Re: [OAUTH-WG] Call for adoption: Token Binding for OAuth 2.0

Brian Campbell <bcampbell@pingidentity.com> Thu, 04 August 2016 16:11 UTC

Return-Path: <bcampbell@pingidentity.com>
X-Original-To: oauth@ietfa.amsl.com
Delivered-To: oauth@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 0F1A312D63E for <oauth@ietfa.amsl.com>; Thu, 4 Aug 2016 09:11:24 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.7
X-Spam-Level:
X-Spam-Status: No, score=-2.7 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, HTML_MESSAGE=0.001, RCVD_IN_DNSWL_LOW=-0.7, SPF_PASS=-0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (1024-bit key) header.d=pingidentity.com
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id Zb6NEDL35EJj for <oauth@ietfa.amsl.com>; Thu, 4 Aug 2016 09:11:22 -0700 (PDT)
Received: from mail-io0-x235.google.com (mail-io0-x235.google.com [IPv6:2607:f8b0:4001:c06::235]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 79E0612B007 for <oauth@ietf.org>; Thu, 4 Aug 2016 09:11:20 -0700 (PDT)
Received: by mail-io0-x235.google.com with SMTP id 38so275230523iol.0 for <oauth@ietf.org>; Thu, 04 Aug 2016 09:11:20 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=pingidentity.com; s=gmail; h=mime-version:in-reply-to:references:from:date:message-id:subject:to :cc; bh=0lxGT0qEvKKSCT4TW/t3cAga4dA+nZvgf/s6zohioz8=; b=C48wlST4CmMMUbRoaN99TfhOE+gi5dCe5JT3/1bg7ixKqJq6Bxa3S0H0AgWl2NiM55 1nsruUL+btIO39bJNQOnYzVoUMd7faENxN5xlns+wC9jyzTJpdg6iBw1p5JjPNxBZSxZ +ox02P+gyEDC9Z5QbzEv05mx+TVUv4WvaaC0E=
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20130820; h=x-gm-message-state:mime-version:in-reply-to:references:from:date :message-id:subject:to:cc; bh=0lxGT0qEvKKSCT4TW/t3cAga4dA+nZvgf/s6zohioz8=; b=EVRzD0Ystwiz6BmhQpk6+GbpUBcRJMBocRDVvfGUTFxJoDFW+1GlZCZx/5tc6Tx/vV 2uGK5jq7cJ+xp0+XX78iIQmJdKKJKfC1u0/v1l8nxkZnu9CkIAmPmtcf9qKJRlsDACeB /UlaeNmG9QHidN+kkWwzrVIychCLBmIQiXoi38PTr1WbNOqxMyLL4k9sgWt1dqVJGANP 01bdlC5ASa3AtU3D7NlVPhIbp7fZkH5ux0i6P2lY//zcFQmEJ0P1ZeQDFybRZ1q+clzz o6oGRQ3VvyS82a5bqfQKlDByhF7bPtGljDcP4qhbYG6JQ6PFSINYrogzjP0LpfyB1JXh rPzw==
X-Gm-Message-State: AEkooutSI7BPeX4IRFu5dHUAUzzh56dMLdAMieJhfQWDZcjWkVKcPsINhpRzi4E6Nc7Hdz7UFDVd4z3slOWLvaIG
X-Received: by 10.107.50.19 with SMTP id y19mr71400028ioy.174.1470327079711; Thu, 04 Aug 2016 09:11:19 -0700 (PDT)
MIME-Version: 1.0
Received: by 10.79.123.14 with HTTP; Thu, 4 Aug 2016 09:10:49 -0700 (PDT)
In-Reply-To: <33052033-0992-ceb8-4390-6837017b140e@gmx.net>
References: <33052033-0992-ceb8-4390-6837017b140e@gmx.net>
From: Brian Campbell <bcampbell@pingidentity.com>
Date: Thu, 04 Aug 2016 10:10:49 -0600
Message-ID: <CA+k3eCSOzSQGqrwV65JUUA4r=UNGvwkPxxri1pYMatAAnZnM3Q@mail.gmail.com>
To: Hannes Tschofenig <hannes.tschofenig@gmx.net>
Content-Type: multipart/alternative; boundary="001a114469c44a556005394133a0"
Archived-At: <https://mailarchive.ietf.org/arch/msg/oauth/ORF_t6IIr7zdpyk8lgTU0yZIuck>
Cc: "oauth@ietf.org" <oauth@ietf.org>
Subject: Re: [OAUTH-WG] Call for adoption: Token Binding for OAuth 2.0
X-BeenThere: oauth@ietf.org
X-Mailman-Version: 2.1.17
Precedence: list
List-Id: OAUTH WG <oauth.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/oauth>, <mailto:oauth-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/oauth/>
List-Post: <mailto:oauth@ietf.org>
List-Help: <mailto:oauth-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/oauth>, <mailto:oauth-request@ietf.org?subject=subscribe>
X-List-Received-Date: Thu, 04 Aug 2016 16:11:24 -0000

I accept these documents as a starting point of the Token binding work in
OAuth.

With emphases on "starting point" because even the initial discussions
about the work in Berlin uncovered changes that'll be necessary or
desirable.

On Wed, Aug 3, 2016 at 1:45 AM, Hannes Tschofenig <hannes.tschofenig@gmx.net
> wrote:

> Hi all,
>
> this is the call for adoption of the 'OAuth 2.0 Token Binding' document
> bundle* following the positive call for adoption at the recent IETF
> meeting in Berlin.
>
> Here are the links to the documents presented at the last IETF meeting:
> https://tools.ietf.org/html/draft-jones-oauth-token-binding-00
> https://tools.ietf.org/html/draft-campbell-oauth-tbpkce-00
>
> Please let us know by August 17th whether you accept / object to the
> adoption of this document as a starting point for work in the OAuth
> working group.
>
> Ciao
> Hannes & Derek
>
> *: We will find out what the best document structure is later, i.e.,
> whether the content should be included in one, two or multiple documents.
>
>
> _______________________________________________
> OAuth mailing list
> OAuth@ietf.org
> https://www.ietf.org/mailman/listinfo/oauth
>
>