Re: [OAUTH-WG] OAuth Digest, Vol 111, Issue 36

2018-01-29 Thread Donald F Coffin
+1 Additionally, RFC 6749 states it SHOULD only be passed in the body as a last resort and only if using the HTTP Authorization header is NOT possible. Best regards, Don Donald F. Coffin Founder/CTO REMI Networks 2335 Dunwoody Xing #E Dunwoody, GA 30338-8221 Phone: (949

Re: [OAUTH-WG] Fixing the Authorization Server Mix-Up: Call for Adoption

2016-02-27 Thread Donald F. Coffin
+1 Best regards, Don Donald F. Coffin Founder/CTO REMI Networks 2335 Dunwoody Xing #E Dunwoody, GA 30338-8221 Phone: (949) 636-8571 Email:<mailto:donald.cof...@reminetworks.com> donald.cof...@reminetworks.com From: Brian Campbell [mailto:

Re: [OAUTH-WG] OAuth 2.0 Discovery Location

2016-02-25 Thread Donald F. Coffin
+1 for “OAuth 2.0 Authorization Server Discovery” Best regards, Don Donald F. Coffin Founder/CTO REMI Networks 2335 Dunwoody Xing #E Dunwoody, GA 30338-8221 Phone: (949) 636-8571 Email:<mailto:donald.cof...@reminetworks.com> donald.cof...@reminetworks.com

Re: [OAUTH-WG] OAuth 2.0 Discovery Location

2016-02-25 Thread Donald F. Coffin
ng. Best regards, Don Donald F. Coffin Founder/CTO REMI Networks 2335 Dunwoody Xing #E Dunwoody, GA 30338-8221 Phone: (949) 636-8571 Email:<mailto:donald.cof...@reminetworks.com> donald.cof...@reminetworks.com From: Nat Sakimura [mailto:sakim...@gmail.co

Re: [OAUTH-WG] OAuth 2.0 Discovery Location

2016-02-25 Thread Donald F. Coffin
of updating the specification to use OAuth 2.0. The industry OpenADE Task Force, which is the technical WG of the UCAIug, defined additional information be returned with the OAuth 2.0 Token Response that includes the URI of the resource to which the AT can be used. Best regards, Don Donald F

Re: [OAUTH-WG] redircet_uri matching algorithm

2015-05-21 Thread Donald F. Coffin
+1 Best regards, Don Donald F. Coffin Founder/CTO REMI Networks 2335 Dunwoody Crossing Suite E Dunwoody, GA 30338-8221 Phone: (949) 636-8571 Email:mailto:donald.cof...@reminetworks.com donald.cof...@reminetworks.com From: Bill Mills [mailto:wmills_92

Re: [OAUTH-WG] Token Chaining Use Case

2015-03-26 Thread Donald F. Coffin
by another AS (which is possible using Justin’s use case)? Best regards, Don Donald F. Coffin Founder/CTO REMI Networks 2335 Dunwoody Crossing Suite E Dunwoody, GA 30338-8221 Phone: (949) 636-8571 Email:mailto:donald.cof...@reminetworks.com donald.cof...@reminetworks.com

Re: [OAUTH-WG] Token Chaining Use Case

2015-03-26 Thread Donald F. Coffin
Pedro, Although the registry could be changed to support the new type format, how is that any different than adding a new grant_type, such as grant_type=token_swap or grant_type=swap? Best regards, Don Donald F. Coffin Founder/CTO REMI Networks 2335 Dunwoody Crossing Suite E Dunwoody, GA

Re: [OAUTH-WG] Token Chaining Use Case

2015-03-26 Thread Donald F. Coffin
a backwards compatibility issue for many implementations. Best regards, Don Donald F. Coffin Founder/CTO REMI Networks 2335 Dunwoody Crossing Suite E Dunwoody, GA 30338-8221 Phone: (949) 636-8571 Email:mailto:donald.cof...@reminetworks.com donald.cof...@reminetworks.com

Re: [OAUTH-WG] Dynamic Client Registration Conference Call: Wed 28 Aug, 2pm PDT: Conference Bridge Details

2013-08-28 Thread Donald F Coffin
+1 Best regards, Don Donald F. Coffin Founder/CTO REMI Networks 22751 El Prado Suite 6216 Rancho Santa Margarita, CA 92688-3836 Phone: (949) 636-8571 Email: donald.cof...@reminetworks.com -Original Message- From: Justin Richer [mailto:jric...@mitre.org] Sent: Wednesday

Re: [OAUTH-WG] TLS question from token revocation draft iesg evaluation

2013-06-03 Thread Donald F Coffin
Stephen, I feel it should be MANDATORY to implement TLS1.2, especially since NIST is in the process of deprecating TLS1.0 as a supported version. Best regards, Don Donald F. Coffin Founder/CTO REMI Networks 22751 El Prado Suite 6216 Rancho Santa Margarita, CA 92688-3836 Phone: (949) 636

Re: [OAUTH-WG] review comments on draft-ietf-oauth-dyn-reg-11.txt

2013-05-31 Thread Donald F Coffin
both the complexity of the access tokens as well as make their usage harder to explain to non-technical individuals who have to understand the differences between the access tokens obtained through the various flows. Just my two cents. Best regards, Don Donald F. Coffin Founder/CTO

Re: [OAUTH-WG] review comments on draft-ietf-oauth-dyn-reg-11.txt

2013-05-31 Thread Donald F Coffin
See my comments inline [DFC] Best regards, Don Donald F. Coffin Founder/CTO REMI Networks 22751 El Prado Suite 6216 Rancho Santa Margarita, CA 92688-3836 Phone: (949) 636-8571 Email:mailto:donald.cof...@reminetworks.com donald.cof...@reminetworks.com From

Re: [OAUTH-WG] Proposed Syntax Changes in Dynamic Registration

2013-05-23 Thread Donald F Coffin
The issue I have with not providing Dynamic Registration capability within OAuth (as the current document proposes) is that to provide a Dynamic Registration capability will then require the implementation of an additional standard to provide such support. At the present time, I am

Re: [OAUTH-WG] Proposed Syntax Changes in Dynamic Registration

2013-05-20 Thread Donald F Coffin
would vote for B as I believe it clarifies intention of the field, but am also satisfied if A is the final result. Best regards, Don Donald F. Coffin Founder/CTO REMI Networks 22751 El Prado Suite 6216 Rancho Santa Margarita, CA 92688-3836 Phone: (949) 636-8571 Email

Re: [OAUTH-WG] Client Credential Expiry and new Registration Access Token - draft-ietf-oauth-dyn-reg-10

2013-05-17 Thread Donald F Coffin
with client application information. Best regards, Don Donald F. Coffin Founder/CTO REMI Networks 22751 El Prado Suite 6216 Rancho Santa Margarita, CA 92688-3836 Phone: (949) 636-8571 Email: donald.cof...@reminetworks.com -Original Message- From: Mike Jones [mailto:michael.jo

Re: [OAUTH-WG] Client Credential Expiry and new Registration Access Token - draft-ietf-oauth-dyn-reg-10

2013-05-17 Thread Donald F Coffin
to access resources, which IMHO is incorrect based on the RFC 6749 definition in section 4.4. Best regards, Don Donald F. Coffin Founder/CTO REMI Networks 22751 El Prado Suite 6216 Rancho Santa Margarita, CA 92688-3836 Phone: (949) 636-8571 Email: donald.cof...@reminetworks.com

Re: [OAUTH-WG] Registration: Scope Values

2013-04-12 Thread Donald F Coffin
+1 Best regards, Don Donald F. Coffin Founder/CTO REMI Networks 22751 El Prado Suite 6216 Rancho Santa Margarita, CA 92688-3836 Phone: (949) 636-8571 Email:mailto:donald.cof...@reminetworks.com donald.cof...@reminetworks.com From: Tim Bray [mailto:twb

Re: [OAUTH-WG] Registration: Scope Values

2013-04-12 Thread Donald F Coffin
+1 Best regards, Don Donald F. Coffin Founder/CTO REMI Networks 22751 El Prado Suite 6216 Rancho Santa Margarita, CA 92688-3836 Phone: (949) 636-8571 Email:mailto:donald.cof...@reminetworks.com donald.cof...@reminetworks.com From: Mike Jones [mailto:michael.jo

Re: [OAUTH-WG] Registration: Scope Values

2013-04-12 Thread Donald F Coffin
Justin, Thanks for the clarification. Best regards, Don Donald F. Coffin Founder/CTO REMI Networks 22751 El Prado Suite 6216 Rancho Santa Margarita, CA 92688-3836 Phone: (949) 636-8571 Email:mailto:donald.cof...@reminetworks.com donald.cof...@reminetworks.com

Re: [OAUTH-WG] draft-ietf-oauth-revocation-05 Questions

2013-02-21 Thread Donald F Coffin
implementation suggestion? Best regards, Don Donald F. Coffin Founder/CTO REMI Networks 22751 El Prado Suite 6216 Rancho Santa Margarita, CA 92688-3836 Phone: (949) 636-8571 Email:mailto:donald.cof...@reminetworks.com donald.cof...@reminetworks.com From: Torsten

Re: [OAUTH-WG] draft-ietf-oauth-revocation-05 Questions

2013-02-21 Thread Donald F Coffin
or existing draft, then it must be an out-of-band customized implementation. Best regards, Don Donald F. Coffin Founder/CTO REMI Networks 22751 El Prado Suite 6216 Rancho Santa Margarita, CA 92688-3836 Phone: (949) 636-8571 Email:mailto:donald.cof...@reminetworks.com

Re: [OAUTH-WG] draft-ietf-oauth-revocation-05 Questions

2013-02-21 Thread Donald F Coffin
Thanks for the clarification. I was not envisioning the end-user directly referencing the token revocation endpoint. The question is how does the end-user know the client did in fact revoke a token using the token revocation endpoint. Best regards, Don Donald F. Coffin Founder/CTO

[OAUTH-WG] Additional Oauth Dynamic Client Registration Protocol Information

2013-02-20 Thread Donald F Coffin
regards, Don Donald F. Coffin Founder/CTO REMI Networks 22751 El Prado Suite 6216 Rancho Santa Margarita, CA 92688-3836 Phone: (949) 636-8571 Email: donald.cof...@reminetworks.com ___ OAuth mailing list OAuth@ietf.org https

Re: [OAUTH-WG] Additional Oauth Dynamic Client Registration Protocol Information

2013-02-20 Thread Donald F Coffin
Mike, Thanks for the information. Best regards, Don Donald F. Coffin Founder/CTO REMI Networks 22751 El Prado Suite 6216 Rancho Santa Margarita, CA 92688-3836 Phone: (949) 636-8571 Email:mailto:donald.cof...@reminetworks.com donald.cof...@reminetworks.com

Re: [OAUTH-WG] Additional Oauth Dynamic Client Registration Protocol Information

2013-02-20 Thread Donald F Coffin
Justin, Thanks for the information. Best regards, Don Donald F. Coffin Founder/CTO REMI Networks 22751 El Prado Suite 6216 Rancho Santa Margarita, CA 92688-3836 Phone: (949) 636-8571 Email:mailto:donald.cof...@reminetworks.com donald.cof...@reminetworks.com

[OAUTH-WG] draft-ietf-oauth-revocation-05 Questions

2013-02-20 Thread Donald F Coffin
, Don Donald F. Coffin Founder/CTO REMI Networks 22751 El Prado Suite 6216 Rancho Santa Margarita, CA 92688-3836 Phone: (949) 636-8571 Email: donald.cof...@reminetworks.com ___ OAuth mailing list OAuth@ietf.org https://www.ietf.org

Re: [OAUTH-WG] I-D Action: draft-ietf-oauth-dyn-reg-06.txt

2013-02-15 Thread Donald F Coffin
this is an oversight and am merely pointing out that it needs to be included. Best regards, Don Donald F. Coffin Founder/CTO REMI Networks 22751 El Prado Suite 6216 Rancho Santa Margarita, CA 92688-3836 Phone: (949) 636-8571 Email: donald.cof...@reminetworks.com -Original Message- From

Re: [OAUTH-WG] Fwd: New Version Notification for draft-richer-oauth-introspection-02.txt

2013-02-14 Thread Donald F Coffin
Does the term Active help clarify the meaning but still confirm to your intention, Justin? Best regards, Don Donald F. Coffin Founder/CTO REMI Networks 22751 El Prado Suite 6216 Rancho Santa Margarita, CA 92688-3836 Phone: (949) 636-8571 Email:mailto:donald.cof

Re: [OAUTH-WG] draft-richer-oauth-introspection-01 scope syntax

2013-02-04 Thread Donald F Coffin
introspective WG feels scope should be a JSON array, then the WG should define a new data element rather than changing the definition of an existing data element already defined by RFC6749. Best regards, Don Donald F. Coffin Founder/CTO REMI Networks 22751 El Prado Suite 6216 Rancho Santa

Re: [OAUTH-WG] draft-ietf-oauth-revocation-04

2013-02-03 Thread Donald F Coffin
Hi Torsten, Best regards, Don Donald F. Coffin Founder/CTO REMI Networks 22751 El Prado Suite 6216 Rancho Santa Margarita, CA 92688-3836 Phone: (949) 636-8571 Email:mailto:donald.cof...@reminetworks.com donald.cof...@reminetworks.com From: Torsten Lodderstedt

Re: [OAUTH-WG] draft-richer-oauth-introspection-01 scope syntax

2013-01-30 Thread Donald F Coffin
and not relevant to a specification, especially since RFC 6749 has already set a documentation precedent.. Best regards, Don Donald F. Coffin Founder/CTO REMI Networks 22751 El Prado Suite 6216 Rancho Santa Margarita, CA 92688-3836 Phone: (949) 636-8571 Email

Re: [OAUTH-WG] draft-ietf-oauth-revocation-04

2013-01-29 Thread Donald F Coffin
George, Thanks for the quick response. I've added my comments after your responses below. Best regards, Don Donald F. Coffin Founder/CTO REMI Networks 22751 El Prado Suite 6216 Rancho Santa Margarita, CA 92688-3836 Phone: (949) 636-8571 Email:mailto:donald.cof