Re: [OAUTH-WG] Shepherd Writeup for draft-ietf-oauth-spop-06.txt

torsten@lodderstedt.net Wed, 18 February 2015 13:16 UTC

Return-Path: <torsten@lodderstedt.net>
X-Original-To: oauth@ietfa.amsl.com
Delivered-To: oauth@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id A9EDD1A1ACC for <oauth@ietfa.amsl.com>; Wed, 18 Feb 2015 05:16:11 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.552
X-Spam-Level:
X-Spam-Status: No, score=-1.552 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, HELO_EQ_DE=0.35, RCVD_IN_DNSWL_NONE=-0.0001, SPF_HELO_PASS=-0.001, SPF_PASS=-0.001] autolearn=no
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id K5PEsNWIQS6K for <oauth@ietfa.amsl.com>; Wed, 18 Feb 2015 05:16:04 -0800 (PST)
Received: from smtprelay03.ispgateway.de (smtprelay03.ispgateway.de [80.67.31.37]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 83D921A1A9A for <oauth@ietf.org>; Wed, 18 Feb 2015 05:16:04 -0800 (PST)
Received: from [80.67.16.136] (helo=webmail.df.eu) by smtprelay03.ispgateway.de with esmtpa (Exim 4.84) (envelope-from <torsten@lodderstedt.net>) id 1YO4Ty-0004Jh-RZ; Wed, 18 Feb 2015 14:16:02 +0100
MIME-Version: 1.0
Content-Type: text/plain; charset="US-ASCII"; format="flowed"
Content-Transfer-Encoding: 7bit
Date: Wed, 18 Feb 2015 14:16:02 +0100
From: torsten@lodderstedt.net
To: Hannes Tschofenig <hannes.tschofenig@gmx.net>
In-Reply-To: <54E370F9.8060209@gmx.net>
References: <54C7BBA4.4030702@gmx.net> <CA+k3eCQCPiAR0s1cX5mC=h2O-5ptVTVq6=cVKHFKu_Adq8bJTg@mail.gmail.com> <2E3D2EE7-8F5F-452D-880A-D62A513AC853@lodderstedt.net> <54E370F9.8060209@gmx.net>
Message-ID: <17faabb6e724fb54f3cb8060a3d9cb08@lodderstedt.net>
X-Sender: torsten@lodderstedt.net
User-Agent: Roundcube Webmail
X-Df-Sender: dG9yc3RlbkBsb2RkZXJzdGVkdC5uZXQ=
Archived-At: <http://mailarchive.ietf.org/arch/msg/oauth/6ZHyVBCX91YTDFs8LTnZiztR3g8>
Cc: oauth@ietf.org, "naa@google.com >> Naveen Agarwal" <naa@google.com>
Subject: Re: [OAUTH-WG] Shepherd Writeup for draft-ietf-oauth-spop-06.txt
X-BeenThere: oauth@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: OAUTH WG <oauth.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/oauth>, <mailto:oauth-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/oauth/>
List-Post: <mailto:oauth@ietf.org>
List-Help: <mailto:oauth-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/oauth>, <mailto:oauth-request@ietf.org?subject=subscribe>
X-List-Received-Date: Wed, 18 Feb 2015 13:16:11 -0000

Hi Hannes,

our implementation supports the "plain" mode only. We just verified 
compliance of our implementation with the current spec. As the only 
deviation, we do not enforce the minimum length of 43 characters of the 
code verifier.

kind regards,
Torsten.

Am 17.02.2015 17:48, schrieb Hannes Tschofenig:
> Hi Torsten,
> 
> does this mean that your implementation is not compliant with the
> current version anymore or that you haven't had time to verify whether
> there are differences to the earlier version?
> 
> Ciao
> Hannes
> 
> 
> On 01/31/2015 05:34 PM, Torsten Lodderstedt wrote:
>> Deutsche Telekom also implemented an early version of the draft last 
>> year.
>> 
>> 
>> 
>> Am 30.01.2015 um 18:50 schrieb Brian Campbell
>> <bcampbell@pingidentity.com <mailto:bcampbell@pingidentity.com>>:
>> 
>>> 
>>> On Tue, Jan 27, 2015 at 9:24 AM, Hannes Tschofenig
>>> <hannes.tschofenig@gmx.net <mailto:hannes.tschofenig@gmx.net>> wrote:
>>> 
>>> 
>>>     1) What implementations of the spec are you aware of?
>>> 
>>> 
>>> We have an AS side implementation of an earlier draft that was
>>> released in June of last year:
>>> http://documentation.pingidentity.com/pages/viewpage.action?pageId=26706844
>>> _______________________________________________
>>> OAuth mailing list
>>> OAuth@ietf.org <mailto:OAuth@ietf.org>
>>> https://www.ietf.org/mailman/listinfo/oauth