I would appreciate knowing what exactly has changed since the last time
this draft was brought to the WG and rejected.

On Tue, Sep 22, 2026 at 1:56 PM Dick Hardt <[email protected]> wrote:

> I'm opposed to adoption of this draft.
>
> It is focussed on binding a key to an access token, which the WG has
> already solved with DPoP (RFC 9449). It is not clear why a new mechanism is
> needed. The editor's note in Section 1 says the draft still needs to give
> guidance on when to use it instead of DPoP or mTLS.
>
> Section 4 introduces a new representation for public keys, the pub
> signature parameter carrying raw key bytes, instead of using JWK (RFC
> 7517). Because of that, Section 5 has to define a new htsk confirmation
> method. A resource server also has to support two algorithm registries and
> two code paths, depending on how the key was bound. The editor's note in
> Section 3.2 acknowledges this.
>
> It ignores the other HTTP message signature key exchange work, all of
> which conveys keys as JWKs:
>
> Web Bot Auth:
> https://datatracker.ietf.org/doc/draft-ietf-webbotauth-httpsig-protocol/
> Signature-Key:
> https://datatracker.ietf.org/doc/draft-hardt-httpbis-signature-key/
> WIMSE: https://datatracker.ietf.org/doc/draft-ietf-wimse-http-signature/
>
>
>
>
>
>
> On Mon, Sep 21, 2026 at 8:17 PM Rifaat Shekh-Yusef <
> [email protected]> wrote:
>
>> All,
>>
>> This is an official call for adoption for the *OAuth Proof of Possession
>> Tokens with HTTP Message Signatures *draft:
>> https://www.ietf.org/archive/id/draft-richer-oauth-httpsig-03.html
>>
>> Please, reply on the mailing list, on whether you support or oppose the
>> adoption of this draft as a WG document by *October 5th*.
>>
>> Regards,
>>  Rifaat & Hannes
>> _______________________________________________
>> OAuth mailing list -- [email protected]
>> To unsubscribe send an email to [email protected]
>>
> _______________________________________________
> OAuth mailing list -- [email protected]
> To unsubscribe send an email to [email protected]
>
_______________________________________________
OAuth mailing list -- [email protected]
To unsubscribe send an email to [email protected]

Reply via email to