Re: [OAUTH-WG] OAuth WG Virtual Office Hours is cancelled this week

2021-03-08 Thread Brian Campbell
I typically take a couple minutes of the Virtual Office Hours call to inquire about the status of the shepherd writeup for the Pushed Authorization Requests draft. With the cancellation of the meeting, I guess I'll do that here by email instead. Any progress on that front? The chairs had previousl

Re: [OAUTH-WG] OAuth mTLS and JWK use/key_ops

2021-03-08 Thread Neil Madden
> On 8 Mar 2021, at 12:50, Neil Madden wrote: > > An interesting question was raised by our developers around the > interpretation of JWK “use” and “key_ops” constraints when publishing a > self-signed certificate for mTLS client authentication. In X.509 the KeyUsage > extension distinguishe

[OAUTH-WG] OAuth mTLS and JWK use/key_ops

2021-03-08 Thread Neil Madden
An interesting question was raised by our developers around the interpretation of JWK “use” and “key_ops” constraints when publishing a self-signed certificate for mTLS client authentication. In X.509 the KeyUsage extension distinguishes between keys intended for use for verifying general signat