Re: [OAUTH-WG] OAuth Signature Draft Pre 00

David Recordon <recordond@gmail.com> Mon, 27 September 2010 13:59 UTC

Return-Path: <recordond@gmail.com>
X-Original-To: oauth@core3.amsl.com
Delivered-To: oauth@core3.amsl.com
Received: from localhost (localhost [127.0.0.1]) by core3.amsl.com (Postfix) with ESMTP id 7FD513A6AFF for <oauth@core3.amsl.com>; Mon, 27 Sep 2010 06:59:18 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.598
X-Spam-Level:
X-Spam-Status: No, score=-2.598 tagged_above=-999 required=5 tests=[BAYES_00=-2.599, HTML_MESSAGE=0.001]
Received: from mail.ietf.org ([64.170.98.32]) by localhost (core3.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id RXTJbkJHpQav for <oauth@core3.amsl.com>; Mon, 27 Sep 2010 06:59:17 -0700 (PDT)
Received: from mail-pv0-f172.google.com (mail-pv0-f172.google.com [74.125.83.172]) by core3.amsl.com (Postfix) with ESMTP id E8AD33A6B36 for <oauth@ietf.org>; Mon, 27 Sep 2010 06:59:16 -0700 (PDT)
Received: by pvg7 with SMTP id 7so1644821pvg.31 for <oauth@ietf.org>; Mon, 27 Sep 2010 06:59:54 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=gamma; h=domainkey-signature:mime-version:received:received:in-reply-to :references:date:message-id:subject:from:to:cc:content-type; bh=zS8DgXWWSYGhokIvtuD86h/oA9l0WCM7mZ/9N9a0xEI=; b=etGVxl/HoEYbYDpcYmc6M46Y3SsJYWCCgwoOvBRcxnWdYO+K8AOqdAvCXu2YXkJKxY UtVq8Jk/T2zuRR2u5aI/NFqmQfXFscCKfETRg53DC902JQh5/525q+oet48EKG2XJj2+ dV8lJPS0bpzjg+Fso5rsyMJYD7JDLHbigZRXM=
DomainKey-Signature: a=rsa-sha1; c=nofws; d=gmail.com; s=gamma; h=mime-version:in-reply-to:references:date:message-id:subject:from:to :cc:content-type; b=JdY9WM0zsxEvI5ycu3bzfP7ngkoUBJgltQT8Dcm4ZTQjmIjUyfiJykAeKYgDC9hcI8 n2v/tlPVwtCq0zmjkK+n7TriwTbEgVJUNkmNEBgyT4usoFnzcgyz6G9ikGKEYg/OGXFk ruIDSivO1AblAjS1/tx1FtfXLVy3JH2HHgp5s=
MIME-Version: 1.0
Received: by 10.142.212.20 with SMTP id k20mr4271118wfg.132.1285595994461; Mon, 27 Sep 2010 06:59:54 -0700 (PDT)
Received: by 10.231.195.159 with HTTP; Mon, 27 Sep 2010 06:59:53 -0700 (PDT)
In-Reply-To: <7C01E631FF4B654FA1E783F1C0265F8C62D263BB@TK5EX14MBXC111.redmond.corp.microsoft.com>
References: <AANLkTikSKX8jisucEbZOUnkGYUz0DnBSB_KWXGM3bJcS@mail.gmail.com> <7C01E631FF4B654FA1E783F1C0265F8C62D263BB@TK5EX14MBXC111.redmond.corp.microsoft.com>
Date: Mon, 27 Sep 2010 06:59:53 -0700
Message-ID: <AANLkTinZbFmWcuALHnd5NFik8HRkKgH0AgMzFMgarrYX@mail.gmail.com>
From: David Recordon <recordond@gmail.com>
To: Nat Sakimura <sakimura@gmail.com>, Yaron Goland <yarong@microsoft.com>
Content-Type: multipart/alternative; boundary="000e0cd30be8931a4504913e24d3"
Cc: oauth <oauth@ietf.org>
Subject: Re: [OAUTH-WG] OAuth Signature Draft Pre 00
X-BeenThere: oauth@ietf.org
X-Mailman-Version: 2.1.9
Precedence: list
List-Id: OAUTH WG <oauth.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/listinfo/oauth>, <mailto:oauth-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/oauth>
List-Post: <mailto:oauth@ietf.org>
List-Help: <mailto:oauth-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/oauth>, <mailto:oauth-request@ietf.org?subject=subscribe>
X-List-Received-Date: Mon, 27 Sep 2010 13:59:18 -0000

I'm a bit confused between the relationship of Nat's I-D and the documents
you and Mike recently posted. Is the goal to have one I-D? Nat's seems to
have fewer options and different modes which makes it easier to read and
understand.


On Mon, Aug 30, 2010 at 11:47 AM, Yaron Goland <yarong@microsoft.com> wrote:

>  BTW, Nat and I, as mentioned below, are talking. Here is my current
> draft. Please keep in mind that it's really just a set of notes trying to
> capture all the issues involved in creating a secure token format so it's a
> bit dense. My hope is that once all the issues are captured it can be
> completely re-written to be in something that looks more like English and is
> easier for actual implementers to follow. But for now I think it gives a
> good sense of the some of the security challenges in creating a secure token
> format.
>
>                 Yaron
>
>
>
> *From:* oauth-bounces@ietf.org [mailto:oauth-bounces@ietf.org] *On Behalf
> Of *Nat Sakimura
> *Sent:* Tuesday, August 24, 2010 6:50 AM
> *To:* oauth
> *Subject:* [OAUTH-WG] OAuth Signature Draft Pre 00
>
>
>
> Hi.
>
>
>
> It has been a few weeks since then I volunteered to do this work.
>
> I have written up to this pre 00 draft then have been doing some reality
> checks on some script languages etc.
>
>
>
> No. This pre-00 draft is far from being feature complete.
>
> I still need to copy and paste the Magic Signatures text etc.
>
> Also, I should add how this spec is being used in some of the major flows.
>
>
>
> However, since I will not be able to work on it this week, I thought it
> would be worthwhile to share this early draft so that you have some clarity
> into the progress.
>
>
>
> Apparently, Yaron has been working on it as well. We will compare the notes
> and try to merge, I hope.
>
>
>
> So, here it is!
>
>
>
> #For those of you who have seen the private draft, it has not been changed
> since July 31.
>
>
>
> Best,
>
>
>
> =nat
>
>
>
>
>
> _______________________________________________
> OAuth mailing list
> OAuth@ietf.org
> https://www.ietf.org/mailman/listinfo/oauth
>
>