[OAUTH-WG] RAR - Example JWT for Payment

2020-03-30 Thread Jared Jennings
I have a question about the example and maybe it's more for clarification than anything. The example contains type and also location. A couple of things 1. Would it add clarity if the domain was the same for both? vs. someorg.com / example.com 2. While only an example, would it bring clerity to pa

Re: [OAUTH-WG] Error Responses in JWT Profile for OAuth 2.0 Access Tokens

2020-03-30 Thread Karl McGuinness
Hi Vittorio, I was chatting with Aaron offline about this issue and my concern is the addition of Authentication Information Claims in this spec opens up more interoperability issues that can’t be addressed with just a JWT Access Token spec. OAuth 2.0 AFAIK, doesn’t define any behaviors around

Re: [OAUTH-WG] IETF 107 Virtual OAuth Sessions

2020-03-30 Thread Matthew De Haast
That sound good Rifaat. Matt On Fri, Mar 27, 2020 at 5:59 PM Rifaat Shekh-Yusef wrote: > This will have no impact on the adoption of the DPoP document. > > Regards, > Rifaat > > > On Fri, Mar 27, 2020 at 11:22 AM Torsten Lodderstedt 40lodderstedt@dmarc.ietf.org> wrote: > >> Hi, >> >> assu