After the meeting last Friday, a bunch of us joined up to work on the HTTP 
Message Signatures draft — huge thanks to Paul, Christian, and Filip for 
joining me and Aaron.

Name:     draft-richer-oauth-httpsig
Revision: 03
Title:    OAuth Proof of Possession Tokens with HTTP Message Signatures
Date:     2026-07-28
Group:    Individual Submission
Pages:    23
URL:      https://www.ietf.org/archive/id/draft-richer-oauth-httpsig-03.txt
Status:   https://datatracker.ietf.org/doc/draft-richer-oauth-httpsig/
HTML:     https://www.ietf.org/archive/id/draft-richer-oauth-httpsig-03.html
HTMLized: https://datatracker.ietf.org/doc/html/draft-richer-oauth-httpsig
Diff:     
https://author-tools.ietf.org/iddiff?url2=draft-richer-oauth-httpsig-03

This new version changes how we present inline public keys, and adds the first 
step of considerations for RS-side validation of bound tokens.

Please read through this when you can, and implement it if you can, and give us 
your comments on here or on GitHub. We've asked the chairs to schedule and 
interim to discuss this work and we'd like to bring this forward for adoption 
modulo the interim discussion.


  *
Justin


_______________________________________________
OAuth mailing list -- [email protected]
To unsubscribe send an email to [email protected]

Reply via email to