Re: [OAUTH-WG] OAuth 2.0 Attestation-Based Client Authentication

2023-07-25 Thread Tom Jones
I have concerns, similar to Orie's, about assertions. Like Orie, I would like to see something like this approved, but it must be secure. The following is the part of the draft that concerns me. Therefore, the client generates a key (Client Instance Key) and (platform specific) attestations to

Re: [OAUTH-WG] OAuth 2.0 Protected Resource Metadata now with WWW-Authenticate

2023-07-25 Thread Giuseppe De Marco
Hi, I am happy that this draft is progressing, draft 01 was adopted two years ago for the Italian Attribute Authorities (SPID Attribute Authorities) because there was a need to publish the metadata of a RS. I see that many steps forward have been made and in a short time. I have read Brian's reacti