Let's suppose that an OAuth 2.0 client is registered for mutual_tls_sender_constrained_access_tokens=true
Is it correct that in the presence of this parameter, and regardless of how "token_endpoint_auth_method" is set, the AS must require a client X.509 cert to be passed to the token endpoint? If yes, then what error should the AS return if no client cert is passed with the token request? https://tools.ietf.org/html/rfc6749#section-5.2 Thanks, Vladimir PS: Noticed a typo - "manor" in #section-4.3
smime.p7s
Description: S/MIME Cryptographic Signature
_______________________________________________ OAuth mailing list [email protected] https://www.ietf.org/mailman/listinfo/oauth
