Skip to content

Authorisation endpoint should use MTLS. #31

@ajmcmiddlin

Description

@ajmcmiddlin

§13.2 of version 0.0.3 of this spec says the authorisation endpoint uses TLS. I believe it should use MTLS.

FAPI part 2 §5.2.2 includes the following.

  1. shall only issue authorization code, access token, and refresh token that are holder of key bound;
  2. shall support [OAUTB] or [MTLS] as a holder of key mechanism;

§11.3 of version 0.0.3 of this spec forbids using OAUTB and therefore only allows MTLS to be used. As a result, for the authorization code to be holder of key bound I believe the authorisation endpoint must use MTLS.

Metadata

Metadata

Assignees

No one assigned

    Labels

    feedbackA general placeholder for feedback.wontfixThis will not be worked on

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions