I support adoption.

One item for after adoption. Section [security considerations] notes that a 
leaked private key allows the token to be re-presented, but says nothing about 
the key itself: where it is held or how long it lives. The same gap is in DPoP 
and 8705, so it's shared, not particular to this draft. Since the editor's note 
already asks for guidance on choosing between HTTPSig, DPoP and mTLS, it may 
help to say that the key's properties are independent of which mechanism is 
chosen. A non-exportable key, and one whose lifetime is bounded by conditions 
rather than a timer, serves all three equally.

Cheers

Thi Nguyen-Huu
CEO
[cid:[email protected]]
winmagic.com<https://winmagic.com/>
[cid:[email protected]]
11-80 Galaxy Blvd.  |  Toronto, ON  |  M9W 4Y8  |  Canada

From: Rifaat Shekh-Yusef <[email protected]>
Sent: Monday, September 21, 2026 3:17 PM
To: oauth <[email protected]>
Subject: [OAUTH-WG] Call for adoption - OAuth Proof of Possession Tokens with 
HTTP Message Signatures

CAUTION:This email originated from outside of the organization. Do not click 
links, open attachments or respond unless you recognize the sender and know 
that the content is safe.

All,

This is an official call for adoption for the OAuth Proof of Possession Tokens 
with HTTP Message Signatures draft:
https://www.ietf.org/archive/id/draft-richer-oauth-httpsig-03.html

Please, reply on the mailing list, on whether you support or oppose the 
adoption of this draft as a WG document by October 5th.

Regards,
 Rifaat & Hannes
_______________________________________________
OAuth mailing list -- [email protected]
To unsubscribe send an email to [email protected]

Reply via email to