Re: [OAUTH-WG] Step-up Authentication Shepherd Review

2022-12-19 Thread Brian Campbell
On Mon, Dec 19, 2022 at 3:38 PM Rifaat Shekh-Yusef wrote: > > > On Mon, Dec 19, 2022 at 4:40 PM Brian Campbell > wrote: > >> Hi Rifaat, >> >> I certainly didn't expect a response over the weekend. Apologies if the >> timing of my message (late afternoon Friday my timezone) unintentionally >>

[OAUTH-WG] I-D Action: draft-ietf-oauth-step-up-authn-challenge-08.txt

2022-12-19 Thread internet-drafts
A New Internet-Draft is available from the on-line Internet-Drafts directories. This draft is a work item of the Web Authorization Protocol WG of the IETF. Title : OAuth 2.0 Step-up Authentication Challenge Protocol Authors : Vittorio Bertocci

Re: [OAUTH-WG] Step-up Authentication Shepherd Review

2022-12-19 Thread Rifaat Shekh-Yusef
On Mon, Dec 19, 2022 at 4:40 PM Brian Campbell wrote: > Hi Rifaat, > > I certainly didn't expect a response over the weekend. Apologies if the > timing of my message (late afternoon Friday my timezone) unintentionally > encouraged weekend work. But with that said, my attempt at a reply is >

Re: [OAUTH-WG] Step-up Authentication Shepherd Review

2022-12-19 Thread Brian Campbell
Hi Rifaat, I certainly didn't expect a response over the weekend. Apologies if the timing of my message (late afternoon Friday my timezone) unintentionally encouraged weekend work. But with that said, my attempt at a reply is below. On Sun, Dec 18, 2022 at 1:42 PM Rifaat Shekh-Yusef wrote: >

[OAUTH-WG] Privacy considerations regarding RAR and authorization_details in AT JWT

2022-12-19 Thread Kai Lehmann
Hi, In the privacy considerations section of the RAR specification (https://www.ietf.org/archive/id/draft-ietf-oauth-rar-21.html#name-privacy-considerationsit) it is stated: “The AS needs to take into consideration the privacy implications when sharing authorization_details with the client or