Re: [Ace] Removal of the Client Token from ACE-OAuth draft

2018-02-09 Thread Benjamin Kaduk
On Fri, Feb 09, 2018 at 09:04:45AM +0100, Ludwig Seitz wrote: > On 2018-02-08 21:08, Benjamin Kaduk wrote: > > > > Right, this seems to be the key point. If there's not any running > > code and not going to be any, it's pretty likely that the spec (for > > this portion) will not actually be usa

Re: [Ace] Removal of the Client Token from ACE-OAuth draft

2018-02-09 Thread Ludwig Seitz
On 2018-02-08 21:08, Benjamin Kaduk wrote: On Thu, Feb 08, 2018 at 12:44:39PM +, Hannes Tschofenig wrote: Hi Göran, I believe there are new data points on this topic since the time the requirements & use case draft was published. A lot of use cases were written down and not all of them are

Re: [Ace] Removal of the Client Token from ACE-OAuth draft

2018-02-08 Thread Benjamin Kaduk
On Thu, Feb 08, 2018 at 12:44:39PM +, Hannes Tschofenig wrote: > Hi Göran, > > I believe there are new data points on this topic since the time the > requirements & use case draft was published. A lot of use cases were written > down and not all of them are still being considered by the folk

Re: [Ace] Removal of the Client Token from ACE-OAuth draft

2018-02-08 Thread Hannes Tschofenig
8 12:36 To: Hannes Tschofenig; ace@ietf.org Subject: Re: [Ace] Removal of the Client Token from ACE-OAuth draft Hi Hannes, The paper you are referring to was the only new data point you included when you started this thread. I’m not questioning the correctness of your analysis, just saying tha

Re: [Ace] Removal of the Client Token from ACE-OAuth draft

2018-02-08 Thread Göran Selander
ilto:goran.selan...@ericsson.com>>, "ace@ietf.org<mailto:ace@ietf.org>" mailto:ace@ietf.org>> Subject: RE: [Ace] Removal of the Client Token from ACE-OAuth draft Hi Göran, I haven’t posted the write-up yet since it is a submission to the workshop and the papers are cur

Re: [Ace] Removal of the Client Token from ACE-OAuth draft

2018-02-08 Thread Hannes Tschofenig
confidence in the work. Ciao Hannes From: Göran Selander [mailto:goran.selan...@ericsson.com] Sent: 08 February 2018 09:22 To: Hannes Tschofenig; ace@ietf.org Subject: Re: [Ace] Removal of the Client Token from ACE-OAuth draft Hi Hannes, From: Ace mailto:ace-boun...@ietf.org>> on behalf of

Re: [Ace] Removal of the Client Token from ACE-OAuth draft

2018-02-08 Thread Göran Selander
Hi Hannes, From: Ace mailto:ace-boun...@ietf.org>> on behalf of Hannes Tschofenig mailto:hannes.tschofe...@arm.com>> Date: Thursday 1 February 2018 at 13:59 To: "ace@ietf.org<mailto:ace@ietf.org>" mailto:ace@ietf.org>> Subject: [Ace] Removal of the Client Token

Re: [Ace] Removal of the Client Token from ACE-OAuth draft

2018-02-05 Thread Hannes Tschofenig
Hi Carsten, > > I will remove that feature from the draft in the next update. > Right. But please put it into a separate draft, so we can — develop it > further and make it ready for use, and — ensure that the base framework is > prepared for additional flows like this. Good idea and maybe we

Re: [Ace] Removal of the Client Token from ACE-OAuth draft

2018-02-04 Thread Carsten Bormann
On Feb 5, 2018, at 08:01, Ludwig Seitz wrote: > > I agree that interest for this use case has been lukewarm at most in the WG. Well, IoT is a vast field and we cannot expect all areas of it to be represented equally well in the WG yet. > I will remove that feature from the draft in the next up

Re: [Ace] Removal of the Client Token from ACE-OAuth draft

2018-02-04 Thread Ludwig Seitz
On 2018-02-01 14:59, Hannes Tschofenig wrote: Hi all, the Client Token is a new mechanism in the ACE-OAuth that aims to solve a scenario where the Client does not have connectivity to the Authorization Server to obtain an access token while the Resource Server does. The solution is therefor

Re: [Ace] Removal of the Client Token from ACE-OAuth draft

2018-02-01 Thread Mike Jones
e. Please remove it! -- Mike -Original Message- From: Ace [mailto:ace-boun...@ietf.org] On Behalf Of Benjamin Kaduk Sent: Thursday, February 1, 2018 6:31 PM To: Hannes Tschofenig Cc: ace@ietf.org Subject: Re: [Ace] Removal of the Client Token from ACE-OAuth draft On

Re: [Ace] Removal of the Client Token from ACE-OAuth draft

2018-02-01 Thread Benjamin Kaduk
On Thu, Feb 01, 2018 at 01:59:48PM +, Hannes Tschofenig wrote: > Hi all, > > the Client Token is a new mechanism in the ACE-OAuth that aims to solve a > scenario where the Client does not have connectivity to the Authorization > Server to obtain an access token while the Resource Server does

[Ace] Removal of the Client Token from ACE-OAuth draft

2018-02-01 Thread Hannes Tschofenig
Hi all, the Client Token is a new mechanism in the ACE-OAuth that aims to solve a scenario where the Client does not have connectivity to the Authorization Server to obtain an access token while the Resource Server does. The solution is therefore for the Client to use the Resource Server to rel