Hi all, 

this is one of the topics we quickly flipped through in the virtual meeting 
last week. 

I see the following open questions:
- Can the client require its instances to use request objects only.
- Are there further requirements on the properties of these objects? Signed 
only, Signed and encrypted, algorithms? 
- Can an AS require ALL clients to use request objects only? 
- Further requirements here as well? 
- Is this tied to PAR or relevant for JAR as well? 

In my opinion, client as well as AS should be able to control enforced use of 
request objects. 

I could imagine the setting for JAR request objects (“request" parameter) and 
request objects in the PAR context differ, as the first case goes through the 
user’s browser whereas the PAR case goes direct from client to AS via a TLS 
protected channel. I therefore feel the settings should be PAR specific. 

What do you think?

best regards,
Torsten. 
_______________________________________________
OAuth mailing list
[email protected]
https://www.ietf.org/mailman/listinfo/oauth

Reply via email to