Re: [OAUTH-WG] New Version Notification for draft-fett-oauth-dpop-03.txt

2019-11-22 Thread Petteri Stenius
Hi all, For browser based apps it is basically limitations of Fetch API that prevent MTLS binding, as Fetch uses client certificate dialogs and stores. Does it make sense to suggest browser vendors fix the Fetch API to better support MTLS? For example if Fetch API allowed setting up a MTLS requ

Re: [OAUTH-WG] I-D Action: draft-ietf-oauth-access-token-jwt-01.txt

2019-07-24 Thread Petteri Stenius
Hi Vittorio, Thanks for working on this. I think this will be valuable. I have a couple of comments. About relationship of this draft with token exchange, introspection and revocation: Should there be a distinct Token Type Identifier defined for JWT Access Token, to enable exchange of referen

Re: [OAUTH-WG] OAuth Security Topics -- Recommend authorization code instead of implicit

2018-11-29 Thread Petteri Stenius
Hi all, I support this proposal of recommending authorization code grant and advising to not use implicit grant. As a developer we value clean and robust specifications with less opportunity for mistakes. Thank you, Petteri Stenius / Ubisecure -Original Message- From: OAuth On Behalf

Re: [OAUTH-WG] Fwd: New Version Notification for draft-lodderstedt-oauth-jwt-introspection-response-00.txt

2018-03-26 Thread Petteri Stenius
ds as well. Relationship with OpenID Connect In OpenID Connect the userinfo endpoint is very similar to introspection endpoint of OAuth. Userinfo supports JWT signing and encryption. Adding JWT signing and encryption to introspection endpoint fills the gap between the two specifica