[Gen-art] review: draft-ietf-oauth-jwt-bearer-10

"Joel M. Halpern" <jmh@joelhalpern.com> Thu, 18 September 2014 21:47 UTC

Return-Path: <jmh@joelhalpern.com>
X-Original-To: gen-art@ietfa.amsl.com
Delivered-To: gen-art@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 794DB1A8997 for <gen-art@ietfa.amsl.com>; Thu, 18 Sep 2014 14:47:19 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.902
X-Spam-Level:
X-Spam-Status: No, score=-1.902 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, RCVD_IN_DNSWL_NONE=-0.0001, SPF_HELO_PASS=-0.001, SPF_PASS=-0.001] autolearn=ham
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id SXt47vg5M3ob for <gen-art@ietfa.amsl.com>; Thu, 18 Sep 2014 14:47:18 -0700 (PDT)
Received: from mailb2.tigertech.net (mailb2.tigertech.net [208.80.4.154]) (using TLSv1.2 with cipher AECDH-AES256-SHA (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id E9DAD1A8994 for <gen-art@ietf.org>; Thu, 18 Sep 2014 14:47:17 -0700 (PDT)
Received: from localhost (localhost [127.0.0.1]) by mailb2.tigertech.net (Postfix) with ESMTP id 3C6121C01DE; Thu, 18 Sep 2014 14:47:17 -0700 (PDT)
X-Virus-Scanned: Debian amavisd-new at b2.tigertech.net
Received: from Joels-MacBook-Pro.local (aptilo2-usaa.ericsson.net [129.192.185.163]) (using TLSv1 with cipher ECDHE-RSA-AES128-SHA (128/128 bits)) (No client certificate requested) by mailb2.tigertech.net (Postfix) with ESMTPSA id 89B3A1C01BE; Thu, 18 Sep 2014 14:47:16 -0700 (PDT)
Message-ID: <541B52DB.8070902@joelhalpern.com>
Date: Thu, 18 Sep 2014 17:47:07 -0400
From: "Joel M. Halpern" <jmh@joelhalpern.com>
User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10.9; rv:24.0) Gecko/20100101 Thunderbird/24.6.0
MIME-Version: 1.0
To: "A. Jean Mahoney" <mahoney@nostrum.com>, gen-art@ietf.org, Kathleen Moriarty <kathleen.moriarty.ietf@gmail.com>
References: <541B461F.4020908@nostrum.com>
In-Reply-To: <541B461F.4020908@nostrum.com>
Content-Type: text/plain; charset="ISO-8859-1"; format="flowed"
Content-Transfer-Encoding: 7bit
Archived-At: http://mailarchive.ietf.org/arch/msg/gen-art/BaZle5JBnflLB07C3g4ciKHjXTM
Subject: [Gen-art] review: draft-ietf-oauth-jwt-bearer-10
X-BeenThere: gen-art@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: "GEN-ART: General Area Review Team" <gen-art.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/gen-art>, <mailto:gen-art-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/gen-art/>
List-Post: <mailto:gen-art@ietf.org>
List-Help: <mailto:gen-art-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/gen-art>, <mailto:gen-art-request@ietf.org?subject=subscribe>
X-List-Received-Date: Thu, 18 Sep 2014 21:47:19 -0000

I am the assigned Gen-ART reviewer for this draft. For background on
Gen-ART, please see the FAQ at

<http://wiki.tools.ietf.org/area/gen/trac/wiki/GenArtfaq>.

Please resolve these comments along with any other Last Call comments
you may receive.

Document: draft-ietf-oauth-jwt-bearer-10
   JSON Web Token (JWT) Profile for OAuth 2.0 Client Authentication and
                           Authorization Grants
Reviewer: Joel M. Halpern
Review Date: 18-Sept-2014
IETF LC End Date: 29-Sept-2014
IESG Telechat date: N/A

Summary: This document appears to be ready for publicaiton as a Proposed 
Standard.

This reviewer would suggest that the General AD check with parties who 
can confirm the two notes below.

Note that the reviewer did not review RFC 6749, 
draft-ietf-oauth-assertions, or draft-ietf-oauth-json-web-token, but 
simply takes as given that the work here is consistent with that work.

Similarly, the reviewer assumes that the subtleties of 
internationalization of issuers (and any other fields that must be 
compared).  It is not obvious whether pointing to the RFC 3986 is 
sufficient, but it is not obviously insufficient.

Major issues: N/A

Minor issues:
     I presume it is clear from the underlying documents whether the 
periods at the ends of intermediate lines in the examples are supposed 
to be there.

Nits/editorial comments: N/A