Re: [OAUTH-WG] Comments on draft-richer-oauth-introspection-04

2013-10-26 Thread Thomas Broyer
On Sat, Oct 26, 2013 at 6:03 PM, Richer, Justin P. wrote: > >> On our backlog is also support for "service accounts" (to use > Google's terminology), so clients will likely need to do some > crypto-related work. Asking them to do it for each and every request to > sign the access token might not

Re: [OAUTH-WG] A couple of questions re dynamic client registration

2013-10-26 Thread Richer, Justin P.
On Oct 25, 2013, at 1:47 PM, Todd W Lainhart mailto:lainh...@us.ibm.com>> wrote: I'm working off this document for our client registration: http://tools.ietf.org/html/draft-ietf-oauth-dyn-reg-14 Section 4 - Client Configuration Endpoint says this: The client MUST use its registration access

Re: [OAUTH-WG] Comments on draft-richer-oauth-introspection-04

2013-10-26 Thread Richer, Justin P.
>> On our backlog is also support for "service accounts" (to use Google's >> terminology), so clients will likely need to do some crypto-related work. >> Asking them to do it for each and every request to sign the access token >> might not be that > > > I assume you mean signing the request or a