oauth-wg / oauth-identity-chaining

Draft specification for Identity Chaining
https://drafts.oauth.net/oauth-identity-chaining/draft-ietf-oauth-identity-chaining.html
Other
4 stars 3 forks source link

Add sender constraining mechanisms #86

Open kburgin3 opened 8 months ago

kburgin3 commented 8 months ago

Add mTLS and DPoP

bc-pi commented 7 months ago

A rough sketch of things that likely need to be accounted for or a least considered in this effort:

The Authorization server acting as client flips around nearly all of the pieces above to make them unworkable. I guess it'd need separate treatment with the definition of something like a proxied "trust me" this is the cnf I need in the final access token. IIRC Kelley had some prior work toward this end somewhere but I can't seem to find it at the moment. Or maybe sender constraining is just out of scope in the AS as client proxy case.