Hi all,

I have published -01 of draft-ekahraman-oauth-attestation-authz-native-app and 
would appreciate a second round of review:

https://datatracker.ietf.org/doc/draft-ekahraman-oauth-attestation-authz-native-app/

The revision incorporates the feedback from the previous review discussion:

https://mailarchive.ietf.org/arch/msg/oauth/HJjD6JLkyXDQ77QonFglUn1cSWM/

The revision attempts to address the main points raised during that review. In 
particular:

* Holder-of-key binding: the Attestation Result now carries the Native 
Application public key, and the Authorization Server is required to verify that 
it matches the key demonstrated through the applicable proof-of-possession 
mechanism. DPoP is specified for public clients, while other deployments can 
define an equivalent PoP profile.

* Attestation Result freshness: explicit expiry and freshness validation have 
been added, including asymmetric clock-skew handling following the discussion 
on the list. 

* Snapshot semantics: the Security Considerations now explicitly state that an 
Attestation Result represents the device/application state at a point in time 
and does not guarantee that the attested state remains unchanged throughout the 
lifetime of an issued access token.

* Relationship to attestation-based client authentication: the Related Work 
section now distinguishes client authentication/instance assurance from the use 
of Attestation Results as input to authorization policy, and explains how the 
two mechanisms can be used together.

* Interoperability: a dedicated Interoperability Considerations section now 
identifies the deployment-specific elements, including Attestation Result 
format and claims and PoP profiles.

There have also been several related consistency and editorial changes around 
PAR-based Attestation Result precheck and DPoP for public clients.

I would particularly appreciate feedback on whether the previous review 
concerns are now adequately addressed, as well as any remaining issues with the 
protocol design, normative requirements, or interoperability model.

Thanks again for the earlier detailed review.

Best Regards

Efe

_______________________________________________
OAuth mailing list -- [email protected]
To unsubscribe send an email to [email protected]

Reply via email to