I support adoption.

HTTP Message Signatures are already being combined with OAuth-protected
requests, and a working-group-defined profile for key assignment and token
binding would be preferable to divergent implementation-specific approaches.

Adoption should not imply that every current design choice is settled. In
particular, I think the working group should clarify when this mechanism is
preferable to DPoP or mTLS, resolve whether the pub/htsk approach is
necessary versus alignment with JWK-based key representation, and define a
sufficiently constrained verification profile to avoid unnecessary
interoperability differences.

Regards,
Arjun Garg


On Mon, 21 Sep 2026 15:16:49 -0400, Rifaat Shekh-Yusef <
[email protected]> wrote:

All, This is an official call for adoption for the *OAuth Proof of
Possession Tokens with HTTP Message Signatures *draft:
https://www.ietf.org/archive/id/draft-richer-oauth-httpsig-03.html Please,
reply on the mailing list, on whether you support or oppose the adoption of
this draft as a WG document by *October 5th*. Regards, Rifaat & Hannes
_______________________________________________
OAuth mailing list -- [email protected]
To unsubscribe send an email to [email protected]

Reply via email to