Re: [OAUTH-WG] Call for adoption - Protected Resource Metadata

2023-08-23 Thread Aaron Parecki
I support adoption. Aaron On Wed, Aug 23, 2023 at 8:02 PM Rifaat Shekh-Yusef wrote: > All, > > This is an official call for adoption for the *Protected Resource > Metadata* draft: > https://datatracker.ietf.org/doc/draft-jones-oauth-resource-metadata/ > > Please, reply on the mailing list and

Re: [OAUTH-WG] Call for adoption - Protected Resource Metadata

2023-08-23 Thread Tobias Looker
I support adoption of this draft. Thanks, [MATTR website] Tobias Looker MATTR +64 273 780 461 tobias.looker@mattr.global [MATTR website] [MATTR on LinkedIn] [MATTR on

Re: [OAUTH-WG] SD-JWT does not meet standard security definitions

2023-08-23 Thread Watson Ladd
On Wed, Aug 23, 2023 at 5:25 PM Orie Steele wrote: > > Hey Watson, > > There are 2 properties that credential subjects are looking for in new > credential formats: > > 1. Selective Disclosure > 2. Unlinkability What's the definition of selective disclosure without unlinkability? I do see that

Re: [OAUTH-WG] SD-JWT does not meet standard security definitions

2023-08-23 Thread Orie Steele
Hey Watson, There are 2 properties that credential subjects are looking for in new credential formats: 1. Selective Disclosure 2. Unlinkability Ideally we would get both of these for JWT and CWT, with new algorithms, and both compact and flat encodings. Ideally, we would have more than 1

Re: [OAUTH-WG] SD-JWT does not meet standard security definitions

2023-08-23 Thread Michael Prorock
"Who exactly has an environment where any of the already existing pairing implementations, or a forthcoming BBS signature scheme wouldn't be available?" I have customers who are required to send regulatory trade data that may have redactions with FIPS compliant cryptography. They are ok with

Re: [OAUTH-WG] SD-JWT does not meet standard security definitions

2023-08-23 Thread Watson Ladd
On Wed, Aug 23, 2023, 1:35 PM David Waite wrote: > > > There are credentials where the user will always have an identifier, per > policy of the type of credential/credential issuer. Not all credentials are > anonymous credentials. But if the credentials aren't anonymous why make SD-JWT? To

Re: [OAUTH-WG] Call for adoption - Protected Resource Metadata

2023-08-23 Thread Heather Flanagan
Hi all, I have to chime in on this one. +1 to supporting it for adoption! -Heather > On Aug 23, 2023, at 3:46 PM, Steinar Noem wrote: > > I support adoption > > ons. 23. aug. 2023 kl. 20:03 skrev Rifaat Shekh-Yusef > mailto:rifaat.s.i...@gmail.com>>: >> All, >> >> This is an official call

Re: [OAUTH-WG] Call for adoption - Protected Resource Metadata

2023-08-23 Thread Steinar Noem
I support adoption ons. 23. aug. 2023 kl. 20:03 skrev Rifaat Shekh-Yusef < rifaat.s.i...@gmail.com>: > All, > > This is an official call for adoption for the *Protected Resource > Metadata* draft: > https://datatracker.ietf.org/doc/draft-jones-oauth-resource-metadata/ > > Please, reply on the

Re: [OAUTH-WG] Call for adoption - Protected Resource Metadata

2023-08-23 Thread Nicole Roy
I support adoption. Nicole ___ OAuth mailing list OAuth@ietf.org https://www.ietf.org/mailman/listinfo/oauth

Re: [OAUTH-WG] Call for adoption - Protected Resource Metadata

2023-08-23 Thread Michael Prorock
I support adoption Mike Prorock CTO - mesur.io On Wed, Aug 23, 2023, 16:21 Giuseppe De Marco wrote: > Hi, > I support the adoption. > > Il mer 23 ago 2023, 21:02 Rifaat Shekh-Yusef ha > scritto: > >> All, >> >> This is an official call for adoption for the *Protected Resource >> Metadata*

Re: [OAUTH-WG] Call for adoption - Protected Resource Metadata

2023-08-23 Thread Giuseppe De Marco
Hi, I support the adoption. Il mer 23 ago 2023, 21:02 Rifaat Shekh-Yusef ha scritto: > All, > > This is an official call for adoption for the *Protected Resource > Metadata* draft: > https://datatracker.ietf.org/doc/draft-jones-oauth-resource-metadata/ > > Please, reply on the mailing list and

Re: [OAUTH-WG] Call for adoption - Protected Resource Metadata

2023-08-23 Thread Pieter Kasselman
I support adoption From: OAuth On Behalf Of Rifaat Shekh-Yusef Sent: Wednesday, August 23, 2023 8:02 PM To: oauth Subject: [OAUTH-WG] Call for adoption - Protected Resource Metadata All, This is an official call for adoption for the Protected Resource Metadata draft:

Re: [OAUTH-WG] Call for adoption - Protected Resource Metadata

2023-08-23 Thread Orie Steele
I support adoption. On Wed, Aug 23, 2023, 5:06 PM Michael Jones wrote: > I support adoption. > > -- Mike > > > -- > *From:* OAuth on behalf of Dick Hardt < > dick.ha...@gmail.com> > *Sent:* Wednesday, August 23, 2023 8:09:46 PM > *To:* Rifaat Shekh-Yusef > *Cc:*

Re: [OAUTH-WG] Call for adoption - Protected Resource Metadata

2023-08-23 Thread Michael Jones
I support adoption. -- Mike From: OAuth on behalf of Dick Hardt Sent: Wednesday, August 23, 2023 8:09:46 PM To: Rifaat Shekh-Yusef Cc: oauth Subject: Re: [OAUTH-WG] Call for adoption - Protected Resource Metadata I support adoption. On Wed, Aug 23, 2023

Re: [OAUTH-WG] SD-JWT does not meet standard security definitions

2023-08-23 Thread David Waite
> On Aug 23, 2023, at 12:33 PM, Watson Ladd wrote: > > On Wed, Aug 23, 2023 at 10:02 AM David Waite > mailto:da...@alkaline-solutions.com>> wrote: >> For example, are you talking about properties for anonymous credentials from >> the academic space as set by [Chaum85] or perhaps [CL01]? Or

[OAUTH-WG] Fwd: NomCom 2023 Reminder that Nominations are Open

2023-08-23 Thread Rifaat Shekh-Yusef
-- Forwarded message - From: NomCom Chair 2023 Date: Wed, Aug 23, 2023 at 1:37 PM Subject: NomCom 2023 Reminder that Nominations are Open To: IETF Announcement List All, The 2023-2024 nominating committee would like to thank everyone who has nominated someone for positions and

Re: [OAUTH-WG] Call for adoption - Protected Resource Metadata

2023-08-23 Thread Dick Hardt
I support adoption. On Wed, Aug 23, 2023 at 12:02 PM Rifaat Shekh-Yusef wrote: > All, > > This is an official call for adoption for the *Protected Resource > Metadata* draft: > https://datatracker.ietf.org/doc/draft-jones-oauth-resource-metadata/ > > Please, reply on the mailing list and let us

[OAUTH-WG] Call for adoption - Protected Resource Metadata

2023-08-23 Thread Rifaat Shekh-Yusef
All, This is an official call for adoption for the *Protected Resource Metadata* draft: https://datatracker.ietf.org/doc/draft-jones-oauth-resource-metadata/ Please, reply on the mailing list and let us know if you are in favor of adopting this draft as WG document, by *Sep 6th.* Regards,

Re: [OAUTH-WG] SD-JWT does not meet standard security definitions

2023-08-23 Thread Watson Ladd
On Wed, Aug 23, 2023 at 10:02 AM David Waite wrote: > > On Aug 23, 2023, at 10:16 AM, Watson Ladd wrote: > > > > On Wed, Aug 23, 2023, 3:35 AM Daniel Fett wrote: > >> > >> Hi Watson, > >> > >> can you please be specific about the "standard, 22 year old security > >> definitions" and "schemes

Re: [OAUTH-WG] SD-JWT does not meet standard security definitions

2023-08-23 Thread David Waite
> On Aug 23, 2023, at 10:16 AM, Watson Ladd wrote: > > On Wed, Aug 23, 2023, 3:35 AM Daniel Fett wrote: >> >> Hi Watson, >> >> can you please be specific about the "standard, 22 year old security >> definitions" and "schemes of this type"? >> >> Not having to make assumptions would

Re: [OAUTH-WG] SD-JWT does not meet standard security definitions

2023-08-23 Thread Watson Ladd
On Wed, Aug 23, 2023, 3:35 AM Daniel Fett wrote: > > Hi Watson, > > can you please be specific about the "standard, 22 year old security > definitions" and "schemes of this type"? > > Not having to make assumptions would certainly help to have a useful > discussion. Unlinkability as defined in

Re: [OAUTH-WG] SD-JWT does not meet standard security definitions

2023-08-23 Thread Daniel Fett
Hi Watson, can you please be specific about the "standard, 22 year old security definitions" and "schemes of this type"? Not having to make assumptions would certainly help to have a useful discussion. -Daniel Am 23.08.23 um 07:32 schrieb Watson Ladd: Dear all, I read with alarm that

Re: [OAUTH-WG] SD-JWT does not meet standard security definitions

2023-08-23 Thread Leif Johansson
Perhaps you can write a draft describing your concerns. Suffice it to say that I don’t think you fully understand the requirements placed on the EUID wallet, nor the way the process to establish the EUID wallet works. For instance: anyone who claims to know what the EUID does or requires