If you want to introduce the notion of non-repudiation (meaning that the client cannot deny issuing an access request to the resource server), then you need to get the client to exercise its secret (eg. by using it in some crypto computation).
When a flow does not include the exercise/usage of the client secret, then you do not get non-repudiation. I think this aspects needs to be made clear in the spec. Which may bring-up the question as to some flows being safer than others. /thomas/ __________________________________________ > -----Original Message----- > From: [email protected] [mailto:[email protected]] On Behalf Of > Eran Hammer-Lahav > Sent: Thursday, June 10, 2010 3:43 PM > To: OAuth WG ([email protected]) > Subject: [OAUTH-WG] Client credentials w/ or w/o secret > > Some of the flows require/allow a client secret while others disallow it > (when the client has no secure means to keep it secret). My question is, do > you plan to issue different credentials for different flows (with or without > secret) or allow the same set to be used, sometimes with and sometimes > without a secret based on the flow? > > EHL > _______________________________________________ > OAuth mailing list > [email protected] > https://www.ietf.org/mailman/listinfo/oauth
smime.p7s
Description: S/MIME cryptographic signature
_______________________________________________ OAuth mailing list [email protected] https://www.ietf.org/mailman/listinfo/oauth
