Re: [OAUTH-WG] OAuth: the ABC attack (the Alice and Bob Collusion attack)

2016-11-10 Thread Nat Sakimura
Thanks Denis for pointing it out. It may be desirable to add ABC attack to the list of threats. Torsten et al. are updating Threat Model and Security Considerations so it could potentially be included in there. Some remarks: - I suppose the assumption is that the Bob does not share his cred

Re: [OAUTH-WG] New Version Notification for draft-campbell-oauth-tls-client-auth-00.txt

2016-11-10 Thread Sergey Beryozkin
On 10/11/16 21:57, Sergey Beryozkin wrote: On 10/11/16 20:10, Vladimir Dzhuvinov wrote: On 03/11/16 19:11, Sergey Beryozkin wrote: Hi In our implementation we support the following scenario: - the client registers its public certificate during the client registration Did you extend the sta

Re: [OAUTH-WG] New Version Notification for draft-campbell-oauth-tls-client-auth-00.txt

2016-11-10 Thread Vladimir Dzhuvinov
On 03/11/16 19:11, Sergey Beryozkin wrote: > Hi > > In our implementation we support the following scenario: > - the client registers its public certificate during the client > registration Did you extend the standard client reg API for this purpose? How does the cert registration actually take