[OAUTH-WG] Francesca Palombini's No Objection on draft-ietf-oauth-jwsreq-32: (with COMMENT)

2021-04-07 Thread Francesca Palombini via Datatracker
Francesca Palombini has entered the following ballot position for draft-ietf-oauth-jwsreq-32: No Objection When responding, please keep the subject line intact and reply to all email addresses included in the To and CC lines. (Feel free to cut this introductory paragraph, however.) Please refer

Re: [OAUTH-WG] I-D Action: draft-ietf-oauth-security-topics-17.txt

2021-04-07 Thread George Fletcher
While this is mostly covered in section 8.6 of RFC 8252 for native apps, I wonder if we shouldn't mention "Client Impersonation" in this doc as well in that any public client can be easily impersonated. Mobile OS's are providing additional mechanisms for "authenticating" the client but it's unc

[OAUTH-WG] I-D Action: draft-ietf-oauth-dpop-03.txt

2021-04-07 Thread internet-drafts
A New Internet-Draft is available from the on-line Internet-Drafts directories. This draft is a work item of the Web Authorization Protocol WG of the IETF. Title : OAuth 2.0 Demonstrating Proof-of-Possession at the Application Layer (DPoP) Authors : Daniel Fett

[OAUTH-WG] Fwd: New Version Notification for draft-ietf-oauth-dpop-03.txt

2021-04-07 Thread Brian Campbell
A new revision of DPoP has been published. The doc history snippet is copied below. The main change here is the addition of an access token hash claim. -03 * Add an access token hash ("ath") claim to the DPoP proof when used in conjunction with the presentation of an access token for

[OAUTH-WG] John Scudder's No Objection on draft-ietf-oauth-jwsreq-32

2021-04-07 Thread John Scudder via Datatracker
John Scudder has entered the following ballot position for draft-ietf-oauth-jwsreq-32: No Objection When responding, please keep the subject line intact and reply to all email addresses included in the To and CC lines. (Feel free to cut this introductory paragraph, however.) Please refer to http

[OAUTH-WG] I-D Action: draft-ietf-oauth-jwsreq-33.txt

2021-04-07 Thread internet-drafts
A New Internet-Draft is available from the on-line Internet-Drafts directories. This draft is a work item of the Web Authorization Protocol WG of the IETF. Title : The OAuth 2.0 Authorization Framework: JWT Secured Authorization Request (JAR) Authors : Nat Saki

Re: [OAUTH-WG] Lars Eggert's No Objection on draft-ietf-oauth-jwsreq-32: (with COMMENT)

2021-04-07 Thread Mike Jones
Thanks for your review, Lars. We've published https://tools.ietf.org/html/draft-ietf-oauth-jwsreq-33 to address your and other IESG comments. Responses are inline below, prefixed by "Mike>". -Original Message- From: Lars Eggert via Datatracker Sent: Tuesday, April 6, 2021 5:19 AM To:

Re: [OAUTH-WG] Éric Vyncke's No Objection on draft-ietf-oauth-jwsreq-32: (with COMMENT)

2021-04-07 Thread Mike Jones
Thanks for your review, Éric. We've published https://tools.ietf.org/html/draft-ietf-oauth-jwsreq-33 to address your and other IESG comments. Responses are inline below, prefixed by "Mike>". -Original Message- From: Éric Vyncke via Datatracker Sent: Tuesday, April 6, 2021 7:49 AM To:

Re: [OAUTH-WG] Martin Duke's No Objection on draft-ietf-oauth-jwsreq-32: (with COMMENT)

2021-04-07 Thread Mike Jones
Thanks for your review, Martin. We've published https://tools.ietf.org/html/draft-ietf-oauth-jwsreq-33 to address your and other IESG comments. Responses are inline below, prefixed by "Mike>". -Original Message- From: Martin Duke via Datatracker Sent: Tuesday, April 6, 2021 12:13 PM

Re: [OAUTH-WG] Francesca Palombini's No Objection on draft-ietf-oauth-jwsreq-32: (with COMMENT)

2021-04-07 Thread Mike Jones
Thanks for your review, Francesca. We've published https://tools.ietf.org/html/draft-ietf-oauth-jwsreq-33 to address your and other IESG comments. Responses are inline below, prefixed by "Mike>". -Original Message- From: Francesca Palombini via Datatracker Sent: Wednesday, April 7, 2

Re: [OAUTH-WG] Benjamin Kaduk's No Objection on draft-ietf-oauth-jwsreq-32: (with COMMENT)

2021-04-07 Thread Mike Jones
Thanks for your review, Ben. We've published https://tools.ietf.org/html/draft-ietf-oauth-jwsreq-33 to address your and other IESG comments. Responses are inline below, prefixed by "Mike>". -Original Message- From: OAuth On Behalf Of Benjamin Kaduk via Datatracker Sent: Tuesday, April

[OAUTH-WG] Murray Kucherawy's No Objection on draft-ietf-oauth-access-token-jwt-12: (with COMMENT)

2021-04-07 Thread Murray Kucherawy via Datatracker
Murray Kucherawy has entered the following ballot position for draft-ietf-oauth-access-token-jwt-12: No Objection When responding, please keep the subject line intact and reply to all email addresses included in the To and CC lines. (Feel free to cut this introductory paragraph, however.) Please

Re: [OAUTH-WG] Éric Vyncke's No Objection on draft-ietf-oauth-jwsreq-32: (with COMMENT)

2021-04-07 Thread Eric Vyncke (evyncke)
Thank you Mike for your reply and your modifications. Regards -éric -Original Message- From: Mike Jones Date: Thursday, 8 April 2021 at 06:44 To: Eric Vyncke , "i...@ietf.org" Cc: "draft-ietf-oauth-jws...@ietf.org" , "oauth-cha...@ietf.org" , "oauth@ietf.org" , "hannes.tschofe...@gm

[OAUTH-WG] Murray Kucherawy's No Objection on draft-ietf-oauth-jwsreq-33: (with COMMENT)

2021-04-07 Thread Murray Kucherawy via Datatracker
Murray Kucherawy has entered the following ballot position for draft-ietf-oauth-jwsreq-33: No Objection When responding, please keep the subject line intact and reply to all email addresses included in the To and CC lines. (Feel free to cut this introductory paragraph, however.) Please refer to