Re: [OAUTH-WG] DPoP and Dynamic Client Registration

2023-11-16 Thread Denis
Hi George, Is is unclear whether you are considering the OAuth 2.X Framework or the three roles model (i.e., with the Holder, the Issuer and the Verifier). Denis Hi, Are there any best practices for clients that want to use Dynamic Client Registration and plan to register a public key (rat

[OAUTH-WG] DPoP and Dynamic Client Registration

2023-11-16 Thread George Fletcher
Hi, Are there any best practices for clients that want to use Dynamic Client Registration and plan to register a public key (rather than receiving back a shared client_secret), to use DPoP to prove possession of the matching private key and also integrity protect the JSON object passed to the regi