Re: [OAUTH-WG] draft-bertocci-oauth-access-token-jwt-00

Vittorio Bertocci <Vittorio@auth0.com> Mon, 06 May 2019 19:26 UTC

Return-Path: <vittorio.bertocci@auth0.com>
X-Original-To: oauth@ietfa.amsl.com
Delivered-To: oauth@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 81A4E120126 for <oauth@ietfa.amsl.com>; Mon, 6 May 2019 12:26:24 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.999
X-Spam-Level:
X-Spam-Status: No, score=-1.999 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, HTML_MESSAGE=0.001, RCVD_IN_DNSWL_NONE=-0.0001, SPF_PASS=-0.001, URIBL_BLOCKED=0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (2048-bit key) header.d=auth0.com
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id jvZf7IXwYNVG for <oauth@ietfa.amsl.com>; Mon, 6 May 2019 12:26:22 -0700 (PDT)
Received: from mail-lj1-x234.google.com (mail-lj1-x234.google.com [IPv6:2a00:1450:4864:20::234]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 458651200E6 for <oauth@ietf.org>; Mon, 6 May 2019 12:26:22 -0700 (PDT)
Received: by mail-lj1-x234.google.com with SMTP id d15so12117039ljc.7 for <oauth@ietf.org>; Mon, 06 May 2019 12:26:22 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=auth0.com; s=google; h=mime-version:references:in-reply-to:from:date:message-id:subject:to :cc; bh=FSHC3kZhwAULSHeFvAfGn3wCJO96NCP4vkr0yik7lYo=; b=QPq02zd8XRbFxbTldomok+heyhLg5S1XQbYtxlx4qwu8SrSiZH9iwYKtkcVEV0vjBs 9T0Sqc12VGSpjDQgqK4PgkOXidklxdljy8kjt1SKnC9M2beJceGBcWnQ6wVl7gg9U+LI lnkn9bWG01FkL8sAflSELeFqm8BuTLabedUVkrVg1hehGkRKmlEEdsn9mS3bP6SC/Q9m kZTcrAHAhyd/9wXnRbnu3tIhs+TBZc835Pd3sSv2GuvXZN8p8tn31/rwoBWAbo95EMxk qUeTgIWk/FviArmHPRLlghEgnSjN6+mI/fV8wjhpoDvYOZ1G8+9SxLNRmuk5OHVZ5EPS a3LA==
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20161025; h=x-gm-message-state:mime-version:references:in-reply-to:from:date :message-id:subject:to:cc; bh=FSHC3kZhwAULSHeFvAfGn3wCJO96NCP4vkr0yik7lYo=; b=H/q8DmKP7ALEJZDsbBhvD3cD6OS1PrdHRScgS1y11iVM767OC/xzkRZBPcYvn6VY0s bBnkOKF+OFnk0f74kqndNSobGbMWQZRdrP8/OZg/jIF5D5/1UET5N3xDQW71cxmiYZAC JruElj1PKbX8xqXDn1HICTkCEDuMrwC/0hFgpzQg79jENpN3zBvKOz4fbtPosWgFI1wo WD1js6KUT43CLX4SsnYzABSAsAkya1Afds0n9vP8JAgR/K04cyQoAHbW1BUMH+taqMyP MWbKud2G6K7LaAhBd6cxDHardoYyRz/LTzpXAMyp6vzDDIfteF7emeGjK4p5NaQQCbQT lqbw==
X-Gm-Message-State: APjAAAV3i5yZh6HHA4UorxxaR4LVLL5obFFp+wsOs/MMQj2+6S6ng8el u83mn16MnCwwft6vOMdHk4ihTYfphg7ApfaSL6cxvA==
X-Google-Smtp-Source: APXvYqzTtc7Kyw0tRV+IaliHNbG6GKGfEZEfVOWLULXOYHSB7nvpLOQ0gy6fIuj9xz1k1bVd1heEMJk/+wRrm1P5U3c=
X-Received: by 2002:a2e:84ca:: with SMTP id q10mr1171984ljh.117.1557170780202; Mon, 06 May 2019 12:26:20 -0700 (PDT)
MIME-Version: 1.0
References: <CAO_FVe6eWy3zppQAij7qxD+ycYL8ebqGJKG0y-A7GhN+0=kb4g@mail.gmail.com> <D610AAEA-892F-4AAD-915D-A0C068F5BFD3@gmail.com> <CAO7Ng+sqzw4O2vt+iCWegBWBGg+-oyqV1j8dF7ADK2TbPec_CQ@mail.gmail.com> <CAHsNOKewL9xCFt6SsP4dz+W0CN_NUZaGMJahF7mSgos_Xbnhhw@mail.gmail.com> <CAO_FVe7c6jLRJ8mD7gw=a6NY3oZcgCh_b5dR8uRXa6Q2c2gmGg@mail.gmail.com> <CA+iA6uje229zrAos3c1TCuJEM+2vmVifNQ2FnKDuj2T4ET2SYA@mail.gmail.com> <a34edf0e-012a-ecc9-e547-3cdc61dca5a4@aol.com> <CA+iA6uh6Q901wEaqGSK7An0z0_iJTjCfvPVN44Qwpb=M_rDONg@mail.gmail.com> <239f40ab-da4d-03fe-4524-0b21a0bcc63e@aol.com> <SN6PR00MB0304BC3C7D438F8A5715B36DF5500@SN6PR00MB0304.namprd00.prod.outlook.com> <CA+iA6ugr+xPfeTFXK2gGBFX8Yw+zGArGfav=Ci5A3qNYUqB7rw@mail.gmail.com> <SN6PR00MB030459810B40D98370728BBAF5500@SN6PR00MB0304.namprd00.prod.outlook.com> <CA+iA6ug1NOpMcPsSr8o24CM3xWy-3z_pxiZhiyPeKxvScMACmg@mail.gmail.com> <CAO_FVe4AP5aWgXAAGj1QxPDFPjyfeaZGWd-b5azrz=ajuHuJdQ@mail.gmail.com> <229496c5-5953-be5d-0456-06ec6ee4caf9@connect2id.com>
In-Reply-To: <229496c5-5953-be5d-0456-06ec6ee4caf9@connect2id.com>
From: Vittorio Bertocci <Vittorio@auth0.com>
Date: Mon, 06 May 2019 12:26:12 -0700
Message-ID: <CAO_FVe4XhWROvPwx4g1spaUrx1vOSCMyiMwP_1DAU-=mMRpc5A@mail.gmail.com>
To: Vladimir Dzhuvinov <vladimir@connect2id.com>
Cc: IETF oauth WG <oauth@ietf.org>
Content-Type: multipart/alternative; boundary="000000000000357c9505883d139e"
Archived-At: <https://mailarchive.ietf.org/arch/msg/oauth/cDRPQtcRZQoETqFfvE1nRWCo0-s>
Subject: Re: [OAUTH-WG] draft-bertocci-oauth-access-token-jwt-00
X-BeenThere: oauth@ietf.org
X-Mailman-Version: 2.1.29
Precedence: list
List-Id: OAUTH WG <oauth.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/oauth>, <mailto:oauth-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/oauth/>
List-Post: <mailto:oauth@ietf.org>
List-Help: <mailto:oauth-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/oauth>, <mailto:oauth-request@ietf.org?subject=subscribe>
X-List-Received-Date: Mon, 06 May 2019 19:26:25 -0000

I am not following, Vladimir. What do you mean? Can you make some examples
to clarify?
The userinfo is always colocated with the AS, hence I would expect most
vendors not to use JWT for the ATs issued for userinfo access

On Mon, May 6, 2019 at 12:21 PM Vladimir Dzhuvinov <vladimir@connect2id.com>
wrote:

>
> https://tools.ietf.org/html/draft-ietf-oauth-access-token-jwt-00#section-2.2.2
>
> In OpenID Connect the access token is consumed by the UserInfo endpoint.
>
> Were there any suggestions to also spec parameter(s) for the claims
> names (with optional locales) for release at the UserInfo endpoint?
>
> Vladimir
>
> _______________________________________________
> OAuth mailing list
> OAuth@ietf.org
> https://www.ietf.org/mailman/listinfo/oauth
>