https://tools.ietf.org/html/draft-ietf-oauth-security-topics-13 mentions or
suggests the use of token binding as an option in a few places. However,
the OAuth 2.0 Token Binding draft expired back in April and is looking
highly unlikely to progress or be updated further.  It's also pretty much
undeployable given the current lack of support in platforms, browsers and
TLS/HTTP libraries. Perhaps the Security Best Current Practice document
should remove reference to draft-ietf-oauth-token-binding or at least
de-emphasize it considerably?

That token binding isn't a viable option leaves only the soon-to-be RFC of
MTLS as the only real option in recommendation of
https://tools.ietf.org/html/draft-ietf-oauth-security-topics-13#section-3.2
which has:
   Authorization servers SHOULD use TLS-based methods for sender-
   constrained access tokens as described in Section 4.8.1.2, such as
   token binding [I-D.ietf-oauth-token-binding] or Mutual TLS for OAuth
   2.0 [I-D.ietf-oauth-mtls] in order to prevent token replay.

Maybe this already rather aspirational SHOULD should allow for non-TLS or
application-based methods as well, to at least allow room in the BCP for
the possibility of using some yet-to-be-determined PoP method that might
come along in the future?

-- 
_CONFIDENTIALITY NOTICE: This email may contain confidential and privileged 
material for the sole use of the intended recipient(s). Any review, use, 
distribution or disclosure by others is strictly prohibited.  If you have 
received this communication in error, please notify the sender immediately 
by e-mail and delete the message and any file attachments from your 
computer. Thank you._
_______________________________________________
OAuth mailing list
[email protected]
https://www.ietf.org/mailman/listinfo/oauth

Reply via email to