What are the learnings? On Tue, Sep 22, 2026 at 4:46 PM Justin Richer <[email protected]> wrote:
> I think a lot has changed in six years, actually. RFC9449 (DPoP) is > published and no longer an active WG item, and one of the arguments at the > time was splitting the group’s attention. RFC9421 (HTTPSig) is also > published and widely deployed, and several proposals have been made to > extend DPoP into spaces that HTTPSig covers natively. We’ve got a few years > of experience in both that can better inform the combination of HTTPSig and > OAuth. We’ve also got people making this combination on their own because > it’s nearly obvious how to fit them together and sign an OAuth message. The > real value of this doc is the key assignment, from which we take a lot of > learnings from both DPoP and mTLS as well as WIMSE’s HTTPSig draft. > > — Justin > > On Sep 22, 2026, at 8:07 AM, Warren Parad <wparad= > [email protected]> wrote: > > I would appreciate knowing what exactly has changed since the last time > this draft was brought to the WG and rejected. > > On Tue, Sep 22, 2026 at 1:56 PM Dick Hardt <[email protected]> wrote: > >> I'm opposed to adoption of this draft. >> >> It is focussed on binding a key to an access token, which the WG has >> already solved with DPoP (RFC 9449). It is not clear why a new mechanism is >> needed. The editor's note in Section 1 says the draft still needs to give >> guidance on when to use it instead of DPoP or mTLS. >> >> Section 4 introduces a new representation for public keys, the pub >> signature parameter carrying raw key bytes, instead of using JWK (RFC >> 7517). Because of that, Section 5 has to define a new htsk confirmation >> method. A resource server also has to support two algorithm registries and >> two code paths, depending on how the key was bound. The editor's note in >> Section 3.2 acknowledges this. >> >> It ignores the other HTTP message signature key exchange work, all of >> which conveys keys as JWKs: >> >> Web Bot Auth: >> https://datatracker.ietf.org/doc/draft-ietf-webbotauth-httpsig-protocol/ >> Signature-Key: >> https://datatracker.ietf.org/doc/draft-hardt-httpbis-signature-key/ >> WIMSE: https://datatracker.ietf.org/doc/draft-ietf-wimse-http-signature/ >> >> >> >> >> >> >> On Mon, Sep 21, 2026 at 8:17 PM Rifaat Shekh-Yusef < >> [email protected]> wrote: >> >>> All, >>> >>> This is an official call for adoption for the *OAuth Proof of >>> Possession Tokens with HTTP Message Signatures *draft: >>> https://www.ietf.org/archive/id/draft-richer-oauth-httpsig-03.html >>> >>> Please, reply on the mailing list, on whether you support or oppose the >>> adoption of this draft as a WG document by *October 5th*. >>> >>> Regards, >>> Rifaat & Hannes >>> _______________________________________________ >>> OAuth mailing list -- [email protected] >>> To unsubscribe send an email to [email protected] >>> >> _______________________________________________ >> OAuth mailing list -- [email protected] >> To unsubscribe send an email to [email protected] >> > _______________________________________________ > OAuth mailing list -- [email protected] > To unsubscribe send an email to [email protected] > > > _______________________________________________ > OAuth mailing list -- [email protected] > To unsubscribe send an email to [email protected] >
_______________________________________________ OAuth mailing list -- [email protected] To unsubscribe send an email to [email protected]
