I'm opposed to adoption of this draft.

It is focussed on binding a key to an access token, which the WG has
already solved with DPoP (RFC 9449). It is not clear why a new mechanism is
needed. The editor's note in Section 1 says the draft still needs to give
guidance on when to use it instead of DPoP or mTLS.

Section 4 introduces a new representation for public keys, the pub
signature parameter carrying raw key bytes, instead of using JWK (RFC
7517). Because of that, Section 5 has to define a new htsk confirmation
method. A resource server also has to support two algorithm registries and
two code paths, depending on how the key was bound. The editor's note in
Section 3.2 acknowledges this.

It ignores the other HTTP message signature key exchange work, all of which
conveys keys as JWKs:

Web Bot Auth:
https://datatracker.ietf.org/doc/draft-ietf-webbotauth-httpsig-protocol/
Signature-Key:
https://datatracker.ietf.org/doc/draft-hardt-httpbis-signature-key/
WIMSE: https://datatracker.ietf.org/doc/draft-ietf-wimse-http-signature/






On Mon, Sep 21, 2026 at 8:17 PM Rifaat Shekh-Yusef <[email protected]>
wrote:

> All,
>
> This is an official call for adoption for the *OAuth Proof of Possession
> Tokens with HTTP Message Signatures *draft:
> https://www.ietf.org/archive/id/draft-richer-oauth-httpsig-03.html
>
> Please, reply on the mailing list, on whether you support or oppose the
> adoption of this draft as a WG document by *October 5th*.
>
> Regards,
>  Rifaat & Hannes
> _______________________________________________
> OAuth mailing list -- [email protected]
> To unsubscribe send an email to [email protected]
>
_______________________________________________
OAuth mailing list -- [email protected]
To unsubscribe send an email to [email protected]

Reply via email to