[OAUTH-WG] draft-ietf-oauth-selective-disclosure-jwt-19 telechat Artart review

2025-05-15 Thread Henry Thompson via Datatracker
Document: draft-ietf-oauth-selective-disclosure-jwt Title: Selective Disclosure for JWTs (SD-JWT) Reviewer: Henry Thompson Review result: Ready with Nits I framed my only major point as a recommendation, not a requirement, and that recommendation was, effectively, declined in subsequent emails. S

[OAUTH-WG] Re: [Last-Call] [OAUTH-WG] draft-ietf-oauth-selective-disclosure-jwt-18 ietf last call Artart review

2025-05-02 Thread Carsten Bormann
On 2. May 2025, at 16:18, Henry S. Thompson wrote: > > Carsten Bormann writes: > >> ... > >> For IETF purposes, JSON text is always UTF-8 encoded, so there is no >> difference. > > I don't agree, based on my reading of 8259. It's clear that a single > U+0076 character can occur in "JSON text

[OAUTH-WG] Re: [Last-Call] [OAUTH-WG] draft-ietf-oauth-selective-disclosure-jwt-18 ietf last call Artart review

2025-05-02 Thread Henry S. Thompson
Carsten Bormann writes: > ... > For IETF purposes, JSON text is always UTF-8 encoded, so there is no > difference. I don't agree, based on my reading of 8259. It's clear that a single U+0076 character can occur in "JSON text", but as such that text is _not_ a byte sequence >> The problem you'v

[OAUTH-WG] Re: [Last-Call] [OAUTH-WG] draft-ietf-oauth-selective-disclosure-jwt-18 ietf last call Artart review

2025-05-02 Thread Carsten Bormann
On 2. May 2025, at 13:09, Henry S. Thompson wrote: > > Carsten Bormann writes: > >> On 2. May 2025, at 12:04, Henry Thompson via Datatracker >> wrote: >>> >>> ["26bc4LT-ac6q2KI6cBW5es", "family_name", "M%xc3%xb6bius"] [2] >> >> The weird %x notation in the third element has nothing to do

[OAUTH-WG] draft-ietf-oauth-selective-disclosure-jwt-18 ietf last call Artart review

2025-05-02 Thread Henry Thompson via Datatracker
Document: draft-ietf-oauth-selective-disclosure-jwt Title: Selective Disclosure for JWTs (SD-JWT) Reviewer: Henry Thompson Review result: Ready with Issues Document: draft-ietf-oauth-selective-disclosure-jwt-18 Title: Selective Disclosure for JWTs (SD-JWT) Reviewer: Henry S. Thompson Review Date:

[OAUTH-WG] draft-ietf-oauth-selective-disclosure-jwt non-selectively disclosable claims

2025-04-03 Thread Chad Parry
The phrase "non-selectively disclosable claims" confused me. At first I interpreted it to mean "claims that are disclosable but not in a selective way." The intended reading is "claims that are not selectively disclosable." The ambiguity is between "(non-selectively) disclosable claims" and "

[OAUTH-WG] draft-ietf-oauth-selective-disclosure-jwt-14: Comments and issues raised during the 1rst and the 2nd WGLC have not been addressed in -14

2024-11-18 Thread Denis
This email is mostly a duplication of the issue #528 that has been added during the week-end: Comments and issues raised during the 1rst and the 2nd WGLC have not been addressed in -14 #528 https://github.com/oauth-wg/oauth-selective-disclosure-jwt/issues/528 However, I have added a ne

Re: [OAUTH-WG] draft-ietf-oauth-selective-disclosure-jwt

2022-12-06 Thread Brian Campbell
rian Campbell > *Sent:* Tuesday, November 29, 2022 11:21 PM > *To:* Hannes Tschofenig > *Cc:* oauth > *Subject:* Re: [OAUTH-WG] draft-ietf-oauth-selective-disclosure-jwt > > > > Hi Hannes, > > > > Though I am yet to officially have my name on the document as

Re: [OAUTH-WG] draft-ietf-oauth-selective-disclosure-jwt

2022-12-05 Thread Hannes Tschofenig
Thanks for the response, Brian. A few remarks below. From: Brian Campbell Sent: Tuesday, November 29, 2022 11:21 PM To: Hannes Tschofenig Cc: oauth Subject: Re: [OAUTH-WG] draft-ietf-oauth-selective-disclosure-jwt Hi Hannes, Though I am yet to officially have my name on the document as a co

Re: [OAUTH-WG] draft-ietf-oauth-selective-disclosure-jwt

2022-12-01 Thread Denis
Hi Brian, My two cents. 1) This draft is about selective-disclosure. The draft should be balanced between enclosure and disclosure. The topic of selective-enclosure should also be addressed. In particular in OAuth, the claims to be incorporated are usually only selected with a coarse granula

Re: [OAUTH-WG] draft-ietf-oauth-selective-disclosure-jwt

2022-11-29 Thread Brian Campbell
Hi Hannes, Though I am yet to officially have my name on the document as a co-author, you did mention me directly :) And so I'll attempt to answer or respond to your questions/statements below. On Mon, Nov 28, 2022 at 7:24 AM Hannes Tschofenig wrote: > Hi Daniel, Hi Kristina, Hi Brian, > > Hi

[OAUTH-WG] draft-ietf-oauth-selective-disclosure-jwt

2022-11-28 Thread Hannes Tschofenig
Hi Daniel, Hi Kristina, Hi Brian, Hi all, Reading through draft-ietf-oauth-selective-disclosure-jwt I was wondering why the document defines new terminology for roles that already exist in OAuth. For example: * Issuer = AS * Holder = Client * Verifier = RS I assume that was done