Re: [OAUTH-WG] Éric Vyncke's No Objection on draft-ietf-oauth-jwsreq-26: (with COMMENT)

Nat Sakimura <sakimura@gmail.com> Thu, 13 August 2020 13:43 UTC

Return-Path: <sakimura@gmail.com>
X-Original-To: oauth@ietfa.amsl.com
Delivered-To: oauth@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 0D0073A0C3E; Thu, 13 Aug 2020 06:43:35 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2.097
X-Spam-Level:
X-Spam-Status: No, score=-2.097 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, FREEMAIL_FROM=0.001, HTML_MESSAGE=0.001, SPF_HELO_NONE=0.001, SPF_PASS=-0.001, URIBL_BLOCKED=0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (2048-bit key) header.d=gmail.com
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id kgiQjh7uUA3e; Thu, 13 Aug 2020 06:43:32 -0700 (PDT)
Received: from mail-wr1-x443.google.com (mail-wr1-x443.google.com [IPv6:2a00:1450:4864:20::443]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 8F7B63A0C3C; Thu, 13 Aug 2020 06:43:32 -0700 (PDT)
Received: by mail-wr1-x443.google.com with SMTP id f12so5306992wru.13; Thu, 13 Aug 2020 06:43:32 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20161025; h=mime-version:references:in-reply-to:from:date:message-id:subject:to :cc; bh=KxZ8Ii9tfwQJ7LpIa9Zc2eocVKRCVElXETA2jpQ/99s=; b=BHjJzuw0gRHdZe1eEVx04sJ8RZhxXXqMxUPjZYbtsGy3JfIuJBx1Zpz1G2afrLFcg+ 65RixP/O/R+tDuEgp+voLNQCxRAnfrnu4aWv9lduYcoTMd/wfLqvxrrm80qrfkp1yHrJ n0hsikC9wZcpVXq+CKwJHb1iOerLMZMzB9ruP1IxNKLvrrbVHybgEyEcdxDNILp6Vr5p nNJKN6FQ9pufGzF10Uksk+T44Q1DUe2Ta4XTkT4UZGnkoXY+Ymh8j4iIHhem2eNfQqrq X6acU5BZKmXM3Iw3tMDROKua9HQLFWDcZA6P+Cfor2HzIWmT/tS/wFWGkMURvytHUiin 81pQ==
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20161025; h=x-gm-message-state:mime-version:references:in-reply-to:from:date :message-id:subject:to:cc; bh=KxZ8Ii9tfwQJ7LpIa9Zc2eocVKRCVElXETA2jpQ/99s=; b=RpsUHOMk9iC5fl6bwNv/6udjgasaey8sylgOokgFpzdIljEWUI6fSKFTSwnGX00oSP KeNwV18MW1woyFFJF6LARWeP4iL8GzMZSpqvu1sS/2tnatdUtvfPCJ5Xa4NjlTS3pn9x dGTWFl1n8Kaymo/0ivWV1dA9AvFUhYPPfjN9Yp4LVANZNoG9dNvahrKfcYbW9kfrY2CS W20uhwGm8ZBVTGoPOYy64kKJfEgWBRZzU3BWpfgQP3ZBMAOFPh952Msv9IixPY9r8AFl Wl4n9RIbt0+LRAqPXSP6D1om8nA5cpRhR1G5eHRP5T4zijNZk2JP5mD4ydgQgECz82TK f8IA==
X-Gm-Message-State: AOAM530gUFf3AZ8UT7tkTK3nk4TA3cSxeEm4ahLJqN2wbf1UkQClprDk TdNITn/ivLb3XLgnjgtF5z/cHKS+AXuCIiaFyTc=
X-Google-Smtp-Source: ABdhPJwrf98kZS6nssN3L377SQXpWRu+lzbGygC5aGIvka6eTcN7p0E+ci4MLFU17+I+mkwPQj+7pZhBbXdxbGebM5k=
X-Received: by 2002:adf:ec8b:: with SMTP id z11mr4039400wrn.51.1597326210804; Thu, 13 Aug 2020 06:43:30 -0700 (PDT)
MIME-Version: 1.0
References: <159661722741.30500.10022053097818080667@ietfa.amsl.com>
In-Reply-To: <159661722741.30500.10022053097818080667@ietfa.amsl.com>
From: Nat Sakimura <sakimura@gmail.com>
Date: Thu, 13 Aug 2020 22:43:19 +0900
Message-ID: <CABzCy2DjEg-c2LxmGgKwu2-B+QNAvrgcNdrSYRsAzNNv4ubKgQ@mail.gmail.com>
To: Éric Vyncke <evyncke@cisco.com>
Cc: The IESG <iesg@ietf.org>, oauth <oauth@ietf.org>, oauth-chairs@ietf.org, draft-ietf-oauth-jwsreq@ietf.org
Content-Type: multipart/alternative; boundary="00000000000062b39505acc27d2d"
Archived-At: <https://mailarchive.ietf.org/arch/msg/oauth/n8HzBXzT_ywWHJCKkMRlOSunidI>
Subject: Re: [OAUTH-WG] Éric Vyncke's No Objection on draft-ietf-oauth-jwsreq-26: (with COMMENT)
X-BeenThere: oauth@ietf.org
X-Mailman-Version: 2.1.29
Precedence: list
List-Id: OAUTH WG <oauth.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/oauth>, <mailto:oauth-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/oauth/>
List-Post: <mailto:oauth@ietf.org>
List-Help: <mailto:oauth-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/oauth>, <mailto:oauth-request@ietf.org?subject=subscribe>
X-List-Received-Date: Thu, 13 Aug 2020 13:43:35 -0000

Thanks, Éric.

Reply inline:

On Wed, Aug 5, 2020 at 5:47 PM Éric Vyncke via Datatracker <noreply@ietf.org>
wrote:

> Éric Vyncke has entered the following ballot position for
> draft-ietf-oauth-jwsreq-26: No Objection
>
> When responding, please keep the subject line intact and reply to all
> email addresses included in the To and CC lines. (Feel free to cut this
> introductory paragraph, however.)
>
>
> Please refer to https://www.ietf.org/iesg/statement/discuss-criteria.html
> for more information about IESG DISCUSS and COMMENT positions.
>
>
> The document, along with other ballot positions, can be found here:
> https://datatracker.ietf.org/doc/draft-ietf-oauth-jwsreq/
>
>
>
> ----------------------------------------------------------------------
> COMMENT:
> ----------------------------------------------------------------------
>
> Thank you for the work put into this document.
>
> Please find below a couple of non-blocking COMMENTs.
>
> I hope that this helps to improve the document,
>
> Regards,
>
> -éric
>
> == COMMENTS ==
> Should the document shepherd's write-up be updated ? It is dated October
> 2016... about 4 years ago.
>
> -- Section 5.2 --
> Based on the long history of this document, is the following statement
> "Many
> phones in the market as of this writing still"  still valid ?
>

Yes, partly because the demand for the authorization request payload is
becoming large these days.
As we can see in the PAR draft, we are precipitating to request_uri
pattern.


>
> -- Section 5.2.1 --
> Suggest to give a hint about the use of tfp.example.org (TFP is expanded
> only
> in section 10.2).
>

You are right. Perhaps it may be better to give two examples, one with TFP
with one-liner explanation and another with URN that is being stored at the
authorization server.


>
> == NITS ==
>
> Please check the ID-NITS at
>
> https://tools.ietf.org/idnits?url=https://tools.ietf.org/id/draft-ietf-oauth-jwsreq-26.txt


Thanks. Will do.


>
>
>
>
> _______________________________________________
> OAuth mailing list
> OAuth@ietf.org
> https://www.ietf.org/mailman/listinfo/oauth
>


-- 
Nat Sakimura (=nat)
Chairman, OpenID Foundation
http://nat.sakimura.org/
@_nat_en