Re: [Gen-art] Gen-ART Last Call review of draft-ietf-oauth-dyn-reg-24

Justin Richer <jricher@mit.edu> Thu, 05 March 2015 12:01 UTC

Return-Path: <jricher@mit.edu>
X-Original-To: gen-art@ietfa.amsl.com
Delivered-To: gen-art@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id D99D71B2C3A for <gen-art@ietfa.amsl.com>; Thu, 5 Mar 2015 04:01:43 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -4.211
X-Spam-Level:
X-Spam-Status: No, score=-4.211 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, RCVD_IN_DNSWL_MED=-2.3, SPF_PASS=-0.001, T_RP_MATCHES_RCVD=-0.01] autolearn=ham
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id DkU-zf60aKmP for <gen-art@ietfa.amsl.com>; Thu, 5 Mar 2015 04:01:39 -0800 (PST)
Received: from dmz-mailsec-scanner-7.mit.edu (dmz-mailsec-scanner-7.mit.edu [18.7.68.36]) (using TLSv1 with cipher DHE-RSA-AES256-SHA (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id F3EC01B2B11 for <gen-art@ietf.org>; Thu, 5 Mar 2015 04:01:38 -0800 (PST)
X-AuditID: 12074424-f79356d000004839-ea-54f845a13a45
Received: from mailhub-auth-3.mit.edu ( [18.9.21.43]) (using TLS with cipher DHE-RSA-AES256-SHA (256/256 bits)) (Client did not present a certificate) by dmz-mailsec-scanner-7.mit.edu (Symantec Messaging Gateway) with SMTP id AC.78.18489.1A548F45; Thu, 5 Mar 2015 07:01:37 -0500 (EST)
Received: from outgoing.mit.edu (outgoing-auth-1.mit.edu [18.9.28.11]) by mailhub-auth-3.mit.edu (8.13.8/8.9.2) with ESMTP id t25C1a7v002616; Thu, 5 Mar 2015 07:01:37 -0500
Received: from [192.168.128.57] (static-96-237-195-53.bstnma.fios.verizon.net [96.237.195.53]) (authenticated bits=0) (User authenticated as jricher@ATHENA.MIT.EDU) by outgoing.mit.edu (8.13.8/8.12.4) with ESMTP id t25C1Ztf017841 (version=TLSv1/SSLv3 cipher=DHE-RSA-AES128-SHA bits=128 verify=NOT); Thu, 5 Mar 2015 07:01:36 -0500
Message-ID: <54F84598.1060703@mit.edu>
Date: Thu, 05 Mar 2015 07:01:28 -0500
From: Justin Richer <jricher@mit.edu>
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; rv:31.0) Gecko/20100101 Thunderbird/31.5.0
MIME-Version: 1.0
To: Brian E Carpenter <brian.e.carpenter@gmail.com>, draft-ietf-oauth-dyn-reg.all@tools.ietf.org, General Area Review Team <gen-art@ietf.org>
References: <54F7D899.6090900@gmail.com>
In-Reply-To: <54F7D899.6090900@gmail.com>
Content-Type: text/plain; charset="utf-8"; format="flowed"
Content-Transfer-Encoding: 7bit
X-Brightmail-Tracker: H4sIAAAAAAAAA+NgFvrOIsWRmVeSWpSXmKPExsUixCmqrbvQ9UeIwfJ5RhZtF/cxWUxf/JDZ 4uqrzywOzB47Z91l91iy5CeTx5fLn9kCmKO4bFJSczLLUov07RK4Mp5ePcpYsJy/4tbXfrYG xgaeLkZODgkBE4lnW06wQthiEhfurWfrYuTiEBJYzCTxZWkXK4SzgVHi9NIlUJlbTBKn+zuY QVp4BdQkLh9sB7NZBFQlXi58wQhiswHZ09e0MIHYogJREj1/utkg6gUlTs58wgIySERgPqPE s907WEASwgIuEmt2PwdrFhLQkNh16h5QnIODU0BTouEt2HxmATOJeZsfQtnyEtvfzmGewCgw C8nYWUjKZiEpW8DIvIpRNiW3Sjc3MTOnODVZtzg5MS8vtUjXXC83s0QvNaV0EyMofNldVHYw Nh9SOsQowMGoxMM7Y+P3ECHWxLLiytxDjJIcTEqivMHGP0KE+JLyUyozEosz4otKc1KLDzFK cDArifDmawHleFMSK6tSi/JhUtIcLErivJt+8IUICaQnlqRmp6YWpBbBZGU4OJQkeKNcgBoF i1LTUyvSMnNKENJMHJwgw3mAhjeB1PAWFyTmFmemQ+RPMSpKifO2gSQEQBIZpXlwvbD08opR HOgVYd7/IFU8wNQE1/0KaDAT0GAtMbDBJYkIKakGRg3r5rsb09a/dFtV5PVm12fDPbmsRwNN J1cu/jzv9PdJpww3J1/2suOwzZ0qctE+qiw094THStMc9ZmPv03V+nkn4swN16uXO9xX/KwU tbT3SZJruWX5/fcTmQ1rlSbf+Ol1S2OuzkfbNjsVL4P00u5bi7PatHIt82ImJpQlJO0Q+td6 4h/zDSWW4oxEQy3mouJEAPzu4pEKAwAA
Archived-At: <http://mailarchive.ietf.org/arch/msg/gen-art/r5F5SYyeB38U45NoVAIphRq4_wI>
X-Mailman-Approved-At: Thu, 05 Mar 2015 04:19:46 -0800
Subject: Re: [Gen-art] Gen-ART Last Call review of draft-ietf-oauth-dyn-reg-24
X-BeenThere: gen-art@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: "GEN-ART: General Area Review Team" <gen-art.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/gen-art>, <mailto:gen-art-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/gen-art/>
List-Post: <mailto:gen-art@ietf.org>
List-Help: <mailto:gen-art-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/gen-art>, <mailto:gen-art-request@ietf.org?subject=subscribe>
X-List-Received-Date: Thu, 05 Mar 2015 12:01:44 -0000

All very good points, thank you for the review. We'll incorporate these 
into the next draft.

  -- Justin

On 3/4/2015 11:16 PM, Brian E Carpenter wrote:
> I am the assigned Gen-ART reviewer for this draft. For background on
> Gen-ART, please see the FAQ at
> <http://wiki.tools.ietf.org/area/gen/trac/wiki/GenArtfaq>.
>
> Please resolve these comments along with any other Last Call comments
> you may receive.
>
> Document: draft-ietf-oauth-dyn-reg-24.txt
> Reviewer: Brian Carpenter
> Review Date: 2015-03-05
> IETF LC End Date: 2015-03-16
> IESG Telechat date:
>
> Summary: Almost ready
> --------
>
> Issues:
> -------
>
>> 2.  Client Metadata
>>    ...
>>    The following client metadata fields are defined by this
>>    specification.
>>    ...
>>    ...
>>    Extensions and profiles of this specification MAY expand this list.
> That definitely needs a forward reference to the IANA Considerations.
> I don't think it's an RFC 2119 MAY, so it should read something like
>
>    Extensions and profiles of this specification may expand this list
>    with metadata names registered in accordance with the IANA Considerations
>    in Section 4 of this document.
>
>>    The authorization server MUST ignore any client metadata values sent
>>    by the client that it does not understand.
> Silently, or with an error report?
>
>> 4.  IANA Considerations
>>
>> 4.1.  OAuth Dynamic Registration Client Metadata Registry
>>
>>    This specification establishes the OAuth Dynamic Registration Client
>>    Metadata registry.
>>
>>    OAuth registration client metadata values are registered with a
>>    Specification Required ...
> This may be a nit but it confused me; surely it isn't metadata *values*
> that are registered; it's metadata names and descriptions?
>
> Nit:
> ----
>
> I expected a reference, presumably [RFC6749], at the first mention
> of OAuth 2.0 (in the first sentence).