Re: [OAUTH-WG] OAuth 2.0 Introspection RFC Issues

2015-11-03 Thread Michael Ciarlillo
Thanks for the feedback. I agree that the spec is not badly designed over all. I just think that the MUST is a bit too restrictive, especially with how none of the OAuth grants requires authentication to begin with except when a client is Confidential or when using Client Credential flow (for o

Re: [OAUTH-WG] Meeting Agenda

2015-11-03 Thread Hannes Tschofenig
Hi all, in addition to the agenda I posted last week I am suggesting to talk about re-chartering of the working group. In that context we will hear various short talks about work we could/should be doing. Ciao Hannes On 10/31/2015 11:14 AM, Hannes Tschofenig wrote: > Please have a look at the m

[OAUTH-WG] draft-ietf-oauth-jwsreq-06 Review Reminder

2015-11-03 Thread Hannes Tschofenig
Hi all, note that the WGLC for expires tomorrow, Thursday, November 5th, as announced here: http://www.ietf.org/mail-archive/web/oauth/current/msg15056.html Please review the document in time for the OAuth WG meeting. Ciao Hannes signature.asc Description: OpenPGP digital signature _

[OAUTH-WG] OAuth Status Update

2015-11-03 Thread Hannes Tschofenig
In time for the WG meeting Derek and I produced a short status update. - Errata Hannes and John to look into it and propose resolution to the list. https://www.rfc-editor.org/errata_search.php?rfc=6749 https://www.rfc-editor.org/errata_search.php?rfc=6819 This item is still pending. - Token Exc