Return-Path: <wmills@yahoo-inc.com>
X-Original-To: oauth@ietfa.amsl.com
Delivered-To: oauth@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix)
 with ESMTP id 4D73521F8880 for <oauth@ietfa.amsl.com>;
 Mon, 12 Dec 2011 17:47:03 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -17.426
X-Spam-Level: 
X-Spam-Status: No, score=-17.426 tagged_above=-999 required=5 tests=[AWL=0.172,
 BAYES_00=-2.599, HTML_MESSAGE=0.001, USER_IN_DEF_WHITELIST=-15]
Received: from mail.ietf.org ([12.22.58.30]) by localhost (ietfa.amsl.com
 [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id 6Q+ytUnqZSUy for
 <oauth@ietfa.amsl.com>; Mon, 12 Dec 2011 17:47:02 -0800 (PST)
Received: from nm15-vm0.bullet.mail.ac4.yahoo.com
 (nm15-vm0.bullet.mail.ac4.yahoo.com [98.139.52.236]) by ietfa.amsl.com
 (Postfix) with SMTP id 40FBB21F84FB for <oauth@ietf.org>;
 Mon, 12 Dec 2011 17:47:02 -0800 (PST)
Received: from [98.139.52.197] by nm15.bullet.mail.ac4.yahoo.com with NNFMP;
 13 Dec 2011 01:46:55 -0000
Received: from [98.139.52.140] by tm10.bullet.mail.ac4.yahoo.com with NNFMP;
 13 Dec 2011 01:46:54 -0000
Received: from [127.0.0.1] by omp1023.mail.ac4.yahoo.com with NNFMP;
 13 Dec 2011 01:46:54 -0000
X-Yahoo-Newman-Property: ymail-3
X-Yahoo-Newman-Id: 947166.72833.bm@omp1023.mail.ac4.yahoo.com
Received: (qmail 98999 invoked by uid 60001); 13 Dec 2011 01:46:54 -0000
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=yahoo-inc.com;
 s=ginc1024; t=1323740814; bh=Tf3rA7FgZ6fzcWPKs0dUbbCYgobvA2QkgTcUHCIKKFQ=;
 h=X-YMail-OSG:Received:X-RocketYMMF:X-Mailer:References:Message-ID:Date:From:Reply-To:Subject:To:In-Reply-To:MIME-Version:Content-Type;
 b=S+I/IeUxD0x8Tlu10CuXeegDAGcRsXV9zetTiSxHWWDw4nDpv+aNFUTzddLQ1zexPV11WqWO5eZxCro35RWJvGOqfSflkyy3lEbuLqgs4XsuIu8/Y5QmYw0B8u+NEItho18/TQsttUHYEeAYkvQ9nAXRmGzdfWnsnDh8Lwi0liE=
DomainKey-Signature: a=rsa-sha1; q=dns; c=nofws; s=ginc1024; d=yahoo-inc.com;
 h=X-YMail-OSG:Received:X-RocketYMMF:X-Mailer:References:Message-ID:Date:From:Reply-To:Subject:To:In-Reply-To:MIME-Version:Content-Type;
 b=V1Yi/mDtNJO5FrqR238mTWkj5Rx1itam4crh0JhtqCkSU+QrYwlcrPqQ6H+fM8aU0tbtPkLMqkDbxGuZoeouDgdoc1LFHFCSR30sZ3lPtXBzj2gB0YXnf95dZX3PmDlkstF+sBFb0B1+yXC0iQ4HMrcQSMg6pNBSKO9zb2jLH20=;
X-YMail-OSG: p96UtzsVM1kas6XakJnkIi2QmSTgrSfQ_KDpni87.eYROE5
 EiyIrpOY58tB5ltG2_OoRtzkIst1jlZUBEvsFf7X8o5e0SB3e6V7XwBmnYEC
 gmCSDhXuikvz97Ca1BiyGF1YBANSqRlamSq8kxXYVY1ZaqJ24xZxxLYc0jd.
 ZRn494mS_e3uZ.d41NY.gijBn5GThpbW5npuIcPaixFACpcGg7E54UIE0A27
 DA7dkpzBMHuOpT8Qs8qn4vLwEjcBX5VhoiHMxymsJK6a_0vT_NzdEsaQHRnf
 r0fy088aNJKGbadvXxxMGBe3drV4AT1FH3FWfsK9jNv67vE7E4VoFOns043F
 7DiZTe5kySu123dPrbDMLELHlr33h2FjHiYfCzYrP4pigu5uuLQwMQSurwTn
 1BgzyRmEVVRmKJ9x1ZsmPHTgj4iLUhtY8jNE-
Received: from [209.131.62.113] by web31816.mail.mud.yahoo.com via HTTP;
 Mon, 12 Dec 2011 17:46:54 PST
X-RocketYMMF: william_john_mills
X-Mailer: YahooMailWebService/0.8.116.331537
References: <8DA2949DB77C2547B14546D35E22A20002D328EC@CH1PRD0302MB127.namprd03.prod.outlook.com>
 <4E1F6AAD24975D4BA5B16804296739435F75FBF7@TK5EX14MBXC283.redmond.corp.microsoft.com>
Message-ID: <1323740814.90630.YahooMailNeo@web31816.mail.mud.yahoo.com>
Date: Mon, 12 Dec 2011 17:46:54 -0800 (PST)
From: William Mills <wmills@yahoo-inc.com>
To: Mike Jones <Michael.Jones@microsoft.com>, "oauth@ietf.org" <oauth@ietf.org>
In-Reply-To: <4E1F6AAD24975D4BA5B16804296739435F75FBF7@TK5EX14MBXC283.redmond.corp.microsoft.com>
MIME-Version: 1.0
Content-Type: multipart/alternative;
 boundary="-1238014912-1519221104-1323740814=:90630"
Subject: Re: [OAUTH-WG] Using OAuth error_code to glean information from the
 server
X-BeenThere: oauth@ietf.org
X-Mailman-Version: 2.1.12
Precedence: list
Reply-To: William Mills <wmills@yahoo-inc.com>
List-Id: OAUTH WG <oauth.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/oauth>,
 <mailto:oauth-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/oauth>
List-Post: <mailto:oauth@ietf.org>
List-Help: <mailto:oauth-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/oauth>,
 <mailto:oauth-request@ietf.org?subject=subscribe>
X-List-Received-Date: Tue, 13 Dec 2011 01:47:03 -0000

---1238014912-1519221104-1323740814=:90630
Content-Type: text/plain; charset=iso-8859-1
Content-Transfer-Encoding: quoted-printable

I don't think the leak of client IDs is a big issue, in any cleartext proto=
col you can just sniff them.=A0 We don't mandate SSL on the protected resou=
rces.=0A=0A=0AAnyone relying on ClientID for a stronger assurance will want=
 to be using SSL and an unguessable ID anyway.=0A=0A=0A=0A_________________=
_______________=0A From: Mike Jones <Michael.Jones@microsoft.com>=0ATo: "oa=
uth@ietf.org" <oauth@ietf.org> =0ASent: Monday, December 12, 2011 4:51 PM=
=0ASubject: [OAUTH-WG] Using OAuth error_code to glean information from the=
 server=0A =0A=0A =0AI recently received an inquiry regarding invalid_clien=
t vs. invalid_grant. =A0It seems that there is a potential information disc=
losure in the specification with respect to how these error codes are used:=
=0A=A0=0Ainvalid_client=0A=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0 Client=
 authentication failed (e.g. unknown client, no=0A=A0=A0=A0=A0=A0=A0=A0=A0=
=A0=A0=A0=A0=A0=A0 client authentication included, or unsupported=0A=A0=A0=
=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0 authentication method).=A0 The authori=
zation server MAY=0A=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0 return an HT=
TP 401 (Unauthorized) status code to indicate=0A=A0=A0=A0=A0=A0=A0=A0=A0=A0=
=A0=A0=A0=A0=A0 which HTTP authentication schemes are supported.=A0 If the=
=0A=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0 client attempted to authentic=
ate via the "Authorization"=0A=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0 re=
quest header field, the authorization server MUST=0A=A0=A0=A0=A0=A0=A0=A0=
=A0=A0=A0=A0=A0=A0=A0 respond with an HTTP 401 (Unauthorized) status code, =
and=0A=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0 include the "WWW-Authentic=
ate" response header field=0A=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0 mat=
ching the authentication scheme used by the client.=0Ainvalid_grant=0A=A0=
=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0 The provided authorization grant (e=
.g. authorization=0A=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0 code, resour=
ce owner credentials, client credentials) is=0A=A0=A0=A0=A0=A0=A0=A0=A0=A0=
=A0=A0=A0=A0=A0 invalid, expired, revoked, does not match the redirection=
=0A=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0 URI used in the authorization=
 request, or was issued to=0A=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0 ano=
ther client.=0A=A0=0AIf one uses invalid_client when the client is unknown =
and invalid_grant when the client credentials are invalid, then an attacker=
 could deduce whether or not a particular client exists.=0A=A0=0AFirst, do =
people agree that this is a potential information leak and that the leak is=
 meaningful?=A0 If so, what mitigation might be suggested?=A0 For instance,=
 might a server choose to use a single error code for both (and potentially=
 other) cases?=0A=A0=0A=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=
=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=
=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0 Thanks,=0A=A0=A0=A0=A0=
=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=
=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=
=A0=A0=A0=A0=A0 -- Mike=0A=A0=0A___________________________________________=
____=0AOAuth mailing list=0AOAuth@ietf.org=0Ahttps://www.ietf.org/mailman/l=
istinfo/oauth
---1238014912-1519221104-1323740814=:90630
Content-Type: text/html; charset=iso-8859-1
Content-Transfer-Encoding: quoted-printable

<html><body><div style=3D"color:#000; background-color:#fff; font-family:Co=
urier New, courier, monaco, monospace, sans-serif;font-size:14pt"><div><spa=
n>I don't think the leak of client IDs is a big issue, in any cleartext pro=
tocol you can just sniff them.&nbsp; We don't mandate SSL on the protected =
resources.<br></span></div><div><span><br></span></div><div><span>Anyone re=
lying on ClientID for a stronger assurance will want to be using SSL and an=
 unguessable ID anyway.<br></span></div><div><br></div>  <div style=3D"font=
-family: Courier New, courier, monaco, monospace, sans-serif; font-size: 14=
pt;"> <div style=3D"font-family: times new roman, new york, times, serif; f=
ont-size: 12pt;"> <font face=3D"Arial" size=3D"2"> <hr size=3D"1">  <b><spa=
n style=3D"font-weight:bold;">From:</span></b> Mike Jones &lt;Michael.Jones=
@microsoft.com&gt;<br> <b><span style=3D"font-weight: bold;">To:</span></b>=
 "oauth@ietf.org" &lt;oauth@ietf.org&gt; <br> <b><span style=3D"font-weight=
:
 bold;">Sent:</span></b> Monday, December 12, 2011 4:51 PM<br> <b><span sty=
le=3D"font-weight: bold;">Subject:</span></b> [OAUTH-WG] Using OAuth error_=
code to glean information from the server<br> </font> <br>=0A<div id=3D"yiv=
999268650">=0A=0A =0A =0A<style><!--=0A#yiv999268650  =0A _filtered #yiv999=
268650 {font-family:Calibri;panose-1:2 15 5 2 2 2 4 3 2 4;}=0A _filtered #y=
iv999268650 {font-family:Tahoma;panose-1:2 11 6 4 3 5 4 4 2 4;}=0A _filtere=
d #yiv999268650 {font-family:"Segoe UI";panose-1:2 11 5 2 4 2 4 2 2 3;}=0A#=
yiv999268650  =0A#yiv999268650 p.yiv999268650MsoNormal, #yiv999268650 li.yi=
v999268650MsoNormal, #yiv999268650 div.yiv999268650MsoNormal=0A=09{margin:0=
in;margin-bottom:.0001pt;font-size:12.0pt;font-family:"serif";}=0A#yiv99926=
8650 a:link, #yiv999268650 span.yiv999268650MsoHyperlink=0A=09{color:blue;t=
ext-decoration:underline;}=0A#yiv999268650 a:visited, #yiv999268650 span.yi=
v999268650MsoHyperlinkFollowed=0A=09{color:purple;text-decoration:underline=
;}=0A#yiv999268650 p=0A=09{margin-top:0in;margin-right:0in;margin-bottom:3.=
0pt;margin-left:0in;font-size:12.0pt;font-family:"sans-serif";}=0A#yiv99926=
8650 pre=0A=09{margin:0in;margin-bottom:.0001pt;font-size:10.0pt;font-famil=
y:"Courier New";}=0A#yiv999268650 p.yiv999268650MsoAcetate, #yiv999268650 l=
i.yiv999268650MsoAcetate, #yiv999268650 div.yiv999268650MsoAcetate=0A=09{ma=
rgin:0in;margin-bottom:.0001pt;font-size:8.0pt;font-family:"sans-serif";}=
=0A#yiv999268650 span.yiv999268650HTMLPreformattedChar=0A=09{font-family:"C=
ourier New";}=0A#yiv999268650 span.yiv999268650BalloonTextChar=0A=09{font-f=
amily:"sans-serif";}=0A#yiv999268650 span.yiv999268650EmailStyle22=0A=09{fo=
nt-family:"sans-serif";}=0A#yiv999268650 span.yiv999268650EmailStyle23=0A=
=09{font-family:"sans-serif";color:#1F497D;}=0A#yiv999268650 span.yiv999268=
650EmailStyle24=0A=09{font-family:"sans-serif";color:#1F497D;}=0A#yiv999268=
650 span.yiv999268650EmailStyle25=0A=09{font-family:"sans-serif";color:#993=
366;}=0A#yiv999268650 span.yiv999268650grey=0A=09{}=0A#yiv999268650 span.yi=
v999268650EmailStyle27=0A=09{font-family:"sans-serif";color:#1F497D;}=0A#yi=
v999268650 span.yiv999268650EmailStyle28=0A=09{font-family:"sans-serif";col=
or:#1F497D;}=0A#yiv999268650 .yiv999268650MsoChpDefault=0A=09{font-size:10.=
0pt;}=0A _filtered #yiv999268650 {margin:1.0in 1.0in 1.0in 1.0in;}=0A#yiv99=
9268650 div.yiv999268650WordSection1=0A=09{}=0A--></style>=0A=0A<div>=0A<di=
v class=3D"yiv999268650WordSection1">=0A<div class=3D"yiv999268650MsoNormal=
"><span style=3D"font-size:11.0pt;color:#1F497D;">I recently received an in=
quiry regarding invalid_client vs. invalid_grant. &nbsp;It seems that there=
 is a potential information disclosure in the specification with=0A respect=
 to how these error codes are used:</span></div> =0A<div class=3D"yiv999268=
650MsoNormal" style=3D""><span style=3D"font-size:11.0pt;color:#1F497D;"> &=
nbsp;</span></div> =0A<div class=3D"yiv999268650MsoNormal" style=3D"margin-=
left:.5in;"><span style=3D"font-size:10.0pt;color:black;">invalid_client</s=
pan></div> =0A<div class=3D"yiv999268650MsoNormal" style=3D"margin-left:.5i=
n;"><span style=3D"font-size:10.0pt;color:black;">&nbsp;&nbsp;&nbsp;&nbsp;&=
nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; Client authenti=
cation failed (e.g.=0A<span style=3D"background:yellow;">unknown client</sp=
an>, no</span></div> =0A<div class=3D"yiv999268650MsoNormal" style=3D"margi=
n-left:.5in;"><span style=3D"font-size:10.0pt;color:black;">&nbsp;&nbsp;&nb=
sp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; clien=
t authentication included, or unsupported</span></div> =0A<div class=3D"yiv=
999268650MsoNormal" style=3D"margin-left:.5in;"><span style=3D"font-size:10=
.0pt;color:black;">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&n=
bsp;&nbsp;&nbsp;&nbsp;&nbsp; authentication method).&nbsp; The authorizatio=
n server MAY</span></div> =0A<div class=3D"yiv999268650MsoNormal" style=3D"=
margin-left:.5in;"><span style=3D"font-size:10.0pt;color:black;">&nbsp;&nbs=
p;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; =
return an HTTP 401 (Unauthorized) status code to indicate</span></div> =0A<=
div class=3D"yiv999268650MsoNormal" style=3D"margin-left:.5in;"><span style=
=3D"font-size:10.0pt;color:black;">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbs=
p;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; which HTTP authentication sche=
mes are supported.&nbsp; If the</span></div> =0A<div class=3D"yiv999268650M=
soNormal" style=3D"margin-left:.5in;"><span style=3D"font-size:10.0pt;color=
:black;">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;=
&nbsp;&nbsp;&nbsp; client attempted to authenticate via the "Authorization"=
</span></div> =0A<div class=3D"yiv999268650MsoNormal" style=3D"margin-left:=
.5in;"><span style=3D"font-size:10.0pt;color:black;">&nbsp;&nbsp;&nbsp;&nbs=
p;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; request head=
er field, the authorization server MUST</span></div> =0A<div class=3D"yiv99=
9268650MsoNormal" style=3D"margin-left:.5in;"><span style=3D"font-size:10.0=
pt;color:black;">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbs=
p;&nbsp;&nbsp;&nbsp;&nbsp; respond with an HTTP 401 (Unauthorized) status c=
ode, and</span></div> =0A<div class=3D"yiv999268650MsoNormal" style=3D"marg=
in-left:.5in;"><span style=3D"font-size:10.0pt;color:black;">&nbsp;&nbsp;&n=
bsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; incl=
ude the "WWW-Authenticate" response header field</span></div> =0A<div class=
=3D"yiv999268650MsoNormal" style=3D"margin-left:.5in;"><span style=3D"font-=
size:10.0pt;color:black;">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&=
nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; matching the authentication scheme used=
 by the client.</span></div> =0A<pre style=3D"margin-left:.5in;"><span styl=
e=3D"color:black;">invalid_grant</span></pre> =0A<pre style=3D"margin-left:=
.5in;"><span style=3D"color:black;">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nb=
sp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; The provided authorization gr=
ant (e.g. authorization</span></pre> =0A<pre style=3D"margin-left:.5in;"><s=
pan style=3D"color:black;">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;=
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; code, resource owner credentials, <spa=
n style=3D"background:yellow;">client credentials</span>) is</span></pre> =
=0A<pre style=3D"margin-left:.5in;"><span style=3D"color:black;">&nbsp;&nbs=
p;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; =
invalid, expired, revoked, does not match the redirection</span></pre> =0A<=
pre style=3D"margin-left:.5in;"><span style=3D"color:black;">&nbsp;&nbsp;&n=
bsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; URI =
used in the authorization request, or was issued to</span></pre> =0A<pre st=
yle=3D"margin-left:.5in;"><span style=3D"color:black;">&nbsp;&nbsp;&nbsp;&n=
bsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; another cl=
ient.</span></pre> =0A<div class=3D"yiv999268650MsoNormal"><span style=3D"f=
ont-size:11.0pt;color:#993366;"> &nbsp;</span></div> =0A<div class=3D"yiv99=
9268650MsoNormal"><span style=3D"font-size:11.0pt;color:#1F497D;">If one us=
es invalid_client when the client is unknown and invalid_grant when the cli=
ent credentials are invalid, then an attacker could deduce whether or not=
=0A a particular client exists.</span></div> =0A<div class=3D"yiv999268650M=
soNormal"><span style=3D"font-size:11.0pt;color:#1F497D;"> &nbsp;</span></d=
iv> =0A<div class=3D"yiv999268650MsoNormal"><span style=3D"font-size:11.0pt=
;color:#1F497D;">First, do people agree that this is a potential informatio=
n leak and that the leak is meaningful?&nbsp; If so, what mitigation might =
be suggested?&nbsp; For instance,=0A might a server choose to use a single =
error code for both (and potentially other) cases?</span></div> =0A<div cla=
ss=3D"yiv999268650MsoNormal"><span style=3D"font-size:11.0pt;color:#1F497D;=
"> &nbsp;</span></div> =0A<div class=3D"yiv999268650MsoNormal"><span style=
=3D"font-size:11.0pt;color:#1F497D;">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&n=
bsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp=
;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&n=
bsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp=
;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&n=
bsp;&nbsp;&nbsp; Thanks,</span></div> =0A<div class=3D"yiv999268650MsoNorma=
l"><span style=3D"font-size:11.0pt;color:#1F497D;">&nbsp;&nbsp;&nbsp;&nbsp;=
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nb=
sp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;=
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nb=
sp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;=
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; -- Mike</span></div> =0A<div class=3D"yiv999=
268650MsoNormal"><span style=3D"font-size:11.0pt;color:#1F497D;"> &nbsp;</s=
pan></div> =0A</div>=0A</div>=0A=0A</div><br>______________________________=
_________________<br>OAuth mailing list<br><a ymailto=3D"mailto:OAuth@ietf.=
org" href=3D"mailto:OAuth@ietf.org">OAuth@ietf.org</a><br><a href=3D"https:=
//www.ietf.org/mailman/listinfo/oauth" target=3D"_blank">https://www.ietf.o=
rg/mailman/listinfo/oauth</a><br><br><br> </div> </div>  </div></body></htm=
l>
---1238014912-1519221104-1323740814=:90630--
