What are the learnings?

On Tue, Sep 22, 2026 at 4:46 PM Justin Richer <[email protected]> wrote:

> I think a lot has changed in six years, actually. RFC9449 (DPoP) is
> published and no longer an active WG item, and one of the arguments at the
> time was splitting the group’s attention. RFC9421 (HTTPSig) is also
> published and widely deployed, and several proposals have been made to
> extend DPoP into spaces that HTTPSig covers natively. We’ve got a few years
> of experience in both that can better inform the combination of HTTPSig and
> OAuth. We’ve also got people  making this combination on their own because
> it’s nearly obvious how to fit them together and sign an OAuth message. The
> real value of this doc is the key assignment, from which we take a lot of
> learnings from both DPoP and mTLS as well as WIMSE’s HTTPSig draft.
>
>  — Justin
>
> On Sep 22, 2026, at 8:07 AM, Warren Parad <wparad=
> [email protected]> wrote:
>
> I would appreciate knowing what exactly has changed since the last time
> this draft was brought to the WG and rejected.
>
> On Tue, Sep 22, 2026 at 1:56 PM Dick Hardt <[email protected]> wrote:
>
>> I'm opposed to adoption of this draft.
>>
>> It is focussed on binding a key to an access token, which the WG has
>> already solved with DPoP (RFC 9449). It is not clear why a new mechanism is
>> needed. The editor's note in Section 1 says the draft still needs to give
>> guidance on when to use it instead of DPoP or mTLS.
>>
>> Section 4 introduces a new representation for public keys, the pub
>> signature parameter carrying raw key bytes, instead of using JWK (RFC
>> 7517). Because of that, Section 5 has to define a new htsk confirmation
>> method. A resource server also has to support two algorithm registries and
>> two code paths, depending on how the key was bound. The editor's note in
>> Section 3.2 acknowledges this.
>>
>> It ignores the other HTTP message signature key exchange work, all of
>> which conveys keys as JWKs:
>>
>> Web Bot Auth:
>> https://datatracker.ietf.org/doc/draft-ietf-webbotauth-httpsig-protocol/
>> Signature-Key:
>> https://datatracker.ietf.org/doc/draft-hardt-httpbis-signature-key/
>> WIMSE: https://datatracker.ietf.org/doc/draft-ietf-wimse-http-signature/
>>
>>
>>
>>
>>
>>
>> On Mon, Sep 21, 2026 at 8:17 PM Rifaat Shekh-Yusef <
>> [email protected]> wrote:
>>
>>> All,
>>>
>>> This is an official call for adoption for the *OAuth Proof of
>>> Possession Tokens with HTTP Message Signatures *draft:
>>> https://www.ietf.org/archive/id/draft-richer-oauth-httpsig-03.html
>>>
>>> Please, reply on the mailing list, on whether you support or oppose the
>>> adoption of this draft as a WG document by *October 5th*.
>>>
>>> Regards,
>>>  Rifaat & Hannes
>>> _______________________________________________
>>> OAuth mailing list -- [email protected]
>>> To unsubscribe send an email to [email protected]
>>>
>> _______________________________________________
>> OAuth mailing list -- [email protected]
>> To unsubscribe send an email to [email protected]
>>
> _______________________________________________
> OAuth mailing list -- [email protected]
> To unsubscribe send an email to [email protected]
>
>
> _______________________________________________
> OAuth mailing list -- [email protected]
> To unsubscribe send an email to [email protected]
>
_______________________________________________
OAuth mailing list -- [email protected]
To unsubscribe send an email to [email protected]

Reply via email to