[OAUTH-WG] PAR metadata

Torsten Lodderstedt <torsten@lodderstedt.net> Tue, 31 December 2019 14:38 UTC

Return-Path: <torsten@lodderstedt.net>
X-Original-To: oauth@ietfa.amsl.com
Delivered-To: oauth@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 4E707120123 for <oauth@ietfa.amsl.com>; Tue, 31 Dec 2019 06:38:57 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2
X-Spam-Level:
X-Spam-Status: No, score=-2 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, RCVD_IN_DNSWL_NONE=-0.0001, SPF_HELO_NONE=0.001, SPF_PASS=-0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (2048-bit key) header.d=lodderstedt.net
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id hpWgtsse0eQ0 for <oauth@ietfa.amsl.com>; Tue, 31 Dec 2019 06:38:55 -0800 (PST)
Received: from mail-wr1-x435.google.com (mail-wr1-x435.google.com [IPv6:2a00:1450:4864:20::435]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 61B2C120131 for <oauth@ietf.org>; Tue, 31 Dec 2019 06:38:55 -0800 (PST)
Received: by mail-wr1-x435.google.com with SMTP id q10so35321021wrm.11 for <oauth@ietf.org>; Tue, 31 Dec 2019 06:38:55 -0800 (PST)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=lodderstedt.net; s=google; h=from:mime-version:subject:message-id:date:cc:to; bh=dSTHEIbc9ShlrTMIayPnR1odvEOgKUC01CfmNJYOo0Y=; b=itar9HUK2JKXwDkUxPcaaa3Dbyx3c/QC75yovdgW6x6T0dB1r8+uOzyi28jBSI+8q5 Igha6EBHffDx/n3VIMZOkdfZSt7kpTpy2zj5kSHVEhABgNEJLTAJxHT+8Gd/nca0Q5gr 9n+cPdtRBA9jC5/B6OHNvN476dlW5s4TbRNlgtewpOGCYaNOlFd+vi2a+R6bQu+9E74g xAyYp6SpR2QI2bSM3mPlRTRAdgr3ZP/BZKiDJe2ALsyueV5ptc5KeCEuDJIZbxydxLXT J/M3SiROaFt8OBnyiJBLqhacyRwvYAdZeeyAJfsPQzeqQnFTKykUcyuHzyspW/WNmwLU Bpvg==
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20161025; h=x-gm-message-state:from:mime-version:subject:message-id:date:cc:to; bh=dSTHEIbc9ShlrTMIayPnR1odvEOgKUC01CfmNJYOo0Y=; b=KcRH/D4tLNxXE9f+tcb9ITppuHlug4rLtbfeQvxBs4FndvaXxAWAF8t0ruDBerbNew FXFqzHad/9sdkE1BgRkQGOLKtZO7AOmtdtRe2uRq4oquKY5XgeXqT8tu2xffNrtzAVpI bx+FCXhcRx3Ci2RsgDq4hnScKUzFtOdp8JpYpeQLJbkvFy02j3jyhP/01PbRrUBLYRET Qo7N4h81lru6zSI1QSz3GqXOIWlI8mNoAfKPhPyoJpn/yXu7rMJtEbhbxmtOjI/R3vKL SSSgD90+cZiMwR07fmmjx8DNB0wctpBLBz8ywwoM2mxRhCOVwH18l+JKhD8DzL0s1MS+ 3B5w==
X-Gm-Message-State: APjAAAXQJ4k1leOHYw5neLcruumXT8CPoqVcf3GPGKaBb0Wd6u7txTi5 eRUsZi85xVqkL57YAgqS2TSPNZNf2aoo+w==
X-Google-Smtp-Source: APXvYqzmGBT/WXr6vloEnvTK2UM6Xd6IBBfan/Gt51qBxa20qZaBKvZa7oDxwitHLDYxGwQliwf4GQ==
X-Received: by 2002:adf:dfc1:: with SMTP id q1mr71810023wrn.155.1577803133634; Tue, 31 Dec 2019 06:38:53 -0800 (PST)
Received: from p200300eb8f1a50e4853495bb51a8296f.dip0.t-ipconnect.de (p200300EB8F1A50E4853495BB51A8296F.dip0.t-ipconnect.de. [2003:eb:8f1a:50e4:8534:95bb:51a8:296f]) by smtp.gmail.com with ESMTPSA id 4sm2639590wmg.22.2019.12.31.06.38.52 (version=TLS1_2 cipher=ECDHE-RSA-AES128-GCM-SHA256 bits=128/128); Tue, 31 Dec 2019 06:38:52 -0800 (PST)
From: Torsten Lodderstedt <torsten@lodderstedt.net>
Content-Type: multipart/signed; boundary="Apple-Mail=_781C8E12-CDB6-4BDC-B277-76AEA867AEF1"; protocol="application/pkcs7-signature"; micalg="sha-256"
Mime-Version: 1.0 (Mac OS X Mail 13.0 \(3608.40.2.2.4\))
Message-Id: <E1C4F217-8A9F-4E26-A488-C17D741C1D34@lodderstedt.net>
Date: Tue, 31 Dec 2019 15:38:21 +0100
To: oauth <oauth@ietf.org>, Filip Skokan <panva.ip@gmail.com>, Dave Tonge <dave.tonge@moneyhub.com>, Nat Sakimura <nat@sakimura.org>, Brian Campbell <bcampbell@pingidentity.com>
X-Mailer: Apple Mail (2.3608.40.2.2.4)
Archived-At: <https://mailarchive.ietf.org/arch/msg/oauth/ZzBw9QMGvvqWWrc7MO1ca7VTY8Q>
Subject: [OAUTH-WG] PAR metadata
X-BeenThere: oauth@ietf.org
X-Mailman-Version: 2.1.29
Precedence: list
List-Id: OAUTH WG <oauth.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/oauth>, <mailto:oauth-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/oauth/>
List-Post: <mailto:oauth@ietf.org>
List-Help: <mailto:oauth-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/oauth>, <mailto:oauth-request@ietf.org?subject=subscribe>
X-List-Received-Date: Tue, 31 Dec 2019 14:39:02 -0000

Hi all,

Ronald just sent me an email asking whether we will define metadata for 

pushed_authorization_endpoint_auth_methods_supported and
pushed_authorization_endpoint_auth_signing_alg_values_supported.

The draft right now utilises the existing token endpoint authentication methods so there is basically no need to define another parameter. The same principle could be applied to signing (and encryption) algorithms as well. 

What’s your opinion?

best regards,
Torsten.