Re: [OAUTH-WG] Secdir Review of draft-ietf-oauth-jwt-bearer-10

2014-10-17 Thread Brian Campbell
I agree with mike that any additional guidance on when you'd want to use an assertion for client authentication vs. when you would want to use one for an authorization grant would belong in the generic assertions specification draft-ietf-oauth-assertions. I'm struggling with what guidance to give

Re: [OAUTH-WG] Secdir Review of draft-ietf-oauth-jwt-bearer-10

2014-10-06 Thread Mike Jones
Thanks for your review, Radia. I've added the working group to the thread so that they're aware of your comments. > From: Radia Perlman [mailto:radiaperl...@gmail.com] > Sent: Monday, September 29, 2014 4:46 PM > To: sec...@ietf.org; The IESG; draft-ietf-oauth-jwt-bearer@tools.ietf.org > Su