

PS: Am I correct that the current token exchange spec can be used with
mTLS and token binding as it is, without any additional changes?

On 03/10/17 16:51, Mike Jones wrote:
> A Microsoft use case has come up in which people would like to perform a 
> token exchange for a SAML token. The spec already defines 
> urn:ietf:params:oauth:token-type:jwt for requesting JWT tokens.  Would 
> anybody object to us adding urn:ietf:params:oauth:token-type:saml2 to the 
> next draft to also give us a standard way to ask for SAML 2.0 tokens?
> It could always be done in its own spec, but adding it in Token Exchange 
> seems more expedient.
>                                                                      -- Mike

Attachment: smime.p7s
Description: S/MIME Cryptographic Signature

OAuth mailing list

Reply via email to