Milestone Update and Rechartering

2014-05-14 Thread Chuck Mortimore
t; > -cmort > > > On Wed, May 14, 2014 at 8:47 AM, Anthony Nadalin wrote: > >> I agree with Phil on this one, there are implementations of this >> already and much interest >> >> >> >> *From:* OAuth [mailto:oauth-boun...@ietf.org] *On Behalf Of *Ph

Re: [OAUTH-WG] OAuth Milestone Update and Rechartering

2014-05-14 Thread Phil Hunt
nthony Nadalin > wrote: > I agree with Phil on this one, there are implementations of this already and > much interest > > > > From: OAuth [mailto:oauth-boun...@ietf.org] On Behalf Of Phil Hunt > Sent: Wednesday, May 14, 2014 8:32 AM > To: Brian Campbell > C

Re: [OAUTH-WG] OAuth Milestone Update and Rechartering

2014-05-14 Thread Chuck Mortimore
gt; *Subject:* Re: [OAUTH-WG] OAuth Milestone Update and Rechartering > > > > On the contrary. I and others are interested. > > > > We are waiting for the charter to pick up the work. > > > > Regardless there will be a new draft shortly. > > > Phil > &

Re: [OAUTH-WG] OAuth Milestone Update and Rechartering

2014-05-14 Thread Bill Mills
I think there's a use case for this work that may or may not be covered by the PoP spec, and in fact I think this work is related to that.  The MAC token work is really one use case of POP tokens.  Rather than shouting it down let's figure out how to solve this use case. On Wednesday, May 14,

Re: [OAUTH-WG] OAuth Milestone Update and Rechartering

2014-05-14 Thread Anthony Nadalin
I agree with Phil on this one, there are implementations of this already and much interest From: OAuth [mailto:oauth-boun...@ietf.org] On Behalf Of Phil Hunt Sent: Wednesday, May 14, 2014 8:32 AM To: Brian Campbell Cc: oauth@ietf.org Subject: Re: [OAUTH-WG] OAuth Milestone Update and

Re: [OAUTH-WG] OAuth Milestone Update and Rechartering

2014-05-14 Thread Justin Richer
I agree with Brian and object to the Authentication work item. I think there’s limited interest and utility in such a draft, especially now that OpenID Connect has been published and its core authentication capabilities are identical to what was called for in the other draft a year ago (a simila

Re: [OAUTH-WG] OAuth Milestone Update and Rechartering

2014-05-14 Thread Chuck Mortimore
Agree with Brian and Justin here. Work is already covered in Connect - cmort On May 14, 2014, at 8:39 AM, Justin Richer wrote: I agree with Brian and object to the Authentication work item. I think there’s limited interest and utility in such a draft, especially now that OpenID Connect has be

Re: [OAUTH-WG] OAuth Milestone Update and Rechartering

2014-05-14 Thread Phil Hunt
On the contrary. I and others are interested. We are waiting for the charter to pick up the work. Regardless there will be a new draft shortly. Phil > On May 14, 2014, at 5:24, Brian Campbell wrote: > > I would object to 'OAuth Authentication' being picked up by the WG as a work > item. T

Re: [OAUTH-WG] OAuth Milestone Update and Rechartering

2014-05-14 Thread Brian Campbell
I would object to 'OAuth Authentication' being picked up by the WG as a work item. The starting point draft has expired and it hasn't really been discusses since Berlin nearly a year ago. As I recall, there was only very limited interest in it even then. I also don't believe it fits well with the

[OAUTH-WG] OAuth Milestone Update and Rechartering

2014-05-08 Thread Hannes Tschofenig
Hi all, you might have seen that we pushed the assertion documents and the JWT documents to the IESG today. We have also updated the milestones on the OAuth WG page. This means that we can plan to pick up new work in the group. We have sent a request to Kathleen to change the milestone for the OA