[OAUTH-WG] Re: [media-types] Re: Request for registering media types and structured suffixes defined by W3C VCWG candidate recommendations

2024-06-10 Thread Orie Steele
https://www.linkedin.com/in/manusporny/ > Founder/CEO - Digital Bazaar, Inc. > https://www.digitalbazaar.com/ > > ___ > media-types mailing list -- media-ty...@ietf.org > To unsubscribe send an email to media-types-le...@ietf.org >

Re: [OAUTH-WG] Signed JWK Sets

2024-03-19 Thread Orie Steele
In SPICE and SCITT, we have discussed similar proposals for "identity documents", which are essentially a signed collection of keys and attributes. I think a generic building block that works for JOSE and COSE would be great. I don't think OAuth is the right place to develop general purpose

Re: [OAUTH-WG] FW: Call for consensus on SPICE charter

2024-02-21 Thread Orie Steele
scovering key material > (references go here), > > > > *From:* Orie Steele > *Sent:* Tuesday, February 20, 2024 10:18 AM > *To:* nada...@prodigy.net > *Cc:* Roman Danyliw ; oauth > *Subject:* Re: [OAUTH-WG] FW: Call for consensus on SPICE charter > > >

Re: [OAUTH-WG] FW: Call for consensus on SPICE charter

2024-02-20 Thread Orie Steele
document to the IESG >for publication >- 10-2025 - Submit a proposed standard document covering a JWP/CWP >profile for digital credentials to the IESG for publication >- 10-2025 - Submit a proposed standard document defining SD-CWT to the >IESG for publication >

[OAUTH-WG] Fwd: [media-types] Last tracker issue for mediaman-suffixes

2024-02-20 Thread Orie Steele
igitalbazaar.com/ ___ media-types mailing list media-ty...@ietf.org https://www.ietf.org/mailman/listinfo/media-types -- ORIE STEELE Chief Technology Officer www.transmute.industries <https://transmute.industries> -- ORIE STEELE Chief Technology Officer www.transm

Re: [OAUTH-WG] FW: Call for consensus on SPICE charter

2024-02-19 Thread Orie Steele
gt; > > > I still think this charter needs more clarity as I point out > Can you suggest text? > > > > > *From:* Orie Steele > *Sent:* Friday, February 16, 2024 10:11 AM > *To:* nada...@prodigy.net > *Cc:* Roman Danyliw ; oauth > *Subject:* Re: [OAUT

[OAUTH-WG] Fwd: [media-types] Last tracker issue for mediaman-suffixes

2024-02-19 Thread Orie Steele
igitalbazaar.com/ ___ media-types mailing list media-ty...@ietf.org https://www.ietf.org/mailman/listinfo/media-types -- ORIE STEELE Chief Technology Officer www.transmute.industries <https://transmute.industries> ___ OA

Re: [OAUTH-WG] FW: Call for consensus on SPICE charter

2024-02-16 Thread Orie Steele
ementing the WG drafts? > > I'm willing to see how we can use these outputs with the other industry > technologies. > > Thank you for your comments. > > > ___ > OAuth mailing list > OAuth@ietf.org > https://www.ietf.org/mailman/listinfo/oauth > -- ORIE STEELE Chief Technology Officer www.transmute.industries <https://transmute.industries> ___ OAuth mailing list OAuth@ietf.org https://www.ietf.org/mailman/listinfo/oauth

Re: [OAUTH-WG] SD-JWT, use of JSON path in disclosure claim name

2024-02-07 Thread Orie Steele
gt; > Disclosures for nationalities > Contents: ["lklxF5jMYlGTPUovMNIvCA", $['nationalities'][0],"US"] > Contents: ["nPuoQnkRFq3BIeAm7AnXFA", $['nationalities'][1],"DE"] > > Each attribute of the streat address can be easily represented as a > different disclosure > Co

Re: [OAUTH-WG] client_id in CWT Claims

2024-01-24 Thread Orie Steele
eil Madden wrote: > RFC8693 didn't register anything for CWT at all. Some other document has > registered scope for CWT and pointed at that RFC as the reference for some > reason. > > -- Neil > > On 24 Jan 2024, at 18:37, Orie Steele wrote: > > I'm working on a document

[OAUTH-WG] client_id in CWT Claims

2024-01-24 Thread Orie Steele
ignments/jwt/jwt.xhtml - https://www.iana.org/assignments/cwt/cwt.xhtml How can I use "client_id" in CWT ? OS -- ORIE STEELE Chief Technology Officer www.transmute.industries <https://transmute.industries> ___ OAuth mailing li

Re: [OAUTH-WG] R: [SPICE] OAuth Digital Credential Status Attestations (typo)

2024-01-23 Thread Orie Steele
;> >>> >> >>> +-+ +---+ >> >>> | | Requests Status Attestation | | >> >>> | |>| | &g

Re: [OAUTH-WG] R: [SPICE] OAuth Digital Credential Status Attestations (typo)

2024-01-19 Thread Orie Steele
ntations - draft 20 (verifier attestation) >> - OpenID for Verifiable Credential Issuance (section "Trust between >> Wallet and Issuer": Device Attestation) >> >> Meantime in the eIDAS Expert group this term is going to be changed to >> "Wallet

[OAUTH-WG] OAuth Digital Credential Status Attestations

2024-01-17 Thread Orie Steele
ohn", "family_name": "Doe", "email": "john...@example.com", "phone_number": "+1-202-555-0101", "address": { "street_address": "123 Main St", "locality": "Anytown", "r

Re: [OAUTH-WG] [EXTERNAL] Issuers: Lamps <> Scitt

2024-01-17 Thread Orie Steele
ate. - https://datatracker.ietf.org/doc/html/draft-ietf-oauth-sd-jwt-vc-01#section-3.5 It seems that based on the OAUTH guidance, the SCITT guidance should match the OAUTH guidance. Regards, OS On Tue, Jan 16, 2024 at 7:46 PM Orie Steele wrote: > There are 3 things that make up the SCITT eco

Re: [OAUTH-WG] Query on correct approach of calculating the "x5t#S256" parameter in the JWKS response

2024-01-16 Thread Orie Steele
ence I would like to query about the correct approach to follow when >> calculating the "x5t#S256" parameter. Or can we accept both these forms as >> correct methods to calculate the mentioned field? >> >> Thanks in advance. >> >> [1] https://datatrack

[OAUTH-WG] Regarding draft-ietf-oauth-status-list-00

2024-01-13 Thread Orie Steele
status-list ? Regards, OS -- ORIE STEELE Chief Technology Officer www.transmute.industries <https://transmute.industries> ___ OAuth mailing list OAuth@ietf.org https://www.ietf.org/mailman/listinfo/oauth

[OAUTH-WG] Audacious Presentations

2023-12-08 Thread Orie Steele
transmute-industries/audacious-presentations Feel free to file issues or open PRs to make corrections. I will provide a full implementation PoC, in the same repo shortly. Regards, OS -- ORIE STEELE Chief Technology Officer www.transmute.industries <https

[OAUTH-WG] SPICE will not support JSON, JWT or SD-JWT

2023-12-07 Thread Orie Steele
claims work out of scope. Regards, OS -- ORIE STEELE Chief Technology Officer www.transmute.industries <https://transmute.industries> ___ OAuth mailing list OAuth@ietf.org https://www.ietf.org/mailman/listinfo/oauth

Re: [OAUTH-WG] Request to add a profile parameter to +jwt and +sd-jwt

2023-11-27 Thread Orie Steele
> > For W3C Verifiable Credentials that could be: > > application/ld+json; profile="https://www.w3.org/ns/credentials; > > Noting that W3C already supports https://www.w3.org/ns/credentials/v2 > > Regards, > > OS > > On Mon, Nov 27, 2023 at 8:55 AM Orie Steele

Re: [OAUTH-WG] Request to add a profile parameter to +jwt and +sd-jwt

2023-11-27 Thread Orie Steele
could be: application/ld+json; profile="https://www.w3.org/ns/credentials; Noting that W3C already supports https://www.w3.org/ns/credentials/v2 Regards, OS On Mon, Nov 27, 2023 at 8:55 AM Orie Steele wrote: > Hello, > > There was a request to add media type parameters to application/s

[OAUTH-WG] Request to add a profile parameter to +jwt and +sd-jwt

2023-11-27 Thread Orie Steele
not apply. Regards, OS -- ORIE STEELE Chief Technology Officer www.transmute.industries <https://transmute.industries> ___ OAuth mailing list OAuth@ietf.org https://www.ietf.org/mailman/listinfo/oauth

Re: [OAUTH-WG] Call for adoption - Transaction Tokens

2023-11-17 Thread Orie Steele
__ > OAuth mailing list > OAuth@ietf.org > https://www.ietf.org/mailman/listinfo/oauth > > > ___ > OAuth mailing list > OAuth@ietf.org > https://www.ietf.org/mailman/listinfo/oauth > -

Re: [OAUTH-WG] Call for adoption - Identity Chaining

2023-11-17 Thread Orie Steele
___ > OAuth mailing list > OAuth@ietf.org > https://www.ietf.org/mailman/listinfo/oauth > > > ___ > OAuth mailing list > OAuth@ietf.org > https://www.ietf.org/mailman/listinfo/oauth > --

[OAUTH-WG] A Discussion of Multiple Suffixes

2023-11-17 Thread Orie Steele
Alexey, please correct anything I miscommunicated. Regards, OS -- ORIE STEELE Chief Technology Officer www.transmute.industries <https://transmute.industries> ___ OAuth mailing list OAuth@ietf.org https://www.ietf.org/mailman/listinfo/oauth

Re: [OAUTH-WG] Relationship between SPICE and OAuth

2023-11-02 Thread Orie Steele
I agree, I don't think one should block the other. In our implementation of SD-CWT, we take advantage of the unprotected header for disclosures, this means we don't need new media types, we are also considering enabling selective disclosure of the header parameters, which would allow the payload

Re: [OAUTH-WG] [SPICE] Relationship between SPICE and OAuth

2023-11-01 Thread Orie Steele
kings, presidents, and voting. We believe in: rough consensus and running >> code". >> _______ >> OAuth mailing list >> OAuth@ietf.org >> https://www.ietf.org/mailman/listinfo/oauth >> > > *CONFIDENTIALITY NOTIC

Re: [OAUTH-WG] Call for adoption - JWT and CWT Status List

2023-10-23 Thread Orie Steele
> > > > > On Tue, Oct 3, 2023 at 8:51 PM John Bradley wrote: > > +1 for adoption > > > > On Sat, Sep 30, 2023, 9:53 AM Rifaat Shekh-Yusef > wrote: > > All, > > This is an official call for adoption for the *JWT and CWT Status List* > draft: > https://datatracker.

Re: [OAUTH-WG] SD-JWT Redaction Reasons

2023-10-20 Thread Orie Steele
y approach would be better than allowing free form responses from the holder. OS On Fri, Oct 20, 2023 at 9:30 AM Daniel Fett wrote: > The Holder can put such information into the KB-JWT, if required. > > -Daniel > Am 20.10.23 um 16:28 schrieb Orie Steele: > > In some ways thi

Re: [OAUTH-WG] SD-JWT Redaction Reasons

2023-10-20 Thread Orie Steele
he verifier. > -Daniel > Am 18.10.23 um 05:03 schrieb Tom Jones: > > That's leaking the existence of PII. That requires permission of the > subject. I think it's way more complicated than you think. > > thx ..Tom (mobile) > > On Tue, Oct 17, 2023, 6:20 AM Orie Steele

[OAUTH-WG] SD-JWT Redaction Reasons

2023-10-17 Thread Orie Steele
ll never be found in the payload, as we know they will hash differently than array encoded disclosures, which will be found in the payload. I'll be giving a presentation on this topic to the W3C Credentials community group later today, happy to shuttle their reactions back to this

Re: [OAUTH-WG] SD-JWT explicit guidance on parsing json strings

2023-10-16 Thread Orie Steele
: > > On Fri, Oct 13, 2023 at 3:53 PM Orie Steele > wrote: > >> Inline (and sorry for repeating points / rambling) : >> > > No need to apologize. > > It is, however, difficult (for me anyway) to engage with all this in a way > that feels productive. Honestly,

Re: [OAUTH-WG] SD-JWT explicit guidance on parsing json strings

2023-10-13 Thread Orie Steele
Thanks David, responses inline: On Fri, Oct 13, 2023 at 6:35 PM David Waite wrote: > > > On Oct 13, 2023, at 3:52 PM, Orie Steele > wrote: > > Inline (and sorry for repeating points / rambling) : > > On Fri, Oct 13, 2023 at 1:25 PM Brian Campbell > wrote: > &g

Re: [OAUTH-WG] SD-JWT explicit guidance on parsing json strings

2023-10-13 Thread Orie Steele
attack... even with our guidance they may not be successful. It's not a silver bullet, nothing in security is, but it is an attack that can be mitigated because its known to be a weak point that's been repeatedly broken: "Deserialization of Untrusted Data" - https://cwe.mitre.org/dat

[OAUTH-WG] SD-JWT explicit guidance on parsing json strings

2023-10-12 Thread Orie Steele
case that the parsing library is vulnerable, the attacker can craft a protected header that exploits the verifier prior to signature verification. Apologies if this has already been discussed. Regards, OS -- ORIE STEELE Chief Technology Officer www.transmute.industries

Re: [OAUTH-WG] Call for adoption - JWT and CWT Status List

2023-09-30 Thread Orie Steele
I support adoption. We have implementations of a similar spec and we don't think it would be good for vendors to have to support both, but that's not under control of OAuth... we hope there will be significant improvements made, after adoption to justify a separate spec, aside from CWT being

[OAUTH-WG] Requesting a reviews of SD-JWT based W3C Verifiable Credentials

2023-09-29 Thread Orie Steele
able-credentials Regards, OS -- ORIE STEELE Chief Technology Officer www.transmute.industries <https://transmute.industries> ___ OAuth mailing list OAuth@ietf.org https://www.ietf.org/mailman/listinfo/oauth

Re: [OAUTH-WG] OAuth and JWT/VC documents

2023-09-29 Thread Orie Steele
s but no actual > content as such, which could be removed to focus the scope of the draft. > > +1 > > > On Tue, Sep 19, 2023 at 1:56 PM Orie Steele > wrote: > >> Excellent. >> >> Inline: >> >> On Tue, Sep 19, 2023 at 2:12 PM wrote: >> >>

Re: [OAUTH-WG] OAuth and JWT/VC documents

2023-09-19 Thread Orie Steele
Excellent. Inline: On Tue, Sep 19, 2023 at 2:12 PM wrote: > Hi Orie, > > best regards, > Torsten. > Am 18. Sept. 2023, 16:01 +0200 schrieb Orie Steele > : > > Torsten, > > Thanks for sharing this excellent framing. > > I agree with everything you said. >

Re: [OAUTH-WG] OAuth and JWT/VC documents

2023-09-18 Thread Orie Steele
t model > (issuer, holder, verifier) used in > draft-ietf-oauth-selective-disclosure-jwt? > > Thanks, > Roman, Hannes, and Rifaat > ___ > OAuth mailing list > OAuth@ietf.org > https://www.ietf.org/mailman/listinfo/oauth > > ___ > OAuth mailing list > OAuth@ietf.org > https://www.ietf.org/mailman/listinfo/oauth > -- ORIE STEELE Chief Technology Officer www.transmute.industries <https://transmute.industries> ___ OAuth mailing list OAuth@ietf.org https://www.ietf.org/mailman/listinfo/oauth

Re: [OAUTH-WG] OAuth and JWT/VC documents

2023-09-18 Thread Orie Steele
I agree with Brian's comments. It's clear to me that SD-JWT has benefited a lot from the expertise of the OAuth WG. OS On Fri, Sep 15, 2023, 4:12 PM Brian Campbell wrote: > Hi Roman, > > I'm going to dodge some of the bigger picture questions but wanted to give > a bit of historical

[OAUTH-WG] SPICE and WIMSE Scoping

2023-09-15 Thread Orie Steele
es emerging that might be good to do that work, and I wonder if folks here agree or have comments on how this is progressing... and I am also still very interested in what the next charter for OAuth might focus on. Regards, OS -- ORIE STEELE Chief Technology Off

Re: [OAUTH-WG] OAuth and JWT/VC documents

2023-09-11 Thread Orie Steele
g, kristina probably has a better take): >> https://openid.net/wg/digital-credentials-protocols/ >> >> Are there things DCP might need from OAuth WG, how might the charter >> align to that work? >> >> >>> ** Is there work to be done around bridging

Re: [OAUTH-WG] OAuth and JWT/VC documents

2023-09-08 Thread Orie Steele
> Thanks, > Roman, Hannes, and Rifaat > _______ > OAuth mailing list > OAuth@ietf.org > https://www.ietf.org/mailman/listinfo/oauth > -- ORIE STEELE Chief Technology Officer www.transmute.industries <https://transmute.industries> ___ OAuth mailing list OAuth@ietf.org https://www.ietf.org/mailman/listinfo/oauth

Re: [OAUTH-WG] SD-JWT does not meet standard security definitions

2023-08-25 Thread Orie Steele
Inline: On Thu, Aug 24, 2023, 6:50 PM Watson Ladd wrote: > On Thu, Aug 24, 2023, 1:32 PM Kristina Yasuda > wrote: > > > > First of all, BBS and SD-JWT are not comparable apple to apple. BBS is a > signature scheme and it needs to be combined with few other things like JWP > or BBS data

Re: [OAUTH-WG] SD-JWT does not meet standard security definitions

2023-08-23 Thread Orie Steele
Hey Watson, There are 2 properties that credential subjects are looking for in new credential formats: 1. Selective Disclosure 2. Unlinkability Ideally we would get both of these for JWT and CWT, with new algorithms, and both compact and flat encodings. Ideally, we would have more than 1

Re: [OAUTH-WG] Call for adoption - Protected Resource Metadata

2023-08-23 Thread Orie Steele
I support adoption. On Wed, Aug 23, 2023, 5:06 PM Michael Jones wrote: > I support adoption. > > -- Mike > > > -- > *From:* OAuth on behalf of Dick Hardt < > dick.ha...@gmail.com> > *Sent:* Wednesday, August 23, 2023 8:09:46 PM > *To:* Rifaat Shekh-Yusef > *Cc:*

[OAUTH-WG] Media Type Parameters for SD-JWT

2023-08-16 Thread Orie Steele
the media type application/sd-jwt or the structured suffix +sd-jwt. Is there a need to signal the content type of the "verified payload"? What is the recommended way to do this? OS -- ORIE STEELE Chief Technology Officer www.transmute.industries <https://transmu

Re: [OAUTH-WG] Call for adoption - Attestation-Based Client Authentication

2023-07-30 Thread Orie Steele
I support adoption On Sun, Jul 30, 2023, 9:14 AM Pieter Kasselman wrote: > I support adoption. > > > > *From:* OAuth *On Behalf Of *Rifaat Shekh-Yusef > *Sent:* Saturday, July 29, 2023 8:27 PM > *To:* oauth > *Subject:* [OAUTH-WG] Call for adoption - Attestation-Based Client > Authentication

Re: [OAUTH-WG] Call for adoption - SD-JWT-based Verifiable Credentials

2023-07-30 Thread Orie Steele
I support adoption. On Sun, Jul 30, 2023, 9:15 AM Pieter Kasselman wrote: > I support adoption of this draft. > > > > *From:* OAuth *On Behalf Of *Rifaat Shekh-Yusef > *Sent:* Saturday, July 29, 2023 8:25 PM > *To:* oauth > *Subject:* [OAUTH-WG] Call for adoption - SD-JWT-based Verifiable >

Re: [OAUTH-WG] OAuth 2.0 Attestation-Based Client Authentication

2023-07-21 Thread Orie Steele
mmunication, including any attachments, is confidential. If you are > not the intended recipient, you should not read it – please contact me > immediately, destroy it, and do not copy or use any part of this > communication or disclose anything about it. Thank you. Please note that

Re: [OAUTH-WG] OAuth 2.0 Attestation-Based Client Authentication

2023-07-20 Thread Orie Steele
or use any part of this > communication or disclose anything about it. Thank you. Please note that > this communication does not designate an information system for the > purposes of the Electronic Transactions Act 2002. > ___ > OAuth mailing list