Re: [OAUTH-WG] [External Sender] Call for adoption - Transaction Tokens

2023-11-22 Thread Steinar Noem
I support adoption of the draft for transaction tokens S On Tue, Nov 14, 2023 at 7:58 AM Rifaat Shekh-Yusef mailto:rifaat.s.i...@gmail.com>> wrote: All, This is an official call for adoption for the Transaction Tokens draft:

Re: [OAUTH-WG] Call for adoption - Identity Chaining

2023-11-22 Thread Steinar Noem
I support adoption Fra: OAuth på vegne av On Tue, Nov 14, 2023 at 4:59 AM Rifaat Shekh-Yusef mailto:rifaat.s.i...@gmail.com>> wrote: All, This is an official call for adoption for the Identity Chaining draft:

Re: [OAUTH-WG] WGLC for Browser-based Apps

2023-08-28 Thread Steinar Noem
*> No, because running a silent flow in an iframe typically uses a web >>>> message response. In essence, the callback is not the redirect URI, but a >>>> minimal JS page that sends the code to the main application context using >>>> the web messaging mechanism. The message will have the origin of the >>>

Re: [OAUTH-WG] Call for adoption - Protected Resource Metadata

2023-08-23 Thread Steinar Noem
ta/ > > Please, reply on the mailing list and let us know if you are in favor of > adopting this draft as WG document, by *Sep 6th.* > > Regards, > Rifaat & Hannes > > ___ > OAuth mailing list > OAuth@ietf.org > https://www.iet

Re: [OAUTH-WG] [SENDER VERFICATION FAILED] Re: Privacy considerations regarding RAR and authorization_details in AT JWT

2023-01-12 Thread Steinar Noem
ietf.org > > https://www.ietf.org/mailman/listinfo/oauth > > ___ > OAuth mailing list > OAuth@ietf.org > https://www.ietf.org/mailman/listinfo/oauth > > > *CONFIDENTIALITY NOTICE: This email may contain confidential and > privileg

Re: [OAUTH-WG] Call for adoption - SD-JWT

2022-07-29 Thread Steinar Noem
error, please notify the sender >> immediately by e-mail and delete the message and any file attachments from >> your computer. Thank you.* > > ___ > OAuth mailing list > OAuth@ietf.org > https://www.ietf.org/mailman/listinfo/oauth &

Re: [OAUTH-WG] An access token claim to identify data processing purposes

2022-04-04 Thread Steinar Noem
the structure for accountability purposes, legal basis and legitimate interest - and reflect certain claims in the access token (JWT). man. 4. apr. 2022 kl. 18:02 skrev Roberto Polli : > Thanks Noem, > > Il giorno lun 4 apr 2022 alle ore 16:32 Steinar Noem > ha scritto: > >> I'm l

Re: [OAUTH-WG] An access token claim to identify data processing purposes

2022-04-04 Thread Steinar Noem
an existing claim/access token request parameter already. > > If such a parameter does not exist, which is the procedure for registering > it? > > Kind regards, > R: > ___ > OAuth mailing list > OAuth@ietf.org > https://www.ietf.o

Re: [OAUTH-WG] WGLC for DPoP Document

2022-03-30 Thread Steinar Noem
or viruses. All calls and emails to and from this company may > be monitored and recorded for legitimate purposes relating to this > company's business. Any opinions expressed in this email (or in any > attachments) are those of the author and do not necessarily represent the > opinions of Moneyhub Financial Technology Limited or of any other group > company. > > ___ > OAuth mailing list > OAuth@ietf.org > https://www.ietf.org/mailman/listinfo/oauth > -- Vennlig hilsen Steinar Noem Partner Udelt AS Systemutvikler | stei...@udelt.no | h...@udelt.no | +47 955 21 620 | www.udelt.no | ___ OAuth mailing list OAuth@ietf.org https://www.ietf.org/mailman/listinfo/oauth

Re: [OAUTH-WG] WGLC for DPoP Document

2022-03-29 Thread Steinar Noem
___ > OAuth mailing list > OAuth@ietf.org > https://www.ietf.org/mailman/listinfo/oauth > -- Vennlig hilsen Steinar Noem Partner Udelt AS Systemutvikler | stei...@udelt.no | h...@udelt.no | +47 955 21 620 | www.udelt.no | __

Re: [OAUTH-WG] WGLC for DPoP Document

2022-03-28 Thread Steinar Noem
th-dpop/ > > Please, provide your feedback on the mailing list by April 11th. > > Regards, > Rifaat & Hannes > > > ___ > OAuth mailing listOAuth@ietf.orghttps://www.ietf.org/mailman/listinfo/oauth > > > __

Re: [OAUTH-WG] OAuth Interim Meeting - April 12 - Security BCP

2021-04-12 Thread Steinar Noem
e the "sub" claim shall contain > either > a globally unique identifier or an identifier specific to an AS-RS pair > which shall be compared with the identifier of the user account. If there > is no match, > the access token shall be discarded. > > In this way, the access token will be linked to the user account

Re: [OAUTH-WG] JSON Web Token (JWT) Profile for OAuth 2.0 Access Tokens

2020-05-13 Thread Steinar Noem
ss-token-jwt/ > > We will be working on the shepherd write-up and then submit the document > to the IESG soon. > > Regards, > Rifaat & Hannes > > ___ > OAuth mailing list > OAuth@ietf.org > https://www.ietf.org/mailman/listinfo/

Re: [OAUTH-WG] OAuth 2.1 - require PKCE?

2020-05-06 Thread Steinar Noem
OpenID Connect >> deployments? How significant is that impact? >> >> >> >> Dick, Aaron, and Torsten >> >> >> >> ᐧ >> ___ >> OAuth mailing list >> OAuth@ietf.org >> https://www.ietf.org/mailman/listinfo/oauth >> > ___ > OAuth mailing list > OAuth@ietf.org > https://www.ietf.org/mailman/listinfo/oauth > > ___ > OAuth mailing list > OAuth@ietf.org > https://www.ietf.org/mailman/listinfo/oauth > -- Vennlig hilsen Steinar Noem Partner Udelt AS Systemutvikler | stei...@udelt.no | h...@udelt.no | +47 955 21 620 | www.udelt.no | ___ OAuth mailing list OAuth@ietf.org https://www.ietf.org/mailman/listinfo/oauth

Re: [OAUTH-WG] Call for Adoption: DPoP

2020-03-24 Thread Steinar Noem
t > OAuth@ietf.org > https://www.ietf.org/mailman/listinfo/oauth > -- Vennlig hilsen Steinar Noem Partner Udelt AS Systemutvikler | stei...@udelt.no | h...@udelt.no | +47 955 21 620 | www.udelt.no | ___ OAuth mailing list OAuth@ietf.org https://www.ietf.org/mailman/listinfo/oauth

Re: [OAUTH-WG] Call for Adoption: OAuth 2.0 Rich Authorization Requests

2020-01-07 Thread Steinar Noem
.___ > > OAuth mailing list > > OAuth@ietf.org > > https://www.ietf.org/mailman/listinfo/oauth > > ___ > OAuth mailing list > OAuth@ietf.org > https://

Re: [OAUTH-WG] I-D Action: draft-ietf-oauth-access-token-jwt-03.txt

2019-12-17 Thread Steinar Noem
vailable at: > https://tools.ietf.org/html/draft-ietf-oauth-access-token-jwt-03 > https://datatracker.ietf.org/doc/html/draft-ietf-oauth-access-token-jwt-03 > > A diff from the previous version is available at: > https://www.ietf.org/rfcdiff?url2=draft-ietf-oauth-access-tok

Re: [OAUTH-WG] Meeting Minutes

2019-12-16 Thread Steinar Noem
>> OAuth mailing list >> OAuth@ietf.org >> https://www.ietf.org/mailman/listinfo/oauth >> > -- > Rob Otto > EMEA Field CTO - Ping Identity > +44 777 135 6092 > > * CONFIDENTIALITY NOTICE: This email may contain confidential and > privileged material for the sole use

Re: [OAUTH-WG] Location and dates for next OAuth Security Workshop

2019-08-10 Thread Steinar Noem
That is good to hear, Nat. I tried to be as polite as possible in my response. lør. 10. aug. 2019 kl. 10:52 skrev Nat Sakimura : > I think Tony was just joking as it was quite a hassle for both of us to > get to Gjøvik for an ISO meeting. > > On Thu, Aug 8, 2019 at 9:50 PM Steinar

Re: [OAUTH-WG] Location and dates for next OAuth Security Workshop

2019-08-08 Thread Steinar Noem
82nhyARt28me4xbE%3Dreserved=0 >> <https://nam06.safelinks.protection.outlook.com/?url=https%3A%2F%2Fwww..ietf.org%2Fmailman%2Flistinfo%2Foauth=02%7C01%7Ctonynad%40microsoft..com%7Cc992681cd6294582fb4308d71bcc627e%7C72f988bf86f141af91ab2d7cd011db47%7C1%7C0%7C637008436963151044=FYlNmnA95zbmhNFZhvXP25yq1tda%2BCBeUi4Kv5S1Odo%3D=0> >> ___ >> OAuth mailing list >> OAuth@ietf.org >> https://www.ietf.org/mailman/listinfo/oauth >> <https://nam06.safelinks.protection.outlook.com/?url=https%3A%2F%2Fwww..ietf.org%2Fmailman%2Flistinfo%2Foauth=02%7C01%7Ctonynad%40microsoft..com%7Cc992681cd6294582fb4308d71bcc627e%7C72f988bf86f141af91ab2d7cd011db47%7C1%7C0%7C637008436963161034=b6bcRyetTMClfOwwsk2PXfRF75c04kg0gHfVPagMLrw%3D=0> >> >> > ___ > OAuth mailing list > OAuth@ietf.org > https://www.ietf.org/mailman/listinfo/oauth > -- Vennlig hilsen Steinar Noem Partner Udelt AS Systemutvikler | stei...@udelt.no | h...@udelt.no | +47 955 21 620 | www.udelt.no | ___ OAuth mailing list OAuth@ietf.org https://www.ietf.org/mailman/listinfo/oauth

Re: [OAUTH-WG] Transaction Authorization with OAuth

2019-04-26 Thread Steinar Noem
ENTIALITY NOTICE: This email may contain confidential and > privileged material for the sole use of the intended recipient(s). Any > review, use, distribution or disclosure by others is strictly prohibited.. > If you have received this communication in error, please notify the sender > i

Re: [OAUTH-WG] Transaction Authorization with OAuth

2019-04-23 Thread Steinar Noem
hopefully signatures will be sufficient.. - S man. 22. apr. 2019 kl. 18:29 skrev Torsten Lodderstedt < tors...@lodderstedt.net>: > HI Steinar, > > > On 22. Apr 2019, at 10:38, Steinar Noem wrote: > > > > Hi Torsten, thank you for writing this clarifying article :) > >

Re: [OAUTH-WG] Transaction Authorization with OAuth

2019-04-22 Thread Steinar Noem
-why-we-need-to-re-think-oauth-scopes-2326e2038948 > > > I look forward to getting your feedback. > > kind regards, > Torsten. > ___ > OAuth mailing list > OAuth@ietf.org > https://www.ietf.org/mailman/listinfo/oauth

Re: [OAUTH-WG] draft-bertocci-oauth-access-token-jwt-00

2019-03-26 Thread Steinar Noem
oop feedback and >>>>incorporate new ideas. John Bradley, Brian Campbell Vladimir Dzhuvinov, >>>>Torsten Lodderstedt, Nat Sakimura, Hannes Tschofenig were all there >>>>and contributed generously to the discussion. Thank you!!! >>>> Note: