We've talked about issuing different client secrets for use with
different flows. We haven't actually implemented it yet and prefer
using something like TPM on devices which support it. A different
secret is at least better than nothing for apps which can't reliably
keep secrets and don't have something like a TPM.

--David


On Thu, Jun 10, 2010 at 12:42 PM, Eran Hammer-Lahav <[email protected]> wrote:
> Some of the flows require/allow a client secret while others disallow it 
> (when the client has no secure means to keep it secret). My question is, do 
> you plan to issue different credentials for different flows (with or without 
> secret) or allow the same set to be used, sometimes with and sometimes 
> without a secret based on the flow?
>
> EHL
> _______________________________________________
> OAuth mailing list
> [email protected]
> https://www.ietf.org/mailman/listinfo/oauth
>
_______________________________________________
OAuth mailing list
[email protected]
https://www.ietf.org/mailman/listinfo/oauth

Reply via email to