Return-Path: <ve7jtb@ve7jtb.com>
X-Original-To: oauth@ietfa.amsl.com
Delivered-To: oauth@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com
 (Postfix) with ESMTP id 6C32B1A0426 for <oauth@ietfa.amsl.com>;
 Thu, 24 Apr 2014 16:07:13 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.9
X-Spam-Level: 
X-Spam-Status: No, score=-1.9 tagged_above=-999 required=5 tests=[BAYES_00=-1.9,
 HTML_MESSAGE=0.001, RCVD_IN_DNSWL_NONE=-0.0001, SPF_PASS=-0.001] autolearn=ham
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com
 [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id Zg7410w1YIUV for
 <oauth@ietfa.amsl.com>; Thu, 24 Apr 2014 16:06:57 -0700 (PDT)
Received: from mail-qg0-f44.google.com (mail-qg0-f44.google.com
 [209.85.192.44]) by ietfa.amsl.com (Postfix) with ESMTP id 5AF5F1A041C for
 <oauth@ietf.org>; Thu, 24 Apr 2014 16:06:57 -0700 (PDT)
Received: by mail-qg0-f44.google.com with SMTP id q108so3308274qgd.31 for
 <oauth@ietf.org>; Thu, 24 Apr 2014 16:06:50 -0700 (PDT)
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net;
 s=20130820;
 h=x-gm-message-state:content-type:mime-version:subject:from
 :in-reply-to:date:cc:message-id:references:to;
 bh=zvFDpSXHchGLkO2R8RtvVMvXCutMkroLRu0vx72BGgE=;
 b=GvNL5+hgRWc14NDBOzVm24hKDrS1VrfOEYJzlJ5mvp1VtMM2K5d3JOGTW0lrpAyUWP
 baNtHhly6NzbZNzBC/D5zezKhzaYXnHlwXbkqcN4QJts3r1BjvQwKVYAgcli1VYcqusz
 XH7uPDkfp5+6aUp9oUgJK37jf7m5+MEawfSMJ+EgCN1i9OiD4zXBMhV/ZMTnSgYeuInh
 Qqrm4Gbk1/H0Bq0vTa7ufR3yuavIJd7kr1nWsQvLZFV7oDsrA/tNmjcveA5oCy1tO2Af
 Vt7WHV4ydeIEBlYz7w6K4h0MypkViRXmY7JohOQFehb77NNadvKa6oqEqpSOGbWeec6G I5YQ==
X-Gm-Message-State: ALoCoQl36TBzepPtzN+Hgj5ySTnPJZZicZFzPoUY9LvAUk0RqBg5JKIPg1j0AZ663g1bt3OMgsoR
X-Received: by 10.224.126.9 with SMTP id a9mr6984347qas.39.1398380810786;
 Thu, 24 Apr 2014 16:06:50 -0700 (PDT)
Received: from [192.168.0.200] ([201.188.30.118]) by mx.google.com with
 ESMTPSA id z6sm10591528qal.6.2014.04.24.16.06.45 for <multiple recipients>
 (version=TLSv1 cipher=ECDHE-RSA-RC4-SHA bits=128/128);
 Thu, 24 Apr 2014 16:06:50 -0700 (PDT)
Content-Type: multipart/alternative;
 boundary="Apple-Mail=_FCF49E0E-44B6-42C3-B027-A184D1C84F2E"
Mime-Version: 1.0 (Mac OS X Mail 7.2 \(1874\))
From: John Bradley <ve7jtb@ve7jtb.com>
In-Reply-To: <4E1F6AAD24975D4BA5B16804296739439A194E11@TK5EX14MBXC288.redmond.corp.microsoft.com>
Date: Thu, 24 Apr 2014 20:06:45 -0300
Message-Id: <7522503E-3D27-4223-8907-1BEBFD5E877C@ve7jtb.com>
References: <5357AA4C.8080707@gmx.net>
 <CA+k3eCR5LKBugDicdAdGRx7Z+G_a7Rdh4=NCY9v0ye-vyncWzQ@mail.gmail.com>
 <5358B907.3030905@gmx.net>
 <4E1F6AAD24975D4BA5B16804296739439A194E11@TK5EX14MBXC288.redmond.corp.microsoft.com>
To: Michael Jones <Michael.Jones@microsoft.com>
X-Mailer: Apple Mail (2.1874)
Archived-At: http://mailarchive.ietf.org/arch/msg/oauth/T0KZZF8bzv-y_kLi2co26GAk_58
Cc: "oauth@ietf.org" <oauth@ietf.org>
Subject: Re: [OAUTH-WG] draft-ietf-oauth-json-web-token-19 Shepherd Write-up
X-BeenThere: oauth@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: OAUTH WG <oauth.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/oauth>,
 <mailto:oauth-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/oauth/>
List-Post: <mailto:oauth@ietf.org>
List-Help: <mailto:oauth-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/oauth>,
 <mailto:oauth-request@ietf.org?subject=subscribe>
X-List-Received-Date: Thu, 24 Apr 2014 23:07:14 -0000
X-List-Received-Date: Thu, 24 Apr 2014 23:07:14 -0000

--Apple-Mail=_FCF49E0E-44B6-42C3-B027-A184D1C84F2E
Content-Transfer-Encoding: quoted-printable
Content-Type: text/plain;
	charset=windows-1252

+1

On Apr 24, 2014, at 7:32 PM, Mike Jones <Michael.Jones@microsoft.com> =
wrote:

> Thanks for doing this, Hannes.  I would suggest making the following =
changes...
> =20
> Change =93It allows OAuth deployments to use a standardized access =
token format, which increases interoperability of OAuth-based =
deployments=94 to =93It defines a standard JSON-based security token =
format, increasing interoperability both among OAuth deployments using =
it and in other application contexts as well=94.
> =20
> I would change http://openid.net/developers/libraries/ to =
http://openid.net/developers/libraries/#jwt (adding the #jwt target =
within the page).
> =20
> I would change =93The draft authors believe that this document is =
ready for publication=94 to =93The document is ready for publication=94.
> =20
> I would change the answer to (15) to say nothing about ECMAScript, =
since it is not a downref, and to only say =93RFC 6755 is a downref, =
since 6755 is informational.=94
> =20
> I would change =93The document shepherd volunteers to become an expert =
review=94 to the following:
> =20
> The document shepherd and the author Michael Jones both volunteer to =
become expert reviewers.  Note that the document recommends that =
multiple expert reviewers be appointed, with the following text (which =
also appears in the JOSE documents):
> =20
>    It is suggested that multiple Designated Experts be appointed who =
are
>    able to represent the perspectives of different applications using
>    this specification, in order to enable broadly-informed review of
>    registration decisions.  In cases where a registration decision =
could
>    be perceived as creating a conflict of interest for a particular
>    Expert, that Expert should defer to the judgment of the other
>    Expert(s).
> =20
> I would change =93The document shepherd has reviewed those examples =
but has not verified the correctness of the cryptographic operations=94 =
to =93The document shepherd has reviewed those examples but has not =
verified the correctness of the cryptographic operations, however Brian =
Campbell has done so=94.
> =20
> Thanks again for moving this forward!
> =20
>                                                             -- Mike
> =20
> -----Original Message-----
> From: OAuth [mailto:oauth-bounces@ietf.org] On Behalf Of Hannes =
Tschofenig
> Sent: Thursday, April 24, 2014 12:11 AM
> To: Brian Campbell
> Cc: oauth@ietf.org
> Subject: Re: [OAUTH-WG] draft-ietf-oauth-json-web-token-19 Shepherd =
Write-up
> =20
> Thanks, Brian. I will add this aspect to the write-up.
> =20
> On 04/24/2014 12:46 AM, Brian Campbell wrote:
> > While OAuth access tokens are a valuable application of JWT, might =
it
> > also be worthwhile to mention that JWT can and will be useful in =
other
> > contexts? Connect's ID Token is one such example:
> > http://openid.net/specs/openid-connect-core-1_0.html#IDToken
> >
> >
> > On Wed, Apr 23, 2014 at 5:55 AM, Hannes Tschofenig
> > <hannes.tschofenig@gmx.net <mailto:hannes.tschofenig@gmx.net>> =
wrote:
> >
> >     Hi all,
> >
> >     I am working on the shepherd writeup for the JWT. Here are a few
> >     questions:
> >
> >     - To the document authors: Please confirm that any and all =
appropriate
> >     IPR disclosures required for full conformance with the =
provisions of BCP
> >     78 and BCP 79 have already been filed.
> >
> >     - To all: I have included various pointers to implementations in =
the
> >     write-up. Maybe there are others that should be included. If so, =
please
> >     let me know.
> >
> >     - To all: Please also go through the text to make sure that I =
correctly
> >     reflect the history and the status of this document.
> >
> >     Here is the latest version of the write-up:
> >   =20
> > =
https://raw.githubusercontent.com/hannestschofenig/tschofenig-ids/mast
> > er/shepherd-writeups/Writeup_OAuth_JWT.txt
> >
> >     Ciao
> >     Hannes
> >
> >     PS: Here is the copy-and-paste text:
> >
> >     --------
> >
> >     Writeup for "JSON Web Token (JWT)"
> > <draft-ietf-oauth-json-web-token-19>
> >
> >     (1) What type of RFC is being requested (BCP, Proposed Standard,
> >     Internet Standard, Informational, Experimental, or Historic)? =
Why is
> >     this the proper type of RFC? Is this type of RFC indicated in =
the title
> >     page header?
> >
> >     The RFC type is 'Standards Track' and the type is indicated in =
the title
> >     page. This document defines the syntax and semantic of =
information
> >     elements.
> >
> >     (2) The IESG approval announcement includes a Document =
Announcement
> >     Write-Up. Please provide such a Document Announcement Write-Up. =
Recent
> >     examples can be found in the "Action" announcements for approved
> >     documents. The approval announcement contains the following =
sections:
> >
> >     Technical Summary:
> >
> >        JSON Web Token (JWT) is a compact URL-safe means of =
representing
> >        claims to be transferred between two parties.  The claims in =
a JWT
> >        are encoded as a JavaScript Object Notation (JSON) object =
that is
> >        used as the payload of a JSON Web Signature (JWS) structure =
or as the
> >        plaintext of a JSON Web Encryption (JWE) structure, enabling =
the
> >        claims to be digitally signed or MACed and/or encrypted.
> >
> >     Working Group Summary:
> >
> >     Was there anything in WG process that is worth noting? For =
example, was
> >     there controversy about particular points or were there =
decisions where
> >     the consensus was particularly rough?
> >
> >     This document was uncontroversial. It allows OAuth deployments =
to use a
> >     standardized access token format, which increases =
interoperability of
> >     OAuth-based deployments.
> >
> >     Document Quality:
> >
> >     This document has gone through many iterations and has received
> >     substantial feedback.
> >
> >     A substantial number of implementations exist, as documented at
> >     http://openid.net/developers/libraries/
> >     (scrowl down to the 'JWT/JWS/JWE/JWK/JWA Implementations' =
section)
> >
> >     An Excel document providing additional details can be found =
here:
> >   =20
> > =
http://www.oauth-v2.org/wp-content/uploads/2014/04/JWT-Implementations
> > .xlsx
> >
> >     Personnel:
> >
> >     The document shepherd is Hannes Tschofenig and the responsible =
area
> >     director is Kathleen Moriarty.
> >
> >     (3) Briefly describe the review of this document that was =
performed by
> >     the Document Shepherd. If this version of the document is not =
ready for
> >     publication, please explain why the document is being forwarded =
to
> >     the IESG.
> >
> >     The draft authors believe that this document is ready for =
publication.
> >     The document has received review comments from working group =
members,
> >     and from the OAuth working group chairs. Implementations exist =
and they
> >     have tested for interoperability as part of the OpenID Connect =
interop
> >     events.
> >
> >     (4) Does the document Shepherd have any concerns about the depth =
or
> >     breadth of the reviews that have been performed?
> >
> >     This document has gotten enough feedback from the working group.
> >
> >     (5) Do portions of the document need review from a particular or =
from
> >     broader perspective, e.g., security, operational complexity, =
AAA, DNS,
> >     DHCP, XML, or internationalization? If so, describe the review =
that took
> >     place.
> >
> >     Since the OAuth working group develops security protocols any =
feedback
> >     from the security community is always appreciated.
> >     The JWT document heavily depends on the work in the JOSE working =
group
> >     since it re-uses the JWE and the JWS specifications.
> >
> >     (6) Describe any specific concerns or issues that the Document =
Shepherd
> >     has with this document that the Responsible Area Director and/or =
the
> >     IESG should be aware of? For example, perhaps he or she is =
uncomfortable
> >     with certain parts of the document, or has concerns whether =
there really
> >     is a need for it. In any event, if the WG has discussed those =
issues and
> >     has indicated that it still wishes to advance the document, =
detail those
> >     concerns here.
> >
> >     The shepherd has no concerns with this document.
> >
> >     (7) Has each author confirmed that any and all appropriate IPR
> >     disclosures required for full conformance with the provisions of =
BCP 78
> >     and BCP 79 have already been filed. If not, explain why?
> >
> >     [[Confirmation from the authors required.]]
> >
> >     (8) Has an IPR disclosure been filed that references this =
document? If
> >     so, summarize any WG discussion and conclusion regarding the IPR
> >     disclosures.
> >
> >     Two IPRs have been filed for the JWT specification this document =
relies
> >     on, see
> >   =20
> > =
http://datatracker.ietf.org/ipr/search/?option=3Ddocument_search&id=3Ddraf=

> > t-ietf-oauth-json-web-token
> >
> >
> >     There was no discussion regarding those two IPRs on the mailing =
list.
> >
> >     (9) How solid is the WG consensus behind this document? Does it
> >     represent the strong concurrence of a few individuals, with =
others being
> >     silent, or does the WG as a whole understand and agree with it?
> >
> >     The working group has consensus to publish this document.
> >
> >     (10) Has anyone threatened an appeal or otherwise indicated =
extreme
> >     discontent? If so, please summarise the areas of conflict in =
separate
> >     email messages to the Responsible Area Director. (It should be =
in a
> >     separate email because this questionnaire is publicly =
available.)
> >
> >     No appeal or extreme discontent has been raised.
> >
> >     (11) Identify any ID nits the Document Shepherd has found in =
this
> >     document. (See http://www.ietf.org/tools/idnits/ and the =
Internet-Drafts
> >     Checklist). Boilerplate checks are not enough; this check needs =
to be
> >     thorough.
> >
> >     The shepherd has checked the nits. The shepherd has not verified =
the
> >     examples for correctness.
> >
> >     (12) Describe how the document meets any required formal review
> >     criteria, such as the MIB Doctor, media type, and URI type =
reviews.
> >
> >     The document does not require a formal review even though it =
contains
> >     JSON-based examples.
> >
> >     (13) Have all references within this document been identified as =
either
> >     normative or informative?
> >
> >     Yes.
> >
> >     (14) Are there normative references to documents that are not =
ready for
> >     advancement or are otherwise in an unclear state? If such =
normative
> >     references exist, what is the plan for their completion?
> >
> >     There are various JOSE documents that have not been published as =
RFCs
> >     yet. As such, this document cannot be published before the =
respective
> >     JOSE documents are finalized.
> >
> >     (15) Are there downward normative references references (see RFC =
3967)?
> >     If so, list these downward references to support the Area =
Director in
> >     the Last Call procedure.
> >
> >     The document contains a reference to
> >
> >        [ECMAScript]
> >                   Ecma International, "ECMAScript Language =
Specification,
> >                   5.1 Edition", ECMA 262, June 2011.
> >
> >     which might require a downref.
> >
> >     RFC 6755 is also a downref.
> >
> >
> >     (16) Will publication of this document change the status of any =
existing
> >     RFCs? Are those RFCs listed on the title page header, listed in =
the
> >     abstract, and discussed in the introduction? If the RFCs are not =
listed
> >     in the Abstract and Introduction, explain why, and point to the =
part of
> >     the document where the relationship of this document to the =
other RFCs
> >     is discussed. If this information is not in the document, =
explain why
> >     the WG considers it unnecessary.
> >
> >     The publication of this document does not change the status of =
other
> >     RFCs.
> >
> >     (17) Describe the Document Shepherd's review of the IANA =
considerations
> >     section, especially with regard to its consistency with the body =
of the
> >     document. Confirm that all protocol extensions that the document =
makes
> >     are associated with the appropriate reservations in IANA =
registries.
> >     Confirm that any referenced IANA registries have been clearly
> >     identified. Confirm that newly created IANA registries include a
> >     detailed specification of the initial contents for the registry, =
that
> >     allocations procedures for future registrations are defined, and =
a
> >     reasonable name for the new registry has been suggested (see RFC =
5226).
> >
> >     The document creates a new registry for JWT claims and populates =
this
> >     registry with values.
> >     It also registers values into two existing registries, namely =
into
> >      * the RFC 6755 created OAuth URN registry, and
> >      * the media type registry
> >
> >     (18) List any new IANA registries that require Expert Review for =
future
> >     allocations. Provide any public guidance that the IESG would =
find useful
> >     in selecting the IANA Experts for these new registries.
> >
> >     The newly created JWT claims registry requires expert review for =
future
> >     allocations. Guidance is given in the document.
> >     The document shepherd volunteers to become an expert review.
> >
> >     (19) Describe reviews and automated checks performed by the =
Document
> >     Shepherd to validate sections of the document written in a =
formal
> >     language, such as XML code, BNF rules, MIB definitions, etc.
> >
> >     There are examples in the document that use a JSON-based =
encoding. The
> >     document shepherd has reviewed those examples but has not =
verified the
> >     correctness of the cryptographic operations.
> >
> >
> >
> >     _______________________________________________
> >     OAuth mailing list
> >     OAuth@ietf.org <mailto:OAuth@ietf.org>
> >     https://www.ietf.org/mailman/listinfo/oauth
> >
> >
> =20
> _______________________________________________
> OAuth mailing list
> OAuth@ietf.org
> https://www.ietf.org/mailman/listinfo/oauth


--Apple-Mail=_FCF49E0E-44B6-42C3-B027-A184D1C84F2E
Content-Transfer-Encoding: quoted-printable
Content-Type: text/html;
	charset=windows-1252

<html><head><meta http-equiv=3D"Content-Type" content=3D"text/html =
charset=3Dwindows-1252"></head><body style=3D"word-wrap: break-word; =
-webkit-nbsp-mode: space; -webkit-line-break: =
after-white-space;">+1<div><br><div><div>On Apr 24, 2014, at 7:32 PM, =
Mike Jones &lt;<a =
href=3D"mailto:Michael.Jones@microsoft.com">Michael.Jones@microsoft.com</a=
>&gt; wrote:</div><br class=3D"Apple-interchange-newline"><blockquote =
type=3D"cite"><div lang=3D"EN-US" link=3D"blue" vlink=3D"purple" =
style=3D"font-family: Helvetica; font-size: 12px; font-style: normal; =
font-variant: normal; font-weight: normal; letter-spacing: normal; =
line-height: normal; orphans: auto; text-align: start; text-indent: 0px; =
text-transform: none; white-space: normal; widows: auto; word-spacing: =
0px; -webkit-text-stroke-width: 0px;"><div class=3D"WordSection1" =
style=3D"page: WordSection1;"><div style=3D"margin: 0in 0in 0.0001pt; =
font-size: 11pt; font-family: Calibri, sans-serif;">Thanks for doing =
this, Hannes.&nbsp; I would suggest making the following =
changes...<o:p></o:p></div><div style=3D"margin: 0in 0in 0.0001pt; =
font-size: 11pt; font-family: Calibri, =
sans-serif;"><o:p>&nbsp;</o:p></div><div style=3D"margin: 0in 0in =
0.0001pt; font-size: 11pt; font-family: Calibri, sans-serif;">Change =93It=
 allows OAuth deployments to use a standardized access token format, =
which increases interoperability of OAuth-based deployments=94 to =93It =
defines a standard JSON-based security token format, increasing =
interoperability both among OAuth deployments using it and in other =
application contexts as well=94.<o:p></o:p></div><div style=3D"margin: =
0in 0in 0.0001pt; font-size: 11pt; font-family: Calibri, =
sans-serif;"><o:p>&nbsp;</o:p></div><div style=3D"margin: 0in 0in =
0.0001pt; font-size: 11pt; font-family: Calibri, sans-serif;">I would =
change<span class=3D"Apple-converted-space">&nbsp;</span><a =
href=3D"http://openid.net/developers/libraries/" style=3D"color: purple; =
text-decoration: =
underline;">http://openid.net/developers/libraries/</a><span =
class=3D"Apple-converted-space">&nbsp;</span>to<span =
class=3D"Apple-converted-space">&nbsp;</span><a =
href=3D"http://openid.net/developers/libraries/#jwt" style=3D"color: =
purple; text-decoration: =
underline;">http://openid.net/developers/libraries/#jwt</a><span =
class=3D"Apple-converted-space">&nbsp;</span>(adding the #jwt target =
within the page).<o:p></o:p></div><div style=3D"margin: 0in 0in =
0.0001pt; font-size: 11pt; font-family: Calibri, =
sans-serif;"><o:p>&nbsp;</o:p></div><div style=3D"margin: 0in 0in =
0.0001pt; font-size: 11pt; font-family: Calibri, sans-serif;">I would =
change =93The draft authors believe that this document is ready for =
publication=94 to =93The document is ready for =
publication=94.<o:p></o:p></div><div style=3D"margin: 0in 0in 0.0001pt; =
font-size: 11pt; font-family: Calibri, =
sans-serif;"><o:p>&nbsp;</o:p></div><div style=3D"margin: 0in 0in =
0.0001pt; font-size: 11pt; font-family: Calibri, sans-serif;">I would =
change the answer to (15) to say nothing about ECMAScript, since it is =
not a downref, and to only say =93RFC 6755 is a downref, since 6755 is =
informational.=94<o:p></o:p></div><div style=3D"margin: 0in 0in =
0.0001pt; font-size: 11pt; font-family: Calibri, =
sans-serif;"><o:p>&nbsp;</o:p></div><div style=3D"margin: 0in 0in =
0.0001pt; font-size: 11pt; font-family: Calibri, sans-serif;">I would =
change =93The document shepherd volunteers to become an expert review=94 =
to the following:<o:p></o:p></div><div style=3D"margin: 0in 0in =
0.0001pt; font-size: 11pt; font-family: Calibri, =
sans-serif;"><o:p>&nbsp;</o:p></div><div style=3D"margin: 0in 0in =
0.0001pt 0.5in; font-size: 11pt; font-family: Calibri, sans-serif;">The =
document shepherd and the author Michael Jones both volunteer to become =
expert reviewers.&nbsp; Note that the document recommends that multiple =
expert reviewers be appointed, with the following text (which also =
appears in the JOSE documents):<o:p></o:p></div><div style=3D"margin: =
0in 0in 0.0001pt; font-size: 11pt; font-family: Calibri, sans-serif; =
page-break-before: always;"><span lang=3D"EN" style=3D"font-size: 12pt; =
font-family: 'Courier New';">&nbsp;</span></div><div style=3D"margin: =
0in 0in 0.0001pt; font-size: 11pt; font-family: Calibri, sans-serif; =
page-break-before: always;"><span lang=3D"EN" style=3D"font-size: 12pt; =
font-family: 'Courier New';">&nbsp;&nbsp; It is suggested that multiple =
Designated Experts be appointed who are<o:p></o:p></span></div><div =
style=3D"margin: 0in 0in 0.0001pt; font-size: 11pt; font-family: =
Calibri, sans-serif; page-break-before: always;"><span lang=3D"EN" =
style=3D"font-size: 12pt; font-family: 'Courier New';">&nbsp;&nbsp; able =
to represent the perspectives of different applications =
using<o:p></o:p></span></div><div style=3D"margin: 0in 0in 0.0001pt; =
font-size: 11pt; font-family: Calibri, sans-serif; page-break-before: =
always;"><span lang=3D"EN" style=3D"font-size: 12pt; font-family: =
'Courier New';">&nbsp;&nbsp; this specification, in order to enable =
broadly-informed review of<o:p></o:p></span></div><div style=3D"margin: =
0in 0in 0.0001pt; font-size: 11pt; font-family: Calibri, sans-serif; =
page-break-before: always;"><span lang=3D"EN" style=3D"font-size: 12pt; =
font-family: 'Courier New';">&nbsp;&nbsp; registration decisions.&nbsp; =
In cases where a registration decision could<o:p></o:p></span></div><div =
style=3D"margin: 0in 0in 0.0001pt; font-size: 11pt; font-family: =
Calibri, sans-serif; page-break-before: always;"><span lang=3D"EN" =
style=3D"font-size: 12pt; font-family: 'Courier New';">&nbsp;&nbsp; be =
perceived as creating a conflict of interest for a =
particular<o:p></o:p></span></div><div style=3D"margin: 0in 0in =
0.0001pt; font-size: 11pt; font-family: Calibri, sans-serif; =
page-break-before: always;"><span lang=3D"EN" style=3D"font-size: 12pt; =
font-family: 'Courier New';">&nbsp;&nbsp; Expert, that Expert should =
defer to the judgment of the other<o:p></o:p></span></div><div =
style=3D"margin: 0in 0in 0.0001pt; font-size: 11pt; font-family: =
Calibri, sans-serif; page-break-before: always;"><span lang=3D"EN" =
style=3D"font-size: 12pt; font-family: 'Courier New';">&nbsp;&nbsp; =
Expert(s).<o:p></o:p></span></div><div style=3D"margin: 0in 0in =
0.0001pt; font-size: 11pt; font-family: Calibri, =
sans-serif;"><o:p>&nbsp;</o:p></div><div style=3D"margin: 0in 0in =
0.0001pt; font-size: 11pt; font-family: Calibri, sans-serif;">I would =
change =93The document shepherd has reviewed those examples but has not =
verified the correctness of the cryptographic operations=94 to =93The =
document shepherd has reviewed those examples but has not verified the =
correctness of the cryptographic operations, however Brian Campbell has =
done so=94.<o:p></o:p></div><div style=3D"margin: 0in 0in 0.0001pt; =
font-size: 11pt; font-family: Calibri, =
sans-serif;"><o:p>&nbsp;</o:p></div><div style=3D"margin: 0in 0in =
0.0001pt; font-size: 11pt; font-family: Calibri, sans-serif;">Thanks =
again for moving this forward!<o:p></o:p></div><div style=3D"margin: 0in =
0in 0.0001pt; font-size: 11pt; font-family: Calibri, =
sans-serif;"><o:p>&nbsp;</o:p></div><div style=3D"margin: 0in 0in =
0.0001pt; font-size: 11pt; font-family: Calibri, =
sans-serif;">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&=
nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nb=
sp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp=
;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&=
nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; =
-- Mike<o:p></o:p></div><div style=3D"margin: 0in 0in 0.0001pt; =
font-size: 11pt; font-family: Calibri, =
sans-serif;"><o:p>&nbsp;</o:p></div><div style=3D"margin: 0in 0in =
0.0001pt; font-size: 11pt; font-family: Calibri, =
sans-serif;">-----Original Message-----<br>From: OAuth [<a =
href=3D"mailto:oauth-bounces@ietf.org">mailto:oauth-bounces@ietf.org</a>] =
On Behalf Of Hannes Tschofenig<br>Sent: Thursday, April 24, 2014 12:11 =
AM<br>To: Brian Campbell<br>Cc: <a =
href=3D"mailto:oauth@ietf.org">oauth@ietf.org</a><br>Subject: Re: =
[OAUTH-WG] draft-ietf-oauth-json-web-token-19 Shepherd =
Write-up</div><div style=3D"margin: 0in 0in 0.0001pt; font-size: 11pt; =
font-family: Calibri, sans-serif;"><o:p>&nbsp;</o:p></div><div =
style=3D"margin: 0in 0in 0.0001pt; font-size: 11pt; font-family: =
Calibri, sans-serif;">Thanks, Brian. I will add this aspect to the =
write-up.<o:p></o:p></div><div style=3D"margin: 0in 0in 0.0001pt; =
font-size: 11pt; font-family: Calibri, =
sans-serif;"><o:p>&nbsp;</o:p></div><div style=3D"margin: 0in 0in =
0.0001pt; font-size: 11pt; font-family: Calibri, sans-serif;">On =
04/24/2014 12:46 AM, Brian Campbell wrote:<o:p></o:p></div><div =
style=3D"margin: 0in 0in 0.0001pt; font-size: 11pt; font-family: =
Calibri, sans-serif;">&gt; While OAuth access tokens are a valuable =
application of JWT, might it<o:p></o:p></div><div style=3D"margin: 0in =
0in 0.0001pt; font-size: 11pt; font-family: Calibri, sans-serif;">&gt; =
also be worthwhile to mention that JWT can and will be useful in =
other<o:p></o:p></div><div style=3D"margin: 0in 0in 0.0001pt; font-size: =
11pt; font-family: Calibri, sans-serif;">&gt; contexts? Connect's ID =
Token is one such example:<o:p></o:p></div><div style=3D"margin: 0in 0in =
0.0001pt; font-size: 11pt; font-family: Calibri, sans-serif;">&gt; <a =
href=3D"http://openid.net/specs/openid-connect-core-1_0.html#IDToken">http=
://openid.net/specs/openid-connect-core-1_0.html#IDToken</a><o:p></o:p></d=
iv><div style=3D"margin: 0in 0in 0.0001pt; font-size: 11pt; font-family: =
Calibri, sans-serif;">&gt;<o:p></o:p></div><div style=3D"margin: 0in 0in =
0.0001pt; font-size: 11pt; font-family: Calibri, =
sans-serif;">&gt;<o:p></o:p></div><div style=3D"margin: 0in 0in =
0.0001pt; font-size: 11pt; font-family: Calibri, sans-serif;">&gt; On =
Wed, Apr 23, 2014 at 5:55 AM, Hannes Tschofenig<o:p></o:p></div><div =
style=3D"margin: 0in 0in 0.0001pt; font-size: 11pt; font-family: =
Calibri, sans-serif;">&gt; &lt;<a =
href=3D"mailto:hannes.tschofenig@gmx.net">hannes.tschofenig@gmx.net</a> =
&lt;<a =
href=3D"mailto:hannes.tschofenig@gmx.net">mailto:hannes.tschofenig@gmx.net=
</a>&gt;&gt; wrote:<o:p></o:p></div><div style=3D"margin: 0in 0in =
0.0001pt; font-size: 11pt; font-family: Calibri, =
sans-serif;">&gt;<o:p></o:p></div><div style=3D"margin: 0in 0in =
0.0001pt; font-size: 11pt; font-family: Calibri, =
sans-serif;">&gt;&nbsp;&nbsp;&nbsp;&nbsp; Hi all,<o:p></o:p></div><div =
style=3D"margin: 0in 0in 0.0001pt; font-size: 11pt; font-family: =
Calibri, sans-serif;">&gt;<o:p></o:p></div><div style=3D"margin: 0in 0in =
0.0001pt; font-size: 11pt; font-family: Calibri, =
sans-serif;">&gt;&nbsp;&nbsp;&nbsp;&nbsp; I am working on the shepherd =
writeup for the JWT. Here are a few<o:p></o:p></div><div style=3D"margin: =
0in 0in 0.0001pt; font-size: 11pt; font-family: Calibri, =
sans-serif;">&gt;&nbsp;&nbsp;&nbsp;&nbsp; =
questions:<o:p></o:p></div><div style=3D"margin: 0in 0in 0.0001pt; =
font-size: 11pt; font-family: Calibri, =
sans-serif;">&gt;<o:p></o:p></div><div style=3D"margin: 0in 0in =
0.0001pt; font-size: 11pt; font-family: Calibri, =
sans-serif;">&gt;&nbsp;&nbsp;&nbsp;&nbsp; - To the document authors: =
Please confirm that any and all appropriate<o:p></o:p></div><div =
style=3D"margin: 0in 0in 0.0001pt; font-size: 11pt; font-family: =
Calibri, sans-serif;">&gt;&nbsp;&nbsp;&nbsp;&nbsp; IPR disclosures =
required for full conformance with the provisions of =
BCP<o:p></o:p></div><div style=3D"margin: 0in 0in 0.0001pt; font-size: =
11pt; font-family: Calibri, sans-serif;">&gt;&nbsp;&nbsp;&nbsp;&nbsp; 78 =
and BCP 79 have already been filed.<o:p></o:p></div><div style=3D"margin: =
0in 0in 0.0001pt; font-size: 11pt; font-family: Calibri, =
sans-serif;">&gt;<o:p></o:p></div><div style=3D"margin: 0in 0in =
0.0001pt; font-size: 11pt; font-family: Calibri, =
sans-serif;">&gt;&nbsp;&nbsp;&nbsp;&nbsp; - To all: I have included =
various pointers to implementations in the<o:p></o:p></div><div =
style=3D"margin: 0in 0in 0.0001pt; font-size: 11pt; font-family: =
Calibri, sans-serif;">&gt;&nbsp;&nbsp;&nbsp;&nbsp; write-up. Maybe there =
are others that should be included. If so, please<o:p></o:p></div><div =
style=3D"margin: 0in 0in 0.0001pt; font-size: 11pt; font-family: =
Calibri, sans-serif;">&gt;&nbsp;&nbsp;&nbsp;&nbsp; let me =
know.<o:p></o:p></div><div style=3D"margin: 0in 0in 0.0001pt; font-size: =
11pt; font-family: Calibri, sans-serif;">&gt;<o:p></o:p></div><div =
style=3D"margin: 0in 0in 0.0001pt; font-size: 11pt; font-family: =
Calibri, sans-serif;">&gt;&nbsp;&nbsp;&nbsp;&nbsp; - To all: Please also =
go through the text to make sure that I correctly<o:p></o:p></div><div =
style=3D"margin: 0in 0in 0.0001pt; font-size: 11pt; font-family: =
Calibri, sans-serif;">&gt;&nbsp;&nbsp;&nbsp;&nbsp; reflect the history =
and the status of this document.<o:p></o:p></div><div style=3D"margin: =
0in 0in 0.0001pt; font-size: 11pt; font-family: Calibri, =
sans-serif;">&gt;<o:p></o:p></div><div style=3D"margin: 0in 0in =
0.0001pt; font-size: 11pt; font-family: Calibri, =
sans-serif;">&gt;&nbsp;&nbsp;&nbsp;&nbsp; Here is the latest version of =
the write-up:<o:p></o:p></div><div style=3D"margin: 0in 0in 0.0001pt; =
font-size: 11pt; font-family: Calibri, =
sans-serif;">&gt;&nbsp;&nbsp;&nbsp;&nbsp;<o:p></o:p></div><div =
style=3D"margin: 0in 0in 0.0001pt; font-size: 11pt; font-family: =
Calibri, sans-serif;">&gt; <a =
href=3D"https://raw.githubusercontent.com/hannestschofenig/tschofenig-ids/=
mast">https://raw.githubusercontent.com/hannestschofenig/tschofenig-ids/ma=
st</a><o:p></o:p></div><div style=3D"margin: 0in 0in 0.0001pt; =
font-size: 11pt; font-family: Calibri, sans-serif;">&gt; =
er/shepherd-writeups/Writeup_OAuth_JWT.txt<o:p></o:p></div><div =
style=3D"margin: 0in 0in 0.0001pt; font-size: 11pt; font-family: =
Calibri, sans-serif;">&gt;<o:p></o:p></div><div style=3D"margin: 0in 0in =
0.0001pt; font-size: 11pt; font-family: Calibri, =
sans-serif;">&gt;&nbsp;&nbsp;&nbsp;&nbsp; Ciao<o:p></o:p></div><div =
style=3D"margin: 0in 0in 0.0001pt; font-size: 11pt; font-family: =
Calibri, sans-serif;">&gt;&nbsp;&nbsp;&nbsp;&nbsp; =
Hannes<o:p></o:p></div><div style=3D"margin: 0in 0in 0.0001pt; =
font-size: 11pt; font-family: Calibri, =
sans-serif;">&gt;<o:p></o:p></div><div style=3D"margin: 0in 0in =
0.0001pt; font-size: 11pt; font-family: Calibri, =
sans-serif;">&gt;&nbsp;&nbsp;&nbsp;&nbsp; PS: Here is the copy-and-paste =
text:<o:p></o:p></div><div style=3D"margin: 0in 0in 0.0001pt; font-size: =
11pt; font-family: Calibri, sans-serif;">&gt;<o:p></o:p></div><div =
style=3D"margin: 0in 0in 0.0001pt; font-size: 11pt; font-family: =
Calibri, sans-serif;">&gt;&nbsp;&nbsp;&nbsp;&nbsp; =
--------<o:p></o:p></div><div style=3D"margin: 0in 0in 0.0001pt; =
font-size: 11pt; font-family: Calibri, =
sans-serif;">&gt;<o:p></o:p></div><div style=3D"margin: 0in 0in =
0.0001pt; font-size: 11pt; font-family: Calibri, =
sans-serif;">&gt;&nbsp;&nbsp;&nbsp;&nbsp; Writeup for "JSON Web Token =
(JWT)"<o:p></o:p></div><div style=3D"margin: 0in 0in 0.0001pt; =
font-size: 11pt; font-family: Calibri, sans-serif;">&gt; =
&lt;draft-ietf-oauth-json-web-token-19&gt;<o:p></o:p></div><div =
style=3D"margin: 0in 0in 0.0001pt; font-size: 11pt; font-family: =
Calibri, sans-serif;">&gt;<o:p></o:p></div><div style=3D"margin: 0in 0in =
0.0001pt; font-size: 11pt; font-family: Calibri, =
sans-serif;">&gt;&nbsp;&nbsp;&nbsp;&nbsp; (1) What type of RFC is being =
requested (BCP, Proposed Standard,<o:p></o:p></div><div style=3D"margin: =
0in 0in 0.0001pt; font-size: 11pt; font-family: Calibri, =
sans-serif;">&gt;&nbsp;&nbsp;&nbsp;&nbsp; Internet Standard, =
Informational, Experimental, or Historic)? Why is<o:p></o:p></div><div =
style=3D"margin: 0in 0in 0.0001pt; font-size: 11pt; font-family: =
Calibri, sans-serif;">&gt;&nbsp;&nbsp;&nbsp;&nbsp; this the proper type =
of RFC? Is this type of RFC indicated in the title<o:p></o:p></div><div =
style=3D"margin: 0in 0in 0.0001pt; font-size: 11pt; font-family: =
Calibri, sans-serif;">&gt;&nbsp;&nbsp;&nbsp;&nbsp; page =
header?<o:p></o:p></div><div style=3D"margin: 0in 0in 0.0001pt; =
font-size: 11pt; font-family: Calibri, =
sans-serif;">&gt;<o:p></o:p></div><div style=3D"margin: 0in 0in =
0.0001pt; font-size: 11pt; font-family: Calibri, =
sans-serif;">&gt;&nbsp;&nbsp;&nbsp;&nbsp; The RFC type is 'Standards =
Track' and the type is indicated in the title<o:p></o:p></div><div =
style=3D"margin: 0in 0in 0.0001pt; font-size: 11pt; font-family: =
Calibri, sans-serif;">&gt;&nbsp;&nbsp;&nbsp;&nbsp; page. This document =
defines the syntax and semantic of information<o:p></o:p></div><div =
style=3D"margin: 0in 0in 0.0001pt; font-size: 11pt; font-family: =
Calibri, sans-serif;">&gt;&nbsp;&nbsp;&nbsp;&nbsp; =
elements.<o:p></o:p></div><div style=3D"margin: 0in 0in 0.0001pt; =
font-size: 11pt; font-family: Calibri, =
sans-serif;">&gt;<o:p></o:p></div><div style=3D"margin: 0in 0in =
0.0001pt; font-size: 11pt; font-family: Calibri, =
sans-serif;">&gt;&nbsp;&nbsp;&nbsp;&nbsp; (2) The IESG approval =
announcement includes a Document Announcement<o:p></o:p></div><div =
style=3D"margin: 0in 0in 0.0001pt; font-size: 11pt; font-family: =
Calibri, sans-serif;">&gt;&nbsp;&nbsp;&nbsp;&nbsp; Write-Up. Please =
provide such a Document Announcement Write-Up. =
Recent<o:p></o:p></div><div style=3D"margin: 0in 0in 0.0001pt; =
font-size: 11pt; font-family: Calibri, =
sans-serif;">&gt;&nbsp;&nbsp;&nbsp;&nbsp; examples can be found in the =
"Action" announcements for approved<o:p></o:p></div><div style=3D"margin: =
0in 0in 0.0001pt; font-size: 11pt; font-family: Calibri, =
sans-serif;">&gt;&nbsp;&nbsp;&nbsp;&nbsp; documents. The approval =
announcement contains the following sections:<o:p></o:p></div><div =
style=3D"margin: 0in 0in 0.0001pt; font-size: 11pt; font-family: =
Calibri, sans-serif;">&gt;<o:p></o:p></div><div style=3D"margin: 0in 0in =
0.0001pt; font-size: 11pt; font-family: Calibri, =
sans-serif;">&gt;&nbsp;&nbsp;&nbsp;&nbsp; Technical =
Summary:<o:p></o:p></div><div style=3D"margin: 0in 0in 0.0001pt; =
font-size: 11pt; font-family: Calibri, =
sans-serif;">&gt;<o:p></o:p></div><div style=3D"margin: 0in 0in =
0.0001pt; font-size: 11pt; font-family: Calibri, =
sans-serif;">&gt;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; JSON Web =
Token (JWT) is a compact URL-safe means of =
representing<o:p></o:p></div><div style=3D"margin: 0in 0in 0.0001pt; =
font-size: 11pt; font-family: Calibri, =
sans-serif;">&gt;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; claims to be =
transferred between two parties.&nbsp; The claims in a =
JWT<o:p></o:p></div><div style=3D"margin: 0in 0in 0.0001pt; font-size: =
11pt; font-family: Calibri, =
sans-serif;">&gt;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; are encoded =
as a JavaScript Object Notation (JSON) object that =
is<o:p></o:p></div><div style=3D"margin: 0in 0in 0.0001pt; font-size: =
11pt; font-family: Calibri, =
sans-serif;">&gt;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; used as the =
payload of a JSON Web Signature (JWS) structure or as =
the<o:p></o:p></div><div style=3D"margin: 0in 0in 0.0001pt; font-size: =
11pt; font-family: Calibri, =
sans-serif;">&gt;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; plaintext of =
a JSON Web Encryption (JWE) structure, enabling the<o:p></o:p></div><div =
style=3D"margin: 0in 0in 0.0001pt; font-size: 11pt; font-family: =
Calibri, sans-serif;">&gt;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; =
claims to be digitally signed or MACed and/or =
encrypted.<o:p></o:p></div><div style=3D"margin: 0in 0in 0.0001pt; =
font-size: 11pt; font-family: Calibri, =
sans-serif;">&gt;<o:p></o:p></div><div style=3D"margin: 0in 0in =
0.0001pt; font-size: 11pt; font-family: Calibri, =
sans-serif;">&gt;&nbsp;&nbsp;&nbsp;&nbsp; Working Group =
Summary:<o:p></o:p></div><div style=3D"margin: 0in 0in 0.0001pt; =
font-size: 11pt; font-family: Calibri, =
sans-serif;">&gt;<o:p></o:p></div><div style=3D"margin: 0in 0in =
0.0001pt; font-size: 11pt; font-family: Calibri, =
sans-serif;">&gt;&nbsp;&nbsp;&nbsp;&nbsp; Was there anything in WG =
process that is worth noting? For example, was<o:p></o:p></div><div =
style=3D"margin: 0in 0in 0.0001pt; font-size: 11pt; font-family: =
Calibri, sans-serif;">&gt;&nbsp;&nbsp;&nbsp;&nbsp; there controversy =
about particular points or were there decisions =
where<o:p></o:p></div><div style=3D"margin: 0in 0in 0.0001pt; font-size: =
11pt; font-family: Calibri, sans-serif;">&gt;&nbsp;&nbsp;&nbsp;&nbsp; =
the consensus was particularly rough?<o:p></o:p></div><div =
style=3D"margin: 0in 0in 0.0001pt; font-size: 11pt; font-family: =
Calibri, sans-serif;">&gt;<o:p></o:p></div><div style=3D"margin: 0in 0in =
0.0001pt; font-size: 11pt; font-family: Calibri, =
sans-serif;">&gt;&nbsp;&nbsp;&nbsp;&nbsp; This document was =
uncontroversial. It allows OAuth deployments to use =
a<o:p></o:p></div><div style=3D"margin: 0in 0in 0.0001pt; font-size: =
11pt; font-family: Calibri, sans-serif;">&gt;&nbsp;&nbsp;&nbsp;&nbsp; =
standardized access token format, which increases interoperability =
of<o:p></o:p></div><div style=3D"margin: 0in 0in 0.0001pt; font-size: =
11pt; font-family: Calibri, sans-serif;">&gt;&nbsp;&nbsp;&nbsp;&nbsp; =
OAuth-based deployments.<o:p></o:p></div><div style=3D"margin: 0in 0in =
0.0001pt; font-size: 11pt; font-family: Calibri, =
sans-serif;">&gt;<o:p></o:p></div><div style=3D"margin: 0in 0in =
0.0001pt; font-size: 11pt; font-family: Calibri, =
sans-serif;">&gt;&nbsp;&nbsp;&nbsp;&nbsp; Document =
Quality:<o:p></o:p></div><div style=3D"margin: 0in 0in 0.0001pt; =
font-size: 11pt; font-family: Calibri, =
sans-serif;">&gt;<o:p></o:p></div><div style=3D"margin: 0in 0in =
0.0001pt; font-size: 11pt; font-family: Calibri, =
sans-serif;">&gt;&nbsp;&nbsp;&nbsp;&nbsp; This document has gone through =
many iterations and has received<o:p></o:p></div><div style=3D"margin: =
0in 0in 0.0001pt; font-size: 11pt; font-family: Calibri, =
sans-serif;">&gt;&nbsp;&nbsp;&nbsp;&nbsp; substantial =
feedback.<o:p></o:p></div><div style=3D"margin: 0in 0in 0.0001pt; =
font-size: 11pt; font-family: Calibri, =
sans-serif;">&gt;<o:p></o:p></div><div style=3D"margin: 0in 0in =
0.0001pt; font-size: 11pt; font-family: Calibri, =
sans-serif;">&gt;&nbsp;&nbsp;&nbsp;&nbsp; A substantial number of =
implementations exist, as documented at<o:p></o:p></div><div =
style=3D"margin: 0in 0in 0.0001pt; font-size: 11pt; font-family: =
Calibri, sans-serif;">&gt;&nbsp;&nbsp;&nbsp;&nbsp; <a =
href=3D"http://openid.net/developers/libraries/">http://openid.net/develop=
ers/libraries/</a><o:p></o:p></div><div style=3D"margin: 0in 0in =
0.0001pt; font-size: 11pt; font-family: Calibri, =
sans-serif;">&gt;&nbsp;&nbsp;&nbsp;&nbsp; (scrowl down to the =
'JWT/JWS/JWE/JWK/JWA Implementations' section)<o:p></o:p></div><div =
style=3D"margin: 0in 0in 0.0001pt; font-size: 11pt; font-family: =
Calibri, sans-serif;">&gt;<o:p></o:p></div><div style=3D"margin: 0in 0in =
0.0001pt; font-size: 11pt; font-family: Calibri, =
sans-serif;">&gt;&nbsp;&nbsp;&nbsp;&nbsp; An Excel document providing =
additional details can be found here:<o:p></o:p></div><div =
style=3D"margin: 0in 0in 0.0001pt; font-size: 11pt; font-family: =
Calibri, sans-serif;">&gt;&nbsp;&nbsp;&nbsp;&nbsp;<o:p></o:p></div><div =
style=3D"margin: 0in 0in 0.0001pt; font-size: 11pt; font-family: =
Calibri, sans-serif;">&gt; <a =
href=3D"http://www.oauth-v2.org/wp-content/uploads/2014/04/JWT-Implementat=
ions">http://www.oauth-v2.org/wp-content/uploads/2014/04/JWT-Implementatio=
ns</a><o:p></o:p></div><div style=3D"margin: 0in 0in 0.0001pt; =
font-size: 11pt; font-family: Calibri, sans-serif;">&gt; =
.xlsx<o:p></o:p></div><div style=3D"margin: 0in 0in 0.0001pt; font-size: =
11pt; font-family: Calibri, sans-serif;">&gt;<o:p></o:p></div><div =
style=3D"margin: 0in 0in 0.0001pt; font-size: 11pt; font-family: =
Calibri, sans-serif;">&gt;&nbsp;&nbsp;&nbsp;&nbsp; =
Personnel:<o:p></o:p></div><div style=3D"margin: 0in 0in 0.0001pt; =
font-size: 11pt; font-family: Calibri, =
sans-serif;">&gt;<o:p></o:p></div><div style=3D"margin: 0in 0in =
0.0001pt; font-size: 11pt; font-family: Calibri, =
sans-serif;">&gt;&nbsp;&nbsp;&nbsp;&nbsp; The document shepherd is =
Hannes Tschofenig and the responsible area<o:p></o:p></div><div =
style=3D"margin: 0in 0in 0.0001pt; font-size: 11pt; font-family: =
Calibri, sans-serif;">&gt;&nbsp;&nbsp;&nbsp;&nbsp; director is Kathleen =
Moriarty.<o:p></o:p></div><div style=3D"margin: 0in 0in 0.0001pt; =
font-size: 11pt; font-family: Calibri, =
sans-serif;">&gt;<o:p></o:p></div><div style=3D"margin: 0in 0in =
0.0001pt; font-size: 11pt; font-family: Calibri, =
sans-serif;">&gt;&nbsp;&nbsp;&nbsp;&nbsp; (3) Briefly describe the =
review of this document that was performed by<o:p></o:p></div><div =
style=3D"margin: 0in 0in 0.0001pt; font-size: 11pt; font-family: =
Calibri, sans-serif;">&gt;&nbsp;&nbsp;&nbsp;&nbsp; the Document =
Shepherd. If this version of the document is not ready =
for<o:p></o:p></div><div style=3D"margin: 0in 0in 0.0001pt; font-size: =
11pt; font-family: Calibri, sans-serif;">&gt;&nbsp;&nbsp;&nbsp;&nbsp; =
publication, please explain why the document is being forwarded =
to<o:p></o:p></div><div style=3D"margin: 0in 0in 0.0001pt; font-size: =
11pt; font-family: Calibri, sans-serif;">&gt;&nbsp;&nbsp;&nbsp;&nbsp; =
the IESG.<o:p></o:p></div><div style=3D"margin: 0in 0in 0.0001pt; =
font-size: 11pt; font-family: Calibri, =
sans-serif;">&gt;<o:p></o:p></div><div style=3D"margin: 0in 0in =
0.0001pt; font-size: 11pt; font-family: Calibri, =
sans-serif;">&gt;&nbsp;&nbsp;&nbsp;&nbsp; The draft authors believe that =
this document is ready for publication.<o:p></o:p></div><div =
style=3D"margin: 0in 0in 0.0001pt; font-size: 11pt; font-family: =
Calibri, sans-serif;">&gt;&nbsp;&nbsp;&nbsp;&nbsp; The document has =
received review comments from working group =
members,<o:p></o:p></div><div style=3D"margin: 0in 0in 0.0001pt; =
font-size: 11pt; font-family: Calibri, =
sans-serif;">&gt;&nbsp;&nbsp;&nbsp;&nbsp; and from the OAuth working =
group chairs. Implementations exist and they<o:p></o:p></div><div =
style=3D"margin: 0in 0in 0.0001pt; font-size: 11pt; font-family: =
Calibri, sans-serif;">&gt;&nbsp;&nbsp;&nbsp;&nbsp; have tested for =
interoperability as part of the OpenID Connect =
interop<o:p></o:p></div><div style=3D"margin: 0in 0in 0.0001pt; =
font-size: 11pt; font-family: Calibri, =
sans-serif;">&gt;&nbsp;&nbsp;&nbsp;&nbsp; events.<o:p></o:p></div><div =
style=3D"margin: 0in 0in 0.0001pt; font-size: 11pt; font-family: =
Calibri, sans-serif;">&gt;<o:p></o:p></div><div style=3D"margin: 0in 0in =
0.0001pt; font-size: 11pt; font-family: Calibri, =
sans-serif;">&gt;&nbsp;&nbsp;&nbsp;&nbsp; (4) Does the document Shepherd =
have any concerns about the depth or<o:p></o:p></div><div style=3D"margin:=
 0in 0in 0.0001pt; font-size: 11pt; font-family: Calibri, =
sans-serif;">&gt;&nbsp;&nbsp;&nbsp;&nbsp; breadth of the reviews that =
have been performed?<o:p></o:p></div><div style=3D"margin: 0in 0in =
0.0001pt; font-size: 11pt; font-family: Calibri, =
sans-serif;">&gt;<o:p></o:p></div><div style=3D"margin: 0in 0in =
0.0001pt; font-size: 11pt; font-family: Calibri, =
sans-serif;">&gt;&nbsp;&nbsp;&nbsp;&nbsp; This document has gotten =
enough feedback from the working group.<o:p></o:p></div><div =
style=3D"margin: 0in 0in 0.0001pt; font-size: 11pt; font-family: =
Calibri, sans-serif;">&gt;<o:p></o:p></div><div style=3D"margin: 0in 0in =
0.0001pt; font-size: 11pt; font-family: Calibri, =
sans-serif;">&gt;&nbsp;&nbsp;&nbsp;&nbsp; (5) Do portions of the =
document need review from a particular or from<o:p></o:p></div><div =
style=3D"margin: 0in 0in 0.0001pt; font-size: 11pt; font-family: =
Calibri, sans-serif;">&gt;&nbsp;&nbsp;&nbsp;&nbsp; broader perspective, =
e.g., security, operational complexity, AAA, DNS,<o:p></o:p></div><div =
style=3D"margin: 0in 0in 0.0001pt; font-size: 11pt; font-family: =
Calibri, sans-serif;">&gt;&nbsp;&nbsp;&nbsp;&nbsp; DHCP, XML, or =
internationalization? If so, describe the review that =
took<o:p></o:p></div><div style=3D"margin: 0in 0in 0.0001pt; font-size: =
11pt; font-family: Calibri, sans-serif;">&gt;&nbsp;&nbsp;&nbsp;&nbsp; =
place.<o:p></o:p></div><div style=3D"margin: 0in 0in 0.0001pt; =
font-size: 11pt; font-family: Calibri, =
sans-serif;">&gt;<o:p></o:p></div><div style=3D"margin: 0in 0in =
0.0001pt; font-size: 11pt; font-family: Calibri, =
sans-serif;">&gt;&nbsp;&nbsp;&nbsp;&nbsp; Since the OAuth working group =
develops security protocols any feedback<o:p></o:p></div><div =
style=3D"margin: 0in 0in 0.0001pt; font-size: 11pt; font-family: =
Calibri, sans-serif;">&gt;&nbsp;&nbsp;&nbsp;&nbsp; from the security =
community is always appreciated.<o:p></o:p></div><div style=3D"margin: =
0in 0in 0.0001pt; font-size: 11pt; font-family: Calibri, =
sans-serif;">&gt;&nbsp;&nbsp;&nbsp;&nbsp; The JWT document heavily =
depends on the work in the JOSE working group<o:p></o:p></div><div =
style=3D"margin: 0in 0in 0.0001pt; font-size: 11pt; font-family: =
Calibri, sans-serif;">&gt;&nbsp;&nbsp;&nbsp;&nbsp; since it re-uses the =
JWE and the JWS specifications.<o:p></o:p></div><div style=3D"margin: =
0in 0in 0.0001pt; font-size: 11pt; font-family: Calibri, =
sans-serif;">&gt;<o:p></o:p></div><div style=3D"margin: 0in 0in =
0.0001pt; font-size: 11pt; font-family: Calibri, =
sans-serif;">&gt;&nbsp;&nbsp;&nbsp;&nbsp; (6) Describe any specific =
concerns or issues that the Document Shepherd<o:p></o:p></div><div =
style=3D"margin: 0in 0in 0.0001pt; font-size: 11pt; font-family: =
Calibri, sans-serif;">&gt;&nbsp;&nbsp;&nbsp;&nbsp; has with this =
document that the Responsible Area Director and/or =
the<o:p></o:p></div><div style=3D"margin: 0in 0in 0.0001pt; font-size: =
11pt; font-family: Calibri, sans-serif;">&gt;&nbsp;&nbsp;&nbsp;&nbsp; =
IESG should be aware of? For example, perhaps he or she is =
uncomfortable<o:p></o:p></div><div style=3D"margin: 0in 0in 0.0001pt; =
font-size: 11pt; font-family: Calibri, =
sans-serif;">&gt;&nbsp;&nbsp;&nbsp;&nbsp; with certain parts of the =
document, or has concerns whether there really<o:p></o:p></div><div =
style=3D"margin: 0in 0in 0.0001pt; font-size: 11pt; font-family: =
Calibri, sans-serif;">&gt;&nbsp;&nbsp;&nbsp;&nbsp; is a need for it. In =
any event, if the WG has discussed those issues and<o:p></o:p></div><div =
style=3D"margin: 0in 0in 0.0001pt; font-size: 11pt; font-family: =
Calibri, sans-serif;">&gt;&nbsp;&nbsp;&nbsp;&nbsp; has indicated that it =
still wishes to advance the document, detail those<o:p></o:p></div><div =
style=3D"margin: 0in 0in 0.0001pt; font-size: 11pt; font-family: =
Calibri, sans-serif;">&gt;&nbsp;&nbsp;&nbsp;&nbsp; concerns =
here.<o:p></o:p></div><div style=3D"margin: 0in 0in 0.0001pt; font-size: =
11pt; font-family: Calibri, sans-serif;">&gt;<o:p></o:p></div><div =
style=3D"margin: 0in 0in 0.0001pt; font-size: 11pt; font-family: =
Calibri, sans-serif;">&gt;&nbsp;&nbsp;&nbsp;&nbsp; The shepherd has no =
concerns with this document.<o:p></o:p></div><div style=3D"margin: 0in =
0in 0.0001pt; font-size: 11pt; font-family: Calibri, =
sans-serif;">&gt;<o:p></o:p></div><div style=3D"margin: 0in 0in =
0.0001pt; font-size: 11pt; font-family: Calibri, =
sans-serif;">&gt;&nbsp;&nbsp;&nbsp;&nbsp; (7) Has each author confirmed =
that any and all appropriate IPR<o:p></o:p></div><div style=3D"margin: =
0in 0in 0.0001pt; font-size: 11pt; font-family: Calibri, =
sans-serif;">&gt;&nbsp;&nbsp;&nbsp;&nbsp; disclosures required for full =
conformance with the provisions of BCP 78<o:p></o:p></div><div =
style=3D"margin: 0in 0in 0.0001pt; font-size: 11pt; font-family: =
Calibri, sans-serif;">&gt;&nbsp;&nbsp;&nbsp;&nbsp; and BCP 79 have =
already been filed. If not, explain why?<o:p></o:p></div><div =
style=3D"margin: 0in 0in 0.0001pt; font-size: 11pt; font-family: =
Calibri, sans-serif;">&gt;<o:p></o:p></div><div style=3D"margin: 0in 0in =
0.0001pt; font-size: 11pt; font-family: Calibri, =
sans-serif;">&gt;&nbsp;&nbsp;&nbsp;&nbsp; [[Confirmation from the =
authors required.]]<o:p></o:p></div><div style=3D"margin: 0in 0in =
0.0001pt; font-size: 11pt; font-family: Calibri, =
sans-serif;">&gt;<o:p></o:p></div><div style=3D"margin: 0in 0in =
0.0001pt; font-size: 11pt; font-family: Calibri, =
sans-serif;">&gt;&nbsp;&nbsp;&nbsp;&nbsp; (8) Has an IPR disclosure been =
filed that references this document? If<o:p></o:p></div><div =
style=3D"margin: 0in 0in 0.0001pt; font-size: 11pt; font-family: =
Calibri, sans-serif;">&gt;&nbsp;&nbsp;&nbsp;&nbsp; so, summarize any WG =
discussion and conclusion regarding the IPR<o:p></o:p></div><div =
style=3D"margin: 0in 0in 0.0001pt; font-size: 11pt; font-family: =
Calibri, sans-serif;">&gt;&nbsp;&nbsp;&nbsp;&nbsp; =
disclosures.<o:p></o:p></div><div style=3D"margin: 0in 0in 0.0001pt; =
font-size: 11pt; font-family: Calibri, =
sans-serif;">&gt;<o:p></o:p></div><div style=3D"margin: 0in 0in =
0.0001pt; font-size: 11pt; font-family: Calibri, =
sans-serif;">&gt;&nbsp;&nbsp;&nbsp;&nbsp; Two IPRs have been filed for =
the JWT specification this document relies<o:p></o:p></div><div =
style=3D"margin: 0in 0in 0.0001pt; font-size: 11pt; font-family: =
Calibri, sans-serif;">&gt;&nbsp;&nbsp;&nbsp;&nbsp; on, =
see<o:p></o:p></div><div style=3D"margin: 0in 0in 0.0001pt; font-size: =
11pt; font-family: Calibri, =
sans-serif;">&gt;&nbsp;&nbsp;&nbsp;&nbsp;<o:p></o:p></div><div =
style=3D"margin: 0in 0in 0.0001pt; font-size: 11pt; font-family: =
Calibri, sans-serif;">&gt; <a =
href=3D"http://datatracker.ietf.org/ipr/search/?option=3Ddocument_search&a=
mp;id=3Ddraf">http://datatracker.ietf.org/ipr/search/?option=3Ddocument_se=
arch&amp;id=3Ddraf</a><o:p></o:p></div><div style=3D"margin: 0in 0in =
0.0001pt; font-size: 11pt; font-family: Calibri, sans-serif;">&gt; =
t-ietf-oauth-json-web-token<o:p></o:p></div><div style=3D"margin: 0in =
0in 0.0001pt; font-size: 11pt; font-family: Calibri, =
sans-serif;">&gt;<o:p></o:p></div><div style=3D"margin: 0in 0in =
0.0001pt; font-size: 11pt; font-family: Calibri, =
sans-serif;">&gt;<o:p></o:p></div><div style=3D"margin: 0in 0in =
0.0001pt; font-size: 11pt; font-family: Calibri, =
sans-serif;">&gt;&nbsp;&nbsp;&nbsp;&nbsp; There was no discussion =
regarding those two IPRs on the mailing list.<o:p></o:p></div><div =
style=3D"margin: 0in 0in 0.0001pt; font-size: 11pt; font-family: =
Calibri, sans-serif;">&gt;<o:p></o:p></div><div style=3D"margin: 0in 0in =
0.0001pt; font-size: 11pt; font-family: Calibri, =
sans-serif;">&gt;&nbsp;&nbsp;&nbsp;&nbsp; (9) How solid is the WG =
consensus behind this document? Does it<o:p></o:p></div><div =
style=3D"margin: 0in 0in 0.0001pt; font-size: 11pt; font-family: =
Calibri, sans-serif;">&gt;&nbsp;&nbsp;&nbsp;&nbsp; represent the strong =
concurrence of a few individuals, with others being<o:p></o:p></div><div =
style=3D"margin: 0in 0in 0.0001pt; font-size: 11pt; font-family: =
Calibri, sans-serif;">&gt;&nbsp;&nbsp;&nbsp;&nbsp; silent, or does the =
WG as a whole understand and agree with it?<o:p></o:p></div><div =
style=3D"margin: 0in 0in 0.0001pt; font-size: 11pt; font-family: =
Calibri, sans-serif;">&gt;<o:p></o:p></div><div style=3D"margin: 0in 0in =
0.0001pt; font-size: 11pt; font-family: Calibri, sans-serif;">&gt;&nbsp; =
&nbsp;&nbsp;&nbsp;The working group has consensus to publish this =
document.<o:p></o:p></div><div style=3D"margin: 0in 0in 0.0001pt; =
font-size: 11pt; font-family: Calibri, =
sans-serif;">&gt;<o:p></o:p></div><div style=3D"margin: 0in 0in =
0.0001pt; font-size: 11pt; font-family: Calibri, =
sans-serif;">&gt;&nbsp;&nbsp;&nbsp;&nbsp; (10) Has anyone threatened an =
appeal or otherwise indicated extreme<o:p></o:p></div><div =
style=3D"margin: 0in 0in 0.0001pt; font-size: 11pt; font-family: =
Calibri, sans-serif;">&gt;&nbsp;&nbsp;&nbsp;&nbsp; discontent? If so, =
please summarise the areas of conflict in separate<o:p></o:p></div><div =
style=3D"margin: 0in 0in 0.0001pt; font-size: 11pt; font-family: =
Calibri, sans-serif;">&gt;&nbsp;&nbsp;&nbsp;&nbsp; email messages to the =
Responsible Area Director. (It should be in a<o:p></o:p></div><div =
style=3D"margin: 0in 0in 0.0001pt; font-size: 11pt; font-family: =
Calibri, sans-serif;">&gt;&nbsp;&nbsp;&nbsp;&nbsp; separate email =
because this questionnaire is publicly available.)<o:p></o:p></div><div =
style=3D"margin: 0in 0in 0.0001pt; font-size: 11pt; font-family: =
Calibri, sans-serif;">&gt;<o:p></o:p></div><div style=3D"margin: 0in 0in =
0.0001pt; font-size: 11pt; font-family: Calibri, =
sans-serif;">&gt;&nbsp;&nbsp;&nbsp;&nbsp; No appeal or extreme =
discontent has been raised.<o:p></o:p></div><div style=3D"margin: 0in =
0in 0.0001pt; font-size: 11pt; font-family: Calibri, =
sans-serif;">&gt;<o:p></o:p></div><div style=3D"margin: 0in 0in =
0.0001pt; font-size: 11pt; font-family: Calibri, =
sans-serif;">&gt;&nbsp;&nbsp;&nbsp;&nbsp; (11) Identify any ID nits the =
Document Shepherd has found in this<o:p></o:p></div><div style=3D"margin: =
0in 0in 0.0001pt; font-size: 11pt; font-family: Calibri, =
sans-serif;">&gt;&nbsp;&nbsp;&nbsp;&nbsp; document. (See <a =
href=3D"http://www.ietf.org/tools/idnits/">http://www.ietf.org/tools/idnit=
s/</a> and the Internet-Drafts<o:p></o:p></div><div style=3D"margin: 0in =
0in 0.0001pt; font-size: 11pt; font-family: Calibri, =
sans-serif;">&gt;&nbsp;&nbsp;&nbsp;&nbsp; Checklist). Boilerplate checks =
are not enough; this check needs to be<o:p></o:p></div><div =
style=3D"margin: 0in 0in 0.0001pt; font-size: 11pt; font-family: =
Calibri, sans-serif;">&gt;&nbsp;&nbsp;&nbsp;&nbsp; =
thorough.<o:p></o:p></div><div style=3D"margin: 0in 0in 0.0001pt; =
font-size: 11pt; font-family: Calibri, =
sans-serif;">&gt;<o:p></o:p></div><div style=3D"margin: 0in 0in =
0.0001pt; font-size: 11pt; font-family: Calibri, =
sans-serif;">&gt;&nbsp;&nbsp;&nbsp;&nbsp; The shepherd has checked the =
nits. The shepherd has not verified the<o:p></o:p></div><div =
style=3D"margin: 0in 0in 0.0001pt; font-size: 11pt; font-family: =
Calibri, sans-serif;">&gt;&nbsp;&nbsp;&nbsp;&nbsp; examples for =
correctness.<o:p></o:p></div><div style=3D"margin: 0in 0in 0.0001pt; =
font-size: 11pt; font-family: Calibri, =
sans-serif;">&gt;<o:p></o:p></div><div style=3D"margin: 0in 0in =
0.0001pt; font-size: 11pt; font-family: Calibri, =
sans-serif;">&gt;&nbsp;&nbsp;&nbsp;&nbsp; (12) Describe how the document =
meets any required formal review<o:p></o:p></div><div style=3D"margin: =
0in 0in 0.0001pt; font-size: 11pt; font-family: Calibri, =
sans-serif;">&gt;&nbsp;&nbsp;&nbsp;&nbsp; criteria, such as the MIB =
Doctor, media type, and URI type reviews.<o:p></o:p></div><div =
style=3D"margin: 0in 0in 0.0001pt; font-size: 11pt; font-family: =
Calibri, sans-serif;">&gt;<o:p></o:p></div><div style=3D"margin: 0in 0in =
0.0001pt; font-size: 11pt; font-family: Calibri, =
sans-serif;">&gt;&nbsp;&nbsp;&nbsp;&nbsp; The document does not require =
a formal review even though it contains<o:p></o:p></div><div =
style=3D"margin: 0in 0in 0.0001pt; font-size: 11pt; font-family: =
Calibri, sans-serif;">&gt;&nbsp;&nbsp;&nbsp;&nbsp; JSON-based =
examples.<o:p></o:p></div><div style=3D"margin: 0in 0in 0.0001pt; =
font-size: 11pt; font-family: Calibri, =
sans-serif;">&gt;<o:p></o:p></div><div style=3D"margin: 0in 0in =
0.0001pt; font-size: 11pt; font-family: Calibri, =
sans-serif;">&gt;&nbsp;&nbsp;&nbsp;&nbsp; (13) Have all references =
within this document been identified as either<o:p></o:p></div><div =
style=3D"margin: 0in 0in 0.0001pt; font-size: 11pt; font-family: =
Calibri, sans-serif;">&gt;&nbsp;&nbsp;&nbsp;&nbsp; normative or =
informative?<o:p></o:p></div><div style=3D"margin: 0in 0in 0.0001pt; =
font-size: 11pt; font-family: Calibri, =
sans-serif;">&gt;<o:p></o:p></div><div style=3D"margin: 0in 0in =
0.0001pt; font-size: 11pt; font-family: Calibri, =
sans-serif;">&gt;&nbsp;&nbsp;&nbsp;&nbsp; Yes.<o:p></o:p></div><div =
style=3D"margin: 0in 0in 0.0001pt; font-size: 11pt; font-family: =
Calibri, sans-serif;">&gt;<o:p></o:p></div><div style=3D"margin: 0in 0in =
0.0001pt; font-size: 11pt; font-family: Calibri, =
sans-serif;">&gt;&nbsp;&nbsp;&nbsp;&nbsp; (14) Are there normative =
references to documents that are not ready for<o:p></o:p></div><div =
style=3D"margin: 0in 0in 0.0001pt; font-size: 11pt; font-family: =
Calibri, sans-serif;">&gt;&nbsp;&nbsp;&nbsp;&nbsp; advancement or are =
otherwise in an unclear state? If such normative<o:p></o:p></div><div =
style=3D"margin: 0in 0in 0.0001pt; font-size: 11pt; font-family: =
Calibri, sans-serif;">&gt;&nbsp;&nbsp;&nbsp;&nbsp; references exist, =
what is the plan for their completion?<o:p></o:p></div><div =
style=3D"margin: 0in 0in 0.0001pt; font-size: 11pt; font-family: =
Calibri, sans-serif;">&gt;<o:p></o:p></div><div style=3D"margin: 0in 0in =
0.0001pt; font-size: 11pt; font-family: Calibri, =
sans-serif;">&gt;&nbsp;&nbsp;&nbsp;&nbsp; There are various JOSE =
documents that have not been published as RFCs<o:p></o:p></div><div =
style=3D"margin: 0in 0in 0.0001pt; font-size: 11pt; font-family: =
Calibri, sans-serif;">&gt;&nbsp;&nbsp;&nbsp;&nbsp; yet. As such, this =
document cannot be published before the respective<o:p></o:p></div><div =
style=3D"margin: 0in 0in 0.0001pt; font-size: 11pt; font-family: =
Calibri, sans-serif;">&gt;&nbsp;&nbsp;&nbsp;&nbsp; JOSE documents are =
finalized.<o:p></o:p></div><div style=3D"margin: 0in 0in 0.0001pt; =
font-size: 11pt; font-family: Calibri, =
sans-serif;">&gt;<o:p></o:p></div><div style=3D"margin: 0in 0in =
0.0001pt; font-size: 11pt; font-family: Calibri, =
sans-serif;">&gt;&nbsp;&nbsp;&nbsp;&nbsp; (15) Are there downward =
normative references references (see RFC 3967)?<o:p></o:p></div><div =
style=3D"margin: 0in 0in 0.0001pt; font-size: 11pt; font-family: =
Calibri, sans-serif;">&gt;&nbsp;&nbsp;&nbsp;&nbsp; If so, list these =
downward references to support the Area Director in<o:p></o:p></div><div =
style=3D"margin: 0in 0in 0.0001pt; font-size: 11pt; font-family: =
Calibri, sans-serif;">&gt;&nbsp;&nbsp;&nbsp;&nbsp; the Last Call =
procedure.<o:p></o:p></div><div style=3D"margin: 0in 0in 0.0001pt; =
font-size: 11pt; font-family: Calibri, =
sans-serif;">&gt;<o:p></o:p></div><div style=3D"margin: 0in 0in =
0.0001pt; font-size: 11pt; font-family: Calibri, =
sans-serif;">&gt;&nbsp;&nbsp;&nbsp;&nbsp; The document contains a =
reference to<o:p></o:p></div><div style=3D"margin: 0in 0in 0.0001pt; =
font-size: 11pt; font-family: Calibri, =
sans-serif;">&gt;<o:p></o:p></div><div style=3D"margin: 0in 0in =
0.0001pt; font-size: 11pt; font-family: Calibri, =
sans-serif;">&gt;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; =
[ECMAScript]<o:p></o:p></div><div style=3D"margin: 0in 0in 0.0001pt; =
font-size: 11pt; font-family: Calibri, =
sans-serif;">&gt;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nb=
sp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; Ecma International, =
"ECMAScript Language Specification,<o:p></o:p></div><div style=3D"margin: =
0in 0in 0.0001pt; font-size: 11pt; font-family: Calibri, =
sans-serif;">&gt;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nb=
sp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; 5.1 Edition", ECMA =
262, June 2011.<o:p></o:p></div><div style=3D"margin: 0in 0in 0.0001pt; =
font-size: 11pt; font-family: Calibri, =
sans-serif;">&gt;<o:p></o:p></div><div style=3D"margin: 0in 0in =
0.0001pt; font-size: 11pt; font-family: Calibri, =
sans-serif;">&gt;&nbsp;&nbsp;&nbsp;&nbsp; which might require a =
downref.<o:p></o:p></div><div style=3D"margin: 0in 0in 0.0001pt; =
font-size: 11pt; font-family: Calibri, =
sans-serif;">&gt;<o:p></o:p></div><div style=3D"margin: 0in 0in =
0.0001pt; font-size: 11pt; font-family: Calibri, =
sans-serif;">&gt;&nbsp;&nbsp;&nbsp;&nbsp; RFC 6755 is also a =
downref.<o:p></o:p></div><div style=3D"margin: 0in 0in 0.0001pt; =
font-size: 11pt; font-family: Calibri, =
sans-serif;">&gt;<o:p></o:p></div><div style=3D"margin: 0in 0in =
0.0001pt; font-size: 11pt; font-family: Calibri, =
sans-serif;">&gt;<o:p></o:p></div><div style=3D"margin: 0in 0in =
0.0001pt; font-size: 11pt; font-family: Calibri, =
sans-serif;">&gt;&nbsp;&nbsp;&nbsp;&nbsp; (16) Will publication of this =
document change the status of any existing<o:p></o:p></div><div =
style=3D"margin: 0in 0in 0.0001pt; font-size: 11pt; font-family: =
Calibri, sans-serif;">&gt;&nbsp;&nbsp;&nbsp;&nbsp; RFCs? Are those RFCs =
listed on the title page header, listed in the<o:p></o:p></div><div =
style=3D"margin: 0in 0in 0.0001pt; font-size: 11pt; font-family: =
Calibri, sans-serif;">&gt;&nbsp;&nbsp;&nbsp;&nbsp; abstract, and =
discussed in the introduction? If the RFCs are not =
listed<o:p></o:p></div><div style=3D"margin: 0in 0in 0.0001pt; =
font-size: 11pt; font-family: Calibri, =
sans-serif;">&gt;&nbsp;&nbsp;&nbsp;&nbsp; in the Abstract and =
Introduction, explain why, and point to the part of<o:p></o:p></div><div =
style=3D"margin: 0in 0in 0.0001pt; font-size: 11pt; font-family: =
Calibri, sans-serif;">&gt;&nbsp;&nbsp;&nbsp;&nbsp; the document where =
the relationship of this document to the other RFCs<o:p></o:p></div><div =
style=3D"margin: 0in 0in 0.0001pt; font-size: 11pt; font-family: =
Calibri, sans-serif;">&gt;&nbsp;&nbsp;&nbsp;&nbsp; is discussed. If this =
information is not in the document, explain why<o:p></o:p></div><div =
style=3D"margin: 0in 0in 0.0001pt; font-size: 11pt; font-family: =
Calibri, sans-serif;">&gt;&nbsp;&nbsp;&nbsp;&nbsp; the WG considers it =
unnecessary.<o:p></o:p></div><div style=3D"margin: 0in 0in 0.0001pt; =
font-size: 11pt; font-family: Calibri, =
sans-serif;">&gt;<o:p></o:p></div><div style=3D"margin: 0in 0in =
0.0001pt; font-size: 11pt; font-family: Calibri, =
sans-serif;">&gt;&nbsp;&nbsp;&nbsp;&nbsp; The publication of this =
document does not change the status of other<o:p></o:p></div><div =
style=3D"margin: 0in 0in 0.0001pt; font-size: 11pt; font-family: =
Calibri, sans-serif;">&gt;&nbsp;&nbsp;&nbsp;&nbsp; =
RFCs.<o:p></o:p></div><div style=3D"margin: 0in 0in 0.0001pt; font-size: =
11pt; font-family: Calibri, sans-serif;">&gt;<o:p></o:p></div><div =
style=3D"margin: 0in 0in 0.0001pt; font-size: 11pt; font-family: =
Calibri, sans-serif;">&gt;&nbsp;&nbsp;&nbsp;&nbsp; (17) Describe the =
Document Shepherd's review of the IANA =
considerations<o:p></o:p></div><div style=3D"margin: 0in 0in 0.0001pt; =
font-size: 11pt; font-family: Calibri, =
sans-serif;">&gt;&nbsp;&nbsp;&nbsp;&nbsp; section, especially with =
regard to its consistency with the body of the<o:p></o:p></div><div =
style=3D"margin: 0in 0in 0.0001pt; font-size: 11pt; font-family: =
Calibri, sans-serif;">&gt;&nbsp;&nbsp;&nbsp;&nbsp; document. Confirm =
that all protocol extensions that the document =
makes<o:p></o:p></div><div style=3D"margin: 0in 0in 0.0001pt; font-size: =
11pt; font-family: Calibri, sans-serif;">&gt;&nbsp;&nbsp;&nbsp;&nbsp; =
are associated with the appropriate reservations in IANA =
registries.<o:p></o:p></div><div style=3D"margin: 0in 0in 0.0001pt; =
font-size: 11pt; font-family: Calibri, =
sans-serif;">&gt;&nbsp;&nbsp;&nbsp;&nbsp; Confirm that any referenced =
IANA registries have been clearly<o:p></o:p></div><div style=3D"margin: =
0in 0in 0.0001pt; font-size: 11pt; font-family: Calibri, =
sans-serif;">&gt;&nbsp;&nbsp;&nbsp;&nbsp; identified. Confirm that newly =
created IANA registries include a<o:p></o:p></div><div style=3D"margin: =
0in 0in 0.0001pt; font-size: 11pt; font-family: Calibri, =
sans-serif;">&gt;&nbsp;&nbsp;&nbsp;&nbsp; detailed specification of the =
initial contents for the registry, that<o:p></o:p></div><div =
style=3D"margin: 0in 0in 0.0001pt; font-size: 11pt; font-family: =
Calibri, sans-serif;">&gt;&nbsp;&nbsp;&nbsp;&nbsp; allocations =
procedures for future registrations are defined, and =
a<o:p></o:p></div><div style=3D"margin: 0in 0in 0.0001pt; font-size: =
11pt; font-family: Calibri, sans-serif;">&gt;&nbsp;&nbsp;&nbsp;&nbsp; =
reasonable name for the new registry has been suggested (see RFC =
5226).<o:p></o:p></div><div style=3D"margin: 0in 0in 0.0001pt; =
font-size: 11pt; font-family: Calibri, =
sans-serif;">&gt;<o:p></o:p></div><div style=3D"margin: 0in 0in =
0.0001pt; font-size: 11pt; font-family: Calibri, =
sans-serif;">&gt;&nbsp;&nbsp;&nbsp;&nbsp; The document creates a new =
registry for JWT claims and populates this<o:p></o:p></div><div =
style=3D"margin: 0in 0in 0.0001pt; font-size: 11pt; font-family: =
Calibri, sans-serif;">&gt;&nbsp;&nbsp;&nbsp;&nbsp; registry with =
values.<o:p></o:p></div><div style=3D"margin: 0in 0in 0.0001pt; =
font-size: 11pt; font-family: Calibri, =
sans-serif;">&gt;&nbsp;&nbsp;&nbsp;&nbsp; It also registers values into =
two existing registries, namely into<o:p></o:p></div><div style=3D"margin:=
 0in 0in 0.0001pt; font-size: 11pt; font-family: Calibri, =
sans-serif;">&gt;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; * the RFC 6755 created =
OAuth URN registry, and<o:p></o:p></div><div style=3D"margin: 0in 0in =
0.0001pt; font-size: 11pt; font-family: Calibri, =
sans-serif;">&gt;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; * the media type =
registry<o:p></o:p></div><div style=3D"margin: 0in 0in 0.0001pt; =
font-size: 11pt; font-family: Calibri, =
sans-serif;">&gt;<o:p></o:p></div><div style=3D"margin: 0in 0in =
0.0001pt; font-size: 11pt; font-family: Calibri, =
sans-serif;">&gt;&nbsp;&nbsp;&nbsp;&nbsp; (18) List any new IANA =
registries that require Expert Review for future<o:p></o:p></div><div =
style=3D"margin: 0in 0in 0.0001pt; font-size: 11pt; font-family: =
Calibri, sans-serif;">&gt;&nbsp;&nbsp;&nbsp;&nbsp; allocations. Provide =
any public guidance that the IESG would find useful<o:p></o:p></div><div =
style=3D"margin: 0in 0in 0.0001pt; font-size: 11pt; font-family: =
Calibri, sans-serif;">&gt;&nbsp;&nbsp;&nbsp;&nbsp; in selecting the IANA =
Experts for these new registries.<o:p></o:p></div><div style=3D"margin: =
0in 0in 0.0001pt; font-size: 11pt; font-family: Calibri, =
sans-serif;">&gt;<o:p></o:p></div><div style=3D"margin: 0in 0in =
0.0001pt; font-size: 11pt; font-family: Calibri, =
sans-serif;">&gt;&nbsp;&nbsp;&nbsp;&nbsp; The newly created JWT claims =
registry requires expert review for future<o:p></o:p></div><div =
style=3D"margin: 0in 0in 0.0001pt; font-size: 11pt; font-family: =
Calibri, sans-serif;">&gt;&nbsp;&nbsp;&nbsp;&nbsp; allocations. Guidance =
is given in the document.<o:p></o:p></div><div style=3D"margin: 0in 0in =
0.0001pt; font-size: 11pt; font-family: Calibri, =
sans-serif;">&gt;&nbsp;&nbsp;&nbsp;&nbsp; The document shepherd =
volunteers to become an expert review.<o:p></o:p></div><div =
style=3D"margin: 0in 0in 0.0001pt; font-size: 11pt; font-family: =
Calibri, sans-serif;">&gt;<o:p></o:p></div><div style=3D"margin: 0in 0in =
0.0001pt; font-size: 11pt; font-family: Calibri, =
sans-serif;">&gt;&nbsp;&nbsp;&nbsp;&nbsp; (19) Describe reviews and =
automated checks performed by the Document<o:p></o:p></div><div =
style=3D"margin: 0in 0in 0.0001pt; font-size: 11pt; font-family: =
Calibri, sans-serif;">&gt;&nbsp;&nbsp;&nbsp;&nbsp; Shepherd to validate =
sections of the document written in a formal<o:p></o:p></div><div =
style=3D"margin: 0in 0in 0.0001pt; font-size: 11pt; font-family: =
Calibri, sans-serif;">&gt;&nbsp;&nbsp;&nbsp;&nbsp; language, such as XML =
code, BNF rules, MIB definitions, etc.<o:p></o:p></div><div =
style=3D"margin: 0in 0in 0.0001pt; font-size: 11pt; font-family: =
Calibri, sans-serif;">&gt;<o:p></o:p></div><div style=3D"margin: 0in 0in =
0.0001pt; font-size: 11pt; font-family: Calibri, =
sans-serif;">&gt;&nbsp;&nbsp;&nbsp;&nbsp; There are examples in the =
document that use a JSON-based encoding. The<o:p></o:p></div><div =
style=3D"margin: 0in 0in 0.0001pt; font-size: 11pt; font-family: =
Calibri, sans-serif;">&gt;&nbsp;&nbsp;&nbsp;&nbsp; document shepherd has =
reviewed those examples but has not verified the<o:p></o:p></div><div =
style=3D"margin: 0in 0in 0.0001pt; font-size: 11pt; font-family: =
Calibri, sans-serif;">&gt;&nbsp;&nbsp;&nbsp;&nbsp; correctness of the =
cryptographic operations.<o:p></o:p></div><div style=3D"margin: 0in 0in =
0.0001pt; font-size: 11pt; font-family: Calibri, =
sans-serif;">&gt;<o:p></o:p></div><div style=3D"margin: 0in 0in =
0.0001pt; font-size: 11pt; font-family: Calibri, =
sans-serif;">&gt;<o:p></o:p></div><div style=3D"margin: 0in 0in =
0.0001pt; font-size: 11pt; font-family: Calibri, =
sans-serif;">&gt;<o:p></o:p></div><div style=3D"margin: 0in 0in =
0.0001pt; font-size: 11pt; font-family: Calibri, =
sans-serif;">&gt;&nbsp;&nbsp;&nbsp;&nbsp; =
_______________________________________________<o:p></o:p></div><div =
style=3D"margin: 0in 0in 0.0001pt; font-size: 11pt; font-family: =
Calibri, sans-serif;">&gt;&nbsp;&nbsp;&nbsp;&nbsp; OAuth mailing =
list<o:p></o:p></div><div style=3D"margin: 0in 0in 0.0001pt; font-size: =
11pt; font-family: Calibri, sans-serif;">&gt;&nbsp;&nbsp;&nbsp;&nbsp; <a =
href=3D"mailto:OAuth@ietf.org">OAuth@ietf.org</a> &lt;<a =
href=3D"mailto:OAuth@ietf.org">mailto:OAuth@ietf.org</a>&gt;<o:p></o:p></d=
iv><div style=3D"margin: 0in 0in 0.0001pt; font-size: 11pt; font-family: =
Calibri, sans-serif;">&gt;&nbsp;&nbsp;&nbsp;&nbsp; <a =
href=3D"https://www.ietf.org/mailman/listinfo/oauth">https://www.ietf.org/=
mailman/listinfo/oauth</a><o:p></o:p></div><div style=3D"margin: 0in 0in =
0.0001pt; font-size: 11pt; font-family: Calibri, =
sans-serif;">&gt;<o:p></o:p></div><div style=3D"margin: 0in 0in =
0.0001pt; font-size: 11pt; font-family: Calibri, =
sans-serif;">&gt;<o:p></o:p></div><div style=3D"margin: 0in 0in =
0.0001pt; font-size: 11pt; font-family: Calibri, =
sans-serif;"><o:p>&nbsp;</o:p></div></div>________________________________=
_______________<br>OAuth mailing list<br><a =
href=3D"mailto:OAuth@ietf.org">OAuth@ietf.org</a><br>https://www.ietf.org/=
mailman/listinfo/oauth</div></blockquote></div><br></div></body></html>=

--Apple-Mail=_FCF49E0E-44B6-42C3-B027-A184D1C84F2E--

