https://tools.ietf.org/html/draft-ietf-oauth-security-topics-13 mentions or suggests the use of token binding as an option in a few places. However, the OAuth 2.0 Token Binding draft expired back in April and is looking highly unlikely to progress or be updated further. It's also pretty much undeployable given the current lack of support in platforms, browsers and TLS/HTTP libraries. Perhaps the Security Best Current Practice document should remove reference to draft-ietf-oauth-token-binding or at least de-emphasize it considerably?
That token binding isn't a viable option leaves only the soon-to-be RFC of MTLS as the only real option in recommendation of https://tools.ietf.org/html/draft-ietf-oauth-security-topics-13#section-3.2 which has: Authorization servers SHOULD use TLS-based methods for sender- constrained access tokens as described in Section 4.8.1.2, such as token binding [I-D.ietf-oauth-token-binding] or Mutual TLS for OAuth 2.0 [I-D.ietf-oauth-mtls] in order to prevent token replay. Maybe this already rather aspirational SHOULD should allow for non-TLS or application-based methods as well, to at least allow room in the BCP for the possibility of using some yet-to-be-determined PoP method that might come along in the future? -- _CONFIDENTIALITY NOTICE: This email may contain confidential and privileged material for the sole use of the intended recipient(s). Any review, use, distribution or disclosure by others is strictly prohibited. If you have received this communication in error, please notify the sender immediately by e-mail and delete the message and any file attachments from your computer. Thank you._
_______________________________________________ OAuth mailing list [email protected] https://www.ietf.org/mailman/listinfo/oauth
