Re: [OAUTH-WG] Generalizing draft-ietf-oauth-jwt-introspection-response-01

2018-11-04 Thread Mike Jones
As discussed during the working group meeting, I agree with the people who spoke up saying that they believe that trying to over-generalize the JWT introspection response mechanism to cover all OAuth interactions would be reaching too far. There are differences in the characteristics of the di

[OAUTH-WG] Financial-grade API: JWT Secured Authorization Response Mode for OAuth 2.0 (JARM)

2018-11-04 Thread Torsten Lodderstedt
Hi all, the Financial-grade API WG at the OpenID Foundation has published a mechanism for signing and encrypting OAuth authorization responses that I would like to bring to your attention. The draft https://openid.net//specs/openid-financial-api-jarm-wd-01.html went already through Implement

[OAUTH-WG] Generalizing draft-ietf-oauth-jwt-introspection-response-01

2018-11-04 Thread Torsten Lodderstedt
Hi all, as mentioned during the presentation this morning, I would like to get a feeling what the working groups thinks about generalizing draft-ietf-oauth-jwt-introspection-response-01 to a mechanism supporting requesting and providing JWT responses from the different OAuth endpoints, such a

[OAUTH-WG] For Tuesday's Session: OAuth2 for Browser-based Apps

2018-11-04 Thread Matthew A. Miller
All, Here is the draft that was foreshadowed for tomorrow's discuss: https://tools.ietf.org/html/draft-parecki-oauth-browser-based-apps-00 -- - m&m Matthew A. Miller ___ OAuth mailing list OAuth@ietf.org https://www.ietf.org/mailman/listinfo/oauth