Re: [OAUTH-WG] draft-ietf-oauth-rar use of “WWW-Authenticate” Response Header

"Oliva Fernandez, Jorge" <Jorge.OlivaFernandez@santander.co.uk> Fri, 26 May 2023 08:14 UTC

Return-Path: <prvs=503ba9c59=Jorge.OlivaFernandez@santander.co.uk>
X-Original-To: oauth@ietfa.amsl.com
Delivered-To: oauth@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 5EF54C1519A3 for <oauth@ietfa.amsl.com>; Fri, 26 May 2023 01:14:36 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -7.093
X-Spam-Level:
X-Spam-Status: No, score=-7.093 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIMWL_WL_HIGH=-0.001, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, HTML_MESSAGE=0.001, RCVD_IN_DNSWL_HI=-5, RCVD_IN_MSPIKE_H5=0.001, RCVD_IN_MSPIKE_WL=0.001, RCVD_IN_ZEN_BLOCKED_OPENDNS=0.001, SPF_NONE=0.001, URIBL_BLOCKED=0.001, URIBL_DBL_BLOCKED_OPENDNS=0.001, URIBL_ZEN_BLOCKED_OPENDNS=0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (2048-bit key) header.d=santander.co.uk header.b="iUvC1f9P"; dkim=fail (1024-bit key) reason="fail (message has been altered)" header.d=santandernet.onmicrosoft.com header.b="GSUYmR1G"
Received: from mail.ietf.org ([50.223.129.194]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id oNma_iK4RBDR for <oauth@ietfa.amsl.com>; Fri, 26 May 2023 01:14:32 -0700 (PDT)
Received: from esa12.santandergroup.c3s2.iphmx.com (esa12.santandergroup.c3s2.iphmx.com [216.71.158.118]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id DE35EC14CF0D for <oauth@ietf.org>; Fri, 26 May 2023 01:14:31 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=simple/simple; d=santander.co.uk; i=@santander.co.uk; q=dns/txt; s=prod.june.2017.ab; t=1685088872; x=1716624872; h=from:to:cc:date:message-id:references:in-reply-to: mime-version:subject; bh=UPNRGnBAui2ydczIfg9xk3rBNGkdx52tV6SVOr113VU=; b=iUvC1f9PuylMqEb79USkTuyiewlp2hNREnmkoJUj3NhHepzi031DRPVo v9QIUoiXgAaGok71MPZeVTFZBMylg9CbMV/KDtUa+85iTYlnXMzFkvJup NiPCTugnE/nme6BlPi9qDvbWdu6MOnxzHIT2twmojwESXCAnLGy4I/0QS ozoWtxM/1f3P50573tVS2G8Mgf2sthLitpvSDmvhjCNk84jEDiPV4xhzk 65WHT0jFI9bwGg6Fb/DA+WO/l8Mrt4Nry+e2uPdAlmexenmOyvyPGhxcg N6qb1groMCNswVVAvuzlsnnhIEOrx/RQFYRDo8Jsc/2xt/4oblCPRHRks Q==;
Received: from unknown (HELO srvexgpvwsk06.santanderuk.corp) ([195.43.49.198]) by ob1.santandergroup.c3s2.iphmx.com with ESMTP/TLS/ECDHE-RSA-AES256-GCM-SHA384; 26 May 2023 10:14:21 +0200
Received: from MAISRVCPRWSK31.sanuk.santanderuk.corp (107.15.166.1) by srvexgpvwsk06.santanderuk.corp (10.10.157.16) with Microsoft SMTP Server id 15.2.1118.26; Fri, 26 May 2023 09:14:20 +0100
Received: from MAISRVCPRWSK15.sanuk.santanderuk.corp (107.15.75.25) by maisrvcprwsk31.sanuk.santanderuk.corp (107.15.75.32) with Microsoft SMTP Server (TLS) id 15.0.1497.48; Fri, 26 May 2023 09:14:20 +0100
Received: from srvexgpvwsk07.santanderuk.corp (10.10.157.17) by MAISRVCPRWSK15.sanuk.santanderuk.corp (107.15.75.25) with Microsoft SMTP Server (TLS) id 15.0.1497.48 via Frontend Transport; Fri, 26 May 2023 09:14:20 +0100
Received: from EUR05-AM6-obe.outbound.protection.outlook.com (10.10.157.4) by smtp-eol.santander.co.uk (10.10.157.17) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.2.1118.26; Fri, 26 May 2023 09:14:19 +0100
ARC-Seal: i=1; a=rsa-sha256; s=arcselector9901; d=microsoft.com; cv=none; b=JPZUbZUmck/EN7qtXLyGHaMNnhVBXiJ5BXWJryj8MHAi41wzZNTbHEJ2OKdm0C/mD5mx+REqB/R92JhDoH1znJwGJqJVPtrnnIqM2WtkSxssSwUey+tTNH/MeqxEt+fknAnJsl1R/JMLJzYPRPLLZeoJzJ9o/+yL5x2t/mk7KwOWDETnUzQq6+YTBlH/i581G5+ovJk53pXC+3LfnLboJ9TZu+kUZMkyBlKfj+IoKkLFx6ePIUGhZ7WM94dDUMd3ZdTmnvVPUVMNT3lgGexYQDmXCS0m9DiCLbg1mQ8mQx3cH9JD2VMumcqzoIZ9DcSeq43oSZk1w9T8YiLrZQE/MA==
ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=microsoft.com; s=arcselector9901; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-AntiSpam-MessageData-ChunkCount:X-MS-Exchange-AntiSpam-MessageData-0:X-MS-Exchange-AntiSpam-MessageData-1; bh=n3CLvROIBNfgPE13ke/G/T5LhzB+6SFz6z1ZaFlQ478=; b=GHxCPTDnusawrgFe0M9bufIWbMhwPY3R5eB1SvHoX+uf4F1+rHeDzGwbnY0ZwmTexlVwkEX3RJCoTzhzqdu/VlAkVEz7xfYpQUmAUC59F2G66VmcJe+gv0FB6AvlY/wOO2sVqX+QZO6KTPRZB0y1nlnW1s6ZNZABzJAD6foLosqQtKqo3eMcUcZIKNE9KLBHRjBo89nwyYtv4RdGVS/upV6uZ32800q6BnSCsUzNJrgEEmQvHjVtYr7R0G328rJ02w1eeuyKofFnlaN8qqzOklvACJHrTbXkj1XgVnRBI0+4HH4GakN+PjhoX812MLVduoQjDIY6JBKidMkt9b8s0g==
ARC-Authentication-Results: i=1; mx.microsoft.com 1; spf=pass smtp.mailfrom=santander.co.uk; dmarc=pass action=none header.from=santander.co.uk; dkim=pass header.d=santander.co.uk; arc=none
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=santandernet.onmicrosoft.com; s=selector2-santandernet-onmicrosoft-com; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-SenderADCheck; bh=n3CLvROIBNfgPE13ke/G/T5LhzB+6SFz6z1ZaFlQ478=; b=GSUYmR1GcTMnbX9eoa/MzV/KiVKhmJrsvkNyOWBHGnjYwVQT4A6N3yI904D135fWbkWEd0kGeEfKTGVMcb+MsKuCjmxciW+NNbPr7GvehdyujBKHyd5352XDF8FAOgyxBp/NCV+R17R3WLufvl5cy8ENhB5yhsQk9gyVfKd8WBs=
Received: from DB8PR04MB6681.eurprd04.prod.outlook.com (2603:10a6:10:10f::33) by AS8PR04MB7558.eurprd04.prod.outlook.com (2603:10a6:20b:23c::7) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.20.6411.29; Fri, 26 May 2023 08:14:13 +0000
Received: from DB8PR04MB6681.eurprd04.prod.outlook.com ([fe80::87e:2ed6:4570:6dcb]) by DB8PR04MB6681.eurprd04.prod.outlook.com ([fe80::87e:2ed6:4570:6dcb%7]) with mapi id 15.20.6433.018; Fri, 26 May 2023 08:14:13 +0000
From: "Oliva Fernandez, Jorge" <Jorge.OlivaFernandez@santander.co.uk>
To: Brian Campbell <bcampbell=40pingidentity.com@dmarc.ietf.org>
CC: "oauth@ietf.org" <oauth@ietf.org>
Thread-Topic: [EXT]Re: [OAUTH-WG] draft-ietf-oauth-rar use of “WWW-Authenticate” Response Header
Thread-Index: AQHZjvo9ScjbHmgd+EuuluxD1c4KpK9rcUuAgADVnAA=
Date: Fri, 26 May 2023 08:14:12 +0000
Message-ID: <0E64099F-0A54-4A56-A022-97A35D30C1D9@santander.co.uk>
References: <41869F2A-F0B1-4409-8739-5BB3A820CBF6@santander.co.uk> <CA+k3eCTWLVns4dAL-ant4Qh_Ler_eYFTx9UBUB3Uv5L-+ZRn+g@mail.gmail.com>
In-Reply-To: <CA+k3eCTWLVns4dAL-ant4Qh_Ler_eYFTx9UBUB3Uv5L-+ZRn+g@mail.gmail.com>
Accept-Language: en-GB, en-US
Content-Language: en-GB
X-MS-Has-Attach:
X-MS-TNEF-Correlator:
authentication-results: dkim=none (message not signed) header.d=none;dmarc=none action=none header.from=santander.co.uk;
x-ms-publictraffictype: Email
x-ms-traffictypediagnostic: DB8PR04MB6681:EE_|AS8PR04MB7558:EE_
x-ms-office365-filtering-correlation-id: ad3e083c-893e-454f-98f7-08db5dc130a0
x-ms-exchange-senderadcheck: 1
x-ms-exchange-antispam-relay: 0
x-microsoft-antispam: BCL:0;
x-microsoft-antispam-message-info: dZ1jBynK/VPSPPTY+MSAcdK6AiS/pVSMpAq8Bgrk3USu4fcjICRnumX+hUzTK3eCCJ+u9BXg2QNbeuPXxzud/EbxGa4tF5XPJ/EF5k/VnyNn8n31p4ajgwlm+14gHP77fsAH1z2UWl7ymnane4g6Alepl/TPwoG/9tWWT+2lrjX782JGUGTZSjZ/Rki1pRoGDcu0YNoCNB7xoXpyu4s8IJLxaOoXhUP0iovOra1KjgLK9zAsmelmQwc3lYBrG5nbQfj0lUKqaiquGR+17TcZTOUfPcTQ88c7Z+553skcnqs+AXwZIxY3QBLkK3S4ywXIJWQtIk2DpmpMZLwwuuvKsdN2k2ANNBAiapIOJJ93plYcevrJAg2rIdKTSPCrOcYa7YIV7qF8Gc+mvuWlZqJVBLN+kAN0q507nv9KR7+PxSYKukRP5RSrXIwzX+3jr3wUH2y3XrCLaUWprKA0VEpSM6x3FTOPLYtnX8x1oJfkCubGuDVIO/WEwSJAKb4UAPVH9ki+aCpZpvsUPZmlXoym36+U2SR+kUn5K6G/ADKdxqhkJRTxdBfETCre5x4JcweZ7dljty5Qel+zXqMGR25wYFdAzCiFa5qCbM2ujl1PoVfBpdISnVD5BOnj5HAPrIii/PWK+ieR8sBnxOeScxOb8flK7/6FjHh70JpJ9gFnnxA=
x-forefront-antispam-report: CIP:255.255.255.255; CTRY:; LANG:en; SCL:1; SRV:; IPV:NLI; SFV:NSPM; H:DB8PR04MB6681.eurprd04.prod.outlook.com; PTR:; CAT:NONE; SFS:(13230028)(4636009)(376002)(39860400002)(366004)(136003)(346002)(396003)(451199021)(38070700005)(6506007)(26005)(53546011)(6512007)(41300700001)(186003)(166002)(8936002)(5660300002)(2616005)(316002)(86362001)(36756003)(38100700002)(76116006)(966005)(10300500001)(64756008)(66946007)(83380400001)(66446008)(4326008)(66556008)(66476007)(122000001)(91956017)(6486002)(10290500003)(478600001)(82960400001)(33656002)(2906002)(71200400001)(45980500001); DIR:OUT; SFP:1102;
x-ms-exchange-antispam-messagedata-chunkcount: 1
x-ms-exchange-antispam-messagedata-0: +nFMfUx29hGVT0nJ70qFmPvtwWroEuuNsKcPx/ghlYKotVsGjgTXZrUxjCed+KZYeR5wnuetRTljPG1DBF5nwZ7mFcxUOFLnr7sV0bxkSj76uE1GSwWXRDKyZfsPlow6ZVc3/HaHqOSWMTfZo3rC17585YGaJ6tgDtSrbWFQJD314DcOy98943BnBtJ6jfnJyIMmROi1yinrzoD8P9Qsr1YI5uIoxO5RetFh2vTVgTZALpgQbTGdFh/Dqvddsf4k7WuUgdV4NExI4MYGid4GMj1GPciY7X+XTkSpCZW7Cdkq/SUYrGMxxXBo4+7+Xe16cntdMIvNLqgvCugCNX3CuJFDfxITRpXovbuhVxSC5ybBPhyewnND8tap7zKw6w3VJ+vb7HK2FJ8qfwGIvRAS/W106Pe6DZgxwJ74lO0gP2dNjCbuh1XJfhPm8MqwuZ5jHHRLuNa/W4hNmMl759PQPe3zii4jSb3201yw+UQBt8xAmJ/6DD41Tn9xYG+hw80d9bXZU94Foe6AjOujK30+X4/DPco73CCcPbTkVpzA0Hgeh6xz1HfpVXzpDNJPB1f/ugbevLg76uaWihNcl7BRLe7KgYJxJjwRdiKtWHQqvz1l9UqfzdZEWiMgCrDrBFxOn2j0PU5reG5yM8wA510Xt8N0rJFiSgA+NrQCVwPTG0aoUtWaHg29+DGaBmoTbTx7RimRjkpWSpJKZ6N2jwTDWH6v1gOhzlm+m6drfJDoD7thJ3U/eFEBoQiUY6lJ2dWIi0qDlTQJwvt9ymgWoE2w8jR+Wvy9cGGPi4T5QZn3Kh4GJsjJkAq6kIW5KqVSOoF1q/KAtweSRzuSVkzHUTzeBfJHKM3mvoam3FRm8XOBJBMc2ANr8ApVmH22u9ezs2EXrnVtDHci7higONMuSg1iT+Hu3OWowBjnRowohI4zjy3Q3j0CHSt/7dgUYvpJmRDZEXfk/URvFzXrLHiW95PzJILDc3sZkSdVQCRuDwQHGs2w9/aP9VK/jaqGmrJqTM+HHNcc5oW2UQACFKqu2A/rXzWIeesNGUSDgQnvaiFRlctSwmv0xo7/xxr7fTv9IwUSs6yhZlTEvytt5mRy/ekshMCUv++Q3NQ5/wR5b8941SyAUToOQy91WaPycSJM6mjLEK/pkxOxeg+SvOX9n2nYYKqppKn1DvxTt927swpJSjk6nBU9jyukZ9FYvoFFMo0+B8lTswYH/+BdEtSJ6sGnbnfKW5GCYM+c0Wjofi9Apo6s35H3OymPd0+yNWiiAniqQOHDDPh8GyzGu/2A0K/rnS8PU2AU6IPPAvwvyp/IzMs/77EaHac4Ajbw41H7LymmJ2tIs3XZeHkaVcnCZfZqBJakjP2iCEgl2HVv0mICNcfC7d+V5Ov2h5bpT7TK//4mSTNBDLVrBoPPpOOBN7cLpgoMK4rk2bayNIuDFZZObeY8+PH4VrugHIJ3Ag7Pus/GZpfIpNz9WInY9P2dq8nla5X6+sEE82M/xwlgCBPixaYdfw12Jyxd3+6e/weRcMi4YHzB9T6TYu6i0HgtQSx6Hba27aMoHEs9sk29wTGnnt7gfdeNgYtP5QjP2RrkLwDYWZ9beC8I8RBB4zuqOHnOJdycS/8rasAnIXbb95yNNTk=
Content-Type: multipart/alternative; boundary="_000_0E64099F0A544A56A02297A35D30C1D9santandercouk_"
MIME-Version: 1.0
X-MS-Exchange-AntiSpam-ExternalHop-MessageData-ChunkCount: 1
X-MS-Exchange-AntiSpam-ExternalHop-MessageData-0: N6eLn/ecMRI47JxuOXjsPI3Cep3gZet+9BNMNXCSegBvjMgSr0CBCRVRk9Tks2JjeqDiBGgpWEbEN+AVBoLsYFQaFgozvsL2OsVi820f4D70uEIbU1JUDpde2mpHH44u0Blwe84FF0W5YM/iLyJX9tRO8U2lo4SDjvnE/z76vOTKB6NXIj5HjXTfyoo086ywF9Bqcask85u/2vASi1XpD9vh0GoWqe3Mp2YriRa6BeXj+CHmuwpFB5A7WLc3RTSwjnZC+YmKGaEMljaiLVe409Hd1hj2m7zwU91O2wDu0S109DDDNqFgfoHsnAp6KYTDYnUDSCn5HSP6ytiCW6xGNMqnksxOwLcgZ+vcB7rNAvgdv5JIo89IBA/chvBoMGWjXVJMPFUZTTwYm1PoyAIhKfrl5+dlhpSPBwoZFpDib3eG9KM3+Vu22cPlm+eJ7dMPbo7i2P1mYwbJl9aWwqcBJsDDylDoXj61HJNiurYB3U/MKguSWEhe72gYyXPzw/j/pTxx6zSIICQ/SNxNGRYm7rdqjYw0xPFulQuy/Bd60wae5SXzLIeplYhNMGF+woAEim1mxob+FECc6e0OEQsgNT/6+w2q5ncSWno8qBqJLgmtkDciKoVezEgNbpxOd3vkrzEMLBVupqUHivLT4d+lLho/ncZP02oYCSRjkuPDmb+RaLOr/0rLvhbkum954rXmzD7OOsVk9puDHga08FakE31B1uOQvY/kqSfPX7R+VAIVUZQONMfrC5LAXyli5iEHzS3iezDrKLlHAYW2gI5AYpOv5Ji16tzj6HR34r/q1o0=
X-MS-Exchange-CrossTenant-AuthAs: Internal
X-MS-Exchange-CrossTenant-AuthSource: DB8PR04MB6681.eurprd04.prod.outlook.com
X-MS-Exchange-CrossTenant-Network-Message-Id: ad3e083c-893e-454f-98f7-08db5dc130a0
X-MS-Exchange-CrossTenant-originalarrivaltime: 26 May 2023 08:14:12.8425 (UTC)
X-MS-Exchange-CrossTenant-fromentityheader: Hosted
X-MS-Exchange-CrossTenant-id: 35595a02-4d6d-44ac-99e1-f9ab4cd872db
X-MS-Exchange-CrossTenant-mailboxtype: HOSTED
X-MS-Exchange-CrossTenant-userprincipalname: ivUgBSwC9mpQeN5orNbRWqiZSMHy6ej3XwnT71a8lAyT+c8QNo6VcJSq904MARRsUvwW7txT5JwqNu3KDvyRPNepMJPH1VLYicLfT2sqWbpIge4bbQrGYaay8XbIw3qx
X-MS-Exchange-Transport-CrossTenantHeadersStamped: AS8PR04MB7558
X-CFilter-Loop: Reflected
Archived-At: <https://mailarchive.ietf.org/arch/msg/oauth/QZW8PfyglTZIplofb_vE25P12Jk>
Subject: Re: [OAUTH-WG] draft-ietf-oauth-rar use of “WWW-Authenticate” Response Header
X-BeenThere: oauth@ietf.org
X-Mailman-Version: 2.1.39
Precedence: list
List-Id: OAUTH WG <oauth.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/oauth>, <mailto:oauth-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/oauth/>
List-Post: <mailto:oauth@ietf.org>
List-Help: <mailto:oauth-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/oauth>, <mailto:oauth-request@ietf.org?subject=subscribe>
X-List-Received-Date: Fri, 26 May 2023 08:14:36 -0000

Thanks for the answer, Bryan!

I’m not sure if I understand correctly, the authorization details are API-specific the same as the “scope” right? Let me know if I’m misinterpreting something but for me RAR is an evolution of the scope, because the scope parameter is not useful for complex authorization decision we introduce a new field, with a rich syntax to describe the operation that is going to be authorized, right? So, if OAuth define that the protected resource is able to indicate problems with the authorization bearer using the WWW-Authenticate Response Header Field, is not exactly the same case when a protected resource needs the rich authorization?

Best regards.

From: OAuth <oauth-bounces@ietf.org> on behalf of Brian Campbell <bcampbell=40pingidentity.com@dmarc.ietf.org>
Date: Thursday, 25 May 2023 at 21:30
To: "Oliva Fernandez, Jorge" <Jorge.OlivaFernandez=40santander.co.uk@dmarc.ietf.org>
Cc: "oauth@ietf.org" <oauth@ietf.org>
Subject: [EXT]Re: [OAUTH-WG] draft-ietf-oauth-rar use of “WWW-Authenticate” Response Header

CAUTION: This message is from an EXTERNAL sender – be vigilant, particularly with links and attachments. If you suspect it, report it immediately using the phishing button.
The thinking was generally that params of WWW-Authenticate Response Header Field weren't a great fit for rich JSON authorization data (both in syntax and semantics).  The authorization detail types are really API-specific things, and as a result, it's expected that the methods by which clients obtain or generate the authorization details are also API-specific. Not sure that exactly answers the question but hopefully helps.



On Thu, May 25, 2023 at 5:16 AM Oliva Fernandez, Jorge <Jorge.OlivaFernandez=40santander.co.uk@dmarc.ietf.org<mailto:40santander.co.uk@dmarc.ietf.org>> wrote:
Hi,

I have been reviewing the last RAR draft (https://datatracker.ietf.org/doc/html/draft-ietf-oauth-rar-23) and I was expecting to find some references about how to use the “WWW-Authenticate” Response Header Field defined in RFC6750 (https://datatracker.ietf.org/doc/html/rfc6750#section-3) in this document.

I think that RAR is a great idea for complex authorization where a “scope” is not enough to describe what you want to authorize, in OAuth 2.0 there exist a way for a protected resource to indicate what “scopes” are need it to consider the request “authorized”, should not be an standard way to do the same for rich authorization request?

Best regards.
Emails aren't always secure, and they may be intercepted or changed after they've been sent. Santander doesn't accept liability if this happens. If you think someone may have interfered with this email, please get in touch with the sender another way. This message doesn't create or change any contract. Santander doesn't accept responsibility for damage caused by any viruses contained in this email or its attachments. Emails may be monitored. If you've received this email by mistake, please let the sender know at once that it's gone to the wrong person and then destroy it without copying, using, or telling anyone about its contents.
Santander UK plc. Registered Office: 2 Triton Square, Regent's Place, London, NW1 3AN, United Kingdom. Registered Number 2294747. Registered in England and Wales. https://www.santander.co.uk. Telephone 0800 389 7000. Calls may be recorded or monitored. Authorised by the Prudential Regulation Authority and regulated by the Financial Conduct Authority and the Prudential Regulation Authority. Our Financial Services Register number is 106054. You can check this on the Financial Services Register by visiting the FCA’s website https://www.fca.org.uk/register.  Santander and the flame logo are registered trademarks.
Ref:[PDB#1-4B]
_______________________________________________
OAuth mailing list
OAuth@ietf.org<mailto:OAuth@ietf.org>
https://www.ietf.org/mailman/listinfo/oauth

CONFIDENTIALITY NOTICE: This email may contain confidential and privileged material for the sole use of the intended recipient(s). Any review, use, distribution or disclosure by others is strictly prohibited.  If you have received this communication in error, please notify the sender immediately by e-mail and delete the message and any file attachments from your computer. Thank you.
Emails aren't always secure, and they may be intercepted or changed after they've been sent. Santander doesn't accept liability if this happens. If you think someone may have interfered with this email, please get in touch with the sender another way. This message doesn't create or change any contract. Santander doesn't accept responsibility for damage caused by any viruses contained in this email or its attachments. Emails may be monitored. If you've received this email by mistake, please let the sender know at once that it's gone to the wrong person and then destroy it without copying, using, or telling anyone about its contents.

Santander UK plc. Registered Office: 2 Triton Square, Regent's Place, London, NW1 3AN, United Kingdom. Registered Number 2294747. Registered in England and Wales. https://www.santander.co.uk. Telephone 0800 389 7000. Calls may be recorded or monitored. Authorised by the Prudential Regulation Authority and regulated by the Financial Conduct Authority and the Prudential Regulation Authority. Our Financial Services Register number is 106054. You can check this on the Financial Services Register by visiting the FCA’s website https://www.fca.org.uk/register.  Santander and the flame logo are registered trademarks.


Ref:[PDB#1-4B]