Let's suppose that an OAuth 2.0 client is registered for

mutual_tls_sender_constrained_access_tokens=true

Is it correct that in the presence of this parameter, and regardless of
how "token_endpoint_auth_method" is set, the AS must require a client
X.509 cert to be passed to the token endpoint? If yes, then what error
should the AS return if no client cert is passed with the token request?

https://tools.ietf.org/html/rfc6749#section-5.2

Thanks,

Vladimir

PS: Noticed a typo - "manor" in #section-4.3

Attachment: smime.p7s
Description: S/MIME Cryptographic Signature

_______________________________________________
OAuth mailing list
[email protected]
https://www.ietf.org/mailman/listinfo/oauth

Reply via email to