I support adoption. One item for after adoption. Section [security considerations] notes that a leaked private key allows the token to be re-presented, but says nothing about the key itself: where it is held or how long it lives. The same gap is in DPoP and 8705, so it's shared, not particular to this draft. Since the editor's note already asks for guidance on choosing between HTTPSig, DPoP and mTLS, it may help to say that the key's properties are independent of which mechanism is chosen. A non-exportable key, and one whose lifetime is bounded by conditions rather than a timer, serves all three equally.
Cheers Thi Nguyen-Huu CEO [cid:[email protected]] winmagic.com<https://winmagic.com/> [cid:[email protected]] 11-80 Galaxy Blvd. | Toronto, ON | M9W 4Y8 | Canada From: Rifaat Shekh-Yusef <[email protected]> Sent: Monday, September 21, 2026 3:17 PM To: oauth <[email protected]> Subject: [OAUTH-WG] Call for adoption - OAuth Proof of Possession Tokens with HTTP Message Signatures CAUTION:This email originated from outside of the organization. Do not click links, open attachments or respond unless you recognize the sender and know that the content is safe. All, This is an official call for adoption for the OAuth Proof of Possession Tokens with HTTP Message Signatures draft: https://www.ietf.org/archive/id/draft-richer-oauth-httpsig-03.html Please, reply on the mailing list, on whether you support or oppose the adoption of this draft as a WG document by October 5th. Regards, Rifaat & Hannes
_______________________________________________ OAuth mailing list -- [email protected] To unsubscribe send an email to [email protected]
