Re: [OAUTH-WG] [UNVERIFIED SENDER] Re: MTLS token endoint & discovery

2019-02-14 Thread Phil Hunt
Brian Apologies for any confusion. I agree with you totally. I was trying to say the pointer is necessary for tls infrastructure agility. I disagreed with Dominick in this case. The supposed complexity reflects real world variability we have to deal with in both browsers and serverless cloud

Re: [OAUTH-WG] [UNVERIFIED SENDER] Re: MTLS token endoint & discovery

2019-02-14 Thread Brian Campbell
Maybe I'm wrong here (it's never out of the question) but based on this previous message and this one I believe that actually you are both in favor (ge

Re: [OAUTH-WG] [UNVERIFIED SENDER] Re: MTLS token endoint & discovery

2019-02-14 Thread Phil Hunt
I feel I have to disagree. I agree that optionality is often complexity and should be avoided. But, I think the optionality here is an agility feature allowing mtls to work across a diversified market of different types of tls terminators with varying capability. Lack of appropriate discovery/o

Re: [OAUTH-WG] [UNVERIFIED SENDER] Re: MTLS token endoint & discovery

2019-02-14 Thread Dominick Baier
Sorry - this was not meant to be snide at all. It was honest feedback that you also need to keep software complexity in mind when creating a spec. Every MAY or OPTIONAL, or do it like this OR that, or send values in arbitrary order adds to complexity. Complexity is the natural enemy of security.

Re: [OAUTH-WG] New User-Managed Access (UMA) drafts

2019-02-14 Thread Hannes Tschofenig
A big thanks to the UMA team for this contribution. I am looking forward to the presentation and discussion at the next IETF meeting. Ciao Hannes From: OAuth On Behalf Of Eve Maler Sent: Mittwoch, 13. Februar 2019 23:01 To: oauth@ietf.org Subject: [OAUTH-WG] New User-Managed Access (UMA) drafts

[OAUTH-WG] Reminder - FW: 4th OAuth Security Workshop - Registration now open!

2019-02-14 Thread Hannes Tschofenig
A short reminder to submit your paper and/or tutorial for the upcoming OAuth Security workshop. From: OAuth On Behalf Of Daniel Fett Sent: Donnerstag, 7. Februar 2019 16:03 To: oauth@ietf.org Subject: [OAUTH-WG] 4th OAuth Security Workshop - Registration now open! All, The registration for th