[OAUTH-WG] RFC 7662 OAuth 2.0 Token Introspection: token_type

2015-11-17 Thread Vladimir Dzhuvinov
The "token_type" parameter in introspection responses - is that supposed to be "access_token" / "refresh_token", or the type of the access token, e.g. "Bearer"? https://tools.ietf.org/html/rfc7662#section-2.2 Section 5.1 in RFC 6749 that is referred to points to section 7.1 which seems to imply t

Re: [OAUTH-WG] RFC 7662 OAuth 2.0 Token Introspection: token_type

2015-11-17 Thread Hannes Tschofenig
Hi Vladimir, it is 'Bearer'. Section 5.1 in RFC 6749 defines the token_type concept and RFC 6750 registers the 'Bearer' token value (since it defines the bearer token concept). We currently have work going on with the PoP token work to also extend the concept further. Ciao Hannes On 11/17/201

Re: [OAUTH-WG] [COSE] A draft on CBOR Web Tokens (CWT)

2015-11-17 Thread Bill Mills
Is a data type mapping form JWT to CBOR sufficient then? On Monday, November 16, 2015 11:26 PM, Hannes Tschofenig wrote: #yiv5390846737 #yiv5390846737 -- _filtered #yiv5390846737 {font-family:Calibri;panose-1:2 15 5 2 2 2 4 3 2 4;} _filtered #yiv5390846737 {font-family:Tahoma;panos

Re: [OAUTH-WG] AD review of draft-ietf-oauth-pop-architecture

2015-11-17 Thread Phil Hunt
Just wanted to let everyone know I intend to respond shortly. I just got back from some holidays and just clearing my backlog now. Cheers Phil > On Nov 16, 2015, at 12:37, Kathleen Moriarty > wrote: > > Hello, > > I reviewed draft-ietf-oauth-pop-architecture and have a few questions. > >