Re: [regext] id_token parameter usage in rdap-openid

2022-01-25 Thread Hollenbeck, Scott
> -Original Message- > From: Tom Harrison > Sent: Tuesday, January 25, 2022 12:04 AM > To: Hollenbeck, Scott > Cc: mario.loffr...@iit.cnr.it; regext@ietf.org > Subject: [EXTERNAL] Re: [regext] id_token parameter usage in rdap-openid > > Caution: This email ori

Re: [regext] id_token parameter usage in rdap-openid

2022-01-24 Thread Tom Harrison
On Mon, Jan 24, 2022 at 02:43:40PM +, Hollenbeck, Scott wrote: > [SAH] The best thing we can do is to explain the situation in > Section 3.1.3.1. What's there now needs to change: > > OLD: > 3.1.3.1. Provider Discovery > > An RDAP server/RP needs to receive an identifier from an End-User >

Re: [regext] id_token parameter usage in rdap-openid

2022-01-24 Thread Hollenbeck, Scott
> -Original Message- > From: Tom Harrison > Sent: Sunday, January 23, 2022 5:11 PM > To: Hollenbeck, Scott > Cc: mario.loffr...@iit.cnr.it; regext@ietf.org > Subject: [EXTERNAL] Re: Re: Re: Re: [regext] id_token parameter usage in > rdap-openid > > Caution:

Re: [regext] id_token parameter usage in rdap-openid

2022-01-24 Thread Mario Loffredo
Il 23/01/2022 23:11, Tom Harrison ha scritto: On Fri, Jan 21, 2022 at 03:10:02PM +, Scott Hollenbeck wrote: On Fri, Jan 21, 2022 at 08:26:20AM +1000, Tom Harrison wrote: But it's not guaranteed that every user identifier will be associated with a host that is implementing issuer discovery.

Re: [regext] id_token parameter usage in rdap-openid

2022-01-23 Thread Tom Harrison
On Fri, Jan 21, 2022 at 03:10:02PM +, Scott Hollenbeck wrote: > On Fri, Jan 21, 2022 at 08:26:20AM +1000, Tom Harrison wrote: >> But it's not guaranteed that every user identifier will be >> associated with a host that is implementing issuer discovery. For >> example, an RDAP server might be c

Re: [regext] id_token parameter usage in rdap-openid

2022-01-21 Thread Hollenbeck, Scott
> -Original Message- > From: Tom Harrison > Sent: Thursday, January 20, 2022 5:26 PM > To: Hollenbeck, Scott > Cc: mario.loffr...@iit.cnr.it; regext@ietf.org > Subject: [EXTERNAL] Re: Re: Re: [regext] id_token parameter usage in rdap- > openid > > Caution:

Re: [regext] id_token parameter usage in rdap-openid

2022-01-20 Thread Tom Harrison
Re: Re: [regext] id_token parameter usage in rdap- >> openid > > [SAH] [snip] > >>> [SAH] I wonder if the changes made in -09 are helpful or not in the >>> context of this discussion. It's worth re-reading the draft to be >>> sure. >> >&

Re: [regext] id_token parameter usage in rdap-openid

2022-01-20 Thread Mario Loffredo
Hi Scott and Tom, Il 20/01/2022 03:08, Tom Harrison ha scritto: On Wed, Jan 19, 2022 at 01:22:04PM +, Scott Hollenbeck wrote: I'm not saying that it is a wrong proposal but it would simply result in refactoring the document. We should give answer to some questions, such as: should the /toke

Re: [regext] id_token parameter usage in rdap-openid

2022-01-20 Thread Hollenbeck, Scott
> -Original Message- > From: Tom Harrison > Sent: Wednesday, January 19, 2022 9:09 PM > To: Hollenbeck, Scott > Cc: mario.loffr...@iit.cnr.it; regext@ietf.org > Subject: [EXTERNAL] Re: Re: [regext] id_token parameter usage in rdap- > openid [SAH] [snip] >

Re: [regext] id_token parameter usage in rdap-openid

2022-01-19 Thread Tom Harrison
On Wed, Jan 19, 2022 at 01:22:04PM +, Scott Hollenbeck wrote: > I'm not saying that it is a wrong proposal but it would simply > result in refactoring the document. We should give answer to some > questions, such as: should the /tokens endpoint still be useful? > which informati

Re: [regext] id_token parameter usage in rdap-openid

2022-01-19 Thread Hollenbeck, Scott
> -Original Message- > From: regext On Behalf Of Tom Harrison > Sent: Tuesday, January 18, 2022 6:14 PM > To: Mario Loffredo > Cc: regext@ietf.org > Subject: [EXTERNAL] Re: [regext] id_token parameter usage in rdap-openid [SAH] snip > The only difference I can see

Re: [regext] id_token parameter usage in rdap-openid

2022-01-18 Thread Tom Harrison
Hi Mario, On Mon, Jan 17, 2022 at 10:58:16AM +0100, Mario Loffredo wrote: > Il 17/01/2022 02:07, Tom Harrison ha scritto: >> On Fri, Jan 14, 2022 at 09:19:55AM +0100, Mario Loffredo wrote: >>> Il 11/01/2022 12:03, Tom Harrison ha scritto: But the relying party must treat the access token as o

Re: [regext] id_token parameter usage in rdap-openid

2022-01-17 Thread Mario Loffredo
Hi Tom, please find my commnets inline. Il 17/01/2022 02:07, Tom Harrison ha scritto: Hi Mario, On Fri, Jan 14, 2022 at 09:19:55AM +0100, Mario Loffredo wrote: Il 11/01/2022 12:03, Tom Harrison ha scritto: On Fri, Dec 17, 2021 at 11:54:57AM +0100, Mario Loffredo wrote: Il 17/12/2021 06:59,

Re: [regext] id_token parameter usage in rdap-openid

2022-01-16 Thread Tom Harrison
Hi Mario, On Fri, Jan 14, 2022 at 09:19:55AM +0100, Mario Loffredo wrote: > Il 11/01/2022 12:03, Tom Harrison ha scritto: >> On Fri, Dec 17, 2021 at 11:54:57AM +0100, Mario Loffredo wrote: >>> Il 17/12/2021 06:59, Tom Harrison ha scritto: I'm not sure that it's possible to remove the ID token

Re: [regext] id_token parameter usage in rdap-openid

2022-01-14 Thread Mario Loffredo
Hi Tom, sorry for the delay in replying. My comments are below. Il 11/01/2022 12:03, Tom Harrison ha scritto: Hi Mario, On Fri, Dec 17, 2021 at 11:54:57AM +0100, Mario Loffredo wrote: Il 17/12/2021 06:59, Tom Harrison ha scritto: On Thu, Nov 11, 2021 at 11:51:13AM +0100, Mario Loffredo wrot

Re: [regext] id_token parameter usage in rdap-openid

2022-01-11 Thread Tom Harrison
Hi Mario, On Fri, Dec 17, 2021 at 11:54:57AM +0100, Mario Loffredo wrote: > Il 17/12/2021 06:59, Tom Harrison ha scritto: >> On Thu, Nov 11, 2021 at 11:51:13AM +0100, Mario Loffredo wrote: >>> I open a separate discussion about the usage of the id_token parameter as >>> defined in the rdap-openid

Re: [regext] id_token parameter usage in rdap-openid

2021-12-17 Thread Hollenbeck, Scott
Below… From: regext On Behalf Of Mario Loffredo Sent: Friday, December 17, 2021 5:55 AM To: regext@ietf.org; Tom Harrison Subject: [EXTERNAL] Re: [regext] id_token parameter usage in rdap-openid Caution: This email originated from outside the organization. Do not click links or open

Re: [regext] id_token parameter usage in rdap-openid

2021-12-17 Thread Mario Loffredo
Hi Tom, Il 17/12/2021 06:59, Tom Harrison ha scritto: Hi Mario, On Thu, Nov 11, 2021 at 11:51:13AM +0100, Mario Loffredo wrote: I open a separate discussion about the usage of the id_token parameter as defined in the rdap-openid document. The document states in section 5.2 that the id_token M

Re: [regext] id_token parameter usage in rdap-openid

2021-12-16 Thread Tom Harrison
Hi Mario, On Thu, Nov 11, 2021 at 11:51:13AM +0100, Mario Loffredo wrote: > I open a separate discussion about the usage of the id_token parameter as > defined in the rdap-openid document. > > The document states in section 5.2 that the id_token MUST be passed in the > query string. > > IMO, the

[regext] id_token parameter usage in rdap-openid

2021-11-11 Thread Mario Loffredo
Hi Scott and folks, I open a separate discussion about the usage of the id_token parameter as defined in the rdap-openid document. The document states in section 5.2 that the id_token MUST be passed in the query string. IMO, there are some drawbacks coming from it: - I intended that the pu