Re: [OAUTH-WG] OAuth 1.0a

Torsten Lodderstedt <torsten@lodderstedt.net> Tue, 14 August 2012 19:42 UTC

Return-Path: <torsten@lodderstedt.net>
X-Original-To: oauth@ietfa.amsl.com
Delivered-To: oauth@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id CAFBF21E8063 for <oauth@ietfa.amsl.com>; Tue, 14 Aug 2012 12:42:41 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.948
X-Spam-Level:
X-Spam-Status: No, score=-1.948 tagged_above=-999 required=5 tests=[AWL=-0.300, BAYES_00=-2.599, HELO_EQ_DE=0.35, HTML_MESSAGE=0.001, J_CHICKENPOX_31=0.6]
Received: from mail.ietf.org ([12.22.58.30]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id O6Y7YCwthWsX for <oauth@ietfa.amsl.com>; Tue, 14 Aug 2012 12:42:41 -0700 (PDT)
Received: from smtprelay03.ispgateway.de (smtprelay03.ispgateway.de [80.67.18.15]) by ietfa.amsl.com (Postfix) with ESMTP id BC33221E8082 for <oauth@ietf.org>; Tue, 14 Aug 2012 12:42:40 -0700 (PDT)
Received: from [91.2.74.115] (helo=[192.168.71.42]) by smtprelay03.ispgateway.de with esmtpsa (TLSv1:AES256-SHA:256) (Exim 4.68) (envelope-from <torsten@lodderstedt.net>) id 1T1N0g-0000zQ-Dh; Tue, 14 Aug 2012 21:42:38 +0200
Message-ID: <502AAA2D.1050404@lodderstedt.net>
Date: Tue, 14 Aug 2012 21:42:37 +0200
From: Torsten Lodderstedt <torsten@lodderstedt.net>
User-Agent: Mozilla/5.0 (Windows NT 6.1; rv:14.0) Gecko/20120713 Thunderbird/14.0
MIME-Version: 1.0
To: William Mills <wmills_92105@yahoo.com>
References: <1344972117.60342.YahooMailNeo@web31802.mail.mud.yahoo.com> <4E1F6AAD24975D4BA5B168042967394366777A7F@TK5EX14MBXC283.redmond.corp.microsoft.com> <1344973056.51964.YahooMailNeo@web31812.mail.mud.yahoo.com>
In-Reply-To: <1344973056.51964.YahooMailNeo@web31812.mail.mud.yahoo.com>
Content-Type: multipart/alternative; boundary="------------080307000904010005070001"
X-Df-Sender: dG9yc3RlbkBsb2RkZXJzdGVkdC1vbmxpbmUuZGU=
Cc: O Auth WG <oauth@ietf.org>
Subject: Re: [OAUTH-WG] OAuth 1.0a
X-BeenThere: oauth@ietf.org
X-Mailman-Version: 2.1.12
Precedence: list
List-Id: OAUTH WG <oauth.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/oauth>, <mailto:oauth-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/oauth>
List-Post: <mailto:oauth@ietf.org>
List-Help: <mailto:oauth-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/oauth>, <mailto:oauth-request@ietf.org?subject=subscribe>
X-List-Received-Date: Tue, 14 Aug 2012 19:42:42 -0000

Hi Bill,

do you need to specify this aspect of your SASL profile now? Why don't 
you wait for the group to complete the work on signing/HoK?

You could also contribute your use cases to drive the discussion.

best regards,
Torsten.

Am 14.08.2012 21:37, schrieb William Mills:
> It's for the OAUTH SASL spec.  I've been writing it with the idea that 
> OAuth 1.0a would work (since I think we'll have extant 1.0a typ[e 
> tokens we want to allow for IMAP), but several folks were saying when 
> this all started that 1.0a was dead and I should not refer to it.
>
> I want to make sure the SASL mechanism is build to properly handle 
> signed auth schemes and not just bearer (cookie) type.
>
> -bill
>
> ------------------------------------------------------------------------
> *From:* Mike Jones <Michael.Jones@microsoft.com>
> *To:* William Mills <wmills_92105@yahoo.com>; O Auth WG <oauth@ietf.org>
> *Sent:* Tuesday, August 14, 2012 12:28 PM
> *Subject:* RE: [OAUTH-WG] OAuth 1.0a
>
> What problem are you trying to solve?
> *From:*oauth-bounces@ietf.org [mailto:oauth-bounces@ietf.org] *On 
> Behalf Of *William Mills
> *Sent:* Tuesday, August 14, 2012 12:22 PM
> *To:* O Auth WG
> *Subject:* [OAUTH-WG] OAuth 1.0a
> What's the general opinion on 1.0a?  Am I stepping in something if I 
> refer to it in another draft?  I want to reference an auth scheme that 
> uses signing and now MAC is apparently going back to the drawing 
> board, so I'm thinking about using 1.0a.
> Thanks,
> -bill
>
>
>
>
> _______________________________________________
> OAuth mailing list
> OAuth@ietf.org
> https://www.ietf.org/mailman/listinfo/oauth