Re: [OAUTH-WG] Call for adoption: OAuth Security Topics

2017-02-20 Thread Hannes Tschofenig
Hi Denis, thanks for your feedback regarding the scope. The scope for this document is limited to the specifications we develop in the IETF OAuth working group. OpenID Connect, UMA, or other specifications need to be dealt with in other SDOs. The document only represents a starting point for wor

Re: [OAUTH-WG] Call for adoption: OAuth Security Topics

2017-02-06 Thread Justin Richer
OpenID Connect is the intellectual property of the OpenID Foundation and it is discussed there. — Justin > On Feb 6, 2017, at 7:30 AM, Denis wrote: > > > The scope of this draft is unclear. The title states: "OAuth Security Topics". > I have some questions: > Does this document intend to cov

Re: [OAUTH-WG] Call for adoption: OAuth Security Topics

2017-02-06 Thread Denis
The scope of this draft is unclear. The title states: "OAuth Security Topics".** I have some questions: * Does this document intend to cover only the OAuth 2.0 delegation protocol (since Justin said that OAuth 2.0 is a delegation protocol) or OpenId Connect as well which is not limited

Re: [OAUTH-WG] Call for adoption: OAuth Security Topics

2017-02-06 Thread Nat Sakimura
A belated +1 On Sat, Feb 4, 2017, 9:08 AM Jim Manico wrote: > I'm just some random idiot am an not in this working group but the work > from > https://tools.ietf.org/html/draft-lodderstedt-oauth-security-topics-00 is > one of the most up to date and useful OAuth security resources every > publis

Re: [OAUTH-WG] Call for adoption: OAuth Security Topics

2017-02-03 Thread Jim Manico
I'm just some random idiot am an not in this working group but the work from https://tools.ietf.org/html/draft-lodderstedt-oauth-security-topics-00 is one of the most up to date and useful OAuth security resources every publis

Re: [OAUTH-WG] Call for adoption: OAuth Security Topics

2017-02-02 Thread Jim Willeke
+! I agree this is needed. -- -jim Jim Willeke On Thu, Feb 2, 2017 at 4:33 PM, John Bradley wrote: > I am in favour of adoption. > > On Feb 2, 2017, at 4:09 AM, Hannes Tschofenig > wrote: > > > > Hi all, > > > > this is the call for adoption of the 'OAuth Security Topics' document > > followin

Re: [OAUTH-WG] Call for adoption: OAuth Security Topics

2017-02-02 Thread Brian Campbell
+ 1 On Thu, Feb 2, 2017 at 12:49 PM, Justin Richer wrote: > +1, it's a good topic and this document is a good starting point. > > -- Justin > > On 2/2/2017 2:09 AM, Hannes Tschofenig wrote: > > Hi all, > > this is the call for adoption of the 'OAuth Security Topics' document > following the pos

Re: [OAUTH-WG] Call for adoption: OAuth Security Topics

2017-02-02 Thread John Bradley
I am in favour of adoption. > On Feb 2, 2017, at 4:09 AM, Hannes Tschofenig > wrote: > > Hi all, > > this is the call for adoption of the 'OAuth Security Topics' document > following the positive call for adoption at the last IETF > meeting in Seoul. > > Here is the document: > https://tools.i

Re: [OAUTH-WG] Call for adoption: OAuth Security Topics

2017-02-02 Thread George Fletcher
+1 for me too :) On 2/2/17 2:09 AM, Hannes Tschofenig wrote: Hi all, this is the call for adoption of the 'OAuth Security Topics' document following the positive call for adoption at the last IETF meeting in Seoul. Here is the document: https://tools.ietf.org/html/draft-lodderstedt-oauth-secur

Re: [OAUTH-WG] Call for adoption: OAuth Security Topics

2017-02-02 Thread Justin Richer
+1, it's a good topic and this document is a good starting point. -- Justin On 2/2/2017 2:09 AM, Hannes Tschofenig wrote: Hi all, this is the call for adoption of the 'OAuth Security Topics' document following the positive call for adoption at the last IETF meeting in Seoul. Here is the doc

Re: [OAUTH-WG] Call for adoption: OAuth Security Topics

2017-02-02 Thread Mike Jones
I support adoption. -- Mike -Original Message- From: OAuth [mailto:oauth-boun...@ietf.org] On Behalf Of Hannes Tschofenig Sent: Wednesday, February 1, 2017 11:10 PM To: oauth@ietf.org Subject: [OAUTH-WG] Call for adoption: OAuth Security Topics Hi all

Re: [OAUTH-WG] Call for adoption: OAuth Security Topics

2017-02-02 Thread Phil Hunt
would be in favor of this > > -Original Message- > From: OAuth [mailto:oauth-boun...@ietf.org] On Behalf Of Hannes Tschofenig > Sent: Wednesday, February 1, 2017 11:10 PM > To: oauth@ietf.org > Subject: [OAUTH-WG] Call for adoption: OAuth Security Topics > > Hi all,

Re: [OAUTH-WG] Call for adoption: OAuth Security Topics

2017-02-02 Thread Anthony Nadalin
I would be in favor of this -Original Message- From: OAuth [mailto:oauth-boun...@ietf.org] On Behalf Of Hannes Tschofenig Sent: Wednesday, February 1, 2017 11:10 PM To: oauth@ietf.org Subject: [OAUTH-WG] Call for adoption: OAuth Security Topics Hi all, this is the call for adoption of

[OAUTH-WG] Call for adoption: OAuth Security Topics

2017-02-01 Thread Hannes Tschofenig
Hi all, this is the call for adoption of the 'OAuth Security Topics' document following the positive call for adoption at the last IETF meeting in Seoul. Here is the document: https://tools.ietf.org/html/draft-lodderstedt-oauth-security-topics-00 The intention with this document is to have a pla