Return-Path: <hidelafoglia@gmail.com>
X-Original-To: oauth@core3.amsl.com
Delivered-To: oauth@core3.amsl.com
Received: from localhost (localhost [127.0.0.1]) by core3.amsl.com (Postfix)
 with ESMTP id 231823A6933 for <oauth@core3.amsl.com>;
 Tue, 21 Sep 2010 22:09:38 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.599
X-Spam-Level: 
X-Spam-Status: No, score=-2.599 tagged_above=-999 required=5
 tests=[BAYES_00=-2.599]
Received: from mail.ietf.org ([64.170.98.32]) by localhost (core3.amsl.com
 [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id UlCYC8AV4UFO for
 <oauth@core3.amsl.com>; Tue, 21 Sep 2010 22:09:24 -0700 (PDT)
Received: from mail-qy0-f179.google.com (mail-qy0-f179.google.com
 [209.85.216.179]) by core3.amsl.com (Postfix) with ESMTP id 02A743A6AD5 for
 <oauth@ietf.org>; Tue, 21 Sep 2010 22:09:16 -0700 (PDT)
Received: by qyk9 with SMTP id 9so266428qyk.10 for <oauth@ietf.org>;
 Tue, 21 Sep 2010 22:09:22 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=gamma;
 h=domainkey-signature:mime-version:received:received:in-reply-to
 :references:date:message-id:subject:from:to:cc:content-type
 :content-transfer-encoding; bh=EOSCj7rWzvuTYnbXxL95xgO+39dXn2seABtL3VjtXG0=;
 b=he3Bmt+hgZsCk8gv2hLvRnbZsvr67jjKBRyNdFJsvy9sW99xGItQTXaJ9jauuTEix+
 fjlMvUPVeEebficBY2nxIHyckh0ULPPmgLx2i+b8+fjFbZ3m8Sxtjj/BqmIP6m4tC2Ro
 jSQUxZPTl7uqIhB/UtMluNHCd8XlUvoLwXrhg=
DomainKey-Signature: a=rsa-sha1; c=nofws; d=gmail.com; s=gamma;
 h=mime-version:in-reply-to:references:date:message-id:subject:from:to
 :cc:content-type:content-transfer-encoding;
 b=LH8QfQ1JmJniEwqD2iGmbYxZMNXoswT4xw54DmnyAUqfGILxcFoLeqw2OxoBn4+ptb
 dN1wYzmj0Jr6MFF6OVT+/WpDdd0oC96YR1h1sE7mpKs4ZfcJJvFdliN06N8glavJhjZj
 UawQ2A5FUDXr8GBNzDQkh+lqLaeU8nz2QEJZU=
MIME-Version: 1.0
Received: by 10.220.50.2 with SMTP id x2mr2086552vcf.21.1285132162212;
 Tue, 21 Sep 2010 22:09:22 -0700 (PDT)
Received: by 10.220.170.196 with HTTP; Tue, 21 Sep 2010 22:09:22 -0700 (PDT)
In-Reply-To: <AANLkTi=3o4_vmQQUGCRYP2gE_-Ar+oKx0bCyBtnGhCPO@mail.gmail.com>
References: <AANLkTikSKX8jisucEbZOUnkGYUz0DnBSB_KWXGM3bJcS@mail.gmail.com>
 <7C01E631FF4B654FA1E783F1C0265F8C62D263BB@TK5EX14MBXC111.redmond.corp.microsoft.com>
 <AANLkTi=3o4_vmQQUGCRYP2gE_-Ar+oKx0bCyBtnGhCPO@mail.gmail.com>
Date: Wed, 22 Sep 2010 14:09:22 +0900
Message-ID: <AANLkTi=KgcWqx0LZgJ38rR23d6SRLLHURH+VTq32ynXB@mail.gmail.com>
From: hdknr hidelafoglia <hidelafoglia@gmail.com>
To: Yaron Goland <yarong@microsoft.com>
Content-Type: text/plain; charset=ISO-8859-1
Content-Transfer-Encoding: quoted-printable
Cc: oauth <oauth@ietf.org>
Subject: Re: [OAUTH-WG] OAuth Signature Draft Pre 00
X-BeenThere: oauth@ietf.org
X-Mailman-Version: 2.1.9
Precedence: list
List-Id: OAUTH WG <oauth.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/listinfo/oauth>,
 <mailto:oauth-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/oauth>
List-Post: <mailto:oauth@ietf.org>
List-Help: <mailto:oauth-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/oauth>,
 <mailto:oauth-request@ietf.org?subject=subscribe>
X-List-Received-Date: Wed, 22 Sep 2010 05:09:38 -0000

Sorry, I was wrong. "If Claim segment ...." is right.

2010/9/22 hdknr hidelafoglia <hidelafoglia@gmail.com>:
> Hi,
>
> If Crypto segment has a switch parameters of encryption or signature,
> JSON Token seems to =A0handle encrypted token as well as signed token.
>
> ---
> hdknr
>
>
> 2010/8/31 Yaron Goland <yarong@microsoft.com>:
>> BTW, Nat and I, as mentioned below, are talking. Here is my current draf=
t.
>> Please keep in mind that it's really just a set of notes trying to captu=
re
>> all the issues involved in creating a secure token format so it's a bit
>> dense. My hope is that once all the issues are captured it can be comple=
tely
>> re-written to be in something that looks more like English and is easier=
 for
>> actual implementers to follow. But for now I think it gives a good sense=
 of
>> the some of the security challenges in creating a secure token format.
>>
>> =A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0=A0 Yaron
>>
>>
>>
>> From: oauth-bounces@ietf.org [mailto:oauth-bounces@ietf.org] On Behalf O=
f
>> Nat Sakimura
>> Sent: Tuesday, August 24, 2010 6:50 AM
>> To: oauth
>> Subject: [OAUTH-WG] OAuth Signature Draft Pre 00
>>
>>
>>
>> Hi.
>>
>>
>>
>> It has been a few weeks since then I volunteered to do this work.
>>
>> I have written up to this pre 00 draft then have been doing some reality
>> checks on some script languages etc.
>>
>>
>>
>> No. This pre-00 draft is far from being feature complete.
>>
>> I still need to copy and paste the Magic Signatures text etc.
>>
>> Also, I should add how this spec is being used in some of the major flow=
s.
>>
>>
>>
>> However, since I will not be able to work on it this week, I thought it
>> would be worthwhile to share this early draft so that you have some clar=
ity
>> into the progress.
>>
>>
>>
>> Apparently, Yaron has been working on it as well. We will compare the no=
tes
>> and try to merge, I hope.
>>
>>
>>
>> So, here it is!
>>
>>
>>
>> #For those of you who have seen the private draft, it has not been chang=
ed
>> since July 31.
>>
>>
>>
>> Best,
>>
>>
>>
>> =3Dnat
>>
>>
>>
>>
>>
>> _______________________________________________
>> OAuth mailing list
>> OAuth@ietf.org
>> https://www.ietf.org/mailman/listinfo/oauth
>>
>>
>
