Re: [OAUTH-WG] DPoP-Nonce IANA HTTP Header

2022-12-21 Thread Justin Richer
Thanks, Brian! — Justin On Dec 20, 2022, at 5:54 PM, Brian Campbell mailto:bcampb...@pingidentity.com>> wrote: Thanks Justin, It'll be fixed in the next draft revision. I happened to notice the oversight as well when working on the AD review and have already added it in the document source

Re: [OAUTH-WG] Privacy considerations regarding RAR and authorization_details in AT JWT

2022-12-21 Thread Justin Richer
Hi Kai, Both of those approaches are common approaches for preventing the leakage of private information in JWTs, and neither is specific to the RAR specification. The use of RAR objects does make it easier to have more specific detail, but that detail could have easily been leaked through a sc

Re: [OAUTH-WG] Privacy considerations regarding RAR and authorization_details in AT JWT

2022-12-21 Thread Brian Campbell
I'll just add that RAR is in the very latter stages of IESG processing for publication, which is a point in the process that is not particularly amenable to changes from the WG. On Wed, Dec 21, 2022 at 7:30 AM Justin Richer wrote: > Hi Kai, > > Both of those approaches are common approaches for

Re: [OAUTH-WG] Implementations - OAuth 2.0 Step-up Authentication Challenge Protocol

2022-12-21 Thread Takahiko Kawasaki
Hi Rifaat, Authlete 2.3, which is planned to be released next month (January 2023), supports OAuth 2.0 Step-up Authentication Challenge Protocol. I've published an article on Authlete's website that explains the specification in detail with many diagrams. OAuth 2.0 Step-up Authentication Challeng

Re: [OAUTH-WG] Implementations - OAuth 2.0 Step-up Authentication Challenge Protocol

2022-12-21 Thread Rifaat Shekh-Yusef
Thanks Takahiko! On Wed, Dec 21, 2022 at 4:33 PM Takahiko Kawasaki wrote: > Hi Rifaat, > > Authlete 2.3, which is planned to be released next month (January 2023), > supports OAuth 2.0 Step-up Authentication Challenge Protocol. I've > published an article on Authlete's website that explains the