The description of OAuth Mutual TLS in
https://tools.ietf.org/html/draft-ietf-oauth-security-topics-13#section-4.8..1.2
says the "client is identified towards the resource server by the
fingerprint of its public key" but it's actually a fingerprint/hash of the
certificate not the public key. See
https://tools.ietf.org/html/draft-ietf-oauth-mtls-17#section-3.1 for
example.

-- 
_CONFIDENTIALITY NOTICE: This email may contain confidential and privileged 
material for the sole use of the intended recipient(s). Any review, use, 
distribution or disclosure by others is strictly prohibited.  If you have 
received this communication in error, please notify the sender immediately 
by e-mail and delete the message and any file attachments from your 
computer. Thank you._
_______________________________________________
OAuth mailing list
[email protected]
https://www.ietf.org/mailman/listinfo/oauth

Reply via email to