-
Notifications
You must be signed in to change notification settings - Fork 5
Closed
Labels
feedbackA general placeholder for feedback.A general placeholder for feedback.wontfixThis will not be worked onThis will not be worked on
Description
§13.2 of version 0.0.3 of this spec says the authorisation endpoint uses TLS. I believe it should use MTLS.
FAPI part 2 §5.2.2 includes the following.
- shall only issue authorization code, access token, and refresh token that are holder of key bound;
- shall support [OAUTB] or [MTLS] as a holder of key mechanism;
§11.3 of version 0.0.3 of this spec forbids using OAUTB and therefore only allows MTLS to be used. As a result, for the authorization code to be holder of key bound I believe the authorisation endpoint must use MTLS.
Metadata
Metadata
Assignees
Labels
feedbackA general placeholder for feedback.A general placeholder for feedback.wontfixThis will not be worked onThis will not be worked on