Re: [OAUTH-WG] AD review of Draft-ietf-dyn-reg

2015-02-18 Thread Sam Hartman
> "Kathleen" == Kathleen Moriarty writes: Kathleen> registry, but setting HTTP Basic as the default seems like Kathleen> a really bad choice. HOBA is on it's way to becoming an Kathleen> RFC from the HTTPAuth working group. HTTPAuth also has an Kathleen> updated version of Ba

Re: [OAUTH-WG] JWT Token on-behalf of Use case

2015-07-07 Thread Sam Hartman
Speaking as someone who is reasonably familiar with Kerberos and the general concepts involved, I find both Microsoft/Kerberos technology ((constrained delegation/protocol transition) and the ws-trust text horribly confusing and would recommend against all of the above as examples of clarity. After

Re: [OAUTH-WG] IPR on OAuth bearer

2012-05-09 Thread Sam Hartman
So, here are statements that you could make as part of this discussion that would be entirely in scope: 1) I've read the IPR. Prior to this disclosure I was interested in developing|deploying|shipping an implementation of this specification. Now I am not. 2) I think you could go so far as to sa