Re: [OAUTH-WG] Removal: HTTP Basic Authentication for Client Credentials

2011-01-18 Thread Marius Scurtescu
gt;> some will not deploy Basic. >> >> EHL >> >> >>> >>> -Original Message- >>> From: Anthony Nadalin [mailto:tony...@microsoft.com] >>> Sent: Tuesday, January 18, 2011 9:28 AM >>> To: Richer, Justin P.; Eran Hammer-Laha

Re: [OAUTH-WG] Removal: HTTP Basic Authentication for Client Credentials

2011-01-18 Thread Igor Faynberg
tin P.; OAuth WG Subject: RE: [OAUTH-WG] Removal: HTTP Basic Authentication for Client Credentials So does requiring the parameter-based approach which has identical security properties. We need to require at least one, and we already know some will not deploy Basic. EHL -Original Me

Re: [OAUTH-WG] Removal: HTTP Basic Authentication for Client Credentials

2011-01-18 Thread Anthony Nadalin
mailto:tony...@microsoft.com] > Sent: Tuesday, January 18, 2011 9:28 AM > To: Richer, Justin P.; Eran Hammer-Lahav; OAuth WG > Subject: RE: [OAUTH-WG] Removal: HTTP Basic Authentication for Client > Credentials > > Concern here is that HTTP Basic Auth provides a straightforward

Re: [OAUTH-WG] Removal: HTTP Basic Authentication for Client Credentials

2011-01-18 Thread Eran Hammer-Lahav
8, 2011 9:28 AM > To: Richer, Justin P.; Eran Hammer-Lahav; OAuth WG > Subject: RE: [OAUTH-WG] Removal: HTTP Basic Authentication for Client > Credentials > > Concern here is that HTTP Basic Auth provides a straightforward interop > profile for the web server profile > >

Re: [OAUTH-WG] Removal: HTTP Basic Authentication for Client Credentials

2011-01-18 Thread Anthony Nadalin
WG Subject: Re: [OAUTH-WG] Removal: HTTP Basic Authentication for Client Credentials +1 to making BASIC optional. I don't think we were going to be supporting it in general, either. -- Justin From: oauth-boun...@ietf.org [oauth-boun...@ietf.org] On B

Re: [OAUTH-WG] Removal: HTTP Basic Authentication for Client Credentials

2011-01-17 Thread Richer, Justin P.
+1 to making BASIC optional. I don't think we were going to be supporting it in general, either. -- Justin From: oauth-boun...@ietf.org [oauth-boun...@ietf.org] On Behalf Of Eran Hammer-Lahav [e...@hueniverse.com] Sent: Saturday, January 15, 2011 1:53 AM