Return-Path: <recordond@gmail.com>
X-Original-To: oauth@core3.amsl.com
Delivered-To: oauth@core3.amsl.com
Received: from localhost (localhost [127.0.0.1]) by core3.amsl.com (Postfix)
 with ESMTP id 7FD513A6AFF for <oauth@core3.amsl.com>;
 Mon, 27 Sep 2010 06:59:18 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.598
X-Spam-Level: 
X-Spam-Status: No, score=-2.598 tagged_above=-999 required=5
 tests=[BAYES_00=-2.599, HTML_MESSAGE=0.001]
Received: from mail.ietf.org ([64.170.98.32]) by localhost (core3.amsl.com
 [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id RXTJbkJHpQav for
 <oauth@core3.amsl.com>; Mon, 27 Sep 2010 06:59:17 -0700 (PDT)
Received: from mail-pv0-f172.google.com (mail-pv0-f172.google.com
 [74.125.83.172]) by core3.amsl.com (Postfix) with ESMTP id E8AD33A6B36 for
 <oauth@ietf.org>; Mon, 27 Sep 2010 06:59:16 -0700 (PDT)
Received: by pvg7 with SMTP id 7so1644821pvg.31 for <oauth@ietf.org>;
 Mon, 27 Sep 2010 06:59:54 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=gamma;
 h=domainkey-signature:mime-version:received:received:in-reply-to
 :references:date:message-id:subject:from:to:cc:content-type;
 bh=zS8DgXWWSYGhokIvtuD86h/oA9l0WCM7mZ/9N9a0xEI=;
 b=etGVxl/HoEYbYDpcYmc6M46Y3SsJYWCCgwoOvBRcxnWdYO+K8AOqdAvCXu2YXkJKxY
 UtVq8Jk/T2zuRR2u5aI/NFqmQfXFscCKfETRg53DC902JQh5/525q+oet48EKG2XJj2+
 dV8lJPS0bpzjg+Fso5rsyMJYD7JDLHbigZRXM=
DomainKey-Signature: a=rsa-sha1; c=nofws; d=gmail.com; s=gamma;
 h=mime-version:in-reply-to:references:date:message-id:subject:from:to
 :cc:content-type;
 b=JdY9WM0zsxEvI5ycu3bzfP7ngkoUBJgltQT8Dcm4ZTQjmIjUyfiJykAeKYgDC9hcI8
 n2v/tlPVwtCq0zmjkK+n7TriwTbEgVJUNkmNEBgyT4usoFnzcgyz6G9ikGKEYg/OGXFk
 ruIDSivO1AblAjS1/tx1FtfXLVy3JH2HHgp5s=
MIME-Version: 1.0
Received: by 10.142.212.20 with SMTP id k20mr4271118wfg.132.1285595994461;
 Mon, 27 Sep 2010 06:59:54 -0700 (PDT)
Received: by 10.231.195.159 with HTTP; Mon, 27 Sep 2010 06:59:53 -0700 (PDT)
In-Reply-To: <7C01E631FF4B654FA1E783F1C0265F8C62D263BB@TK5EX14MBXC111.redmond.corp.microsoft.com>
References: <AANLkTikSKX8jisucEbZOUnkGYUz0DnBSB_KWXGM3bJcS@mail.gmail.com>
 <7C01E631FF4B654FA1E783F1C0265F8C62D263BB@TK5EX14MBXC111.redmond.corp.microsoft.com>
Date: Mon, 27 Sep 2010 06:59:53 -0700
Message-ID: <AANLkTinZbFmWcuALHnd5NFik8HRkKgH0AgMzFMgarrYX@mail.gmail.com>
From: David Recordon <recordond@gmail.com>
To: Nat Sakimura <sakimura@gmail.com>, Yaron Goland <yarong@microsoft.com>
Content-Type: multipart/alternative; boundary=000e0cd30be8931a4504913e24d3
Cc: oauth <oauth@ietf.org>
Subject: Re: [OAUTH-WG] OAuth Signature Draft Pre 00
X-BeenThere: oauth@ietf.org
X-Mailman-Version: 2.1.9
Precedence: list
List-Id: OAUTH WG <oauth.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/listinfo/oauth>,
 <mailto:oauth-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/oauth>
List-Post: <mailto:oauth@ietf.org>
List-Help: <mailto:oauth-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/oauth>,
 <mailto:oauth-request@ietf.org?subject=subscribe>
X-List-Received-Date: Mon, 27 Sep 2010 13:59:18 -0000

--000e0cd30be8931a4504913e24d3
Content-Type: text/plain; charset=ISO-8859-1

I'm a bit confused between the relationship of Nat's I-D and the documents
you and Mike recently posted. Is the goal to have one I-D? Nat's seems to
have fewer options and different modes which makes it easier to read and
understand.


On Mon, Aug 30, 2010 at 11:47 AM, Yaron Goland <yarong@microsoft.com> wrote:

>  BTW, Nat and I, as mentioned below, are talking. Here is my current
> draft. Please keep in mind that it's really just a set of notes trying to
> capture all the issues involved in creating a secure token format so it's a
> bit dense. My hope is that once all the issues are captured it can be
> completely re-written to be in something that looks more like English and is
> easier for actual implementers to follow. But for now I think it gives a
> good sense of the some of the security challenges in creating a secure token
> format.
>
>                 Yaron
>
>
>
> *From:* oauth-bounces@ietf.org [mailto:oauth-bounces@ietf.org] *On Behalf
> Of *Nat Sakimura
> *Sent:* Tuesday, August 24, 2010 6:50 AM
> *To:* oauth
> *Subject:* [OAUTH-WG] OAuth Signature Draft Pre 00
>
>
>
> Hi.
>
>
>
> It has been a few weeks since then I volunteered to do this work.
>
> I have written up to this pre 00 draft then have been doing some reality
> checks on some script languages etc.
>
>
>
> No. This pre-00 draft is far from being feature complete.
>
> I still need to copy and paste the Magic Signatures text etc.
>
> Also, I should add how this spec is being used in some of the major flows.
>
>
>
> However, since I will not be able to work on it this week, I thought it
> would be worthwhile to share this early draft so that you have some clarity
> into the progress.
>
>
>
> Apparently, Yaron has been working on it as well. We will compare the notes
> and try to merge, I hope.
>
>
>
> So, here it is!
>
>
>
> #For those of you who have seen the private draft, it has not been changed
> since July 31.
>
>
>
> Best,
>
>
>
> =nat
>
>
>
>
>
> _______________________________________________
> OAuth mailing list
> OAuth@ietf.org
> https://www.ietf.org/mailman/listinfo/oauth
>
>

--000e0cd30be8931a4504913e24d3
Content-Type: text/html; charset=ISO-8859-1
Content-Transfer-Encoding: quoted-printable

I&#39;m a bit confused between the relationship of Nat&#39;s I-D and the do=
cuments you and Mike recently posted. Is the goal to have one I-D? Nat&#39;=
s seems to have fewer options and different modes which makes it easier to =
read and understand.<div>
<br><br><div class=3D"gmail_quote">On Mon, Aug 30, 2010 at 11:47 AM, Yaron =
Goland <span dir=3D"ltr">&lt;<a href=3D"mailto:yarong@microsoft.com">yarong=
@microsoft.com</a>&gt;</span> wrote:<br><blockquote class=3D"gmail_quote" s=
tyle=3D"margin:0 0 0 .8ex;border-left:1px #ccc solid;padding-left:1ex;">






<div lang=3D"EN-US" link=3D"blue" vlink=3D"purple">
<div>
<p class=3D"MsoNormal"><span style=3D"font-size:11.0pt;color:#1F497D">BTW, =
Nat and I, as mentioned below, are talking. Here is my current draft. Pleas=
e keep in mind that it&#39;s really just a set of notes trying to capture a=
ll the
 issues involved in creating a secure token format so it&#39;s a bit dense.=
 My hope is that once all the issues are captured it can be completely re-w=
ritten to be in something that looks more like English and is easier for ac=
tual implementers to follow. But for
 now I think it gives a good sense of the some of the security challenges i=
n creating a secure token format.</span></p>
<p class=3D"MsoNormal"><span style=3D"font-size:11.0pt;color:#1F497D">=A0=
=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0 Yaron</span></p>
<p class=3D"MsoNormal"><span style=3D"font-size:11.0pt;color:#1F497D">=A0</=
span></p>
<div style=3D"border:none;border-left:solid blue 1.5pt;padding:0in 0in 0in =
4.0pt">
<div>
<div style=3D"border:none;border-top:solid #B5C4DF 1.0pt;padding:3.0pt 0in =
0in 0in">
<p class=3D"MsoNormal"><b><span style=3D"font-size:10.0pt">From:</span></b>=
<span style=3D"font-size:10.0pt"> <a href=3D"mailto:oauth-bounces@ietf.org"=
 target=3D"_blank">oauth-bounces@ietf.org</a> [mailto:<a href=3D"mailto:oau=
th-bounces@ietf.org" target=3D"_blank">oauth-bounces@ietf.org</a>]
<b>On Behalf Of </b>Nat Sakimura<br>
<b>Sent:</b> Tuesday, August 24, 2010 6:50 AM<br>
<b>To:</b> oauth<br>
<b>Subject:</b> [OAUTH-WG] OAuth Signature Draft Pre 00</span></p>
</div>
</div><div><div></div><div class=3D"h5">
<p class=3D"MsoNormal">=A0</p>
<p class=3D"MsoNormal">Hi.=A0 </p>
<div>
<p class=3D"MsoNormal">=A0</p>
</div>
<div>
<p class=3D"MsoNormal">It has been a few weeks since then I volunteered to =
do this work.=A0</p>
</div>
<div>
<p class=3D"MsoNormal">I have written up to this pre 00 draft then have bee=
n doing some reality checks on some script languages etc.=A0</p>
</div>
<div>
<p class=3D"MsoNormal">=A0</p>
</div>
<div>
<p class=3D"MsoNormal">No. This pre-00 draft is far from being feature comp=
lete.=A0</p>
</div>
<div>
<p class=3D"MsoNormal">I still need to copy and paste the Magic Signatures =
text etc.=A0</p>
</div>
<div>
<p class=3D"MsoNormal">Also, I should add how this spec is being used in so=
me of the major flows.=A0</p>
</div>
<div>
<p class=3D"MsoNormal">=A0</p>
</div>
<div>
<p class=3D"MsoNormal">However, since I will not be able to work on it this=
 week, I thought it would be worthwhile to share this early draft so that y=
ou have some clarity into the progress.=A0</p>
</div>
<div>
<p class=3D"MsoNormal">=A0</p>
</div>
<div>
<p class=3D"MsoNormal">Apparently, Yaron has been working on it as well. We=
 will compare the notes and try to merge, I hope.=A0</p>
</div>
<div>
<p class=3D"MsoNormal">=A0</p>
</div>
<div>
<p class=3D"MsoNormal">So, here it is!=A0</p>
</div>
<div>
<p class=3D"MsoNormal">=A0</p>
</div>
<div>
<p class=3D"MsoNormal">#For those of you who have seen the private draft, i=
t has not been changed since July 31.=A0</p>
</div>
<div>
<p class=3D"MsoNormal">=A0</p>
</div>
<div>
<p class=3D"MsoNormal">Best,=A0</p>
</div>
<div>
<p class=3D"MsoNormal">=A0</p>
</div>
<div>
<p class=3D"MsoNormal">=3Dnat</p>
</div>
<div>
<p class=3D"MsoNormal">=A0</p>
</div>
<div>
<p class=3D"MsoNormal">=A0</p>
</div>
</div></div></div>
</div>
</div>

<br>_______________________________________________<br>
OAuth mailing list<br>
<a href=3D"mailto:OAuth@ietf.org">OAuth@ietf.org</a><br>
<a href=3D"https://www.ietf.org/mailman/listinfo/oauth" target=3D"_blank">h=
ttps://www.ietf.org/mailman/listinfo/oauth</a><br>
<br></blockquote></div><br></div>

--000e0cd30be8931a4504913e24d3--
