The IETF OAuth working group<https://datatracker.ietf.org/wg/oauth/about/> has 
adopted the JWK Thumbprint 
URI<https://www.ietf.org/archive/id/draft-ietf-oauth-jwk-thumbprint-uri-00.html>
 specification. The abstract of the specification is:

This specification registers a kind of URI that represents a JSON Web Key (JWK) 
Thumbprint value. JWK Thumbprints are defined in RFC 7638. This enables JWK 
Thumbprints to be used, for instance, as key identifiers in contexts requiring 
URIs.



The need for this arose during specification work in the OpenID Connect working 
group<https://openid.net/wg/connect/>. In particular, JWK Thumbprint URIs are 
used as key identifiers that can be syntactically distinguished from other 
kinds of identifiers also expressed as URIs in the Self-Issued OpenID Provider 
v2<https://openid.net/specs/openid-connect-self-issued-v2-1_0.html> 
specification.



Given that the specification does only one simple thing in a straightforward 
manner, we believe that it is ready for working group last call.



The specification is available at:
*    https://www.ietf.org/archive/id/draft-ietf-oauth-jwk-thumbprint-uri-00.html

                                                       -- Mike

P.S.  This note was also posted at https://self-issued.info/?p=2242 and as 
@selfissued<https://twitter.com/selfissued/>.

_______________________________________________
OAuth mailing list
[email protected]
https://www.ietf.org/mailman/listinfo/oauth

Reply via email to