<html>
<head>
<meta http-equiv="Content-Type" content="text/html; charset=UTF-8">
</head>
<body>
<p><br>
</p>
<div class="moz-cite-prefix">On 1/29/24 1:20 PM, Kristian Smith
wrote:<br>
</div>
<blockquote type="cite"
cite="mid:DM4PR21MB3707EC5F442B3E06BB3979BC957E2@DM4PR21MB3707.namprd21.prod.outlook.com">
<meta http-equiv="Content-Type" content="text/html; charset=UTF-8">
<style type="text/css" style="display:none;">P {margin-top:0;margin-bottom:0;}</style>
<div class="elementToProof" style="font-family: Aptos,
Aptos_EmbeddedFont, Aptos_MSFontService, Calibri, Helvetica,
sans-serif; font-size: 11pt; color: rgb(0, 0, 0);">
[Mike to Bcc]</div>
<div class="elementToProof" style="font-family: Aptos,
Aptos_EmbeddedFont, Aptos_MSFontService, Calibri, Helvetica,
sans-serif; font-size: 11pt; color: rgb(0, 0, 0);">
<br>
</div>
<div class="elementToProof" style="font-family: Aptos,
Aptos_EmbeddedFont, Aptos_MSFontService, Calibri, Helvetica,
sans-serif; font-size: 11pt; color: rgb(0, 0, 0);">
Hi David,</div>
<div class="elementToProof" style="font-family: Aptos,
Aptos_EmbeddedFont, Aptos_MSFontService, Calibri, Helvetica,
sans-serif; font-size: 11pt; color: rgb(0, 0, 0);">
<br>
</div>
<div class="elementToProof" style="font-family: Aptos,
Aptos_EmbeddedFont, Aptos_MSFontService, Calibri, Helvetica,
sans-serif; font-size: 11pt; color: rgb(0, 0, 0);">
Thanks for reaching out. After a cursory look, you are correct.
The "ctx" parameter is not listed in RFC 7515. </div>
<div class="elementToProof" style="font-family: Aptos,
Aptos_EmbeddedFont, Aptos_MSFontService, Calibri, Helvetica,
sans-serif; font-size: 11pt; color: rgb(0, 0, 0);">
<br>
</div>
<div class="elementToProof" style="font-family: Aptos,
Aptos_EmbeddedFont, Aptos_MSFontService, Calibri, Helvetica,
sans-serif; font-size: 11pt; color: rgb(0, 0, 0);">
It appears that we discuss derivation of the "ctx" parameter in
an earlier section (3.1.5.1.3.3). I will suggest the following
as a modification to the doc:</div>
<div class="elementToProof" style="font-family: Aptos,
Aptos_EmbeddedFont, Aptos_MSFontService, Calibri, Helvetica,
sans-serif; font-size: 11pt; color: rgb(0, 0, 0);">
<br>
</div>
<div class="elementToProof" style="font-family: Aptos,
Aptos_EmbeddedFont, Aptos_MSFontService, Calibri, Helvetica,
sans-serif; font-size: 11pt; color: rgb(0, 0, 0);">
<b>From:</b></div>
<p class="elementToProof" style="margin-top: 0px; margin-bottom:
0px;"><span style="font-family: Verdana, sans-serif; font-size:
9pt; color: rgb(0, 0, 0);">"The JWT header fields MUST be
given the following values. See
<a href="https://go.microsoft.com/fwlink/?LinkId=691168"
id="OWA435f9084-2ae4-5e06-961f-d5f7dbfc91a0"
class="OWAAutoLink" data-loopstyle="linkonly"
style="margin-top: 0px; margin-bottom: 0px;"
moz-do-not-send="true">
[RFC7515]</a> section 4 for field descriptions."</span></p>
<div class="elementToProof" style="font-family: Aptos,
Aptos_EmbeddedFont, Aptos_MSFontService, Calibri, Helvetica,
sans-serif; font-size: 11pt; color: rgb(0, 0, 0);">
<br>
</div>
<div class="elementToProof" style="font-family: Aptos,
Aptos_EmbeddedFont, Aptos_MSFontService, Calibri, Helvetica,
sans-serif; font-size: 11pt; color: rgb(0, 0, 0);">
<b>To:</b></div>
<p class="elementToProof" style="margin-top: 0px; margin-bottom:
0px;"><span style="font-family: Verdana, sans-serif; font-size:
9pt; color: rgb(0, 0, 0);">"The JWT header fields MUST be
given the following values. See
<a href="https://go.microsoft.com/fwlink/?LinkId=691168"
id="OWA1149b617-6b4a-4e0f-9071-d58a463b6265"
class="OWAAutoLink" data-loopstyle="linkonly"
style="margin-top: 0px; margin-bottom: 0px;"
moz-do-not-send="true">
[RFC7515]</a> section 4 for field descriptions.</span><span
style="font-family: Aptos, Aptos_EmbeddedFont,
Aptos_MSFontService, Calibri, Helvetica, sans-serif;
font-size: 11pt; color: rgb(0, 0, 0);"> The derivation for the
"ctx" parameter is discussed in section
</span><span style="font-family: Verdana, sans-serif; font-size:
9pt; color: rgb(0, 0, 0);"><a
href="#Section_89dfb8d623b84963890891b34340e367"
id="OWAca18a29c-a3ff-6508-2396-c2e7e889caf0"
class="OWAAutoLink" data-loopstyle="linkonly"
style="margin-top: 0px; margin-bottom: 0px;"
moz-do-not-send="true">3.1.5.1.3.3</a>."</span></p>
<div class="elementToProof" style="font-family: Aptos,
Aptos_EmbeddedFont, Aptos_MSFontService, Calibri, Helvetica,
sans-serif; font-size: 11pt; color: rgb(0, 0, 0);">
<br>
</div>
<div class="elementToProof" style="font-family: Aptos,
Aptos_EmbeddedFont, Aptos_MSFontService, Calibri, Helvetica,
sans-serif; font-size: 11pt; color: rgb(0, 0, 0);">
Would this document modification provide the needed clarity?</div>
</blockquote>
Yes, that sounds fine.<br>
<pre class="moz-signature" cols="72">--
David Mulder
Labs Software Engineer, Samba
SUSE
1221 S Valley Grove Way, Suite 500
Pleasant Grove, UT 84062
(P)+1 385.208.2989
<a class="moz-txt-link-abbreviated" href="mailto:dmulder@suse.com">dmulder@suse.com</a>
<a class="moz-txt-link-freetext" href="http://www.suse.com">http://www.suse.com</a></pre>
</body>
</html>