Re: [OAUTH-WG] status of bearer token redelegation drafts

Phil Hunt <phil.hunt@oracle.com> Mon, 03 November 2014 20:05 UTC

Return-Path: <phil.hunt@oracle.com>
X-Original-To: oauth@ietfa.amsl.com
Delivered-To: oauth@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id BC8401A00B5 for <oauth@ietfa.amsl.com>; Mon, 3 Nov 2014 12:05:46 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -4.195
X-Spam-Level:
X-Spam-Status: No, score=-4.195 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, J_CHICKENPOX_12=0.6, RCVD_IN_DNSWL_MED=-2.3, RP_MATCHES_RCVD=-0.594, SPF_PASS=-0.001] autolearn=ham
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id feH4YRQIFOcn for <oauth@ietfa.amsl.com>; Mon, 3 Nov 2014 12:05:42 -0800 (PST)
Received: from aserp1040.oracle.com (aserp1040.oracle.com [141.146.126.69]) (using TLSv1 with cipher DHE-RSA-AES256-SHA (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 6079A1A871F for <oauth@ietf.org>; Mon, 3 Nov 2014 12:05:42 -0800 (PST)
Received: from ucsinet21.oracle.com (ucsinet21.oracle.com [156.151.31.93]) by aserp1040.oracle.com (Sentrion-MTA-4.3.2/Sentrion-MTA-4.3.2) with ESMTP id sA3K5dVK022448 (version=TLSv1/SSLv3 cipher=DHE-RSA-AES256-SHA bits=256 verify=OK); Mon, 3 Nov 2014 20:05:40 GMT
Received: from userz7022.oracle.com (userz7022.oracle.com [156.151.31.86]) by ucsinet21.oracle.com (8.14.4+Sun/8.14.4) with ESMTP id sA3K5dv2026832 (version=TLSv1/SSLv3 cipher=DHE-RSA-AES256-SHA bits=256 verify=NO); Mon, 3 Nov 2014 20:05:39 GMT
Received: from abhmp0011.oracle.com (abhmp0011.oracle.com [141.146.116.17]) by userz7022.oracle.com (8.14.5+Sun/8.14.4) with ESMTP id sA3JHSHh007771; Mon, 3 Nov 2014 19:17:28 GMT
Received: from [192.168.1.9] (/24.87.24.131) by default (Oracle Beehive Gateway v4.0) with ESMTP ; Mon, 03 Nov 2014 12:05:38 -0800
References: <545760D7.3090900@surfnet.nl>
Mime-Version: 1.0 (1.0)
In-Reply-To: <545760D7.3090900@surfnet.nl>
Content-Type: text/plain; charset="us-ascii"
Content-Transfer-Encoding: quoted-printable
Message-Id: <120800A0-5DB0-4E12-AB13-684810348D38@oracle.com>
X-Mailer: iPhone Mail (12B411)
From: Phil Hunt <phil.hunt@oracle.com>
Date: Mon, 03 Nov 2014 12:05:29 -0800
To: Bas Zoetekouw <bas.zoetekouw@surfnet.nl>
X-Source-IP: ucsinet21.oracle.com [156.151.31.93]
Archived-At: http://mailarchive.ietf.org/arch/msg/oauth/gxY9Gxv6ATFjx8QTkXM72m56hSg
Cc: OAuth WG <oauth@ietf.org>
Subject: Re: [OAUTH-WG] status of bearer token redelegation drafts
X-BeenThere: oauth@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: OAUTH WG <oauth.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/oauth>, <mailto:oauth-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/oauth/>
List-Post: <mailto:oauth@ietf.org>
List-Help: <mailto:oauth-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/oauth>, <mailto:oauth-request@ietf.org?subject=subscribe>
X-List-Received-Date: Mon, 03 Nov 2014 20:05:47 -0000

I believe there are now 3 independently written drafts. 

No working group work has been done. 

Maybe it is time for the WG to work on this?

It just doesn't seem to have as much priority as other issues like proof of possession tokens. 

Phil

> On Nov 3, 2014, at 03:02, Bas Zoetekouw <bas.zoetekouw@surfnet.nl> wrote:
> 
> Hi All,
> 
> For a client of ours, I am looking into OAuth token redelegation from
> one RS to another.  I've found two drafts that more or less describe the
> scenario they want to implement:
> https://tools.ietf.org/html/draft-richer-oauth-chain-00 and
> http://tools.ietf.org/html/draft-hunt-oauth-chain-01
> Could anyone comment on the status of those? 
> In particular I'ld be interested in hearing whether anyone is using
> either of those specs in practice, and whether there is any progress on
> the drafts.
> 
> Best regards,
> Bas Zoetekouw.
> SURFnet.
> 
> -- 
> Bas Zoetekouw
> SURFnet Advanced Services
> Tel: +31 30 2305362   Fax: +31 30 2305329
> SURFnet -  POBox 19035 -  NL-3501 DA Utrecht - The Netherlands
> 
> _______________________________________________
> OAuth mailing list
> OAuth@ietf.org
> https://www.ietf.org/mailman/listinfo/oauth