Re: [OAUTH-WG] Call for adoption: JWT Usage in OAuth2 Access Tokens

2019-04-16 Thread Schanzenbach, Martin
> On 15. Apr 2019, at 18:20, Sascha Preibisch wrote: > > Thanks, Martin! > > I understand. I just think it is difficult to get this adopted if > clients now have to include the target resource in their request in > order to place that into the 'aud' field. Unless the client has > somehow regis

[OAUTH-WG] I-D Action: draft-ietf-oauth-jwt-bcp-05.txt

2019-04-16 Thread internet-drafts
A New Internet-Draft is available from the on-line Internet-Drafts directories. This draft is a work item of the Web Authorization Protocol WG of the IETF. Title : JSON Web Token Best Current Practices Authors : Yaron Sheffer Dick Hardt

[OAUTH-WG] Fwd: New Version Notification for draft-ietf-oauth-jwt-bcp-05.txt

2019-04-16 Thread Yaron Sheffer
This version addresses Genart comments. Thanks to Brian Carpenter for his review! Yaron Forwarded Message Subject: New Version Notification for draft-ietf-oauth-jwt-bcp-05.txt Date: Tue, 16 Apr 2019 02:46:10 -0700 From: internet-dra...@ietf.org To: Michael B. Jones , D

[OAUTH-WG] (no subject)

2019-04-16 Thread Wendy Irene Haas
tls_client_auth_subject_dn An [RFC4514] string representation of the expected subject distinguished name of the certificate, which the OAuth client will use in mutual TLS authentication. tls_client_auth_san_dns A string containing the value of an expected dNSName SAN entry in the certificate, which