Re: [OAUTH-WG] proof-of-possession-02 unencrypted oct JWK in encrypted JWT okay?

2015-08-31 Thread Mike Jones
-- Mike From: John Bradley [mailto:ve7...@ve7jtb.com<mailto:ve7...@ve7jtb.com>] Sent: Tuesday, August 11, 2015 4:05 PM To: Mike Jones Cc: Brian Campbell; oauth Subject: Re: [OAUTH-WG] proof-of-possession-02 unencrypted oct JWK in encrypted JWT okay? OK On Aug 11, 2015, at 12:57 AM, Mik

Re: [OAUTH-WG] proof-of-possession-02 unencrypted oct JWK in encrypted JWT okay?

2015-08-31 Thread Brian Campbell
feedback, Brian! > > > > -- Mike > > > > *From:* John Bradley [mailto:ve7...@ve7jtb.com] > *Sent:* Tuesday, August 11, 2015 4:05 PM > *To:* Mike Jones > *Cc:* Brian Campbell; oauth > *Subject:* Re: [OAUTH-WG] proof-of-possession-02 unencrypted oct JWK in > enc

Re: [OAUTH-WG] proof-of-possession-02 unencrypted oct JWK in encrypted JWT okay?

2015-08-28 Thread Mike Jones
] Sent: Tuesday, August 11, 2015 4:05 PM To: Mike Jones Cc: Brian Campbell; oauth Subject: Re: [OAUTH-WG] proof-of-possession-02 unencrypted oct JWK in encrypted JWT okay? OK On Aug 11, 2015, at 12:57 AM, Mike Jones mailto:michael.jo...@microsoft.com>> wrote: As discussed in the thread “[OAUTH

Re: [OAUTH-WG] proof-of-possession-02 unencrypted oct JWK in encrypted JWT okay?

2015-08-11 Thread John Bradley
Sunday, March 22, 2015 11:41 PM > To: oauth > Subject: [OAUTH-WG] proof-of-possession-02 unencrypted oct JWK in encrypted > JWT okay? > > When the JWT is itself encrypted as a JWE, would it not be reasonable to have > a symmetric key be represented in the cnf claim with the jwk mem

Re: [OAUTH-WG] proof-of-possession-02 unencrypted oct JWK in encrypted JWT okay?

2015-08-11 Thread Brian Campbell
mpbell > *Sent:* Sunday, March 22, 2015 11:41 PM > *To:* oauth > *Subject:* [OAUTH-WG] proof-of-possession-02 unencrypted oct JWK in > encrypted JWT okay? > > > > When the JWT is itself encrypted as a JWE, would it not be reasonable to > have a symmetric key be represented

Re: [OAUTH-WG] proof-of-possession-02 unencrypted oct JWK in encrypted JWT okay?

2015-08-10 Thread Mike Jones
encrypted. This will happen in -04. -- Mike From: OAuth [mailto:oauth-boun...@ietf.org] On Behalf Of Brian Campbell Sent: Sunday, March 22, 2015 11:41 PM To: oauth Subject: [OAUTH-WG] proof-of-possession-02 unencrypted oct JWK in encrypted

[OAUTH-WG] proof-of-possession-02 unencrypted oct JWK in encrypted JWT okay?

2015-03-22 Thread Brian Campbell
When the JWT is itself encrypted as a JWE, would it not be reasonable to have a symmetric key be represented in the cnf claim with the jwk member as an unencrypted JSON Web Key? Is such a possibility left as an exercise to the reader? Or should it be more explicitly allowed or disallowed?