Re: [OAUTH-WG] Barry Leiba's No Objection on draft-ietf-oauth-token-exchange-18: (with COMMENT)

2019-07-18 Thread Eve Maler
Regarding your “higher importance” comment on Section 1.1 about the impersonation semantic below: Eve Maler (sent from my iPad) | cell +1 425 345 6756 > On Jul 18, 2019, at 4:06 PM, Barry Leiba via Datatracker > wrote: > > Barry Leiba has entered the following ballot position

[OAUTH-WG] New User-Managed Access (UMA) drafts

2019-02-13 Thread Eve Maler
://kantarainitiative.org/confluence/display/uma/UMA+Implementations [2] https://tools.ietf.org/html/draft-maler-oauth-umagrant [3] https://tools.ietf.org/html/draft-maler-oauth-umafedauthz *Eve Maler*Cell +1 425.345.6756 | Skype: xmlgrrl | Twitter: @xmlgrrl _

Re: [OAUTH-WG] Auth Server / Resource Server Coordination

2015-10-13 Thread Eve Maler
cp190 <https://tools.ietf.org/html/bcp190>, but > I think it's a good source of inspiration) > ___ > OAuth mailing list > OAuth@ietf.org > https://www.ietf.org/mailman/listinfo/oauth Eve Maler | cell +1 425.345.6756 | Skype: xmlgrrl | Twitter: @xmlgrrl | Calendar: xmlg...@gmail.com ___ OAuth mailing list OAuth@ietf.org https://www.ietf.org/mailman/listinfo/oauth

Re: [OAUTH-WG] Review of draft-ietf-oauth-introspection-01

2014-12-02 Thread Eve Maler
e >>>> identifier and get back something that lets you, the RS, check the >>>> signature. >>>> >>>> -- Justin >>>> >>>> On Dec 2, 2014, at 1:40 PM, Bill Mills >>> <mailto:wmills_92...@yahoo.com>> wrote: >>>> >>>>> "However, I think it's very clear how PoP tokens

Re: [OAUTH-WG] Review of draft-ietf-tram-turn-third-party-authz-01

2014-08-24 Thread Eve Maler
PP). Maybe you want to say that (in addition to the > assumed relationship between the two entities). If there is no > relationship between the two parties then they will certainly be a > challenge to get this done securely. Eve Maler http://www.xmlgrrl.com/blog

Re: [OAUTH-WG] Confirmation: Call for Adoption of "OAuth Token Introspection" as an OAuth Working Group Item

2014-07-29 Thread Eve Maler
gt;> Hi all, >>>> >>>> during the IETF #90 OAuth WG meeting, there was strong consensus in >>>> adopting the "OAuth Token Introspection" >>>> (draft-richer-oauth-introspection-06.txt) specification as an OAuth WG >>>> work item. >>>> >>>> We would

Re: [OAUTH-WG] Confirmation: Call for Adoption of "OAuth Token Introspection" as an OAuth Working Group Item

2014-07-29 Thread Eve Maler
gt;>> comments along to the list in your response to this Call for Adoption. >>>>>> >>>>>> Ciao >>>>>> Hannes & Derek >>>>>> >>>>>> >>>>>> ___

Re: [OAUTH-WG] Confirmation: Call for Adoption of "OAuth Token Introspection" as an OAuth Working Group Item

2014-07-28 Thread Eve Maler
f > you have issues/edits/comments on the document, please send these > comments along to the list in your response to this Call for Adoption. > > Ciao > Hannes & Derek > > ___ > OAuth mailing list > OAuth@ietf.org &

Re: [OAUTH-WG] draft-ietf-oauth-jwt-bearer != access tokens (was Re: draft-ietf-oauth-jwt-bearer Shepherd Write-up)

2014-04-30 Thread Eve Maler
[1] http://keycloak.org > [2] http://tools.ietf.org/html/__rfc6750 > <http://tools.ietf.org/html/rfc6750> > > > -- > Bill Burke > JBoss, a division of Red Hat > http://bill.burkecentral.com > > ___ > OA

Re: [OAUTH-WG] Dynamic Registration Plan: Your Feedback Needed!

2014-01-30 Thread Eve Maler
o do soon). We have to restart the WGLC due to discussions last > years and the resulting changes to these documents. > > Ciao > Hannes & Derek > > PS: Derek and I also think that Phil should become co-auhor of these > documents for his contributions. > &

Re: [OAUTH-WG] Comments on draft-richer-oauth-introspection-04

2013-10-23 Thread Eve Maler
t provided? you'd > have *more* information returned? I understand that this is just a framework > and each server would have its own rules, but you're then either saying too > much or too few. > > Thanks in advance for any guidance about how to achieve my

Re: [OAUTH-WG] Refactoring Dynamic Registration

2013-08-27 Thread Eve Maler
his does >> increase the optionality by making the client configuration endpoint >> parameters optional, but that's the tradeoff for having things cut this way. >> >> You can read both the specs here: >> >> http://tools.ietf.org/html/draft-richer-oaut

Re: [OAUTH-WG] Dynamic Client Registration Conference Call: Thu 22 Aug, 2pm PDT

2013-08-19 Thread Eve Maler
her topics you would like to bring >>>>>> up? >>>>>> - -BEGIN PGP SIGNATURE- >>>>>> Version: GnuPG/MacGPG2 v2.0.19 (Darwin) >>>>>> Comment: GPGTools - http://gpgtools.org >>>>>> >>>>>> i

Re: [OAUTH-WG] Charter- was Re: Client Instances of An Application - Was: Re: Last call review of draft-ietf-oauth-dyn-reg-10

2013-05-22 Thread Eve Maler
...@oracle.com >> On 2013-05-21, at 10:52 AM, Mike Jones wrote: >> >> No information is being thrown away. Developers can use dynamic >> registration to obtain a client_id and then have all the client instances >> use that client_id if they choose - just

Re: [OAUTH-WG] JWT - scope claim missing

2013-03-11 Thread Eve Maler
most likely one. >> > Using scope requires a relatively tight binding between the RS and AS, >> > UMA uses a different mechanism that describes finer grained operations. >> > The AS may include roles, user, or other more abstract claims that the the >

Re: [OAUTH-WG] New Version Notification for draft-richer-oauth-introspection-02.txt

2013-02-07 Thread Eve Maler
tus: >>> http://datatracker.ietf.org/doc/draft-richer-oauth-introspection >>> Htmlized: >>> http://tools.ietf.org/html/draft-richer-oauth-introspection-02 >>> Diff: >>> http://www.ietf.org/rfcdiff?url2=draft-richer-oauth-

Re: [OAUTH-WG] Client cannot specify the token type it needs

2013-01-23 Thread Eve Maler
simple solution may be to allow the client to register > via the dynamic registration proposal the token types it supports and then > the AS can use that data as a filtering mechanism when the client asks for a > token. > > Thanks, > George > > On 1/23/13 12:23 PM, Eve Maler

Re: [OAUTH-WG] Concerning OAuth introspection

2013-01-23 Thread Eve Maler
odd W Lainhart wrote: > >> > On the other hand, it's a useful exercise to imagine how much more benefit >> > could potentially be gotten "for free" if we look at it through a >> > pure-REST lens, not just with what's already been specified but the w

Re: [OAUTH-WG] Concerning OAuth introspection

2013-01-23 Thread Eve Maler
Rudely responding to myself: I'm not saying this approach should definitely be taken, just that it's a good idea to spend 15 minutes looking at the benefits and downsides of it vs. the current laser-focus approach. Eve On 23 Jan 2013, at 9:28 AM, Eve Maler wrote: >

Re: [OAUTH-WG] Concerning OAuth introspection

2013-01-23 Thread Eve Maler
ration (wording to be determine) OPTIONAL inquire (default) | revoke >>>>> ... >>>>> resource_idOPTIONAL >>>>> client_id OPTIONAL >>>>> client_secret

Re: [OAUTH-WG] Client cannot specify the token type it needs

2013-01-23 Thread Eve Maler
t; OAuth mailing list > > OAuth@ietf.org > > https://www.ietf.org/mailman/listinfo/oauth > > > > -- > Thanks & Regards, > Prabath > > Mobile : +94 71 809 6732 > > http://blog.facilelogin.com > http://RampartFAQ.com > ___ > OAuth mailing list > OAuth@ietf.org > https://www.ietf.org/mailman/listinfo/oauth Eve Maler http://www.xmlgrrl.com/blog +1 425 345 6756 http://www.twitter.com/xmlgrrl ___ OAuth mailing list OAuth@ietf.org https://www.ietf.org/mailman/listinfo/oauth

Re: [OAUTH-WG] Concerning OAuth introspection

2013-01-23 Thread Eve Maler
d like to recommend is to add "action"/"operation" to the >>>>> request. (and potentially add client_id and client_secret) >>>>> >>>>> So the request will be like : >>>>> token

Re: [OAUTH-WG] OAuth 2.0 Resource Registration draft -- FW: New Version Notification for draft-hardjono-oauth-resource-reg-00.txt

2012-12-28 Thread Eve Maler
On 28 Dec 2012, at 5:58 AM, "Anganes, Amanda L" wrote: > Hi Eve and Thomas, > > On 12/27/12 8:11 PM, "Eve Maler" wrote: > >> Amanda, thanks for the lightning-fast comments back. A couple of additional >> notes on top of Thomas's response: &g

Re: [OAUTH-WG] OAuth 2.0 Resource Registration draft -- FW: New Version Notification for draft-hardjono-oauth-resource-reg-00.txt

2012-12-27 Thread Eve Maler
oauth-resource-reg >>> Revision: 00 >>> Title: OAuth 2.0 Resource Set Registration >>> Creation date: 2012-12-27 >>> WG ID: Individual Submission >>> Number of pages: 19 >>> URL: >>> http://www.ietf.org/internet

Re: [OAUTH-WG] Assertion Framework - Why does issuer have to be either the client or a third party token service?

2012-12-05 Thread Eve Maler
> > > token service. > > > > Conceptually, it could be any token service (functionality) > > > residingin any of > > > > > > > > the stakeholders (Resource Owner, OAuth Client, Authorization Server, > > > > or > > > >

Re: [OAUTH-WG] New Version Notification for draft-richer-oauth-introspection-00.txt

2012-12-04 Thread Eve Maler
nfo that would come back from such a token introspection would be, > and what it means. Different types of tokens (Bearer, MAC, HOK) are going to > have different types of metadata associated with them, probably, but there > are a few core pieces (expiration, scopes) that would be common

Re: [OAUTH-WG] New Version Notification for draft-richer-oauth-introspection-00.txt

2012-12-04 Thread Eve Maler
s.ietf.org/html/draft-richer-oauth-introspection-00 >> >> >> Abstract: >> This specification defines a method for a client or protected >> resource to query an OAuth authorization server to determine meta- >> information about an OAuth token. >> >> >> >> >> >> The IETF Secre

Re: [OAUTH-WG] New Version Notification for draft-richer-oauth-introspection-00.txt

2012-12-04 Thread Eve Maler
ch simpler. > > But even so, I think the simple case of "I have a token and want to know > about it" needs to be supported without extra scaffolding. > > -- Justin > \ Eve Maler http://www.xmlgrrl.com/blog +1 425 345 6756

[OAUTH-WG] My earlier comments on the dyn client reg draft

2012-12-04 Thread Eve Maler
nspecified or omitted" redundant? What's the difference? 5. Security Considerations - I assume that, eventually, the RP/IdP language from the OpenID Connect draft will need to be genericized. Eve Maler htt

Re: [OAUTH-WG] Resource owner initiated OAuth delegation

2012-10-23 Thread Eve Maler
UMA? >> Not talking about UMA, Bob is not separate between roles in OAUTH, >> so don't have to redelegate in OAUTH? >> >> >> >> >> >> ___ >> OAuth mailing list >>

Re: [OAUTH-WG] Resource owner initiated OAuth delegation

2012-10-23 Thread Eve Maler
usecase Hardjono rediscribed may not necessarily invloving > "redelegation", a more general case would be the Babysitter directly show > delegation to the Teacher and walk the child home. > Eve Maler http://www.xmlgrrl.com/blog +1 425 345

Re: [OAUTH-WG] Resource owner initiated OAuth delegation

2012-10-11 Thread Eve Maler
Behalf >> Of zhou.suj...@zte.com.cn >> Sent: Thursday, October 11, 2012 4:45 AM >> To: Eve Maler >> Cc: oauth@ietf.org WG >> Subject: Re: [OAUTH-WG] Resource owner initiated OAuth delegation >> >> >> Hi,Eve >> >> "Having an RO li

Re: [OAUTH-WG] Resource owner initiated OAuth delegation

2012-10-10 Thread Eve Maler
: > > Hi, Eve, >The requester you described corresponds to Client in OAuth, so it is still > client initiated delegation, not what Prabath wants. > > > > Eve Maler > 2012-10-11 06:54 > > 收件人 > Prabath Siriwardena > 抄送 > zhou.suj...@zte.com.cn, &q

Re: [OAUTH-WG] Resource owner initiated OAuth delegation

2012-10-10 Thread Eve Maler
ve some pointers..? > > Thanks & regards, > -Prabath > > On Wed, Oct 10, 2012 at 3:20 PM, Eve Maler wrote: > There are a number of implicit actions happening here that ideally should be > accounted for. If Alice is the RO and Bob is operating the client, then when >

Re: [OAUTH-WG] Resource owner initiated OAuth delegation

2012-10-10 Thread Eve Maler
ronous presence would be ideal. Otherwise I suspect it's impractical in normal use. Eve On 9 Oct 2012, at 6:49 PM, zhou.suj...@zte.com.cn wrote: > > Hi,Prabath > > > Prabath Siriwardena > 2012-10-09 20:35 > > 收件人 > zhou.suj...@zte.com.cn > 抄送 &g

Re: [OAUTH-WG] Resource owner initiated OAuth delegation

2012-10-08 Thread Eve Maler
from the > Authorization Server.[just like passing the refresh_token] > > WDYT ? > > Thanks & regards, > -Prabath > > On Sun, Oct 7, 2012 at 11:05 AM, Eve Maler wrote: > Hi Prabath, > > As far as I know, OAuth itself generally isn't used to let one hum

Re: [OAUTH-WG] Resource owner initiated OAuth delegation

2012-10-07 Thread Eve Maler
://blog.facilelogin.com/2012/10/ationwhat-oauth-lacks-resource-owner.html > > -- > Thanks & Regards, > Prabath > > Mobile : +94 71 809 6732 > > http://blog.facilelogin.com > http://RampartFAQ.com > ________

Re: [OAUTH-WG] Implementation Support and Community

2012-08-23 Thread Eve Maler
Point everyone to StackOverflow with an "oauth" tag >> >> >> -- Justin (who is not volunteering himself to host or moderate the group) >> ___ >> OAuth mailing list >> OAuth@ietf.org >&g

Re: [OAUTH-WG] [apps-discuss] OAuth discovery registration.

2012-06-14 Thread Eve Maler
bit hairy to put a JSON list inside a > quoted application data value. > > Do we want something like a "capabilities" list which could include > dynamic_client_registration_supported and perhaps others? > > -bill > > > > > - Original Message - >&

Re: [OAUTH-WG] Dynamic clients, URI, and stuff Re: Discussion needed on username and password ABNF definitions

2012-06-13 Thread Eve Maler
-- Mike >> >> >> >> P.S. If anyone has a better ABNF for UNICODENOCTRLCHAR than "> >> Unicode character other than ( %x0-1F / %x7F )>", please send it to me! >> > >> > As noted before, here's an example: >> > <http://green

Re: [OAUTH-WG] [apps-discuss] OAuth discovery registration.

2012-06-13 Thread Eve Maler
gt;>> apps-discuss mailing list >>> apps-disc...@ietf.org >>> https://www.ietf.org/mailman/listinfo/apps-discuss >> >> Questo messaggio e i suoi allegati sono indirizzati esclusivamente alle >> persone >> indicate. La diffusione, copia o qualsiasi altra azione derivante dalla >> conoscenza di queste informazioni sono rigorosamente vietate. Qualora >> abbiate >> ricevuto questo documento per errore siete cortesemente pregati di darne >> immediata comunicazione al mittente e di provvedere alla sua distruzione, >> Grazie. >> >> This e-mail and any attachments is confidential and may contain privileged >> information intended for the addressee(s) only. Dissemination, copying, >> printing >> or use by anybody else is unauthorised. If you are not the intended >> recipient, >> please delete this message and any attachments and advise the sender by >> return >> e-mail, Thanks. >> > ___ > OAuth mailing list > OAuth@ietf.org > https://www.ietf.org/mailman/listinfo/oauth > Eve Maler http://www.xmlgrrl.com/blog +1 425 345 6756 http://www.twitter.com/xmlgrrl ___ OAuth mailing list OAuth@ietf.org https://www.ietf.org/mailman/listinfo/oauth

Re: [OAUTH-WG] Meeting slot for the Vancouver IETF meeting requested

2012-06-04 Thread Eve Maler
__ >> OAuth mailing list >> OAuth@ietf.org >> https://www.ietf.org/mailman/listinfo/oauth > ___ > OAuth mailing list > OAuth@ietf.org > https://www.ietf.org/mailman/listinfo/oauth Eve Maler

Re: [OAUTH-WG] IIW and OAuth

2012-04-22 Thread Eve Maler
that we can get them > out of the door. > (And thanks to those who have already read them.) > > ___________ > OAuth mailing list > OAuth@ietf.org > https://www.ietf.org/mailman/listinfo/oauth Eve Maler

Re: [OAUTH-WG] Updated Charter to the IESG (this weekend)

2012-04-22 Thread Eve Maler
s, >>>>> Torsten. >>>>> >>>>> Am 16.04.2012 21:04, schrieb Justin Richer: >>>>>> >>>>>>>> OK, but with SWD and discovery off the table, can this now be >>>>>>>> considered to be withi

Re: [OAUTH-WG] Dynamic Client Registration

2012-04-13 Thread Eve Maler
with some meta-data). > > Is this too far fetched? > > Ciao > Hannes > > ___ > OAuth mailing list > OAuth@ietf.org > https://www.ietf.org/mailman/listinfo/oauth Eve Maler http://www.

Re: [OAUTH-WG] Issue token for another user

2012-03-11 Thread Eve Maler
e scope to > user=user_id (where user_id would be the identifier for the user Bob)? > > -David > ___ > OAuth mailing list > OAuth@ietf.org > https://www.ietf.org/mailman/listinfo/oauth Eve Maler

Re: [OAUTH-WG] OAuth 2.0 and Access Control Lists (ACL)

2011-12-19 Thread Eve Maler
s >> the resource? >> ___ >> OAuth mailing list >> OAuth@ietf.org >> https://www.ietf.org/mailman/listinfo/oauth >> > > _______ > OAuth mailing list > OAuth@ietf.org

Re: [OAUTH-WG] Rechartering

2011-10-22 Thread Eve Maler
imple-web-discovery-00 >> >> >> >> We have the following questions: >> >> a) Are you interested in any of the above-listed items? (as a reviewer, >> co-author, implementer, or someone who would like to deploy). It is also >> useful to know if you think that we shouldn't work on a specific item. >> >> b) Are there other items you would like to see the group working on? >> >> Note: In case your document is expired please re-submit it. >> >> Ciao >> Hannes & Barry >> >> ___ >> OAuth mailing list >> OAuth@ietf.org >> https://www.ietf.org/mailman/listinfo/oauth > > > > ___ > OAuth mailing list > OAuth@ietf.org > https://www.ietf.org/mailman/listinfo/oauth Eve Maler http://www.xmlgrrl.com/blog +1 425 345 6756 http://www.twitter.com/xmlgrrl ___ OAuth mailing list OAuth@ietf.org https://www.ietf.org/mailman/listinfo/oauth

Re: [OAUTH-WG] Second Last Call: (Web Host Metadata) to Proposed Standard -- feedback

2011-07-03 Thread Eve Maler
. Maybe I'm >>> just scarred by WS-*, but it seems very over-engineered for what it does. I >>> understand that the communities had reasons for using it to leverage an >>> existing user base for their specific user cases, but I don't see any >>> rea

Re: [OAUTH-WG] Fwd: [oauth] Good list of OAuth open source?

2011-06-24 Thread Eve Maler
com/hueniverse/node-mac >> or 'npm install mac' >> >> A browser JS lib is available at: >> >> https://sled.com/scripts/mac.js >> >> Both are used in production. >> >> EHL >> >> >>> -Original Message- >

Re: [OAUTH-WG] Fwd: [oauth] Good list of OAuth open source?

2011-06-24 Thread Eve Maler
hub.com/teohm/teohm.github.com/wiki/OAuth > > Anyone knows if there is an open source OAuth2 server reference > implementation that reflects the latest draft 16, and unit-tested > against the security considerations in section 10? > > On Sat, Jun 25, 2011 at 1:02 AM, Eve Ma

[OAUTH-WG] Fwd: [oauth] Good list of OAuth open source?

2011-06-24 Thread Eve Maler
Zero response from the other list. Any suggestions from folks here? Begin forwarded message: > From: Eve Maler > Date: 20 June 2011 4:54:56 PM PDT > To: oa...@googlegroups.com > Subject: [oauth] Good list of OAuth open source? > Reply-To: oa...@googlegroups.com > > The lis

[OAUTH-WG] Looking for feedback on "client-server OAuth" usage

2011-05-16 Thread Eve Maler
is to folks you know who might be interested to respond. Thanks in advance, Eve Eve Maler http://www.xmlgrrl.com/blog +1 425 345 6756 http://www.twitter.com/xmlgrrl ___ OAuth mailing list

Re: [OAUTH-WG] New Working Group Items?

2011-02-11 Thread Eve Maler
gt; interface between the authorization server and the protected resource. >> It could increase the productivity of creating the oauth protected web >> services when the auth server can be treated as an off the shelf piece >> of code. >> Then it would be up t

Re: [OAUTH-WG] Feedback on preliminary draft 11 from implementers of draft 10

2010-12-04 Thread Eve Maler
d nonstandard. :-) See the "Resource Registration" spec link from our Working Drafts page for more info; if there's sufficient interest, we could contribute it as an IETF I-D soonish: http://kantarainitiative.org/confluence/display/uma/Working+Drafts

Re: [OAUTH-WG] So back to use cases? (was RE: Call for Consensus on Document Split)

2010-10-28 Thread Eve Maler
solve. This would still allow slimy political manipulation of the process by >> manipulating the use case list, but that would be progress. It's better to >> have a protocol that solves a politically-defined set of problems than to >> have >> a politically-defined protocol that solves no identified problem. Eve Maler http://www.xmlgrrl.com/blog +1 425 345 6756 http://www.twitter.com/xmlgrrl ___ OAuth mailing list OAuth@ietf.org https://www.ietf.org/mailman/listinfo/oauth

Re: [OAUTH-WG] Opensource impl yet?

2010-10-15 Thread Eve Maler
> https://www.ietf.org/mailman/listinfo/oauth > > > ___ > OAuth mailing list > OAuth@ietf.org > https://www.ietf.org/mailman/listinfo/oauth Eve Maler http://www.xmlgrrl.com/blog +1

Re: [OAUTH-WG] Comparing the JSON Token drafts

2010-10-01 Thread Eve Maler
n help prevent a token from being repurposed from one context to > another, by having a clear (and cryptographically verified) declaration that > “This is a JSON token”. I understand this motivation and am open to > discussions on how to best achieve it, while still providing as little > mechanism

Re: [OAUTH-WG] Basic signature support in the core specification

2010-09-25 Thread Eve Maler
need to be spec'ed -- the question is if the signature spec is in core or a >> separate spec. >> >> For people that don't need signatures, having them separate keeps the core >> spec simpler. Having a separate spec enables other groups to reuse the >> si

Re: [OAUTH-WG] Basic signature support in the core specification

2010-09-24 Thread Eve Maler
re of the group. > > EHL > > ___ > OAuth mailing list > OAuth@ietf.org > https://www.ietf.org/mailman/listinfo/oauth Eve Maler http://www.xmlgrrl.com/blog +1 425 345 6756 http://www.twitter.com/xmlgrrl

Re: [OAUTH-WG] Rechartering

2010-09-14 Thread Eve Maler
241 400 730 0, > http://comlounge.net > Blog: http://mrtopf.de/blog, Twitter: http://twitter.com/mrtopf > > Podcasts: > Der OpenWeb-Podcast (http://openwebpodcast.de) > Data Without Borders (http://datawithoutborders.net) > Politisches: http://politfunk.de/ > &g

Re: [OAUTH-WG] Proposal for OAuth dynamic client registration

2010-08-11 Thread Eve Maler
understanding) to serve different clients (or their > home web apps) on the same host. What about using JRD or XRD? This would > allow for a client-URL-related discovery. > > What means for authentication a client against its home web app. do you > envision? > > regards, >

[OAUTH-WG] Proposal for OAuth dynamic client registration

2010-08-10 Thread Eve Maler
ion Tool > Date: 10 August 2010 12:23:59 PM PDT > To: e...@xmlgrrl.com > Cc: c...@comlounge.net, m.p.machu...@ncl.ac.uk > Subject: New Version Notification for draft-oauth-dyn-reg-v1-00 > > > A new version of I-D, draft-oauth-dyn-reg-v1-00.txt has been successfully > submitte

Re: [OAUTH-WG] resource server id needed?

2010-08-03 Thread Eve Maler
> to indicate the resource URL to the authz server. The scope? > > regards, > Torsten. > > > > Am 02.08.2010 um 02:16 schrieb Eve Maler : > >> I'm not sure if you mean "address" as in "handle", or "address" as in >>

Re: [OAUTH-WG] resource server id needed?

2010-08-01 Thread Eve Maler
. Eve On 28 Jul 2010, at 11:32 PM, Torsten Lodderstedt wrote: > Eve, > > how does UMA plan to address resource servers during the OAuth end-user > authorization process? > > regards, > Torsten. > > Am 29.07.2010 02:37, schrieb Eve Maler: >> >> B

Re: [OAUTH-WG] resource server id needed?

2010-07-28 Thread Eve Maler
o the authz server is not an issue. >> But this implies the client asks for full access to the users media storage. >> Since our client is a gallery application, it requires the "GET" permission >> only. How does the client know which of the scope valu

Re: [OAUTH-WG] OAuth & Protected feeds

2010-07-28 Thread Eve Maler
TOS acknowledgement on the initial subscription > request by a given user, subsequent requests will not provide a > precondition_uri. > > 3) It is also worth exploring this flow as a suitable and more > flexible alternative to the traditional Web Server flow. > > > Questions? Comments? Suggestions? > > > -- > darren bounds > dar...@cliqset.com > ___ > OAuth mailing list > OAuth@ietf.org > https://www.ietf.org/mailman/listinfo/oauth > Eve Maler http://www.xmlgrrl.com/blog http://www.twitter.com/xmlgrrl http://www.linkedin.com/in/evemaler ___ OAuth mailing list OAuth@ietf.org https://www.ietf.org/mailman/listinfo/oauth

Re: [OAUTH-WG] "access grant" terminology

2010-07-12 Thread Eve Maler
t and will be confusing when used with assertions and >> other grant types. >> >> So I'm open to other ideas but not this one. >> >> Note that since this term impacts the name of the current 'grant_type' >> parameter, changing it means code changes.

Re: [OAUTH-WG] POLL: Are you going to Maastricht?

2010-07-11 Thread Eve Maler
> OAuth mailing list > OAuth@ietf.org > https://www.ietf.org/mailman/listinfo/oauth Eve Maler http://www.xmlgrrl.com/blog http://www.twitter.com/xmlgrrl http://www.linkedin.com/in/evemaler ___ OAuth mailing list OAuth@ietf.org https://www.ietf.org/mailman/listinfo/oauth

Re: [OAUTH-WG] What to do about 'realm'

2010-07-11 Thread Eve Maler
ly you need to separately provide > a token endpoint as well). > > -- > James Manger > _______ > OAuth mailing list > OAuth@ietf.org > https://www.ietf.org/mailman/listinfo/oauth Eve Maler http://www.xmlgrrl.com/blog http://www.twitter.com/x

Re: [OAUTH-WG] Partially standardized format for access tokens?

2010-06-04 Thread Eve Maler
I'll defend to the death >> your right to say it." - S. G. Tallentyre >> >> ___ >> OAuth mailing list >> OAuth@ietf.org >> https://www.ietf.org/mailman/listinfo/oauth >> > > ___ > OAuth mailing list > OAuth@ietf.org > https://www.ietf.org/mailman/listinfo/oauth Eve Maler e...@xmlgrrl.com http://www.xmlgrrl.com/blog ___ OAuth mailing list OAuth@ietf.org https://www.ietf.org/mailman/listinfo/oauth

Re: [OAUTH-WG] [oauth] #6: Make automated self-registration of unique clients possible

2010-05-17 Thread Eve Maler
, and that it's pretty much the right length and organization for its current purpose. So never mind. :) Eve Eve Maler e...@xmlgrrl.com http://www.xmlgrrl.com/blog ___ OAuth mailing list OAuth@ietf.org https://www.ietf.org/mailman/listinfo/oauth

Re: [OAUTH-WG] Scope - Coming to a Consensus

2010-05-01 Thread Eve Maler
liable shorthand for an access feature. For read and write and even delete permissions on (say) identity data accessed by URL, it's pretty much all the expressiveness you need, and ideally the same documentation easily covers both features and scopes. For any API that's more

Re: [OAUTH-WG] Autonomous clients and resource owners (editorial)

2010-04-26 Thread Eve Maler
alf a > resource owner that is not themselves … it then seems the resource owner > must provide some level of consent outside the OAuth specific flow. > > Thanks. > > Doug > > > From: oauth-boun...@ietf.org [mailto:oauth-boun...@ietf.org] On Behalf Of Eve > M

[OAUTH-WG] Autonomous clients and resource owners (editorial)

2010-04-23 Thread Eve Maler
e the client is acting for itself (the client is also the resource owner)." to something like: "...and autonomous flows where the client is acting on behalf of a different resource owner." Thanks, Eve On 21 Apr 2010, at 4:43 PM, Eve Maler wrote: > Tacking this resp

Re: [OAUTH-WG] 'Scope' parameter proposal

2010-04-22 Thread Eve Maler
hing to do. > > I'm hopeful that either PoCo or the IMAP SASL/OAuth work ends up > showing how automatic interop is possible. > > But I'd hate to have OAuth2 recommend something that doesn't actually work. > > Cheers, > Brian > __________

Re: [OAUTH-WG] Issue: 'username' parameter proposal

2010-04-21 Thread Eve Maler
Thanks! On 21 Apr 2010, at 5:12 PM, Eran Hammer-Lahav wrote: > This is part of the delegation flows so username should be just fine… > > EHL > > From: oauth-boun...@ietf.org [mailto:oauth-boun...@ietf.org] On Behalf Of Eve > Maler > Sent: Wednesday, April 21, 2010 4

Re: [OAUTH-WG] Issue: 'username' parameter proposal

2010-04-21 Thread Eve Maler
is made to get an access token via the User-Agent flow in >> immediate mode (or with any redirect without prompting the user) >> -ob now has an access token for Mary and (posts activities, schedules >> events, gets contacts) as Mary >> Hilarity ensues >> >> Secondary goal: Provide a hint for non-immediate mode >> >> On Thu, Apr 15, 2010 at 11:55 AM, Eran Hammer-Lahav >> wrote: >> Evan Gilbert proposed a 'username' request parameter to allow the client to >> limit the end user to authenticate using the provided authorization server >> identifier. The proposal has not been discussed or supported by others, and >> has not received a security review. >> >> Proposal: Obtain further discussion and support from others, as well as a >> security review of the proposal. Otherwise, do nothing. >> >> EHL >> >> ___ >> OAuth mailing list >> OAuth@ietf.org >> https://www.ietf.org/mailman/listinfo/oauth >> >> >> >> >> >> ___ >> OAuth mailing list >> OAuth@ietf.org >> https://www.ietf.org/mailman/listinfo/oauth >> >> >> >> >> ___ >> OAuth mailing list >> OAuth@ietf.org >> https://www.ietf.org/mailman/listinfo/oauth >> >> > > ___ > OAuth mailing list > OAuth@ietf.org > https://www.ietf.org/mailman/listinfo/oauth Eve Maler e...@xmlgrrl.com http://www.xmlgrrl.com/blog ___ OAuth mailing list OAuth@ietf.org https://www.ietf.org/mailman/listinfo/oauth

Re: [OAUTH-WG] 'Scope' parameter proposal

2010-04-20 Thread Eve Maler
l, you will need to define a bigger set: > email_read, email_write, contacts_read, contacts_write. On the other hand, if > a write access is for all authorized resources, you need: email, contacts, > read, write. > > > Given that, returning a single scope value if that is all that makes sense > > to the > > resource will likely address many use cases. > > This is true when looking at a single resource. > > EHL > > ___ > OAuth mailing list > OAuth@ietf.org > https://www.ietf.org/mailman/listinfo/oauth > > ___ > OAuth mailing list > OAuth@ietf.org > https://www.ietf.org/mailman/listinfo/oauth Eve Maler e...@xmlgrrl.com http://www.xmlgrrl.com/blog ___ OAuth mailing list OAuth@ietf.org https://www.ietf.org/mailman/listinfo/oauth

Re: [OAUTH-WG] new co-chair

2010-03-25 Thread Eve Maler
> OAuth mailing list > OAuth@ietf.org > https://www.ietf.org/mailman/listinfo/oauth Eve Maler e...@xmlgrrl.com http://www.xmlgrrl.com/blog ___ OAuth mailing list OAuth@ietf.org https://www.ietf.org/mailman/listinfo/oauth

Re: [OAUTH-WG] First draft of OAuth 2.0

2010-03-24 Thread Eve Maler
t use SAML > SSO messages to get an Access Token (comparable to OpenID/OAuth hybrid). > > Anybody else interested? > > paul Eve Maler e...@xmlgrrl.com http://www.xmlgrrl.com/blog ___ OAuth mailing list OAuth@ietf.org https://www.ietf.org/mailman/listinfo/oauth

Re: [OAUTH-WG] First draft of OAuth 2.0

2010-03-24 Thread Eve Maler
le specs. SAML offered guidelines for people writing third-party profiles and extensions, and a lighter-weight version of this might be nice to have on record if there's any complexity to it. Eve Eve Maler e...@xmlgrrl.com http://www.xmlgrrl.com/blog

[OAUTH-WG] What are the OAuth design principles?

2010-03-22 Thread Eve Maler
erberos just be used for your use cases?" The UMA principles might be able to inform how the OAuth WG makes its case for why Kerberos doesn't suffice. (If we discover it does, hey, our work here is done. :-) Eve Eve Maler e...@xmlgrrl.c

Re: [OAUTH-WG] First draft of OAuth 2.0

2010-03-21 Thread Eve Maler
Selected thoughts in response: On 21 Mar 2010, at 3:51 PM, David Recordon wrote: > Thanks! Comments inline and updated the repo > (http://github.com/daveman692/OAuth-2.0/commit/3193098ff45168dd0a65456334428b20215f848a). > > On Sun, Mar 21, 2010 at 12:03 PM, Eve Maler wrote: >

Re: [OAUTH-WG] First draft of OAuth 2.0

2010-03-21 Thread Eve Maler
that this or that can be spec'd in the >> server docs and the client hard coded to the docs; this is fine for >> some features but not for very general ones that everybody needs to >> use. Eve Maler e...@xmlgrrl.com http://www.xmlgrrl.com/blog

Re: [OAUTH-WG] First draft of OAuth 2.0

2010-03-21 Thread Eve Maler
access token and then make a refresh call where you ask for a > token secret. This causes the auth server to mark the token as > no longer being valid as a bearer token via SSL. This > performance tradeoff seems realistic given many use cases focus > on high-volume API transactions and thus the one additional > request at the onset should be noise. The signature mechanism is > currently from OAuth 1.0. > > Obviously I couldn't have made so much progress so quickly if it weren't for > WRAP and I hope that 2.0 both addresses the WRAP use cases as well as those > we all have been discussing here. I hope that I haven't missed anyone who > contributed to prior work and am happy to add other authors if I have (and > they wish to be added)! > > Thanks, > --David > > [1] http://www.ietf.org/mail-archive/web/oauth/current/msg01225.html > Eve Maler e...@xmlgrrl.com http://www.xmlgrrl.com/blog ___ OAuth mailing list OAuth@ietf.org https://www.ietf.org/mailman/listinfo/oauth

Re: [OAUTH-WG] Dinner Sunday?

2010-03-20 Thread Eve Maler
ll be in Anaheim Sunday evening, but should > we try to put a dinner together? 7pm-ish? Eve Maler e...@xmlgrrl.com http://www.xmlgrrl.com/blog ___ OAuth mailing list OAuth@ietf.org https://www.ietf.org/mailman/listinfo/oauth

Re: [OAUTH-WG] Signatures, Why?

2010-03-16 Thread Eve Maler
on manager would ask a requester to produce in order to prove suitability for getting access. (The authorizing user might be delegating access to some protected web resource that contains identity claims about themselves; this is well outside the UMA core protocol.)

Re: [OAUTH-WG] Signatures, Why?

2010-03-12 Thread Eve Maler
bate has been more about whether clients need to use signatures > when requesting access tokens, or when using access tokens. On one > side there are people who would prefer bearer tokens, and on the other > side there are folks who want crypto in various bits of the protocol > to meet

[OAUTH-WG] Token validation and other host/authz communication

2010-03-12 Thread Eve Maler
cal token validation (which ends up looking like a hybrid remote/local means of validation). Eve Maler e...@xmlgrrl.com http://www.xmlgrrl.com/blog ___ OAuth mailing list OAuth@ietf.org https://www.ietf.org/mailman/listinfo/oauth

Re: [OAUTH-WG] Signatures, Why?

2010-03-12 Thread Eve Maler
re signatures needed? >>> - What do signatures need to protect? >>> >>> Let's try to outline the use cases! Please reply here, so that we have >>> a good idea of what they are as we move towards the Anaheim WG. >>> >> This was a valuable thr

Re: [OAUTH-WG] Recent UMA work that may inform this group's deliberations

2010-03-09 Thread Eve Maler
Thanks for your further feedback. Just a couple of comments back (eliding other portions of the thread): On 8 Mar 2010, at 2:21 PM, Dick Hardt wrote: > On 2010-03-05, at 6:57 AM, Eve Maler wrote: >>>> >>>> 2c. Currently, WRAP doesn't say anything about how t

Re: [OAUTH-WG] Recent UMA work that may inform this group's deliberations

2010-03-05 Thread Eve Maler
More below... On 4 Mar 2010, at 5:43 PM, Dick Hardt wrote: > Thanks Eve, comments inserted ... > > On 2010-03-04, at 12:51 PM, Eve Maler wrote: > >> As requested on today's call, here's a description of the places where UMA >> seems to need "more&qu

Re: [OAUTH-WG] Recent UMA work that may inform this group's deliberations

2010-03-04 Thread Eve Maler
ient/requester along with sending the token for validation. The note you're responding to just above is this third case. Eve > > > On 2010-03-04, at 11:01 AM, Eve Maler wrote: > >> Folks may be interested to see the following experiment being performed in >> the

Re: [OAUTH-WG] Recent UMA work that may inform this group's deliberations

2010-03-04 Thread Eve Maler
nformation in various ways. It may not be acceptable in some UMA use cases, e.g., to use replayable tokens. As I promised on the call, I'll work with the UMA group to research this issue as precisely as possible in preparation for Anaheim, ideally including specific guidance from

[OAUTH-WG] Recent UMA work that may inform this group's deliberations

2010-03-04 Thread Eve Maler
. Please note the final comments in today's UMA telecon minutes for cautions about additional requirements we have: http://kantarainitiative.org/confluence/display/uma/UMA+telecon+2010-03-04 Eve Eve Maler e...@xmlgrrl.com http://www.xmlgrrl.com

[OAUTH-WG] UMA use cases (was Re: proposed agenda for second interim meeting)

2010-02-03 Thread Eve Maler
ed message. >>>> >>>> - With regards to #4, how should the challenge identify the token to >>>> be >>> used (realm comes free, do we need another)? >>>> >>>> - Should a single token support multiple signature algorithms? This >&

Re: [OAUTH-WG] terminology

2010-02-02 Thread Eve Maler
. >> >> The terms used in OAuth WRAP are a superset of OAuth 1.0 with changes >> to provide additional clarity. > > I meant to say "agreed, where possible and reasonable". The point of > this exercise is to make sure that we differentiate where that makes >

Re: [OAUTH-WG] FYI, UMA webinar followup

2010-01-29 Thread Eve Maler
ed for the seminar, got the bridge info, dialed in and nobody > was there. > Are there slides available? > >> -Original Message- >> From: oauth-boun...@ietf.org [mailto:oauth-boun...@ietf.org] >> On Behalf Of ext Eve Maler >> Sent: 25 January, 2010 14

[OAUTH-WG] FYI, UMA webinar followup

2010-01-25 Thread Eve Maler
nce/display/uma/Meetings+and+Minutes Eve Eve Maler e...@xmlgrrl.com http://www.xmlgrrl.com/blog ___ OAuth mailing list OAuth@ietf.org https://www.ietf.org/mailman/listinfo/oauth

  1   2   >