If you want to introduce the notion
of non-repudiation (meaning that the client
cannot deny issuing an access request to the resource
server), then you need to get the client
to exercise its secret (eg. by using it
in some crypto computation).

When a flow does not include the exercise/usage
of the client secret, then you do not get non-repudiation.
I think this aspects needs to be made clear
in the spec. Which may bring-up the question
as to some flows being safer than others.

/thomas/
__________________________________________


> -----Original Message-----
> From: [email protected] [mailto:[email protected]] On Behalf Of
> Eran Hammer-Lahav
> Sent: Thursday, June 10, 2010 3:43 PM
> To: OAuth WG ([email protected])
> Subject: [OAUTH-WG] Client credentials w/ or w/o secret
> 
> Some of the flows require/allow a client secret while others disallow it
> (when the client has no secure means to keep it secret). My question is,
do
> you plan to issue different credentials for different flows (with or
without
> secret) or allow the same set to be used, sometimes with and sometimes
> without a secret based on the flow?
> 
> EHL
> _______________________________________________
> OAuth mailing list
> [email protected]
> https://www.ietf.org/mailman/listinfo/oauth

Attachment: smime.p7s
Description: S/MIME cryptographic signature

_______________________________________________
OAuth mailing list
[email protected]
https://www.ietf.org/mailman/listinfo/oauth

Reply via email to