I would appreciate knowing what exactly has changed since the last time this draft was brought to the WG and rejected.
On Tue, Sep 22, 2026 at 1:56 PM Dick Hardt <[email protected]> wrote: > I'm opposed to adoption of this draft. > > It is focussed on binding a key to an access token, which the WG has > already solved with DPoP (RFC 9449). It is not clear why a new mechanism is > needed. The editor's note in Section 1 says the draft still needs to give > guidance on when to use it instead of DPoP or mTLS. > > Section 4 introduces a new representation for public keys, the pub > signature parameter carrying raw key bytes, instead of using JWK (RFC > 7517). Because of that, Section 5 has to define a new htsk confirmation > method. A resource server also has to support two algorithm registries and > two code paths, depending on how the key was bound. The editor's note in > Section 3.2 acknowledges this. > > It ignores the other HTTP message signature key exchange work, all of > which conveys keys as JWKs: > > Web Bot Auth: > https://datatracker.ietf.org/doc/draft-ietf-webbotauth-httpsig-protocol/ > Signature-Key: > https://datatracker.ietf.org/doc/draft-hardt-httpbis-signature-key/ > WIMSE: https://datatracker.ietf.org/doc/draft-ietf-wimse-http-signature/ > > > > > > > On Mon, Sep 21, 2026 at 8:17 PM Rifaat Shekh-Yusef < > [email protected]> wrote: > >> All, >> >> This is an official call for adoption for the *OAuth Proof of Possession >> Tokens with HTTP Message Signatures *draft: >> https://www.ietf.org/archive/id/draft-richer-oauth-httpsig-03.html >> >> Please, reply on the mailing list, on whether you support or oppose the >> adoption of this draft as a WG document by *October 5th*. >> >> Regards, >> Rifaat & Hannes >> _______________________________________________ >> OAuth mailing list -- [email protected] >> To unsubscribe send an email to [email protected] >> > _______________________________________________ > OAuth mailing list -- [email protected] > To unsubscribe send an email to [email protected] >
_______________________________________________ OAuth mailing list -- [email protected] To unsubscribe send an email to [email protected]
