Re: [OAUTH-WG] Call for adoption: JWT Usage in OAuth2 Access Tokens

John Bradley <ve7jtb@ve7jtb.com> Mon, 08 April 2019 17:34 UTC

Return-Path: <ve7jtb@ve7jtb.com>
X-Original-To: oauth@ietfa.amsl.com
Delivered-To: oauth@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 59F941201EA for <oauth@ietfa.amsl.com>; Mon, 8 Apr 2019 10:34:27 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.902
X-Spam-Level:
X-Spam-Status: No, score=-1.902 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIMWL_WL_MED=-0.001, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, RCVD_IN_DNSWL_NONE=-0.0001, SPF_PASS=-0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (2048-bit key) header.d=ve7jtb-com.20150623.gappssmtp.com
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id c11EIdMx_ISj for <oauth@ietfa.amsl.com>; Mon, 8 Apr 2019 10:34:25 -0700 (PDT)
Received: from mail-qt1-x831.google.com (mail-qt1-x831.google.com [IPv6:2607:f8b0:4864:20::831]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 4E1C2120105 for <oauth@ietf.org>; Mon, 8 Apr 2019 10:34:25 -0700 (PDT)
Received: by mail-qt1-x831.google.com with SMTP id s15so8094982qtn.3 for <oauth@ietf.org>; Mon, 08 Apr 2019 10:34:25 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=ve7jtb-com.20150623.gappssmtp.com; s=20150623; h=subject:to:references:from:message-id:date:user-agent:mime-version :in-reply-to:content-transfer-encoding:content-language; bh=fbUFHbcTr9LyuKlbcCUT4klQjBGRFzl2bRBVd2pv5VA=; b=19lwk64z1K0i+fpBaZNYqc+IweVcZ2jBepnetQ1nM2/V+9bbVk9GsRwJsAJ0MdarWO mHtgBIqfm08oW+i8mDnp0bP4VgU86K7W+6kFe+nDpXnTl9QdmGf6SH71zcp3lvM6WAd3 sIAOSzKNuMnTK2ppSDfA/8bdafbkv7Y/KgWZb+R56ZNvaVxu9mJQAqtaD3XNcq4RWJFW 4xGpvCk7vk+rZRK+UBRIC6eiDCHwpO5cRTY9Qrq4rbDHCE/9e343O6EO4hgtM9S+gCSm jwOlUu4LdSCOr4ZJeqp7Mt3TaYVj0QZ58Q0iRTANhuXjUuFe9vVXX3zmbJSlNBdNE+cY iGnw==
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20161025; h=x-gm-message-state:subject:to:references:from:message-id:date :user-agent:mime-version:in-reply-to:content-transfer-encoding :content-language; bh=fbUFHbcTr9LyuKlbcCUT4klQjBGRFzl2bRBVd2pv5VA=; b=ANLHBOQCpRYCqPZTrKksjgVbyd3n3iAn0j6kZTIPyacPzO55UyyXFW28CV/r0Ntj7b qe8JRKBW9tck2K3v87kHzkbcD8rOy1oicFJrm9po6u6qqbfAFK1CoaAlyQq3UYu35XIc 2Y/mushUYl3sc3g3TSmov69sBUUQC2TOgqaB9fXJeJ0nAN+JprJIEmZRUk1kG2nRFxKs zm8d4115BveKmNeejSD7HHtnjWMSpoP0tLgtzDVsVKLLEIrVX5lwUYAGVNrjaQP2PbOU /Gw/0BJ9G9eDjlL3mCSXvwRrQEhwweNCJUIur5M1Cgl9jxRDoproifN3olw8USuFWmgn /xBw==
X-Gm-Message-State: APjAAAVYq1m6qkm5bKLUN3ZmkXzSVmXTVJ3m6AKH/KHHOdfP155zP6Y9 CAo28bD2i05rjdNttOH/QBkPP/Sde52sQA==
X-Google-Smtp-Source: APXvYqxLc3qDyfbT51KnxMNc+hlQEkNsH8xV0q+P7Zarkk0FYbJUvTOEZblE4d0jJWvtFlOuDRNpHg==
X-Received: by 2002:ac8:2d02:: with SMTP id n2mr25342275qta.229.1554744863593; Mon, 08 Apr 2019 10:34:23 -0700 (PDT)
Received: from [192.168.8.105] ([181.203.40.167]) by smtp.gmail.com with ESMTPSA id m46sm20531203qtk.95.2019.04.08.10.34.22 for <oauth@ietf.org> (version=TLS1_3 cipher=AEAD-AES128-GCM-SHA256 bits=128/128); Mon, 08 Apr 2019 10:34:22 -0700 (PDT)
To: oauth@ietf.org
References: <AM6PR08MB36861CE2351D6922D5F8F91FFA2C0@AM6PR08MB3686.eurprd08.prod.outlook.com>
From: John Bradley <ve7jtb@ve7jtb.com>
Message-ID: <7caf266b-559b-52dc-e5fd-68d43c827ef8@ve7jtb.com>
Date: Mon, 08 Apr 2019 19:34:18 +0200
User-Agent: Mozilla/5.0 (Windows NT 10.0; WOW64; rv:66.0) Gecko/20100101 Thunderbird/66.0
MIME-Version: 1.0
In-Reply-To: <AM6PR08MB36861CE2351D6922D5F8F91FFA2C0@AM6PR08MB3686.eurprd08.prod.outlook.com>
Content-Type: text/plain; charset="utf-8"; format="flowed"
Content-Transfer-Encoding: 7bit
Content-Language: en-US
Archived-At: <https://mailarchive.ietf.org/arch/msg/oauth/U3zbMxv7pjuAVPPejhu8TZMJ_cw>
Subject: Re: [OAUTH-WG] Call for adoption: JWT Usage in OAuth2 Access Tokens
X-BeenThere: oauth@ietf.org
X-Mailman-Version: 2.1.29
Precedence: list
List-Id: OAUTH WG <oauth.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/oauth>, <mailto:oauth-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/oauth/>
List-Post: <mailto:oauth@ietf.org>
List-Help: <mailto:oauth-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/oauth>, <mailto:oauth-request@ietf.org?subject=subscribe>
X-List-Received-Date: Mon, 08 Apr 2019 17:34:27 -0000

I agree this should be adopted as a working group document.


On 4/8/2019 7:07 PM, Hannes Tschofenig wrote:
> Hi all,
>
> this is the call for adoption of the 'JWT Usage in OAuth2 Access Tokens'  document following the positive feedback at the last IETF meeting in Prague.
>
> Here is the document:
> https://tools.ietf.org/html/draft-bertocci-oauth-access-token-jwt-00
>
> Please let us know by April 22nd whether you accept / object to the
> adoption of this document as a starting point for work in the OAuth
> working group.
>
> Ciao
> Hannes & Rifaat
>
> IMPORTANT NOTICE: The contents of this email and any attachments are confidential and may also be privileged. If you are not the intended recipient, please notify the sender immediately and do not disclose the contents to any other person, use it for any purpose, or store or copy the information in any medium. Thank you.
>
> _______________________________________________
> OAuth mailing list
> OAuth@ietf.org
> https://www.ietf.org/mailman/listinfo/oauth