oauth-wg / draft-ietf-oauth-attestation-based-client-auth

Other
10 stars 7 forks source link

Extend the draft to define a new grant type #58

Open Sakurann opened 10 months ago

Sakurann commented 10 months ago

Can this draft be extended to define a new grant type urn:ietf:params:oauth:client-assertion-type:jwt-client-attestation where a sender-constrained JWT can be used to request an Access Token? for example, i think it would be useful in use-cases like catena-x https://github.com/eclipse-tractusx/identity-trust/issues/34 (cc @c2bo) Inspiration for the suggestion is https://www.rfc-editor.org/rfc/rfc7523, which defined urn:ietf:params:oauth:grant-type:jwt-bearer both for client authentication and a new grant type.

tplooker commented 10 months ago

@Sakurann can you please elaborate on the usecase here, the attached issue doesn't provide any context.