Re: [OAUTH-WG] Shepherd writeup for OAuth 2.0 Authorization Server Metadata

Hannes Tschofenig <hannes.tschofenig@gmx.net> Tue, 07 March 2017 19:07 UTC

Return-Path: <hannes.tschofenig@gmx.net>
X-Original-To: oauth@ietfa.amsl.com
Delivered-To: oauth@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 045EB129490 for <oauth@ietfa.amsl.com>; Tue, 7 Mar 2017 11:07:21 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.601
X-Spam-Level:
X-Spam-Status: No, score=-2.601 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, FREEMAIL_FROM=0.001, RCVD_IN_DNSWL_LOW=-0.7, RCVD_IN_MSPIKE_H2=-0.001, RP_MATCHES_RCVD=-0.001, SPF_PASS=-0.001, URIBL_BLOCKED=0.001] autolearn=ham autolearn_force=no
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id kcSXoxH7HYbQ for <oauth@ietfa.amsl.com>; Tue, 7 Mar 2017 11:07:14 -0800 (PST)
Received: from mout.gmx.net (mout.gmx.net [212.227.15.15]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 8DBF412949F for <oauth@ietf.org>; Tue, 7 Mar 2017 11:07:13 -0800 (PST)
Received: from [192.168.91.177] ([80.92.114.23]) by mail.gmx.com (mrgmx001 [212.227.17.190]) with ESMTPSA (Nemesis) id 0MRGTX-1cq78B3XbD-00UZBs; Tue, 07 Mar 2017 20:07:05 +0100
To: Mike Jones <Michael.Jones@microsoft.com>, "oauth@ietf.org" <oauth@ietf.org>, Phil Hunt <phil.hunt@oracle.com>
References: <70253643-d036-e333-f94d-597039206777@gmx.net> <CY4PR21MB0504CEE31B03DDEDEB50B79DF52F0@CY4PR21MB0504.namprd21.prod.outlook.com>
From: Hannes Tschofenig <hannes.tschofenig@gmx.net>
Openpgp: id=071A97A9ECBADCA8E31E678554D9CEEF4D776BC9
Message-ID: <fe5beedf-1f2e-cf15-f70d-361edacb47e7@gmx.net>
Date: Tue, 07 Mar 2017 20:07:03 +0100
User-Agent: Mozilla/5.0 (X11; Linux x86_64; rv:45.0) Gecko/20100101 Thunderbird/45.7.0
MIME-Version: 1.0
In-Reply-To: <CY4PR21MB0504CEE31B03DDEDEB50B79DF52F0@CY4PR21MB0504.namprd21.prod.outlook.com>
Content-Type: multipart/signed; micalg="pgp-sha512"; protocol="application/pgp-signature"; boundary="IQgdUcC3KBS3JJOoCm7UGa2Ir2a7b8SSn"
X-Provags-ID: V03:K0:37AjLeq0nz/nvK5fG8ALi8/2P0b2qcNDI9IXRRiksKxfRKxNSp3 di+He0gJ41ssmT3lSh621/SRJKp5jetqq4xZE1FlJWU90dnnE868hHyCVPrToAFeD1s7c/l HCOheGOj4NgS6HmPJa3Qm+WI7V1hJj1gfdDDSEjzpIqi0MSdyChSn3zm91iinEMg604MAWJ i2EkbrkVyAZv5KaMwrmpw==
X-UI-Out-Filterresults: notjunk:1;V01:K0:Ff0v/WrYgbA=:SrOTcI5VA7flZ+ChTVuZv5 A4RPpAq5BgCkvCN0kYwKBhfJJDyF033L21KEe6LQT+y+k61cStVaawlKdteJgqLMyaFBeqMpj /gJODt2DsFY4XdHNc4mkSen7JWt6I4jzbODWOyAoQrFC0KVLMASg29Lg8Y3a1lxNUYA4cfVhn UKCKHtNPPIUh9h3iWtfh1j+K2ZGmfTMDo4l4pBKKtUBk2iSv53wZrlV1K7Gy3LlkiXMVZBSiA aZsC/JLIMROWHGrYk7rL+XQFByMCYS9z5Ob0M+f5sLeN1zuL7v/2dcOg2INNdc10u/hH/wzpF F41ss1XXjsnGDa2aIkyt7I2ju/v1I9HJWs5O6KmCMCErppPHZnRZutqz9+yfSQFBHk8iRimkR rdjwGJ0iK3X7JeOtiTqKoikT4fLNWTS7ARCcrFi+ST6SdyjXPOaaV9dxGvf+L4g7FsL2zDGhC z7UBMlNBJG+VSllxAQN4cB0kSaPq+fngdxE9SC82TIOYXERHJjUt9rHBnq+NO2K+Zt5CTGmEw fMSmCP7RWqf0Q1b0SJBmw16Z1RWi43biy1hhWxeenDa5RkXNcC1K2D3xNmdrBl8Mcf5hMmL8/ aWgYyBe/MFj4AIq1H4napqDYn93OhTVcmYOGhC1EGXlL1LvH0wbJo9qau9jqP47nSwyLwnur/ xWfEwDOMBcnXkBwHt79atOaOh+c0ptoZiogE/68LkOtXywbrCVFclHsHxbyWDUQMHAqnqT9TE t+AozHhdOLBUflnH/LH31GmCfJoZ9up6b3c03vBhzODVN6m5J9DG7YFCDK0=
Archived-At: <https://mailarchive.ietf.org/arch/msg/oauth/6UqpkO5xk5_g9cyhgt63pNizty0>
Subject: Re: [OAUTH-WG] Shepherd writeup for OAuth 2.0 Authorization Server Metadata
X-BeenThere: oauth@ietf.org
X-Mailman-Version: 2.1.17
Precedence: list
List-Id: OAUTH WG <oauth.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/oauth>, <mailto:oauth-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/oauth/>
List-Post: <mailto:oauth@ietf.org>
List-Help: <mailto:oauth-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/oauth>, <mailto:oauth-request@ietf.org?subject=subscribe>
X-List-Received-Date: Tue, 07 Mar 2017 19:07:21 -0000

Hi Mike

thanks for the quick response and for the wording suggestions.

Regarding the implementations are OpenID Connect implementations
required to implement this functionality?

On 03/07/2017 07:58 PM, Mike Jones wrote:
> 1) Implementation & deployment status of the spec
> 
> Microsoft has at least four deployments of the specification.
> William Denniss has said that Google uses the specification.  I
> believe that Ping Identity also uses it.  The specification is used
> by https://tools.ietf.org/html/draft-ietf-oauth-token-binding-01 and
> https://tools.ietf.org/html/draft-ietf-oauth-device-flow-04.

Ciao
Hannes