Re: [OAUTH-WG] draft-ietf-oauth-jwt-bearer Shepherd Write-up

2014-05-06 Thread Nat Sakimura
I was pinged by Mike that the attached message below apparently did not go through to the list. Perhaps it was due to too much "quotation". So, I am forwarding it again, this time with much less "quotes" from earlier massages in the thread. The points in this message is: - I am not aware of any I

[OAUTH-WG] JSON Payload signature (re: draft-richer-oauth-signed-http-request-01.txt)

2014-05-06 Thread Phil Hunt
Justin, Any discussion on including JSON payloads in the signed requests? Had an interesting conversation with Bill and I think this would be a useful optional feature. Phil @independentid www.independentid.com phil.h...@oracle.com ___ OAuth mail

Re: [OAUTH-WG] JSON Payload signature (re: draft-richer-oauth-signed-http-request-01.txt)

2014-05-06 Thread Richer, Justin P.
Seems like a reasonable extension to me, in that it shouldn't break things, really. Is the suggestion to define a particular member for "other stuff" or to state that you're allowed to add other stuff inside the payload object? But on the other hand, I'm wondering why other parts of the protocol

Re: [OAUTH-WG] JSON Payload signature (re: draft-richer-oauth-signed-http-request-01.txt)

2014-05-06 Thread Phil Hunt
Well... In the case of scim which takes json requests and gives json responses, it would be nice to have signed transactions including json payload from http body. This could be easily layer on top of scim without required any change to scim. If however someone wants a json body like a jwt as

[OAUTH-WG] AUTO: Codur Sreedhar Pranam is out of the office (returning Thu 05/15/2014)

2014-05-06 Thread Codur Sreedhar Pranam
I am out of the office from Tue 05/06/2014 until Thu 05/15/2014. If anything is urgent then please contact my blue pages manager Chiang Kai Note: This is an automated response to your message "OAuth Digest, Vol 67, Issue 5" sent on 05/07/2014 8:34:06. This is the only notification you will r