Return-Path: <eran@hueniverse.com>
X-Original-To: oauth@core3.amsl.com
Delivered-To: oauth@core3.amsl.com
Received: from localhost (localhost [127.0.0.1]) by core3.amsl.com (Postfix)
 with ESMTP id 858263A6918 for <oauth@core3.amsl.com>;
 Mon, 27 Sep 2010 21:42:13 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.492
X-Spam-Level: 
X-Spam-Status: No, score=-2.492 tagged_above=-999 required=5 tests=[AWL=0.106,
 BAYES_00=-2.599, HTML_MESSAGE=0.001]
Received: from mail.ietf.org ([64.170.98.32]) by localhost (core3.amsl.com
 [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id meSKEwXp4kRb for
 <oauth@core3.amsl.com>; Mon, 27 Sep 2010 21:42:09 -0700 (PDT)
Received: from p3plex1out01.prod.phx3.secureserver.net
 (p3plex1out01.prod.phx3.secureserver.net [72.167.180.17]) by core3.amsl.com
 (Postfix) with SMTP id CF9DE3A6C30 for <oauth@ietf.org>;
 Mon, 27 Sep 2010 21:42:08 -0700 (PDT)
Received: (qmail 824 invoked from network); 28 Sep 2010 04:42:47 -0000
Received: from unknown (HELO smtp.ex1.secureserver.net) (72.167.180.21) by
 p3plex1out01.prod.phx3.secureserver.net with SMTP; 28 Sep 2010 04:42:47 -0000
Received: from P3PW5EX1MB01.EX1.SECURESERVER.NET ([10.6.135.20]) by
 P3PW5EX1HT003.EX1.SECURESERVER.NET ([72.167.180.21]) with mapi;
 Mon, 27 Sep 2010 21:42:48 -0700
From: Eran Hammer-Lahav <eran@hueniverse.com>
To: Lukas Rosenstock <lr@lukasrosenstock.net>
Date: Mon, 27 Sep 2010 21:42:52 -0700
Thread-Topic: [OAUTH-WG] Document Management Issue (Signatures)
Thread-Index: ActejPaEa2GxTh9KSfmVuA3qtdceCgAOoVbA
Message-ID: <90C41DD21FB7C64BB94121FBBC2E72343D460DB5B3@P3PW5EX1MB01.EX1.SECURESERVER.NET>
References: <3D3C75174CB95F42AD6BCC56E5555B45031BA596@FIESEXC015.nsn-intra.net>
 <DB4FC8C2-816C-4527-8EC4-BC22B171B34C@oracle.com>
 <90C41DD21FB7C64BB94121FBBC2E72343D460DB374@P3PW5EX1MB01.EX1.SECURESERVER.NET>
 <AANLkTim-5hYzBqzXYK=qZaK3HXiLyzE5XqFAJuPCYo5S@mail.gmail.com>
In-Reply-To: <AANLkTim-5hYzBqzXYK=qZaK3HXiLyzE5XqFAJuPCYo5S@mail.gmail.com>
Accept-Language: en-US
Content-Language: en-US
X-MS-Has-Attach: 
X-MS-TNEF-Correlator: 
acceptlanguage: en-US
Content-Type: multipart/alternative;
 boundary="_000_90C41DD21FB7C64BB94121FBBC2E72343D460DB5B3P3PW5EX1MB01E_"
MIME-Version: 1.0
Cc: "oauth@ietf.org" <oauth@ietf.org>
Subject: Re: [OAUTH-WG] Document Management Issue (Signatures)
X-BeenThere: oauth@ietf.org
X-Mailman-Version: 2.1.9
Precedence: list
List-Id: OAUTH WG <oauth.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/listinfo/oauth>,
 <mailto:oauth-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/oauth>
List-Post: <mailto:oauth@ietf.org>
List-Help: <mailto:oauth-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/oauth>,
 <mailto:oauth-request@ietf.org?subject=subscribe>
X-List-Received-Date: Tue, 28 Sep 2010 04:42:13 -0000

--_000_90C41DD21FB7C64BB94121FBBC2E72343D460DB5B3P3PW5EX1MB01E_
Content-Type: text/plain; charset="us-ascii"
Content-Transfer-Encoding: quoted-printable

Maybe, but that's something we actually have wide consensus that is not nee=
ded. The current draft replaces signatures for obtaining an access token us=
ing other means.

EHL

From: Lukas Rosenstock [mailto:lr@lukasrosenstock.net]
Sent: Monday, September 27, 2010 2:43 PM
To: Eran Hammer-Lahav
Cc: oauth@ietf.org
Subject: Re: [OAUTH-WG] Document Management Issue (Signatures)


2010/9/27 Eran Hammer-Lahav <eran@hueniverse.com<mailto:eran@hueniverse.com=
>>
I would also be happy with the core only dealing with *getting* a token, an=
d moving all text about *using* a token to other documents. This will produ=
ce three parts:


1.       Getting a document

2.       Using bearer tokens

3.       Using cryptographic tokens

Won't there be any scenarios in which signatures are required for getting a=
 token, like in OAuth 1 (the request is signed with the client id/secret)?


--_000_90C41DD21FB7C64BB94121FBBC2E72343D460DB5B3P3PW5EX1MB01E_
Content-Type: text/html; charset="us-ascii"
Content-Transfer-Encoding: quoted-printable

<html xmlns:v=3D"urn:schemas-microsoft-com:vml" xmlns:o=3D"urn:schemas-micr=
osoft-com:office:office" xmlns:w=3D"urn:schemas-microsoft-com:office:word" =
xmlns:m=3D"http://schemas.microsoft.com/office/2004/12/omml" xmlns=3D"http:=
//www.w3.org/TR/REC-html40"><head><META HTTP-EQUIV=3D"Content-Type" CONTENT=
=3D"text/html; charset=3Dus-ascii"><meta name=3DGenerator content=3D"Micros=
oft Word 14 (filtered medium)"><style><!--
/* Font Definitions */
@font-face
	{font-family:Calibri;
	panose-1:2 15 5 2 2 2 4 3 2 4;}
@font-face
	{font-family:Tahoma;
	panose-1:2 11 6 4 3 5 4 4 2 4;}
/* Style Definitions */
p.MsoNormal, li.MsoNormal, div.MsoNormal
	{margin:0in;
	margin-bottom:.0001pt;
	font-size:12.0pt;
	font-family:"Times New Roman","serif";}
a:link, span.MsoHyperlink
	{mso-style-priority:99;
	color:blue;
	text-decoration:underline;}
a:visited, span.MsoHyperlinkFollowed
	{mso-style-priority:99;
	color:purple;
	text-decoration:underline;}
p
	{mso-style-priority:99;
	mso-margin-top-alt:auto;
	margin-right:0in;
	mso-margin-bottom-alt:auto;
	margin-left:0in;
	font-size:12.0pt;
	font-family:"Times New Roman","serif";}
span.EmailStyle18
	{mso-style-type:personal-reply;
	font-family:"Calibri","sans-serif";
	color:#1F497D;}
.MsoChpDefault
	{mso-style-type:export-only;
	font-family:"Calibri","sans-serif";}
@page WordSection1
	{size:8.5in 11.0in;
	margin:1.0in 1.0in 1.0in 1.0in;}
div.WordSection1
	{page:WordSection1;}
--></style><!--[if gte mso 9]><xml>
<o:shapedefaults v:ext=3D"edit" spidmax=3D"1026" />
</xml><![endif]--><!--[if gte mso 9]><xml>
<o:shapelayout v:ext=3D"edit">
<o:idmap v:ext=3D"edit" data=3D"1" />
</o:shapelayout></xml><![endif]--></head><body lang=3DEN-US link=3Dblue vli=
nk=3Dpurple><div class=3DWordSection1><p class=3DMsoNormal><span style=3D'f=
ont-size:11.0pt;font-family:"Calibri","sans-serif";color:#1F497D'>Maybe, bu=
t that&#8217;s something we actually have wide consensus that is not needed=
. The current draft replaces signatures for obtaining an access token using=
 other means.<o:p></o:p></span></p><p class=3DMsoNormal><span style=3D'font=
-size:11.0pt;font-family:"Calibri","sans-serif";color:#1F497D'><o:p>&nbsp;<=
/o:p></span></p><p class=3DMsoNormal><span style=3D'font-size:11.0pt;font-f=
amily:"Calibri","sans-serif";color:#1F497D'>EHL<o:p></o:p></span></p><p cla=
ss=3DMsoNormal><span style=3D'font-size:11.0pt;font-family:"Calibri","sans-=
serif";color:#1F497D'><o:p>&nbsp;</o:p></span></p><div style=3D'border:none=
;border-left:solid blue 1.5pt;padding:0in 0in 0in 4.0pt'><div><div style=3D=
'border:none;border-top:solid #B5C4DF 1.0pt;padding:3.0pt 0in 0in 0in'><p c=
lass=3DMsoNormal><b><span style=3D'font-size:10.0pt;font-family:"Tahoma","s=
ans-serif"'>From:</span></b><span style=3D'font-size:10.0pt;font-family:"Ta=
homa","sans-serif"'> Lukas Rosenstock [mailto:lr@lukasrosenstock.net] <br><=
b>Sent:</b> Monday, September 27, 2010 2:43 PM<br><b>To:</b> Eran Hammer-La=
hav<br><b>Cc:</b> oauth@ietf.org<br><b>Subject:</b> Re: [OAUTH-WG] Document=
 Management Issue (Signatures)<o:p></o:p></span></p></div></div><p class=3D=
MsoNormal><o:p>&nbsp;</o:p></p><p class=3DMsoNormal><o:p>&nbsp;</o:p></p><d=
iv><p class=3DMsoNormal>2010/9/27 Eran Hammer-Lahav &lt;<a href=3D"mailto:e=
ran@hueniverse.com">eran@hueniverse.com</a>&gt;<o:p></o:p></p><div><div><p =
class=3DMsoNormal style=3D'mso-margin-top-alt:auto;mso-margin-bottom-alt:au=
to'><span style=3D'font-size:11.0pt;color:#1F497D'>I would also be happy wi=
th the core only dealing with *<b>getting</b>* a token, and moving all text=
 about *<b>using</b>* a token to other documents. This will produce three p=
arts:</span><o:p></o:p></p><p class=3DMsoNormal style=3D'mso-margin-top-alt=
:auto;mso-margin-bottom-alt:auto'><span style=3D'font-size:11.0pt;color:#1F=
497D'>&nbsp;</span><o:p></o:p></p><p><span style=3D'font-size:11.0pt;color:=
#1F497D'>1.</span><span style=3D'font-size:7.0pt;color:#1F497D'>&nbsp;&nbsp=
;&nbsp;&nbsp;&nbsp;&nbsp; </span><span style=3D'font-size:11.0pt;color:#1F4=
97D'>Getting a document</span><o:p></o:p></p><p><span style=3D'font-size:11=
.0pt;color:#1F497D'>2.</span><span style=3D'font-size:7.0pt;color:#1F497D'>=
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; </span><span style=3D'font-size:11.0pt=
;color:#1F497D'>Using bearer tokens</span><o:p></o:p></p><p><span style=3D'=
font-size:11.0pt;color:#1F497D'>3.</span><span style=3D'font-size:7.0pt;col=
or:#1F497D'>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; </span><span style=3D'font=
-size:11.0pt;color:#1F497D'>Using cryptographic tokens</span><o:p></o:p></p=
></div></div><div><p class=3DMsoNormal><o:p>&nbsp;</o:p></p></div><div><p c=
lass=3DMsoNormal>Won't there be any scenarios in which signatures are requi=
red for getting a token, like in OAuth 1 (the request is signed with the cl=
ient id/secret)?<o:p></o:p></p></div><div><p class=3DMsoNormal><o:p>&nbsp;<=
/o:p></p></div></div></div></div></body></html>=

--_000_90C41DD21FB7C64BB94121FBBC2E72343D460DB5B3P3PW5EX1MB01E_--
