Re: [OAUTH-WG] Advertise PKCE support in OAuth 2.0 Discovery (draft-jones-oauth-discovery-00)

William Denniss <wdenniss@google.com> Tue, 19 January 2016 02:59 UTC

Return-Path: <wdenniss@google.com>
X-Original-To: oauth@ietfa.amsl.com
Delivered-To: oauth@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 941E11A8928 for <oauth@ietfa.amsl.com>; Mon, 18 Jan 2016 18:59:00 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.379
X-Spam-Level:
X-Spam-Status: No, score=-1.379 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, FM_FORGED_GMAIL=0.622, HTML_MESSAGE=0.001, RP_MATCHES_RCVD=-0.001, SPF_PASS=-0.001] autolearn=no
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id gXPelKsDBSVn for <oauth@ietfa.amsl.com>; Mon, 18 Jan 2016 18:58:58 -0800 (PST)
Received: from mail-ob0-x232.google.com (mail-ob0-x232.google.com [IPv6:2607:f8b0:4003:c01::232]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 9FBDD1A8925 for <oauth@ietf.org>; Mon, 18 Jan 2016 18:58:58 -0800 (PST)
Received: by mail-ob0-x232.google.com with SMTP id is5so176615495obc.0 for <oauth@ietf.org>; Mon, 18 Jan 2016 18:58:58 -0800 (PST)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=20120113; h=mime-version:in-reply-to:references:from:date:message-id:subject:to :cc:content-type; bh=8OM5UfwBmLfSg6LFDSb3bPPmU8YlY8wEiEIg8ex0VCA=; b=bBJZK8W/W5mxwKlIMFFYo+yQ2Fm3vRlnV8kyV0RlMbjX4ydib1J9ImX7uThEfsar/i JwS0BgnCaLfc2Y6A1sUWuANrbCJH1niuuat2Rx/nsMdtiwGaswTXmJMqsjaMrUmDHSdT AxBqlxGeesD0eEV65e0k8kB4OrWhslMGVordHCr6F8hiZElTK9Y2v2E7H3PrvjC4TAHk ojypgyvH3eqCsR0mZkN+KdmAAo5Bzp6dTBPI7kYVGIekQcPoj4GmmFN8WWkgU8mmXhrY IG25J/MXJxSAJjuAq3kwwp33t8Zs5seXnhjtfXm4aF9+VxZKOycILWmjlYExwMgsfgm8 uOPA==
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20130820; h=x-gm-message-state:mime-version:in-reply-to:references:from:date :message-id:subject:to:cc:content-type; bh=8OM5UfwBmLfSg6LFDSb3bPPmU8YlY8wEiEIg8ex0VCA=; b=Rv7rw/nKKrPwtd70D3ZhHdSPTOrQfXqVF1e9hyuAHlyB9ctO5MtISJwl8ZTPzvySql V9CL5V333Fd56jUnubuI5SxpVVnQuqc4dOVjd6+k2KfA5A5rYND9uEfMol18AnQB0PAH JEKDBwZXPtFtqxWRmr8Etz1bDeLtnPxFA1pDP6edkVJPiopg1XG0LaJ18p3IUCRth5fh 6p6hAPx4QYtrGwBsgdXSFfzqysPBMOuBc/kE1dAocN2JXv0oTceATzU2XYq04kEGwl02 AtITP0pSIVqCBeyLO4WjA0bJUQTbZt8s44C9KyAChDOYg+RT/aha2yllk8tlA4MCitOg 112w==
X-Gm-Message-State: ALoCoQm4zQJz0Fx1rcIPMoGBBkImxnkvsfCn5z2J+l3A2I1ZconPVvblcI7lDfXkQXAJiTTvgzhCrDCOGV6KYvmbZKoEGpCb3tetqqGC6WN347sXtWptpR8=
X-Received: by 10.60.51.70 with SMTP id i6mr22212979oeo.3.1453172337972; Mon, 18 Jan 2016 18:58:57 -0800 (PST)
MIME-Version: 1.0
Received: by 10.182.227.39 with HTTP; Mon, 18 Jan 2016 18:58:37 -0800 (PST)
In-Reply-To: <568D5610.6000506@lodderstedt.net>
References: <568D24DD.3050501@connect2id.com> <EA392E73-1C01-42DC-B21D-09F570239D5E@ve7jtb.com> <CAAP42hAA6SOvfxjfuQdjoPfSh3HmK=a7PCQ_sPXTmDg+AQ6sug@mail.gmail.com> <568D5610.6000506@lodderstedt.net>
From: William Denniss <wdenniss@google.com>
Date: Mon, 18 Jan 2016 18:58:37 -0800
Message-ID: <CAAP42hA8SyOOkJ-D299VgvQUdQv6NXqxSt9R0TK7Zk7JaU56eQ@mail.gmail.com>
To: Torsten Lodderstedt <torsten@lodderstedt.net>
Content-Type: multipart/alternative; boundary="001a11c301cc00e4490529a70d0c"
Archived-At: <http://mailarchive.ietf.org/arch/msg/oauth/lMr2OEOLKSNtAwlCYR_AVFFXP7Y>
Cc: "oauth@ietf.org" <oauth@ietf.org>
Subject: Re: [OAUTH-WG] Advertise PKCE support in OAuth 2.0 Discovery (draft-jones-oauth-discovery-00)
X-BeenThere: oauth@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: OAUTH WG <oauth.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/oauth>, <mailto:oauth-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/oauth/>
List-Post: <mailto:oauth@ietf.org>
List-Help: <mailto:oauth-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/oauth>, <mailto:oauth-request@ietf.org?subject=subscribe>
X-List-Received-Date: Tue, 19 Jan 2016 02:59:00 -0000

Seems like we agree this should be added. How should it look?

Two ideas:

"code_challenge_methods_supported": ["plain", "S256"]

or

"pkce_methods_supported": ["plain", "S256"]



On Wed, Jan 6, 2016 at 9:59 AM, Torsten Lodderstedt <torsten@lodderstedt.net
> wrote:

> +1
>
>
> Am 06.01.2016 um 18:25 schrieb William Denniss:
>
> +1
>
> On Wed, Jan 6, 2016 at 6:40 AM, John Bradley <ve7jtb@ve7jtb.com> wrote:
>
>> Good point.  Now that PKCE is a RFC we should add it to discovery.
>>
>> John B.
>> > On Jan 6, 2016, at 9:29 AM, Vladimir Dzhuvinov <vladimir@connect2id.com>
>> wrote:
>> >
>> > I just noticed PKCE support is missing from the discovery metadata.
>> >
>> > Is it a good idea to add it?
>> >
>> > Cheers,
>> >
>> > Vladimir
>> >
>> > --
>> > Vladimir Dzhuvinov
>> >
>> >
>> > _______________________________________________
>> > OAuth mailing list
>> > OAuth@ietf.org
>> > https://www.ietf.org/mailman/listinfo/oauth
>>
>> _______________________________________________
>> OAuth mailing list
>> OAuth@ietf.org
>> https://www.ietf.org/mailman/listinfo/oauth
>>
>
>
>
> _______________________________________________
> OAuth mailing listOAuth@ietf.orghttps://www.ietf.org/mailman/listinfo/oauth
>
>
>