oauth-wg / oauth-cross-device-security

Other
10 stars 8 forks source link

Update Guidance on using FIDO #129

Closed PieterKas closed 2 months ago

PieterKas commented 2 months ago

Feedback from Dean Saxe during WGLC

  1. Section 6.2.3.5 could be softened a bit. The first sentence should include, “… and a suitable FIDO credential is not available on the consumption device.” In most patterns, this mechanism is used to bootstrap a new credential on the device, rather than using this mechanism for authN every time.

https://mailarchive.ietf.org/arch/msg/oauth/T9XDSCqvVWPQAjDHjkH9iOQXsOo/

PieterKas commented 2 months ago

Adressed in #136