[OAUTH-WG] OAuth WG Agenda @ IETF115

2022-11-02 Thread Rifaat Shekh-Yusef
All, Here is our agenda for the two official sessions in London next week: Monday Nov 7th == Chairs Update - Rifaat/Hannes - 15 minutes Browser-based apps and OAuth 2.1- Aaron - 30 minutes SD-JWT - Daniel - 30 Step-up Authentication - Brian - 15 Interactive Authentication of Non-I

[OAUTH-WG] Step-up Auth: request acr as essential

2022-11-02 Thread Takahiko Kawasaki
Hello, If a client application wants to make the authorization server return error=unmet_authentication_requirements when none of requested ACRs is satisfied, the client application should request the "acr" claim as an "essential" claim. A straightforward way is to embed "acr":{"essential":true,"v