Re: [OAUTH-WG] draft-ietf-oauth-mtls-03: enforcing mutual_tls_sender_constrained_access_tokens

2017-08-28 Thread Vladimir Dzhuvinov
On 28/08/17 18:53, Brian Campbell wrote: > "invalid_client" is the appropriate error, if the client is > configured/registered for MTLS authentication, because it's effectively > failed client authentication. > > I would say that "invalid_request" is probably the appropriate error for a > public cl

Re: [OAUTH-WG] some implementation feedback with the PKI method of OAuth MTLS client authentication

2017-08-28 Thread Nat Sakimura
+1 Sent from Astro for Android On 2017-08-29 at 4:33 AM, Torsten wrote: +1 for removing tls_client_auth_root Am 28.08.2017 um 20:24 schrieb John Bradley : Having discussed it with Brian, I agree that removing “tls_client_auth_root” is the way to go. It would be hard to implement in some cases, and

Re: [OAUTH-WG] some implementation feedback with the PKI method of OAuth MTLS client authentication

2017-08-28 Thread Torsten Lodderstedt
+1 for removing tls_client_auth_root > Am 28.08.2017 um 20:24 schrieb John Bradley : > > Having discussed it with Brian, I agree that removing “tls_client_auth_root” > is the way to go. > It would be hard to implement in some cases, and it is up to the AS to > configure the roots it trusts fo

Re: [OAUTH-WG] some implementation feedback with the PKI method of OAuth MTLS client authentication

2017-08-28 Thread John Bradley
Having discussed it with Brian, I agree that removing “tls_client_auth_root” is the way to go. It would be hard to implement in some cases, and it is up to the AS to configure the roots it trusts for client authentication. In reality every TLS client auth deployment is likely to have custom ru

[OAUTH-WG] some implementation feedback with the PKI method of OAuth MTLS client authentication

2017-08-28 Thread Brian Campbell
Some feedback was received recently off-list that pointed out difficulties with implementation around the "tls_client_auth_root_dn" constraint in the PKI method of OAuth MTLS client authentication from draft-ietf-oauth-mtls-03. Basically the feedback was that popular web servers such as Nginx and A

Re: [OAUTH-WG] draft-ietf-oauth-mtls-03: enforcing mutual_tls_sender_constrained_access_tokens

2017-08-28 Thread Brian Campbell
"invalid_client" is the appropriate error, if the client is configured/registered for MTLS authentication, because it's effectively failed client authentication. I would say that "invalid_request" is probably the appropriate error for a public client with mutual_tls_sender_constrained_access_token