[OAUTH-WG] draft-ietf-oauth-introspection

2014-11-30 Thread Anthony Nadalin
Comments Intro about the authentication conext, not sure what this is since there is no authentication context in Oauth Use of Oauth2, mixed with use of Oauth, pick one allows holder of a token to query so anything/anyone that has a token can use this endpoint? Introspection Endpoint Use of

[OAUTH-WG] [internet-dra...@ietf.org] New Version Notification for draft-yu-oauth-token-translation-01.txt

2014-11-30 Thread Tom Yu
Added more technical details and examples. ---BeginMessage--- A new version of I-D, draft-yu-oauth-token-translation-01.txt has been successfully submitted by Tom Yu and posted to the IETF repository. Name: draft-yu-oauth-token-translation Revision: 01 Title: A Kerberos

Re: [OAUTH-WG] [internet-dra...@ietf.org] New Version Notification for draft-yu-oauth-token-translation-01.txt

2014-11-30 Thread Justin Richer
Tom, I think this is interesting and important work as it could help more directly bridge the gap between Kerberos deployments (more common in enterprise/LAN environments) and the OAuth/web/mobile world. When you get down to it, there are really two things going on here: mapping Kerberos

Re: [OAUTH-WG] Shepherd Review of draft-ietf-oauth-dyn-reg-management-05

2014-11-30 Thread Justin Richer
Hannes, I’ve had a chance to more thoroughly re-read both the drafts and your notes, I think you’re actually correct about the IANA registration. We register “client_id” and “client_secret”, even though they can’t be requested by the client. As such, we do need to register

[OAUTH-WG] I-D Action: draft-ietf-oauth-introspection-01.txt

2014-11-30 Thread internet-drafts
A New Internet-Draft is available from the on-line Internet-Drafts directories. This draft is a work item of the Web Authorization Protocol Working Group of the IETF. Title : OAuth 2.0 Token Introspection Author : Justin Richer Filename:

Re: [OAUTH-WG] draft-ietf-oauth-introspection

2014-11-30 Thread Justin Richer
Tony, thanks for the comments. Your timing is great, as I was just today sitting down to polish the introspection draft into a proper WG document ready for the last-call tomorrow. I’ve just posted the updated draft, and I think that you’ll find it addresses your concerns. More direct answers