On 1/15/10 10:29 AM, "John Panzer" <jpan...@google.com> wrote:

> I think the question at hand is:  If a server says it wants to do bearer
> tokens and no TLS, is a client obligated to interop in order to claim spec
> compliance?

Its a tricky question because HTTPS is not a parameter or extension you
negotiate. It is dictated by the URI of the protected resource you are
trying to access, and clients should never assume that the http:// resource
is the same as the https:// resource, just with more/less security.

EHL

_______________________________________________
OAuth mailing list
OAuth@ietf.org
https://www.ietf.org/mailman/listinfo/oauth

Reply via email to