seems you are contradicting yourself. 

You criticised the MUST and suggested to include some examples. I bought into 
your argument and suggested to refer to the security doc for examples and 
additional explanations. That's what this document is intended for, to provide 
background beyond what we can cover in the core spec.

And I don't think the spec already makes that point. But you are free to refer 
me to the respective text.


Eran Hammer-Lahav <> schrieb:

>I still don’t find it useful. I think the existing text overall makes
>this point already.
>From: Torsten Lodderstedt []
>Sent: Wednesday, July 06, 2011 12:48 AM
>To: Eran Hammer-Lahav; OAuth WG
>Subject: Re: Section 10.1 (Client authentication)
>Hi Eran,
>I would suggest to change it to SHOULD and add a reference to
> sections
>3.7 and 5.2.3.
>Eran Hammer-Lahav <<>>
>It's a pointless MUST given how undefined the requirements are. It will
>only be understood by security experts and they don't really need it.
>At a minimum, it needs some examples.
>From: Torsten Lodderstedt
>Date: Wed, 1 Jun 2011 00:53:37 -0700
>To: Eran Hammer-lahav
><<>>, OAuth WG
>Subject: Section 10.1 (Client authentication)
>Hi Eran,
>would you please add the following sentence (which was contained in the
>original security considerations text) to the second paragraph of
>section 1.0.1?
>Alternatively, authorization servers MUST utilize
>    other means than client authentication to achieve their security
>    objectives.
>I think it's important to state that authorization server should
>consider alternative way to validate the client identity if secrets
>cannot be used. The security threat document also suggest some.

OAuth mailing list

Reply via email to