oauth-wg / oauth-identity-chaining

Draft specification for Identity Chaining
https://drafts.oauth.net/oauth-identity-chaining/draft-ietf-oauth-identity-chaining.html
Other
4 stars 3 forks source link

Confirmation key transfer #106

Open PieterKas opened 2 weeks ago

PieterKas commented 2 weeks ago

If we choose to keep this section in this part off the spec, should we add more clarification on why the "requested_cnf" claim may have to be included in the assertion grant (e.g. make it clear the purpose of this claim is allow the Authorization Server in Domain B to bind the key to the requested_cnf claim)?