Re: [OAUTH-WG] WGLC on draft-ietf-oauth-mtls-07

2018-03-30 Thread Vivek Biswas
AuthzServer/Backend Server, so that the headers passed are not compromised.   This is a MOST common scenario in a real world. And we don’t want everyone come up with their own names for the header. There should be some kind of standardization around the header names.   Regards Vivek Biswas, CISSP

Re: [OAUTH-WG] About Big Brother and draft-campbell-oauth-resource-indicators-00

2016-11-17 Thread Vivek Biswas
be an absolute URI or a String as well. Regards Vivek Biswas, CISSP Consulting Member, Security Oracle Corporation.   From: Denis [mailto:denis.i...@free.fr] Sent: Tuesday, November 15, 2016 3:50 AM To: oauth@ietf.org Subject: [OAUTH-WG] About Big Brother and draft-campbell-oauth-res

Re: [OAUTH-WG] URGENT: WPAD attack exposes URL contents evenoverHTTPS

2016-07-28 Thread Vivek Biswas
PKCE256 becomes mandatory in that case. PKCE plain is prone to same attack as that of state or none.   Also PKCE256 should generate new code challenge for every Authorization request.   -Vivek Biswas Consulting Member@Security Oracle.   From: ve7...@ve7jtb.com [mailto:ve7...@ve7jtb.com

Re: [OAUTH-WG] RFC 7662 on OAuth 2.0 Token Introspection

2015-10-21 Thread Vivek Biswas
Yes indeed a nice job  . I have one question on the RFC. Not sure where I can submit request for comments. Hence, adding to this email thread In the use-case mentioned belowThe following is a non-normative example response for a token that has been revoked or is otherwise invalid: H

[OAUTH-WG] JWT Token on-behalf of Use case

2015-06-25 Thread Vivek Biswas -T (vibiswas - XORIANT CORPORATION at Cisco)
which denote the On-behalf-of User. For e.g., a Customer Representative trying to create token on behalf of a customer and trying to execute services specific for that specific customer. Regards, Vivek Biswas, [CISSP] Cisco Systems, Inc<http://www.cisco.com/> Bldg. J, San Jose, USA, Phone: +1