[OAUTH-WG] Re: Shepherd Review - Updates to JWT Client Authentication and Assertion-Based Authorization Grants

Michael Jones <michael_b_jones@hotmail.com> Mon, 02 March 2026 05:20 UTC

Return-Path: <michael_b_jones@hotmail.com>
X-Original-To: oauth@mail2.ietf.org
Delivered-To: oauth@mail2.ietf.org
Received: from localhost (localhost [127.0.0.1]) by mail2.ietf.org (Postfix) with ESMTP id 4A560C17139E for <oauth@mail2.ietf.org>; Sun, 1 Mar 2026 21:20:30 -0800 (PST)
X-Virus-Scanned: amavisd-new at ietf.org
X-Spam-Flag: NO
X-Spam-Score: -0.222
X-Spam-Level:
X-Spam-Status: No, score=-0.222 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, FORGED_HOTMAIL_RCVD2=0.874, FREEMAIL_FROM=0.001, FREEMAIL_REPLY=1, HTML_MESSAGE=0.001, RCVD_IN_DNSWL_NONE=-0.0001, RCVD_IN_MSPIKE_H2=0.001, RCVD_IN_VALIDITY_CERTIFIED_BLOCKED=0.001, RCVD_IN_VALIDITY_RPBL_BLOCKED=0.001, SPF_PASS=-0.001] autolearn=no autolearn_force=no
Authentication-Results: mail2.ietf.org (amavisd-new); dkim=pass (2048-bit key) header.d=hotmail.com
Received: from mail2.ietf.org ([166.84.6.31]) by localhost (mail2.ietf.org [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id fpNduM9aJsre for <oauth@mail2.ietf.org>; Sun, 1 Mar 2026 21:20:29 -0800 (PST)
Received: from DM5PR21CU001.outbound.protection.outlook.com (mail-centralusazolkn19011037.outbound.protection.outlook.com [52.103.13.37]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange ECDHE (P-384) server-signature ECDSA (P-256) server-digest SHA256) (No client certificate requested) by mail2.ietf.org (Postfix) with ESMTPS id 98EB6C171396 for <oauth@ietf.org>; Sun, 1 Mar 2026 21:20:29 -0800 (PST)
ARC-Seal: i=1; a=rsa-sha256; s=arcselector10001; d=microsoft.com; cv=none; b=CWbGQEhBFyiYaPE3KBpKWHr0paMU9Q4ckYrpr7tHbOizdU+Y8IuXiN6aw1xG36XvODbf3dFPwDdUSKa1IhLZOugsnFjHM1aAF9yGR0lmddhxbNBa8RAUTKNN2OeBxI7A7GHufVdagRX9M2U2eZmFib7zkDPB69cpzrfbNwSFUtXm7+KluFiFIAT7ORysWY3W6e5PzJFAo2QetYEzSkEzNCwoUtoZBgYtvpwk1Rp1ReYZHuu0OqpNPUUg/gowsfCtM80RYnvdnB2SMNzNg3q6zmNOpjKCVQk4JKdpa0Qm3r0ua2crz7AwjPnppz0M55caxJX6+H681dmC5PTKWhC7Sw==
ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=microsoft.com; s=arcselector10001; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-AntiSpam-MessageData-ChunkCount:X-MS-Exchange-AntiSpam-MessageData-0:X-MS-Exchange-AntiSpam-MessageData-1; bh=KyANHBgwtV6PDY9Mngc22pcHVsnu3UxoUZO4HOHBFf8=; b=DY0jWcJEmVnGMvPiPcA+8KlomCm3Q3808X8ZyXE2TiBBZp4sGOLEIIivpy6As8573lBDib+ifPj65xvl0pCdkYHlkHCcj8kXX3H+xpn0nFiw5jBnLO84r2t2y8MV0abuvVDu8pC/Kybl5Oh6ESAfGqjhmgqOKQxbvO/Vgg9I5l0X2fiM63xmOrwe5/TSQVoJOIwP0JbRwSuHHqW+4ENPlwHSlfzp8QkH17zhkaYJ/1OrPDljrA0udEPJHzYfD6mGwsRI5e2qStS5S+lsJ+WmsP0ea6JyVSUugFsNUQhdJXroFt24RCZpjxs/qUkghbUCSH27+m0mMxHXB5FsEkrHCw==
ARC-Authentication-Results: i=1; mx.microsoft.com 1; spf=none; dmarc=none; dkim=none; arc=none
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=hotmail.com; s=selector1; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-SenderADCheck; bh=KyANHBgwtV6PDY9Mngc22pcHVsnu3UxoUZO4HOHBFf8=; b=EP8PsE31L2kzwT+oPwkUGvR1IforUqxu32oTsYuBV9rNpgLica+2amiDvnMPGLMTjtYyctV57U2FwjzyYGI3l5e62Zms30uyJi0kr8R8fV8PVCC3O0SU1rdpy3BwrS7FGEd7M58ClSQLhFs03itps0NiFWdc0bPlBvCQI63xgCkIP54aNC5pCpcz0eaFmPWez7ZIe67rqcY+jHih9pVeV6AtbxP0nDTzX8wQ9hBlPPcFzMgaFmVJR8o0sTDEWlgCx4nBrUyazIYt2rUZoj2QFu32FxnIgRUvn2CmbT6AbxVhNrgLTPRUPFDpsF5XqRTTY+iHrsZ5MQxz5L0EuWCfKA==
Received: from MW2PR12MB2508.namprd12.prod.outlook.com (2603:10b6:907:9::23) by PH7PR12MB5808.namprd12.prod.outlook.com (2603:10b6:510:1d4::18) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.20.9654.21; Mon, 2 Mar 2026 05:20:21 +0000
Received: from MW2PR12MB2508.namprd12.prod.outlook.com ([fe80::56bc:c104:6e90:8b08]) by MW2PR12MB2508.namprd12.prod.outlook.com ([fe80::56bc:c104:6e90:8b08%5]) with mapi id 15.20.9654.020; Mon, 2 Mar 2026 05:20:21 +0000
From: Michael Jones <michael_b_jones@hotmail.com>
To: Rifaat Shekh-Yusef <rifaat.s.ietf@gmail.com>, oauth <oauth@ietf.org>
Thread-Topic: [OAUTH-WG] Shepherd Review - Updates to JWT Client Authentication and Assertion-Based Authorization Grants
Thread-Index: AQHcpPs4hW8JUq8txkixHrrgK4Jr7rWamzlwgAAjIgA=
Date: Mon, 02 Mar 2026 05:20:21 +0000
Message-ID: <MW2PR12MB25080DBEA076B4D7409841F3B77EA@MW2PR12MB2508.namprd12.prod.outlook.com>
References: <CADNypP9s3GX355yWhvuVMkfUv2FE-t_hxQE5ORXD6vBYETW9pw@mail.gmail.com> <BL0PR12MB24998FCB664BE141FED19E7FB77EA@BL0PR12MB2499.namprd12.prod.outlook.com>
In-Reply-To: <BL0PR12MB24998FCB664BE141FED19E7FB77EA@BL0PR12MB2499.namprd12.prod.outlook.com>
Accept-Language: en-US
Content-Language: en-US
X-MS-Has-Attach:
X-MS-TNEF-Correlator:
x-ms-publictraffictype: Email
x-ms-traffictypediagnostic: MW2PR12MB2508:EE_|PH7PR12MB5808:EE_
x-ms-office365-filtering-correlation-id: ff9b2bd1-ca5c-4bd2-1c97-08de781b6676
x-microsoft-antispam: BCL:0;ARA:14566002|12050799012|13091999003|8062599012|8060799015|19110799012|15080799012|31061999003|461199028|9400799043|10035399007|440099028|3412199025|102099032|19061999003|52005399003|40105399003;
x-microsoft-antispam-message-info: hwqg97o4Kx0lizvFcRrO3BVXmQ/FjzDxMOnOhhqLOCzQsBNKXc2IYzbx5Pl2jPvrnmy6QMJdTC4S7ruf5+Sep1LclxrOs2MKOW3llpkqIbf09i2i74L3RMG6oTMaXfmIog7vjbSwhVviwyMHRn579KMxnvfEmFJflL9ZYwIDKt6fItx2hB8/k0RlXXZYHlZxabydCE63sCchUoGQ6TjXWIuZvCnqmEOaV51Xkska9VqHFdgtrbcZ64ejQT4GswWnM23H0Gc9zEt4bomyQqHNMcyQNSXS4Bl9HBRnGceY0Xx8r1KPFHUHOu5PIJrulW8e6js0NpIVji8dWAuOQgfA7cr6cy36hSx2f+k4zEbXsyfCfZ3Y2mY5c8rpX1rhKJH/lplkmbLhnQc9uQiUNwej2iHJpxqgtvi98OZ4/srnbf/dHEwnGJr9Ss1SyLdnD5evq7Psy2GTJIe0XdAb1uDgYEnwJnP/W9eNjU5SEaN2YuvwRVDCRJgXsWDx/Xk/J6OucIUvjDoDMnT99jS0ihRG79JCt+VksXtYJi5Ef7IGPYmn/Re47qkKZVmU564HVu2CwvFsROtvUMHkFTo75G1HgXBvCZaG9i0WlC5VLzJwGd7JC/QC/tU5+/6A6vePtgoWnUi1rHHFgMGXu4cU1o8BphrhXX5xCYZb6AnQl3/8TO/4M+XFq+PKoOLJxn2O5bCvICxHj3xJePREq5yPp0fmYpfUfSAyERK6ctnhCcuvJlpzJlAYX0KYA140giRgqmj+Aw4tCYh/enW0e9Y1ZxfGEcku5ExzWpjcxGsFvPqeY04c1QtqZ6D5gd/sMOiTDh3wN8r2N+lf1WGteOyORgu80HUephgMsJve3Jik5jTBUFQmB+HWALAZKt+pENbK7u8lWiyAp04OeEv/0pDOx9ErIfqrITnMFCq1NyHljJSalK2Nw3AwHmDSClY7Fe0PKIrTVfiBxBxgXVkTyoJh36bByb5u4vHRERyQmRBB7i5LHSRSYMYEWD8NCVWW9gE/SCU8QZC8KCqKw4/gB0cpM66vrWHMHi1g2elzeRwr0asKgYpRtiuJyRMApnLaDKF//ZHj
x-ms-exchange-antispam-messagedata-chunkcount: 1
x-ms-exchange-antispam-messagedata-0: 2Ni5EY17sGvBX230xBwiH7Du77hEu4p6q/C2U9XD5A4hik/szWOTSbfduIeJ8talo4IPAWs8QGxOYufDWnHWcHe8RPEt/OUFu5RKdyq5PeSZ1BVFxzqo90Kt1H+NSHBtD32yfG81po8wx2C7Oxbe35KUZfKXTHWpMyAywoCIqIqXLkoBGPWyZ+B+et5q1tiqlZCn2fukEdUaGHWu9h56rgoQuzK7ZhPbhuHnru/6+BwqMVa4PB1DKH1YvJGNeog5C6KVBhPSvvzJiiDImxIOd5D8TL2zdTDJ62O1jTkhEQMd3Ht6K4y3cHVAREYmVIK25MKg98qAtW+RN5pYIbTf7i2BLsHqA8TNTyLoyBkAGqa6rH+NFPVh5/qKv80ROCvkmox0woG+MB6dOMwWbA5qo1QQ49zPlwgo96E2e3r2jYVBdbXU47AXN/I5ezNzXZdW51h6ZVn1Un/wI8Nj0moKJSD8pVnMopNAxEcVFjISLl9yi+XZhyGETWVGtK5Hjjm1xwHaux/zPcZmifHIDaY7aQ1iS0Tf2a3/Qw0S/s3qoqmcTk/kj8z+JYsYvv8BuqjBQlFhu1OSn4r/ZvydMH+vN1H9mBFZlrFfhVaeWJwCnfGSY83Qb12q4tdsS02d0IoPT5sTP0aDxu7a739PeWI6U83z1I19GJpA1mowTfv1KM7C1rOZJqBHb+2nkWhqrkzun/gJk+6fyW4K5BySg89K3ojCFvxBfASwg7gVxRhmvoDxE3S6scAl8ApamwK56+EHI2Yi34pDrXUG9wzprx7PW97pLSoFdn+angjvuSal61tKOzeYBskbDQ+RnDWtC4XX3aMCAeiiwejPb4vx3ksjnuTgy+BVBa3/SluVGFXDKU3fR3l3TBw38AGMc3Bhm9XZnPeiEoZd5eTwnv1AKkgiUJS8fCFq3si0JJtplDS6YVz+CtiNvlltu7xhUauBUF4oERGKiqRxub03syMZxq6TUmSo0s+Rn7ZPDGI3/raMoMaeUqyWKC0A3XMDqk7xUkOJgdROBE2Czm59klpXki85hNIRxjx6VgKoOEogx31j6XF+8S/ZIPSe4CogRLaTwJuyHsibWSpqLmzEDGA/q3ZnvqV/pc04N22RapIfGhWnsqAb7IYTLmAz9PEhCb6FZciQndKxwl3DJXca9Isr5kiynFmsi9nyfm0pJtmymZBPtpPyDKXrQqI2Z0Pb34e1tkYHjCEA4XOOTiFJ/VQPWLK9HvTmZvfLb/+TiKXjv/VMSja1quVwMyP1Tqs3R8ZbtQZAC/yvSlesbLdJiNH6e/1e7E+WyQDBihldN19i3ijtFeNOrJRxwYX24S7+jHdHDUo+jpj/nlUFMQx6sXWU9ONzUd42QrYtbjK9eDRy7nawaQJTHNi6iC5w24OmXI961ENM
Content-Type: multipart/alternative; boundary="_000_MW2PR12MB25080DBEA076B4D7409841F3B77EAMW2PR12MB2508namp_"
MIME-Version: 1.0
X-OriginatorOrg: sct-15-20-9412-4-msonline-outlook-10359.templateTenant
X-MS-Exchange-CrossTenant-AuthAs: Internal
X-MS-Exchange-CrossTenant-AuthSource: MW2PR12MB2508.namprd12.prod.outlook.com
X-MS-Exchange-CrossTenant-RMS-PersistedConsumerOrg: 00000000-0000-0000-0000-000000000000
X-MS-Exchange-CrossTenant-Network-Message-Id: ff9b2bd1-ca5c-4bd2-1c97-08de781b6676
X-MS-Exchange-CrossTenant-originalarrivaltime: 02 Mar 2026 05:20:21.1287 (UTC)
X-MS-Exchange-CrossTenant-fromentityheader: Hosted
X-MS-Exchange-CrossTenant-id: 84df9e7f-e9f6-40af-b435-aaaaaaaaaaaa
X-MS-Exchange-CrossTenant-rms-persistedconsumerorg: 00000000-0000-0000-0000-000000000000
X-MS-Exchange-Transport-CrossTenantHeadersStamped: PH7PR12MB5808
Message-ID-Hash: HPTD3UFPXY4DE6O73T4MDXVTOWDQQNZC
X-Message-ID-Hash: HPTD3UFPXY4DE6O73T4MDXVTOWDQQNZC
X-MailFrom: michael_b_jones@hotmail.com
X-Mailman-Rule-Misses: dmarc-mitigation; no-senders; approved; emergency; loop; banned-address; member-moderation; header-match-oauth.ietf.org-0; nonmember-moderation; administrivia; implicit-dest; max-recipients; max-size; news-moderation; no-subject; digests; suspicious-header
X-Mailman-Version: 3.3.9rc6
Precedence: list
Subject: [OAUTH-WG] Re: Shepherd Review - Updates to JWT Client Authentication and Assertion-Based Authorization Grants
List-Id: OAUTH WG <oauth.ietf.org>
Archived-At: <https://mailarchive.ietf.org/arch/msg/oauth/LO6XukEnYw62UpMPI4y4oPAGRs0>
List-Archive: <https://mailarchive.ietf.org/arch/browse/oauth>
List-Help: <mailto:oauth-request@ietf.org?subject=help>
List-Owner: <mailto:oauth-owner@ietf.org>
List-Post: <mailto:oauth@ietf.org>
List-Subscribe: <mailto:oauth-join@ietf.org>
List-Unsubscribe: <mailto:oauth-leave@ietf.org>

Your shepherd comments are applied in https://github.com/oauth-wg/draft-ietf-oauth-rfc7523bis/pull/25, Rifaat.  Please review.

                                                                Thanks,
                                                                -- Mike

From: Michael Jones
Sent: Sunday, March 1, 2026 7:40 PM
To: 'Rifaat Shekh-Yusef' <rifaat.s.ietf@gmail.com>; oauth <oauth@ietf.org>
Subject: RE: [OAUTH-WG] Shepherd Review - Updates to JWT Client Authentication and Assertion-Based Authorization Grants

Thanks for your review, Rifaat.  Replies inline prefixed by "Mike>".

From: Rifaat Shekh-Yusef <rifaat.s.ietf@gmail.com<mailto:rifaat.s.ietf@gmail.com>>
Sent: Monday, February 23, 2026 11:32 AM
To: oauth <oauth@ietf.org<mailto:oauth@ietf.org>>
Subject: [OAUTH-WG] Shepherd Review - Updates to JWT Client Authentication and Assertion-Based Authorization Grants

Hi,

As the shepherd for this document, I have reviewed version 05 of the draft
https://www.ietf.org/archive/id/draft-ietf-oauth-rfc7523bis-05.html

and I have the following comments/questions:

Section 3
It is RECOMMENDED that SAML Bearer Assertions not be used for client authentication.

Should the RECOMMENDED be a MUST? If not, can you add some text to explain when SAML Bearer Assertions could still be used?
Mike> How about we change it to say:
It is RECOMMENDED that SAML Bearer Assertions not be used for client authentication for any new applications.  (The authors are not actually aware of any applications using this feature of RFC 7522.)  Should any applications already be doing this in the manner described in RFC 7522, it is left to the discretion of their implementers and deployers whether to migrate away from this feature and/or potentially tighten the audience values used in a manner parallel to the changes being made in RFC 7523.

Section 5, Second paragraph,
"The paragraph describing the audience value in Section 2"

You might want to explicitly state which paragraph this is referring to.
Mike> How about we change it to say:
The last paragraph of Section 2 of [RFC9126] , which describes the audience value, is replaced by:


Section 5, Last paragraph,
"Client authentication JWTs SHOULD be explicitly..."

Can you elaborate on what this is a "SHOULD" to make it clear to the implementer?
Mike> The previous paragraph, beginning "The introduction of strong typing for JWTs" already gives ample reasons why this should be done but is not required.  I don't believe any additional text is needed in this case.

Section 8.2

It seems to me that the following references should be moved to the Normative References section:
IANA.MediaTypes, IANA.OAuthParameters, OpenID.Core, RFC2046, and RFC6838
I agree with you about OpenID.Core because implementers need to use normative definitions contained in it.  The other references are only used to inform the IANA registrations - not implementers, and so need not be normative.  It's not customary to make such references normative.  (Of course, if the IESG disagrees, we can always do this later.)


Regards,
 Rifaat

I will create a PR applying these proposed changes later this evening.

                                                                Thanks again,
                                                                -- Mike