Re: [OAUTH-WG] Security BCP Review

2022-04-16 Thread Rifaat Shekh-Yusef
On Mon, Apr 11, 2022 at 11:13 AM Daniel Fett wrote: > Hi Rifaat, > Am 14.02.22 um 22:26 schrieb Rifaat Shekh-Yusef: > > As part of the preparation for the shepherd write-up, I reviewed the > document and have the following comments: > > https://www.ietf.org/archive/id/draft-ietf-oauth-security-to

Re: [OAUTH-WG] Security BCP Review

2022-04-11 Thread Daniel Fett
Hi Rifaat, Am 14.02.22 um 22:26 schrieb Rifaat Shekh-Yusef: As part of the preparation for the shepherd write-up, I reviewed the document and have the following comments: https://www.ietf.org/archive/id/draft-ietf-oauth-security-topics-19.html

[OAUTH-WG] Security BCP Review

2022-02-14 Thread Rifaat Shekh-Yusef
As part of the preparation for the shepherd write-up, I reviewed the document and have the following comments: https://www.ietf.org/archive/id/draft-ietf-oauth-security-topics-19.html General comment The document refers to a number of drafts that are not active anymore, e.g., token binding, pop

[OAUTH-WG] Security BCP Review

2019-11-05 Thread Lee McGovern
As discussed on call yesterday here is my comments after review of https://tools.ietf.org/html/draft-ietf-oauth-security-topics-13 3.1 - "Clients MUST memorize which authorization server they sent an authorization request to" - is memorize the best synonym here, perhaps store or retain is more