[OAUTH-WG] Re: AD comments on draft-ietf-oauth-sd-jwt-vc

Brian Campbell <bcampbell@pingidentity.com> Fri, 14 August 2026 22:43 UTC

Return-Path: <bcampbell@pingidentity.com>
X-Original-To: oauth@mail2.ietf.org
Delivered-To: oauth@mail2.ietf.org
Received: from localhost (localhost [127.0.0.1]) by mail2.ietf.org (Postfix) with ESMTP id A448112A1BBFD for <oauth@mail2.ietf.org>; Fri, 14 Aug 2026 15:43:39 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=ietf.org; s=ietf1; t=1786747419; bh=OgdNkksoFE4lxhmAog4su6o3LdYIlrRvn+/kQulBBOQ=; h=References:In-Reply-To:From:Date:Subject:To:Cc; b=DUUHO4vV66GX2GAuS8FsgHks4Bu9myuy6BZ/Cm90xEXfGCKa3cU8bPNPnALiJsm58 URJnDplS80rvvAeFteJIJsPU+ENa8Ohi86hAtsY7dPm9/ydj/DfxIAoKc6+HppyRzG Dc4TC5PHDtu/aiTJ/NrucT0wX5Mx1U8DXFDktS6w=
X-Virus-Scanned: amavisd-new at ietf.org
X-Spam-Flag: NO
X-Spam-Score: -0.854
X-Spam-Level:
X-Spam-Status: No, score=-0.854 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, HTML_MESSAGE=0.001, NORMAL_HTTP_TO_IP=0.001, NUMERIC_HTTP_ADDR=1.242, RCVD_IN_DNSWL_NONE=-0.0001, SPF_HELO_NONE=0.001, SPF_NONE=0.001] autolearn=unavailable autolearn_force=no
Authentication-Results: mail2.ietf.org (amavisd-new); dkim=pass (2048-bit key) header.d=pingidentity.com
Received: from mail2.ietf.org ([166.84.6.31]) by localhost (mail2.ietf.org [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id iTi-t44_Qe3n for <oauth@mail2.ietf.org>; Fri, 14 Aug 2026 15:43:37 -0700 (PDT)
Received: from mail-ua1-x92c.google.com (mail-ua1-x92c.google.com [IPv6:2607:f8b0:4864:20::92c]) (using TLSv1.3 with cipher TLS_AES_128_GCM_SHA256 (128/128 bits) key-exchange X25519 server-signature ECDSA (P-256) server-digest SHA256) (No client certificate requested) by mail2.ietf.org (Postfix) with ESMTPS id 6141E12A1BBD9 for <oauth@ietf.org>; Fri, 14 Aug 2026 15:43:37 -0700 (PDT)
Received: by mail-ua1-x92c.google.com with SMTP id a1e0cc1a2514c-977258a75d9so948618241.3 for <oauth@ietf.org>; Fri, 14 Aug 2026 15:43:37 -0700 (PDT)
ARC-Seal: i=1; a=rsa-sha256; t=1786747411; cv=none; d=google.com; s=arc-20260327; b=aJgqFsA7qNq4DrUJRWVMk9AsD8yUbOynCedipz5uqqTEiMb0g8UiNL0YSCQVyoCFtw HWqTIfvPw/mv39kgl7ntyCYsEFc2GPD77IGBNxvwg/ULSQKgLXFFUvJ1YmPgfUQJcROu maJHM2slnRjsSXMpm67WRLJnKZvrGhfRb5RZK2VwIFpwRgaItcEd81ZuhImPDofiod3b sjz/vFWwpvNZmpj6IuzfHCZeqsmt0YecLdpNdTm5ZCM5Qehy0qfrL6we8aX+qo+p3qfb VeReo7rTSH1Vwrq08Feprr7WC3HPi2O+G9fspZej0kKGJYQLN+MkxUWEbrx8RJ/5edjh uBTA==
ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=arc-20260327; h=cc:to:subject:message-id:date:from:in-reply-to:references :mime-version:dkim-signature; bh=khKVAkfBAcHvCvaoZjhZzcqQqPVaRo0UFXHRDrpZkhY=; fh=iUEx9z0U1dyRGgVTwsHhNYCOuOdxsbLJZ+7eX2o6G3k=; b=rvH3/ZcYJeCYDBfVdK8D+AqYWb3mwE37FiWs+ZdwSH7OSOttbc7eTgnicuDKXfoN38 HD9B13Fyq3kT4wnvTVDHwiJvbtb2N2IRa/4HtYLDSsKUM3bOENb7z/M15vdimesi2ytT Uj7NzFFswrujfL0255+A+/OteVkZ0JU79i5I3yNkBZq7yDtGnfmucTqXBuw4x00iXbEe 6I2enxFcnH5bXk5c9DcccY0CdmX6oGSDpsJ3wG+QR/zw2Ao2UEP02SWAM2pLtAvd3+kV 1dk9nbInk5qHF7W6e02aCPUGmW4RMLMOtxkN1la/YKN+MHq+PfJpS1biIRZqaqzuul8N ZYFg==; darn=ietf.org
ARC-Authentication-Results: i=1; mx.google.com; arc=none
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=pingidentity.com; s=google; t=1786747411; x=1787352211; darn=ietf.org; h=content-type:cc:to:subject:message-id:date:from:in-reply-to :references:mime-version:from:to:cc:subject:date:message-id:reply-to :content-type; bh=khKVAkfBAcHvCvaoZjhZzcqQqPVaRo0UFXHRDrpZkhY=; b=RgG6JZXPeaBcMr9Vp6aGuvDQ5+Taw2dWQe1bTI63EA0vVzZ7k7MPesZnKHWR2YzYg0 ssHxYWRwdk+fpzSJrAMf9PxDVg4D1ER25PYzaNrQZtYWxlIwbEM9x7XZSk/LrkBs1JXl /DR9r7fcQICXUTEE7msec7PVBSfUss5CB6cGFl2p/mtFQoDtivYNo02hqhi846uw2wVd 26CwCNCo/rBz2bhi5kRhdm1LuLZbplugct8l1VgwBDLqnNsQjHtdrokY198pa9Y9Rhya D/N1rzBNFs57SFwTDHFSohKE0mx/tfHEDX8XaDVzUvxUY2oRvyWs5bZ/uDC00A64qfUM hHLA==
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1786747411; x=1787352211; h=content-type:cc:to:subject:message-id:date:from:in-reply-to :references:mime-version:x-gm-gg:x-gm-message-state:from:to:cc :subject:date:message-id:reply-to:content-type; bh=khKVAkfBAcHvCvaoZjhZzcqQqPVaRo0UFXHRDrpZkhY=; b=mln54vhH5sK7qCUKyMuv5POl0RSowgrkBevNLlA2L1mAhRPKh54ZfKJNWOE4CjUb5V Au8NgFb+mZPjPGzyT4mpAWiYB10+rAOXO7Ykjf/mxTHrzMUDzGd/zdMdfY1SEBEQ5jhS LTuSR6leudvYaZ4l6fZpgpB/BfgqMJgLpUC8tneNUthGUGhpG3lxr6wjZUH6Gf+ObYWj WB5hAEFNvuU8MSAIREFya31Io/OEuoHuq/1SAkNXNqoYGEEGRo9UHzeYK+1ttCosqQC8 auR3Yptng+cHZs/M5a1vUYB6wjy+RcgDHj5veO+xtRcDzS5LhouROTDAsJfpz1aHUDWF 3OAA==
X-Forwarded-Encrypted: i=1; AHgh+RpgLgQ0He4+OYRMnL5MAeqISIkR8oPLIiZTvRJ3iPZe4RzidcjF1yTwZxzq5ydg6fE2HOZpBg==@ietf.org
X-Gm-Message-State: AOJu0YyUR0IMjHjGJ1lUOhe6QKtK3TdxJRLOFPrO9dsqT8Xt67KMhhJ7 PhRuJqpRiHH+m9BtMS8c1aldd7RhvbSBHtD9tXmyF2rkf0h+WFib1K4q4MoEV7DQVFZisBUCItw JiJjsZojap73C+vinRz7vWPkuVtrp2MjsnW/89XtmqJs3Yrt46K4m19KHZ6ZAIfwjaDWwRsPdOP X1I0h+Z4/dFWFDBg==
X-Gm-Gg: AR+sD13BV5C/grcdglg9i/2TUw9SdOK8Runy3bPah1bXuiAV/FeFhqXGM9JSuty9rUj TLpVY3e31061oifgRnMKRf5h918yU4DpuNdePAUgT32R0H/jnxAZE6HDT1MQNj5uja7v50QoZyI jhcYnkE9WR/1/wZgwrrXQtJmGVd3OALkZrl+j0TsbJYkHxiRVi97MGC6JUlPuVUBS3TSIVzwVjg XITP+ejyRk/i8pt88qm22bU8J4M44xpGbYG3E8eMzkP5Kfjj1jN+/cDZOJRL9r30BvvmIiQo6eh fCBbKOQ9yzuRrekaLewIpeWQ4gxADKybF7DGBoNkdnY0eetNz+DSOHN9m3mTyE7Gh5dX4/LpY/7 ZU6XUF/UaWFOyY5UlJVXTbtGzQX4cgwt+O5mjbWXPQ1qEfL8vH+Xx/CSzukBt7A==
X-Received: by 2002:a05:6102:8541:10b0:76f:eaa2:6f80 with SMTP id ada2fe7eead31-76feaa27880mr860914137.1.1786747411188; Fri, 14 Aug 2026 15:43:31 -0700 (PDT)
MIME-Version: 1.0
References: <CAGgd1OecETcA-yQAokc72Hp+twufe0_UJRnWLDuNAitXhMkioQ@mail.gmail.com>
In-Reply-To: <CAGgd1OecETcA-yQAokc72Hp+twufe0_UJRnWLDuNAitXhMkioQ@mail.gmail.com>
From: Brian Campbell <bcampbell@pingidentity.com>
Date: Fri, 14 Aug 2026 16:43:05 -0600
X-Gm-Features: AcwNN1X-Ce8GHm7gvDw-ImvtHLvg96zfZ5xz1zZjy1CVxpd6kEOf4kdMmK0DTQI
Message-ID: <CA+k3eCRzv_cGh03_iY6oq9UW97sPKq==POW=KMmOM+WTZFHufQ@mail.gmail.com>
To: Deb Cooley <debcooley1@gmail.com>
Content-Type: multipart/alternative; boundary="000000000000bf65fb0659098c8d"
Message-ID-Hash: QR3Q2CWDBSRSP4VIHFPH2A4RB74M3TBG
X-Message-ID-Hash: QR3Q2CWDBSRSP4VIHFPH2A4RB74M3TBG
X-MailFrom: bcampbell@pingidentity.com
X-Mailman-Rule-Misses: dmarc-mitigation; no-senders; approved; emergency; loop; banned-address; member-moderation; header-match-oauth.ietf.org-0; nonmember-moderation; administrivia; implicit-dest; max-recipients; max-size; news-moderation; no-subject; digests; suspicious-header
CC: draft-ietf-oauth-sd-jwt-vc.authors@ietf.org, Web Authorization Protocol Working Group <oauth-chairs@ietf.org>, oauth <oauth@ietf.org>
X-Mailman-Version: 3.3.9rc6
Precedence: list
Subject: [OAUTH-WG] Re: AD comments on draft-ietf-oauth-sd-jwt-vc
List-Id: OAUTH WG <oauth.ietf.org>
Archived-At: <https://mailarchive.ietf.org/arch/msg/oauth/HJKqKZmC0FZCtVarQjoq32nqlxo>
List-Archive: <https://mailarchive.ietf.org/arch/browse/oauth>
List-Help: <mailto:oauth-request@ietf.org?subject=help>
List-Owner: <mailto:oauth-owner@ietf.org>
List-Post: <mailto:oauth@ietf.org>
List-Subscribe: <mailto:oauth-join@ietf.org>
List-Unsubscribe: <mailto:oauth-leave@ietf.org>

These things take time. No apologies needed. Which I guess means I
shouldn't apologize for this reply being slow. Regardless, thank you for
the review. Responses are inline below and updates to the draft are en
route via https://github.com/oauth-wg/oauth-sd-jwt-vc/pull/423

On Mon, Aug 10, 2026 at 10:10 AM Deb Cooley <debcooley1@gmail.com> wrote:

> Apologies for how long this took. Here are my comments on the draft:
>
> General comment (I've left examples below):  There are a bunch of nested
> fields (probably the wrong word, maybe claims is better?) where the top
> level is OPTIONAL, but then sub fields are MUST, for example see my comment
> on Section 2.2.2.3, and 4.5.1.  [There are more, I just lost the will to
> comment on each of them].  I can think of two ways to 'clarify' this.  1.
> Make a general statement up front (intro, terminology, somewhere like
> that).  Or add the phrase 'if used...'.  The second is more obvious to a
> reader 'in the moment', but the first might be easier for the author.  I'm
> happy to chat about this.  Also let me know if I've gotten this wrong (not
> the first, nor the last time).
>

The wording in 2.2.2.3 was odd at best and maybe wrong. I've tried to
remedy that at
https://github.com/oauth-wg/oauth-sd-jwt-vc/pull/423/changes#diff-e750c0958ca10e395b4d3b77bb5aafccc668b4a1a50675dda79a8d90b39a2468R320

I'm pretty firmly of the opinion that the others throughout section 4, even
after you lost your will, can be reasonably understood to mean, "the thing
is optional and when used these are the requirements but when not used the
requirements don't apply." How can requirements apply to something that
doesn't exist?



>
> Section 2.2.1, last paragraph:  Any idea how long a 'reasonable
> transitional period' is?  Maybe state that determining what is 'reasonable'
> is out of scope for this specification, or similar.  I'm fine leaving this
> alone, but it may draw comments.
>

We aren't really sure but after discussing it further, we feel it's
probably reasonable to consider that period as having reasonably past and
remove that whole paragraph.



>
> Section 2.2.2.1, Figure 3:  I had to look up Russ Lasky (don't judge - my
> husband laughed).  For some of these fields, the IETF has guidance on
> entries that have been reserved.  When you can, please use those.  Here is
> the easiest link:
> https://datatracker.ietf.org/doc/statement-iesg-statement-on-assignable-codepoints-for-examples-in-ietf-specifications/
> . This comment applies everywhere you have examples.
>

AFAICT Russ's email address is okay because it uses the reserved .example
TLD from https://datatracker.ietf.org/doc/html/rfc2606#section-2

I also see John Doe's email address of johndoe@example.com, which I think
is also okay because it's using a reserved example second level domain name
from https://datatracker.ietf.org/doc/html/rfc2606#section-3

Similarly, all (that I can find) https:// URLs in examples throughout the
document use either a reserved TLD or reserved second-level domain. And all
the URNs start with urn:example:, which seems okay.

The moose out front shoulda told ya all this.



> Section 2.2.2.2:  I would add at least a tiny bit more information about
> why this could/should be used.  Perhaps some of the information in this
> message would work:
> https://mailarchive.ietf.org/arch/msg/oauth/1Idb9zZ5Qgjo_QOWyqZqpaUs9Cs/
>

Makes sense. Will add a bit.



>
>
> Section 2.2.2.3, para 2:  If some of the fields below are optional, then
> how does the 'are used within...' work?  Maybe 'if used within...'? (if an
> optional field isn't chosen, then it isn't used within the SD-JWT component)
>

See prior reply about 2.2.2.3 and fixing it.



>
> Section 4.5:  Consider whether sentences 2 and 3 would be better listed
> under the bullet for locale.  The advantage is that it puts all the
> normative requirements for this object in one place.
>

Reading this again, I think it'd be preferable to just not use the big 2119
langue in sentences 2 and 3.



>
> Section 4.5.1:  So according to the bullet above, the rendering object is
> optional, but this section has many MUSTs.  Perhaps, add 'if included'
> somewhere in the first sentence?  Or perhaps the rendering object is really
> 'REQUIRED'?
>

See prior reply about all of section 4 and not changing it.



>
> Section 6:  Either put a link to the SVG security information somewhere in
> Section 6, or list those recommendations in Section 6 with a link to it
> from Section 4.5.1.2.2.
>
> References:
> RFC 2397 is listed as legacy.  is there a more recent specification?  [I
> certainly don't see anything linked to it, and I'm fine if there isn't, but
> just in case, I'm asking.]
>

I am not aware of one, wasn't able to find anything, and one of the LLMs
confidently tells me that the "canonical reference is RFC 2397."


>
> Section 8.1 and Informative References:  To make these easier to find,
> please add:  https://www.iana.org/assignments/jwt#claims
>

yup


>
>
> Section 8.2 and Informative References:  To make these easier to find,
> please add:  https://www.iana.org/assignments/media-types#application
>

yup



>
>
> Also, I have asked for an http directorate review in advance of IETF Last
> Call...
>

Thank you. We've tried to address everything in it, see
https://mailarchive.ietf.org/arch/msg/oauth/dfnha_5m3_v62skUqVDHMd_yI4Q/



>
> I'm happy to take questions/comments.
>
> Deb
> Sec AD
>
>

-- 
_CONFIDENTIALITY NOTICE: This email may contain confidential and privileged 
material for the sole use of the intended recipient(s). Any review, use, 
distribution or disclosure by others is strictly prohibited.  If you have 
received this communication in error, please notify the sender immediately 
by e-mail and delete the message and any file attachments from your 
computer. Thank you._