[OAUTH-WG] BOF about "JSON Cryptographic Syntax and Processing"

Hannes Tschofenig <hannes.tschofenig@gmx.net> Mon, 10 January 2011 09:17 UTC

Return-Path: <hannes.tschofenig@gmx.net>
X-Original-To: oauth@core3.amsl.com
Delivered-To: oauth@core3.amsl.com
Received: from localhost (localhost [127.0.0.1]) by core3.amsl.com (Postfix) with ESMTP id CDC3D28C113 for <oauth@core3.amsl.com>; Mon, 10 Jan 2011 01:17:00 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -102.438
X-Spam-Level:
X-Spam-Status: No, score=-102.438 tagged_above=-999 required=5 tests=[AWL=0.161, BAYES_00=-2.599, USER_IN_WHITELIST=-100]
Received: from mail.ietf.org ([64.170.98.32]) by localhost (core3.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id 7aBok0Z+5Pc7 for <oauth@core3.amsl.com>; Mon, 10 Jan 2011 01:17:00 -0800 (PST)
Received: from mail.gmx.net (mailout-de.gmx.net [213.165.64.23]) by core3.amsl.com (Postfix) with SMTP id 6FCA028C0F6 for <oauth@ietf.org>; Mon, 10 Jan 2011 01:16:59 -0800 (PST)
Received: (qmail invoked by alias); 10 Jan 2011 09:19:11 -0000
Received: from unknown (EHLO [10.255.131.194]) [192.100.123.77] by mail.gmx.net (mp055) with SMTP; 10 Jan 2011 10:19:11 +0100
X-Authenticated: #29516787
X-Provags-ID: V01U2FsdGVkX1+q4KEuepGqQJs9xScwBehDc5XzeQXqsGmG80DRL8 jMfJzYSuX7necy
From: Hannes Tschofenig <hannes.tschofenig@gmx.net>
Content-Type: text/plain; charset="us-ascii"
Content-Transfer-Encoding: quoted-printable
Date: Mon, 10 Jan 2011 11:19:09 +0200
Message-Id: <B1468A0F-7286-4263-A028-2F21C890EA77@gmx.net>
To: oauth@ietf.org
Mime-Version: 1.0 (Apple Message framework v1082)
X-Mailer: Apple Mail (2.1082)
X-Y-GMX-Trusted: 0
Subject: [OAUTH-WG] BOF about "JSON Cryptographic Syntax and Processing"
X-BeenThere: oauth@ietf.org
X-Mailman-Version: 2.1.9
Precedence: list
List-Id: OAUTH WG <oauth.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/listinfo/oauth>, <mailto:oauth-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/oauth>
List-Post: <mailto:oauth@ietf.org>
List-Help: <mailto:oauth-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/oauth>, <mailto:oauth-request@ietf.org?subject=subscribe>
X-List-Received-Date: Mon, 10 Jan 2011 09:17:00 -0000

Hi all, 

Mike had posted a mail about version -01 of the JSON Web Token document:
http://www.ietf.org/mail-archive/web/oauth/current/msg04912.html

The usage of JSON and security applied to it became crucial to the work in OAuth.  
As we start our re-chartering it would be logical to add it to our charter as well. 

While this is my first choice there may be resistance in doing so since we expand our charter quite a bit. 
As a backup, I would therefore like to propose to (a) try to include it in the OAuth re-chartering and (b) at the same time request a BOF at the next IETF meeting. 

Here is the charter writeup for the BOF: 
http://ietherpad.com/ce7Vc6AAay

Interestingly enough there are others in the IETF who also want to standardize JSON signing and encryption (but for other use cases). I am in contact with them and will try to combine our effort to reach the goal faster. 

Your comments on the charter writeup are appreciated. 

Ciao
Hannes