Re: [OAUTH-WG] Call for adoption: JWT Usage in OAuth2 Access Tokens

Neil Madden <neil.madden@forgerock.com> Tue, 09 April 2019 08:43 UTC

Return-Path: <neil.madden@forgerock.com>
X-Original-To: oauth@ietfa.amsl.com
Delivered-To: oauth@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 0CCBA120779 for <oauth@ietfa.amsl.com>; Tue, 9 Apr 2019 01:43:15 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2
X-Spam-Level:
X-Spam-Status: No, score=-2 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, RCVD_IN_DNSWL_NONE=-0.0001, SPF_PASS=-0.001, URIBL_BLOCKED=0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (1024-bit key) header.d=forgerock.com
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id xHmHGfa7r6wZ for <oauth@ietfa.amsl.com>; Tue, 9 Apr 2019 01:43:12 -0700 (PDT)
Received: from mail-ed1-x529.google.com (mail-ed1-x529.google.com [IPv6:2a00:1450:4864:20::529]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id C75C4120789 for <oauth@ietf.org>; Tue, 9 Apr 2019 01:43:11 -0700 (PDT)
Received: by mail-ed1-x529.google.com with SMTP id d1so14127372edd.13 for <oauth@ietf.org>; Tue, 09 Apr 2019 01:43:11 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=forgerock.com; s=google; h=mime-version:subject:from:in-reply-to:date:cc :content-transfer-encoding:message-id:references:to; bh=/2pzpomSjSL6a5eaonmVQjzi81h1itLpurW5rNautuQ=; b=Lijrit4Xpbph8ZraCwq/AF3w8kb6fdENP4jFcCvbfR2431CgkZTY0dfxB5ACDPpfVN 2D8kJCnkLDoahUW/LUJuLgXNSCNA063r4MCDhTaTExl+lCunsyaBafcATq06FmChU5s4 8Vmr1NyfTS5qvjgjdjifzp1lTqqgKQyx2rq40=
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20161025; h=x-gm-message-state:mime-version:subject:from:in-reply-to:date:cc :content-transfer-encoding:message-id:references:to; bh=/2pzpomSjSL6a5eaonmVQjzi81h1itLpurW5rNautuQ=; b=eAmlt7HcM3bfTMjStFNNIy0MArnoUikHvQM9MixWxqe57yhaDfVuZu8HdXmY7FOlS7 md8mLPVJw4DjUtey6TENpteMqMtpB2mkGHVu/o9YNLCo9BpphdN74BNOh4w0rWweS9e8 XEy4iMneHUQXFcEyv02HnemRV5/ItMz8KRVf7tMajAQ++5xGYv1GRJUcITNe7n2U00X9 r37dQK4GsHtV4z0xwsPexSWVTJRtk4l1gyUXqFRAGKsDAv+OnukKQ7182dhVd9el+AJj RrYTCtNyLE91HNq78QntG3OQEm9poMTq4kVDFcldcBDjpR1AeAtdv8fcaxHYvPmn4V0X YGow==
X-Gm-Message-State: APjAAAWGZ6FFLy6HOjyV2QkdRIp06u6mJxpzFf1CMj8k23798Phc2iB4 Q006hMcqFJhcTKv+W+ypDBTEJlnT/aI=
X-Google-Smtp-Source: APXvYqxUwrHfq7tM6b8G2F1U7jiydi6f+9S5w8IOYJdIwl63YQS0FCBOCs32OMVB0HG0VMADBrOw7Q==
X-Received: by 2002:a17:906:498b:: with SMTP id p11mr20025345eju.119.1554799390097; Tue, 09 Apr 2019 01:43:10 -0700 (PDT)
Received: from [192.168.2.118] (77-44-110-214.xdsl.murphx.net. [77.44.110.214]) by smtp.gmail.com with ESMTPSA id l22sm5817974eja.67.2019.04.09.01.43.08 (version=TLS1_2 cipher=ECDHE-RSA-AES128-GCM-SHA256 bits=128/128); Tue, 09 Apr 2019 01:43:09 -0700 (PDT)
Content-Type: text/plain; charset="utf-8"
Mime-Version: 1.0 (Mac OS X Mail 12.2 \(3445.102.3\))
From: Neil Madden <neil.madden@forgerock.com>
In-Reply-To: <AM6PR08MB36861CE2351D6922D5F8F91FFA2C0@AM6PR08MB3686.eurprd08.prod.outlook.com>
Date: Tue, 09 Apr 2019 09:43:07 +0100
Cc: "oauth@ietf.org" <oauth@ietf.org>
Content-Transfer-Encoding: quoted-printable
Message-Id: <E7C5B628-A305-4048-AA54-19DA0B92A284@forgerock.com>
References: <AM6PR08MB36861CE2351D6922D5F8F91FFA2C0@AM6PR08MB3686.eurprd08.prod.outlook.com>
To: Hannes Tschofenig <Hannes.Tschofenig@arm.com>
X-Mailer: Apple Mail (2.3445.102.3)
Archived-At: <https://mailarchive.ietf.org/arch/msg/oauth/0JUIBv4hjL0BM3Tgbp4N8aA_KqQ>
Subject: Re: [OAUTH-WG] Call for adoption: JWT Usage in OAuth2 Access Tokens
X-BeenThere: oauth@ietf.org
X-Mailman-Version: 2.1.29
Precedence: list
List-Id: OAUTH WG <oauth.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/oauth>, <mailto:oauth-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/oauth/>
List-Post: <mailto:oauth@ietf.org>
List-Help: <mailto:oauth-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/oauth>, <mailto:oauth-request@ietf.org?subject=subscribe>
X-List-Received-Date: Tue, 09 Apr 2019 08:43:20 -0000

I support adoption of this draft.

— Neil

> On 8 Apr 2019, at 18:07, Hannes Tschofenig <Hannes.Tschofenig@arm.com> wrote:
> 
> Hi all,
> 
> this is the call for adoption of the 'JWT Usage in OAuth2 Access Tokens'  document following the positive feedback at the last IETF meeting in Prague.
> 
> Here is the document:
> https://tools.ietf.org/html/draft-bertocci-oauth-access-token-jwt-00
> 
> Please let us know by April 22nd whether you accept / object to the
> adoption of this document as a starting point for work in the OAuth
> working group.
> 
> Ciao
> Hannes & Rifaat
> 
> IMPORTANT NOTICE: The contents of this email and any attachments are confidential and may also be privileged. If you are not the intended recipient, please notify the sender immediately and do not disclose the contents to any other person, use it for any purpose, or store or copy the information in any medium. Thank you.
> 
> _______________________________________________
> OAuth mailing list
> OAuth@ietf.org
> https://www.ietf.org/mailman/listinfo/oauth