Return-Path: <torsten@lodderstedt.net>
X-Original-To: oauth@core3.amsl.com
Delivered-To: oauth@core3.amsl.com
Received: from localhost (localhost [127.0.0.1]) by core3.amsl.com (Postfix)
 with ESMTP id E6CBC3A6924 for <oauth@core3.amsl.com>;
 Mon, 28 Jun 2010 11:07:39 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.367
X-Spam-Level: 
X-Spam-Status: No, score=-1.367 tagged_above=-999 required=5 tests=[AWL=0.881,
 BAYES_00=-2.599, HELO_EQ_DE=0.35, HTML_MESSAGE=0.001]
Received: from mail.ietf.org ([64.170.98.32]) by localhost (core3.amsl.com
 [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id gZH0h-WPGOcC for
 <oauth@core3.amsl.com>; Mon, 28 Jun 2010 11:07:39 -0700 (PDT)
Received: from smtprelay02.ispgateway.de (smtprelay02.ispgateway.de
 [80.67.18.14]) by core3.amsl.com (Postfix) with ESMTP id C92863A68E8 for
 <oauth@ietf.org>; Mon, 28 Jun 2010 11:07:38 -0700 (PDT)
Received: from p4fff2973.dip.t-dialin.net ([79.255.41.115] helo=[127.0.0.1])
 by smtprelay02.ispgateway.de with esmtpa (Exim 4.68) (envelope-from
 <torsten@lodderstedt.net>) id 1OTIkF-0000eF-A0;
 Mon, 28 Jun 2010 20:07:47 +0200
Message-ID: <4C28E4F2.6060605@lodderstedt.net>
Date: Mon, 28 Jun 2010 20:07:46 +0200
From: Torsten Lodderstedt <torsten@lodderstedt.net>
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.0; de;
 rv:1.9.1.10) Gecko/20100512 Thunderbird/3.0.5
MIME-Version: 1.0
To: Dick Hardt <dick.hardt@gmail.com>
References: <90C41DD21FB7C64BB94121FBBC2E72343B3EC84ADE@P3PW5EX1MB01.EX1.SECURESERVER.NET>
 <269A7D01-CB98-46F3-9D17-C0AAA31041E4@gmail.com>
In-Reply-To: <269A7D01-CB98-46F3-9D17-C0AAA31041E4@gmail.com>
Content-Type: multipart/alternative;
 boundary="------------080709060204070201090706"
X-Df-Sender: 141509
Cc: "OAuth WG \(oauth@ietf.org\)" <oauth@ietf.org>
Subject: Re: [OAUTH-WG] What to do about 'realm'
X-BeenThere: oauth@ietf.org
X-Mailman-Version: 2.1.9
Precedence: list
List-Id: OAUTH WG <oauth.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/listinfo/oauth>,
 <mailto:oauth-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/oauth>
List-Post: <mailto:oauth@ietf.org>
List-Help: <mailto:oauth-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/oauth>,
 <mailto:oauth-request@ietf.org?subject=subscribe>
X-List-Received-Date: Mon, 28 Jun 2010 18:07:40 -0000

This is a multi-part message in MIME format.
--------------080709060204070201090706
Content-Type: text/plain; charset=windows-1252; format=flowed
Content-Transfer-Encoding: 8bit

+1

Am 28.06.2010 07:37, schrieb Dick Hardt:
> I vote for (3) unless a good (4) is suggested.
>
> On 2010-06-27, at 6:51 PM, Eran Hammer-Lahav wrote:
>
>> Over the past year many people expressed concerns about the use of 
>> the ‘realm’ WWW-Authenticate header parameter. The parameter is 
>> defined in RFC 2617 as required, and is allowed to have 
>> scheme-specific structure.
>> We have a few options:
>> 1. Leave it as required under the definition of RFC 2617 (i.e. 
>> provide no help, developers will need to ready 2617 and figure out 
>> what to do with it).
>> 2. Update 2617 to remove the requirement – this is not going to be 
>> easy or possible to predict success.
>> 3. Provide specific guidance as to what to do with the realm parameter.
>> 4. Something else.
>> Comments?
>> EHL
>> _______________________________________________
>> OAuth mailing list
>> OAuth@ietf.org <mailto:OAuth@ietf.org>
>> https://www.ietf.org/mailman/listinfo/oauth
>
>
> _______________________________________________
> OAuth mailing list
> OAuth@ietf.org
> https://www.ietf.org/mailman/listinfo/oauth
>    

--------------080709060204070201090706
Content-Type: text/html; charset=windows-1252
Content-Transfer-Encoding: 8bit

<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN">
<html>
<head>
  <meta content="text/html; charset=windows-1252"
 http-equiv="Content-Type">
</head>
<body bgcolor="#ffffff" text="#000000">
+1<br>
<br>
Am 28.06.2010 07:37, schrieb Dick Hardt:
<blockquote cite="mid:269A7D01-CB98-46F3-9D17-C0AAA31041E4@gmail.com"
 type="cite"><base href="x-msg://96/">I vote for (3) unless a good (4)
is suggested.
  <div><br>
  <div>
  <div>On 2010-06-27, at 6:51 PM, Eran Hammer-Lahav wrote:</div>
  <br class="Apple-interchange-newline">
  <blockquote type="cite"><span class="Apple-style-span"
 style="border-collapse: separate; font-family: Helvetica; font-style: normal; font-variant: normal; font-weight: normal; letter-spacing: normal; line-height: normal; orphans: 2; text-indent: 0px; text-transform: none; white-space: normal; widows: 2; word-spacing: 0px; font-size: medium;">
    <div link="blue" vlink="purple" lang="EN-US">
    <div class="WordSection1" style="page: WordSection1;">
    <div
 style="margin: 0in 0in 0.0001pt; font-size: 11pt; font-family: Calibri,sans-serif;">Over
the past year many people expressed concerns about the use of the
‘realm’ WWW-Authenticate header parameter. The parameter is defined in
RFC 2617 as required, and is allowed to have scheme-specific structure.<o:p></o:p></div>
    <div
 style="margin: 0in 0in 0.0001pt; font-size: 11pt; font-family: Calibri,sans-serif;"><o:p> </o:p></div>
    <div
 style="margin: 0in 0in 0.0001pt; font-size: 11pt; font-family: Calibri,sans-serif;">We
have a few options:<o:p></o:p></div>
    <div
 style="margin: 0in 0in 0.0001pt; font-size: 11pt; font-family: Calibri,sans-serif;"><o:p> </o:p></div>
    <div
 style="margin: 0in 0in 0.0001pt; font-size: 11pt; font-family: Calibri,sans-serif;">1.
Leave it as required under the definition of RFC 2617 (i.e. provide no
help, developers will need to ready 2617 and figure out what to do with
it).<o:p></o:p></div>
    <div
 style="margin: 0in 0in 0.0001pt; font-size: 11pt; font-family: Calibri,sans-serif;">2.
Update 2617 to remove the requirement – this is not going to be easy or
possible to predict success.<o:p></o:p></div>
    <div
 style="margin: 0in 0in 0.0001pt; font-size: 11pt; font-family: Calibri,sans-serif;">3.
Provide specific guidance as to what to do with the realm parameter.<o:p></o:p></div>
    <div
 style="margin: 0in 0in 0.0001pt; font-size: 11pt; font-family: Calibri,sans-serif;">4.
Something else.<o:p></o:p></div>
    <div
 style="margin: 0in 0in 0.0001pt; font-size: 11pt; font-family: Calibri,sans-serif;"><o:p> </o:p></div>
    <div
 style="margin: 0in 0in 0.0001pt; font-size: 11pt; font-family: Calibri,sans-serif;">Comments?<o:p></o:p></div>
    <div
 style="margin: 0in 0in 0.0001pt; font-size: 11pt; font-family: Calibri,sans-serif;"><o:p> </o:p></div>
    <div
 style="margin: 0in 0in 0.0001pt; font-size: 11pt; font-family: Calibri,sans-serif;">EHL<o:p></o:p></div>
    </div>
_______________________________________________<br>
OAuth mailing list<br>
    <a moz-do-not-send="true" href="mailto:OAuth@ietf.org"
 style="color: blue; text-decoration: underline;">OAuth@ietf.org</a><br>
    <a moz-do-not-send="true"
 href="https://www.ietf.org/mailman/listinfo/oauth"
 style="color: blue; text-decoration: underline;">https://www.ietf.org/mailman/listinfo/oauth</a><br>
    </div>
    </span></blockquote>
  </div>
  <br>
  </div>
  <pre wrap="">
<fieldset class="mimeAttachmentHeader"></fieldset>
_______________________________________________
OAuth mailing list
<a class="moz-txt-link-abbreviated" href="mailto:OAuth@ietf.org">OAuth@ietf.org</a>
<a class="moz-txt-link-freetext" href="https://www.ietf.org/mailman/listinfo/oauth">https://www.ietf.org/mailman/listinfo/oauth</a>
  </pre>
</blockquote>
</body>
</html>

--------------080709060204070201090706--

