Can this draft be extended to define a new grant type urn:ietf:params:oauth:client-assertion-type:jwt-client-attestation where a sender-constrained JWT can be used to request an Access Token? for example, i think it would be useful in use-cases like catena-x https://github.com/eclipse-tractusx/identity-trust/issues/34 (cc @c2bo)
Inspiration for the suggestion is https://www.rfc-editor.org/rfc/rfc7523, which defined urn:ietf:params:oauth:grant-type:jwt-bearer both for client authentication and a new grant type.
Can this draft be extended to define a new grant type
urn:ietf:params:oauth:client-assertion-type:jwt-client-attestation
where a sender-constrained JWT can be used to request an Access Token? for example, i think it would be useful in use-cases like catena-x https://github.com/eclipse-tractusx/identity-trust/issues/34 (cc @c2bo) Inspiration for the suggestion is https://www.rfc-editor.org/rfc/rfc7523, which definedurn:ietf:params:oauth:grant-type:jwt-bearer
both for client authentication and a new grant type.