Re: [OAUTH-WG] Agenda Proposal

Hannes Tschofenig <hannes.tschofenig@gmx.net> Mon, 21 March 2016 22:18 UTC

Return-Path: <hannes.tschofenig@gmx.net>
X-Original-To: oauth@ietfa.amsl.com
Delivered-To: oauth@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 85D0E12D0BF for <oauth@ietfa.amsl.com>; Mon, 21 Mar 2016 15:18:44 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.602
X-Spam-Level:
X-Spam-Status: No, score=-2.602 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, FREEMAIL_FROM=0.001, RCVD_IN_DNSWL_LOW=-0.7, RCVD_IN_MSPIKE_H2=-0.001, RP_MATCHES_RCVD=-0.001, SPF_PASS=-0.001] autolearn=ham autolearn_force=no
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id CYAzKWW-Kgw4 for <oauth@ietfa.amsl.com>; Mon, 21 Mar 2016 15:18:41 -0700 (PDT)
Received: from mout.gmx.net (mout.gmx.net [212.227.17.21]) (using TLSv1.2 with cipher DHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id E203B12D119 for <oauth@ietf.org>; Mon, 21 Mar 2016 15:18:22 -0700 (PDT)
Received: from [192.168.10.140] ([94.79.182.6]) by mail.gmx.com (mrgmx103) with ESMTPSA (Nemesis) id 0MdaiW-1aPMJg1oVQ-00PNKi; Mon, 21 Mar 2016 23:18:16 +0100
To: Phil Hunt <phil.hunt@oracle.com>
References: <56F05664.1010507@gmx.net> <9AED819A-6392-4115-99CF-D97E93BD0554@oracle.com>
From: Hannes Tschofenig <hannes.tschofenig@gmx.net>
Openpgp: id=071A97A9ECBADCA8E31E678554D9CEEF4D776BC9
Message-ID: <56F0732B.7090600@gmx.net>
Date: Mon, 21 Mar 2016 23:18:19 +0100
User-Agent: Mozilla/5.0 (X11; Linux x86_64; rv:38.0) Gecko/20100101 Thunderbird/38.6.0
MIME-Version: 1.0
In-Reply-To: <9AED819A-6392-4115-99CF-D97E93BD0554@oracle.com>
Content-Type: multipart/signed; micalg="pgp-sha512"; protocol="application/pgp-signature"; boundary="h4FuclXRrQ4hKNATO83TiTeJ9adsrowS9"
X-Provags-ID: V03:K0:Z42buL7JFL6yWm9LZLnL3U+bZ2o+yiBgH156nwt8juCFNej6z6y c5EIHaFnWHRNyUu2oJR3qp51il+c7juACBlu0XtkOXmd2bJYlYtnk59K9Gk/NcHOLvqFkVy bheY2b61ryqOVU1xTKGFmddUlcT5TPJ3CBTPdG88PGyDsbhxCqIm2ABHq66+wa/HYJApxZH ObaSlfBxhtEYxV4iwnjlg==
X-UI-Out-Filterresults: notjunk:1;V01:K0:jc+KlT35RYA=:CR8OeLPVc0Y6g5dLoZudYb cLtbGK7DRQZv9QZ1k+2UuV9f/ZrKXfHmqiwq7YVzRbXejUGxg2RtNqjAJtAg9vjcy2xR/fDfR jqeI2AIN94FSq0bV0ZwzmilTEseta4X2Uob8pbK08+W2YJu9ZN8q7SwgV3IUFw2qvB9shn0w8 ay1ZUFNYyEaOKk50+oly3/z1ISAy8J/I3FQzrHC0R3fTXMdeKPkYF1d2VuQ6rZE+/Br8mC7nN Ayk9K6br9t5rPZBUhvXG+loBqODG8Fd8+ejnwwCY708f2d0qsMFSQCVbxcKr9TDyF0BSMSieu KIbTsj79zeWBB5V2EfAHqJBSgysLfl2HBD779rHhKTWPQqJl9EgKh6sUoRzrVk3eXGwmff1Nz XBepv1s/z4Bw03c8v6l0WDgi/YaBvb6XDi0nWnQfuD2UjG9aWgK8g/+/kyrOaWL0hWIrXBqpo oppWj0Przi1A28G35o7q5Hvw3k1ukZ6T4+cPUbs8cZJlho4alk0mSDpQG0ROlHu0e8XK1Iawe acU6Jqs5BzJZl//pogLDMlKoyV+yYH6lgl8d1V6DYuvipgOH+67HvojAmAAAX6s2atSkyQ2x5 q5vzVjTYYavoEGlDaSGiNZGX7pvtUDf5vvP2N/wTj6Rrq1siYFi07cHvAkY01VSHsFMqXJ3rh KoEa/PLM45slRy4FhLmrNDPPITciLoyn5Efyk8uRFJuglxCypGOUIHh80ufbzoiChFXPTHEQK NgJMw7YzejYE+ez9VK9baZHUXsI5krGH/m5ekcDbvrPz6YNPmGTTX87TKvw=
Archived-At: <http://mailarchive.ietf.org/arch/msg/oauth/bvW8mW62GcmlWpc8v5xsDr12B9I>
Cc: "oauth@ietf.org" <oauth@ietf.org>
Subject: Re: [OAUTH-WG] Agenda Proposal
X-BeenThere: oauth@ietf.org
X-Mailman-Version: 2.1.17
Precedence: list
List-Id: OAUTH WG <oauth.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/oauth>, <mailto:oauth-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/oauth/>
List-Post: <mailto:oauth@ietf.org>
List-Help: <mailto:oauth-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/oauth>, <mailto:oauth-request@ietf.org?subject=subscribe>
X-List-Received-Date: Mon, 21 Mar 2016 22:18:44 -0000

Hi Phil,

we can put this topic as an additional agenda item to the list by
removing time from the PoP and the mix-up agenda items

Ciao
Hannes

On 03/21/2016 09:46 PM, Phil Hunt wrote:
> I’m not sure you intend to discuss it in the Mix-up section, but I think
> we need time to discuss the correct configuration of clients and the
> resource/aud relationship issues
> (specifically: draft-campbell-oauth-resource-indicators
> <http://tools.ietf.org/id/draft-campbell-oauth-resource-indicators-01.txt> and draft-hunt-oauth-bound-config
> <http://tools.ietf.org/id/draft-hunt-oauth-bound-config-00.txt>).
> 
> There is apparently overlap with mix-up mitigation (either in reality or
> perception), so I think it is important to have a verbal discussion on
> this to get to consensus and understanding of the separate issues.
> 
> As for POP-architecture, that has been on hold pending the mix-up
> discussions and understanding of dynamic client risks.  So, not much
> need to discuss from my perspective.
> 
> Thanks,
> 
> Phil
> 
> @independentid
> www.independentid.com <http://www.independentid.com>
> phil.hunt@oracle.com <mailto:phil.hunt@oracle.com>
> 
> 
> 
> 
> 
>> On Mar 21, 2016, at 1:15 PM, Hannes Tschofenig
>> <hannes.tschofenig@gmx.net <mailto:hannes.tschofenig@gmx.net>> wrote:
>>
>> Hi all,
>>
>> I need your help creating the agenda for the next meeting. We have a 2
>> 1/2 hour slot and many different topics to discuss. I put a strawman
>> proposal together but there are various things missing:
>>
>> * who volunteers to present and to lead the discussion,
>> * what time allocation is appropriate,
>> * what you are trying to accomplish during the meeting (goals), and
>> * what other items would you like to discuss (I know there are various
>> items missing from the list).
>>
>> So, you input is needed!
>>
>> -------
>>
>> IETF 95 OAuth Meeting Agenda
>> Wednesday, 10:00-12:30
>> Chairs: Hannes Tschofenig/Derek Atkins
>>
>> - Status Update (Hannes, 5 min)
>>
>> - OAuth 2.0 JWT Authorization Request (Nat, 15 min )
>> https://datatracker.ietf.org/doc/draft-ietf-oauth-jwsreq/
>>
>> - OAuth 2.0 Mix-Up Mitigation (TBD, 45 min)
>> https://datatracker.ietf.org/doc/draft-ietf-oauth-mix-up-mitigation/
>>
>> - Proof-of-Possession (TBD, 35 min)
>> http://datatracker.ietf.org/doc/draft-ietf-oauth-proof-of-possession/
>> http://datatracker.ietf.org/doc/draft-ietf-oauth-pop-architecture/
>> http://datatracker.ietf.org/doc/draft-ietf-oauth-pop-key-distribution/
>> https://datatracker.ietf.org/doc/draft-ietf-oauth-signed-http-request/
>>
>> - Token Exchange (TBD, 15 min)
>> https://datatracker.ietf.org/doc/draft-ietf-oauth-token-exchange/
>>
>> - OAuth 2.0 for Native Apps (William, 15 min)
>> http://datatracker.ietf.org/doc/draft-wdenniss-oauth-native-apps/
>>
>> - Authentication Method Reference Values (Mike, 15 min)
>> https://datatracker.ietf.org/doc/draft-ietf-oauth-amr-values/
>>
>> - Conclusion (Hannes, 5 min)
>>
>> -------
>>
>> The latest version can be found at:
>> https://www.ietf.org/proceedings/95/agenda/agenda-95-oauth
>>
>> Ciao
>> Hannes & Derek
>>
>> _______________________________________________
>> OAuth mailing list
>> OAuth@ietf.org
>> https://www.ietf.org/mailman/listinfo/oauth
>