Re: [OAUTH-WG] [SPICE] Relationship between SPICE and OAuth

2023-11-04 Thread Leif Johansson
I agree with Dick, Watson et al. To me moving some work around is a natural consequence of the identity area and the 3 party model growing in importance in the IETF and elsewhere. Given what’s happening in the EU and elsewhere this should not cone as a surprise to anyone.Cheers Leif3 nov. 2023 kl.

Re: [OAUTH-WG] [SPICE] Relationship between SPICE and OAuth

2023-11-03 Thread Dick Hardt
One source of delays could be different chairs that don't have the same context. Hard to imagine why the people participating in the oauth group would not keep participating in a spice group. I don't have a strong opinion -- but I am surprised by the angst expressed about having a discussion abou

Re: [OAUTH-WG] [SPICE] Relationship between SPICE and OAuth

2023-11-03 Thread Brent Zundel
I agree with Watson. I also don't understand what delays in the work would occur as a consequence of managing it in a different group. On Fri, Nov 3, 2023, 9:49 AM wrote: > Hi Denis, > > > > It is true that the current OAuth charter does not address the three party > model. > > > > This is why R

Re: [OAUTH-WG] [SPICE] Relationship between SPICE and OAuth

2023-11-03 Thread hannes.tschofenig
Hi Denis, It is true that the current OAuth charter does not address the three party model. This is why Rifaat and I have put an agenda item to the OAuth meeting to discuss a charter update. We will talk about this new charter on Tuesday after the WIMSE and the SPICE BOFs took place.

Re: [OAUTH-WG] [SPICE] Relationship between SPICE and OAuth

2023-11-01 Thread Dick Hardt
I can't help myself to not reply to this ... :) On Wed, Nov 1, 2023 at 11:18 AM Denis wrote: > > > Bridging the architectural narrative used in the core OAuth framework (AS, > RS, RO) and in the three roles model > (Holder, Issuer, Verifier) would not be appropriate. > I'm not sure "would not

Re: [OAUTH-WG] [SPICE] Relationship between SPICE and OAuth

2023-11-01 Thread Denis
Hi Hannes, The current charter of the OAuth WG is available at: https://datatracker.ietf.org/wg/oauth/about/ The major problem is that both this charter and the OAuth 2.1 (or OAuth 2.0) authorization framework cannot currently address the three roles model with an Holder, an Issuer and Verif

Re: [OAUTH-WG] [SPICE] Relationship between SPICE and OAuth

2023-11-01 Thread Orie Steele
I was also surprised to see this agenda, based on the discussions on OAUTH and SPICE lists. I am supportive of recapping, the great work that is happening at OAUTH, and how that work is applied outside of OAUTH to none OAUTH use cases. I don't think work items that are close to the finish line sh