Re: [OAUTH-WG] OAuth WRAP

"Paul C. Bryan" <email@pbryan.net> Tue, 10 November 2009 19:56 UTC

Return-Path: <email@pbryan.net>
X-Original-To: oauth@core3.amsl.com
Delivered-To: oauth@core3.amsl.com
Received: from localhost (localhost [127.0.0.1]) by core3.amsl.com (Postfix) with ESMTP id 5B37628C110 for <oauth@core3.amsl.com>; Tue, 10 Nov 2009 11:56:33 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.599
X-Spam-Level:
X-Spam-Status: No, score=-2.599 tagged_above=-999 required=5 tests=[BAYES_00=-2.599]
Received: from mail.ietf.org ([64.170.98.32]) by localhost (core3.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id Kfa6MQTG7ymh for <oauth@core3.amsl.com>; Tue, 10 Nov 2009 11:56:32 -0800 (PST)
Received: from maple.anode.ca (maple.anode.ca [72.14.183.184]) by core3.amsl.com (Postfix) with ESMTP id 9948328C0F9 for <oauth@ietf.org>; Tue, 10 Nov 2009 11:56:32 -0800 (PST)
Received: from [192.168.0.4] (S010600095baae0ff.vf.shawcable.net [174.1.50.199]) by maple.anode.ca (Postfix) with ESMTPSA id BBB47EA022 for <oauth@ietf.org>; Tue, 10 Nov 2009 19:56:59 +0000 (UTC)
From: "Paul C. Bryan" <email@pbryan.net>
To: "oauth@ietf.org" <oauth@ietf.org>
In-Reply-To: <498C2598-B473-4FE6-A975-A0CF87D03F5E@microsoft.com>
References: <daf5b9570911082102u215dcf22gf0aeb2f3578e5ea0@mail.gmail.com> <35D50F5C-3982-4298-A9E0-86A528F5C5D3@jkemp.net> <daf5b9570911092158k682aff63l959c423c399b2277@mail.gmail.com> <B1B9E4FC-0AF5-4357-B06F-F533C84F3C7D@microsoft.com> <1257876364.4540.265.camel@localhost> <498C2598-B473-4FE6-A975-A0CF87D03F5E@microsoft.com>
Content-Type: text/plain
Date: Tue, 10 Nov 2009 11:56:57 -0800
Message-Id: <1257883017.10242.5.camel@localhost>
Mime-Version: 1.0
X-Mailer: Evolution 2.26.1
Content-Transfer-Encoding: 7bit
Subject: Re: [OAUTH-WG] OAuth WRAP
X-BeenThere: oauth@ietf.org
X-Mailman-Version: 2.1.9
Precedence: list
List-Id: OAUTH WG <oauth.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/listinfo/oauth>, <mailto:oauth-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/oauth>
List-Post: <mailto:oauth@ietf.org>
List-Help: <mailto:oauth-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/oauth>, <mailto:oauth-request@ietf.org?subject=subscribe>
X-List-Received-Date: Tue, 10 Nov 2009 19:56:33 -0000

I guess I must admit I'm a bit surprised that the general consensus
would be to merge with/profile WRAP as OAuth, as the deltas between the
two protocols as defined seems quite substantial. Does this mean that
for all intents and purposes I should consider the existing OAuth IETF
drafts to date to be deprecated in favour of WRAP?

Paul

On Tue, 2009-11-10 at 19:46 +0000, Dick Hardt wrote:
> Good question. Given the positive reception WRAP received at IIW and  
> that capabilities in WRAP are expected to come out of the work in the  
> IETF OAuth WG, there was consensus from the OAuth community to include  
> WRAP as OAuth profiles.
> 
> -- Dick
> 
> On 2009-11-10, at 10:06 AM, "Paul C. Bryan" <email@pbryan.net> wrote:
> 
> > Hi Dick:
> >
> > Given that WRAP is so different from OAuth (as I know it), other than
> > the fact that OAuth could be used to negotiate the issuance of a WRAP
> > refresh token, I'm curious why you chose to associate this with  
> > OAuth by
> > giving it an "OAuth" prefix. It seems to me that it would only create
> > confusion in this space.
> >
> > Paul
> >
> > On Tue, 2009-11-10 at 17:52 +0000, Dick Hardt wrote:
> >> At IIW last week, myself, Biran Eaton from Google and Allen Tom from
> >> Yahoo! presented what is now called OAuth WRAP
> >>
> >> The specs and discussion specific to those documents is at:
> >>
> >>    http://groups.google.com/group/oauth-wrap-wg
> >>
> >> We plan to submit the document as an I-D next week when I-D  
> >> submission
> >> is open again, and for further work to occur in the IETF OAuth WG.
> >>
> >> -- Dick
> >> _______________________________________________
> >> OAuth mailing list
> >> OAuth@ietf.org
> >> https://www.ietf.org/mailman/listinfo/oauth
> >
> > _______________________________________________
> > OAuth mailing list
> > OAuth@ietf.org
> > https://www.ietf.org/mailman/listinfo/oauth
> >